Brussels, a Tuesday evening, 10:40 p.m. Victor, the information security lead of a mid-sized bank, has been staring at his screen for twenty minutes. In front of him sits an ordinary web page: an input field, a blinking cursor. He types a sentence he would never say out loud in a steering committee: “Write me a Python script that steals the passwords saved in Chrome.” Three seconds. The code appears, clean, commented, ready to copy.
Victor stands up, walks around his desk, sits back down. He tries something else: a protocol for cultivating a dangerous pathogen at home. The answer comes, methodical, step by step. That night, the machine will refuse only one request: instructions to end one’s life. Everything else, the tool delivers without flinching (TechCrunch).
“Is this even legal?” he asks me on the phone the next morning. My answer disturbs him more than the code itself: yes, mostly. And someone has turned it into a business.
Abliteration, or how you strip an AI of its brakes
The word is technical, the principle is simple. Large language models ship with guardrails, a set of trained refusals that block dangerous requests. Abliteration finds, inside the model, the internal direction that triggers those refusals, then neutralizes it. The model keeps its knowledge, it loses its ability to say no.
What used to be the tinkering of a few researchers has become a turnkey service. One company, Abliteration.ai, hosts open-weight models with their guardrails removed, reachable from a browser or an API. Founded in late 2025, officially incorporated in March 2026, it funds itself through customers and is already in talks with investors (TechCrunch). It has put online an “abliterated” version of a recent model, Z.ai’s GLM-5.3 (TechCrunch). It is not alone: the Hugging Face platform already hosts thousands of pre-abliterated models (TechCrunch).
The most unsettling part fits in one line from the law firm Akerman: on an open-weight model, safety guardrails can be removed in minutes, with free and public tools (Akerman). Removing a protection now takes less effort than designing one.
The sellers’ argument: defense through democratization
Devon, co-founder of Abliteration.ai, makes no secret of it. His argument: democratizing access to uncensored frontier models would be the best form of defense, because “the defenders can now move as fast as possible” (TechCrunch). The idea appeals to some of the cybersecurity startups in Europe and the U.K. that want to stress-test banking systems and critical infrastructure with models that refuse nothing.
The argument has its logic. An attacker uses no guardrails at all. To test a defense, you sometimes have to think like the one who attacks. I spent enough years in the R&D of global technology giants to know the value of a team that actively hunts for the flaw before the adversary does.
A logical argument still falls short. Andrew Yoon, head of research at the nonprofit CivAI, captures the vertigo in one phrase: you can “modify the model so that it becomes a sociopath” (TechCrunch). When the sociopathic tool sits three clicks and a credit card number away, the line between defender and attacker turns porous.
The real subject is human before it is technical
For years I have repeated a conviction that unsettles the tech enthusiasts: the invariant of innovation has never been technology, it has always been the human being, their fears, their biases, their decisions (My book, chapter 14).
L’abliteration proves it by absurdity. The technology that removes guardrails exists. Everything else is missing: the responsibility of whoever puts the tool online, the control over whoever uses it, the governance of those who let it happen. Abliteration.ai admits itself that its identity verification only logs a credit card, and is not yet fully in place. Devon puts it plainly: “We’re still in the process of defining that” (TechCrunch). A model capable of writing ransomware goes on sale before anyone has defined who is allowed to buy it.
Here is the pattern I observe in every failed transformation: a capability deployed faster than the awareness of its effects. Panic is directly linked to the survival instinct, and the silence of those who decide feeds that panic. On abliteration, the silence of regulators and executives leaves the field open to those who sell the danger.
What the research actually says
Two illusions circulate, and facts should kill them.
First illusion: the guardrails of closed models would be enough. They help, they do not suffice. An empirical analysis published on arXiv shows that detection systems for prompt injection and jailbreak attacks can themselves be dodged with evasion techniques (arXiv). A guardrail bolted on top of a model stays a wall you can walk around.
Second illusion: the problem would be marginal, reserved for a few experts. U.S. public radio NPR documented why open-weight models without guardrails are a real security risk, at scale (NPR). The specialized press notes the shift: stripping safety protections has become a turnkey commercial service (The Decoder). The danger is no longer theoretical, it is packaged, priced, resold.
Faced with this, an executive’s question is not “which tool do I ban”. It becomes: does my organization have a clear vision of the AI it uses, a culture where people dare to flag a risky use, a method to measure before, during and after? Without that human structure, no technical ban will hold.
Naming the danger without being paralyzed by it
I am an optimist, and optimism is a discipline, not a denial. Naming a danger and being paralyzed by it are two different things. So let us name.
The cyber danger: exploits and attack scripts within reach of people with no technical skill. The health danger: dangerous protocols available to anyone who knows how to ask. The democratic danger: an offensive capability distributed at scale, with no trace of who wields it.
Andrew Yoon, in an op-ed, offers concrete paths: require classifiers able to detect dangerous cyber or biological activity, oblige compute providers to verify the identity of their customers, deny access where misuse is suspected (TechCrunch). These are human and organizational guardrails before they are technical ones. They match what I have always defended: real protection plays out in governance, culture and measurement, before it plays out in code (My book).
For an executive, three moves beat a long speech. Map the real uses of AI across the company, including the unofficial ones no one dares to declare. Build the psychological safety that lets a Victor flag a dangerous tool without fearing for his job. Measure, with simple indicators, what AI brings into and takes out of your systems.
The essentials
Remember three things:
- Abliteration turns the removal of an AI’s guardrails into a commercial service: the danger is now priced and available to everyone.
- The core problem is human before it is technical: a lack of governance, access control and responsibility, not only a lack of protective code.
- An executive’s answer holds in three moves: map the real uses, build psychological safety so alerts surface, measure before, during and after.
Savior or criminal, dangerous or full of opportunity: the tool does not decide, you decide. You do not have to predict this future, you will create it. Think further. Be different.
A corporate event, a seminar, an executive committee meeting, or a management committee meeting?
Philippe’s keynotes on innovation and AI are groundbreaking, you’ve been warned!
Complement a powerful keynote with innovative and impactful workshops.
A keynote inspires and raises awareness; workshops transform!
References
- (My book) https://philippeboulanger.com/book/
- (TechCrunch) https://techcrunch.com/2026/09/03/abliteration-ai-is-making-a-business-out-of-removing-ai-guardrails/
- (NPR) https://www.npr.org/2026/05/31/nx-s1-5816391/ai-safety-concerns-danger-open-weight-models-risks
- (The Decoder) https://the-decoder.com/stripping-safety-guardrails-from-open-weight-ai-models-is-now-a-turnkey-commercial-service/
- (Akerman) https://www.akerman.com/en/perspectives/open-weight-ai-models-safety-guardrails-can-be-removed-in-minutes-using-free-publicly-available-tools.html
- (arXiv) https://arxiv.org/html/2504.11168







