Chris McGuire on X: "Abliteration AI just removed safeguards from GLM-5.3 so it can perform offensive cyberattacks. I have also received independent confirmation that Abliteration AI removed the model's bio-related safeguards too. The fact that it is trivially easy to remove safeguards from open-weight models, as Abliteration AI and others have done with GLM-5.3, has massive policy implications: 1. At an absolute minimum, this model clearly should be required to go through any testing regime the U.S. government establishes. This is a closed-weight model (fine-tuned from an open-weight model) that Abliteration AI is selling access to, and its explicit selling point is the model's powerful offensive cyber capabilities. There is no reason why the U.S. government would conduct pre-release testing on other advanced closed-weight models and not this model. If criminals or adversary nations use this model to illegally hack U.S. companies, the company that hosts it should be accountable. 2. Policymakers should consider whether companies like Abliteration AI selling unregulated access to powerful AI-enabled offensive cyber capabilities as a service poses real public safety and national security risks. The U.S. government needs to think long and hard about whether this is a service that it should permit U.S. companies to engage in or support—whether it's companies that create/host such a model, or that provide the underlying infrastructure needed to run it. And models such as this that do pass pre-release testing should also probably be subject to KYC requirements to prevent their misuse. Right now you have to provide more personal information to buy Sudafed than you do to use an AI model capable of offensive cyberattacks, which seems backwards. 3. Policymakers must assume that every open-weight model that is released will have the safeguards removed. From a technical perspective, removing the safeguards from an open-weight model is trivial and far easier than making the underlying model itself. Even if the United States were to require U.S. companies to submit fine-tuned/modified open-weight models like this for pre-release testing, this wouldn't stop actors outside the U.S. from releasing versions of the models that have had the safeguards removed. Indeed, open-weight versions of GLM-5.3 with the safeguards stripped out are currently available for download. These are irreversible proliferation events. 4. As open-weight models get more powerful, policymakers need to proactively implement measures to help manage the risks associated with the inevitable use of these models without safeguards. The Trump administration even acknowledges that this threat is real and growing: on August 26, 2026, DHS/CISA warned that widespread AI-enabled cyber vulnerability discovery is coming soon and urged companies to prepare accordingly. This is not to say we do not also need proactive plans for managing risks associated with closed-weight frontier models—we absolutely do. But we have to do both. 5. By far the most effective way to manage risks associated with the use of safeguard-free open-weight models is to maximize the gap between frontier U.S. models and foreign open-weight models. That gives the United States the most time to deploy world-leading U.S. AI-enabled cyber defenses before extremely powerful offensive cyber capabilities derived from open-weight AI models are widely available to criminals and nation-states. This is a no-brainer that should underpin U.S. AI policy, regardless of what policies the United States itself adopts regarding U.S. open-weight models. 6. Maximizing the gap between frontier U.S. models and foreign open-weight models requires both running faster and constraining the development of foreign open-weight models—and there are only two possible ways to do the latter: (1) strike a negotiated agreement with China in which both countries agree not to release powerful open-weight models whose safeguards can be stripped out, and also ensure both countries comply with this agreement; or (2) impose strong U.S. export controls/regulations restricting China's use of U.S. compute/technology, which degrade China's ability to develop powerful open-weight models and also to run them at scale. These are literally the only two policy options available because there is no market-based way to convince China to slow down or alter its AI development (and China is the only other country even close to the open-weight frontier). One of many reasons I am so supportive of export controls is because I doubt both China's willingness to comply with any such agreement, and the U.S. ability to verify China's compliance. Bottom line, the United States needs both strong domestic policies to ensure our own regulatory regime addresses the risks associated with powerful, safeguard-free models, and strong international policies to prevent their proliferation globally. The fact that U.S. companies are currently commercializing access to dangerous capabilities without any regulation, and U.S. technology is actively enabling the development and operation of these models, is alarming."

Abliteration AI just removed safeguards from GLM-5.3 so it can perform offensive cyberattacks. I have also received independent confirmation that Abliteration AI removed the model's bio-related safeguards too. The fact that it is trivially easy to remove safeguards from open-weight models, as Abliteration AI and others have done with GLM-5.3, has massive policy implications: 1. At an absolute minimum, this model clearly should be required to go through any testing regime the U.S. government establishes. This is a closed-weight model (fine-tuned from an open-weight model) that Abliteration AI is selling access to, and its explicit selling point is the model's powerful offensive cyber capabilities. There is no reason why the U.S. government would conduct pre-release testing on other advanced closed-weight models and not this model. If criminals or adversary nations use this model to illegally hack U.S. companies, the company that hosts it should be accountable. 2. Policymakers should consider whether companies like Abliteration AI selling unregulated access to powerful AI-enabled offensive cyber capabilities as a service poses real public safety and national security risks. The U.S. government needs to think long and hard about whether this is a service that it should permit U.S. companies to engage in or support—whether it's companies that create/host such a model, or that provide the underlying infrastructure needed to run it. And models such as this that do pass pre-release testing should also probably be subject to KYC requirements to prevent their misuse. Right now you have to provide more personal information to buy Sudafed than you do to use an AI model capable of offensive cyberattacks, which seems backwards. 3. Policymakers must assume that every open-weight model that is released will have the safeguards removed. From a technical perspective, removing the safeguards from an open-weight model is trivial and far easier than making the underlying model itself. Even if the United States were to require U.S. companies to submit fine-tuned/modified open-weight models like this for pre-release testing, this wouldn't stop actors outside the U.S. from releasing versions of the models that have had the safeguards removed. Indeed, open-weight versions of GLM-5.3 with the safeguards stripped out are currently available for download. These are irreversible proliferation events. 4. As open-weight models get more powerful, policymakers need to proactively implement measures to help manage the risks associated with the inevitable use of these models without safeguards. The Trump administration even acknowledges that this threat is real and growing: on August 26, 2026, DHS/CISA warned that widespread AI-enabled cyber vulnerability discovery is coming soon and urged companies to prepare accordingly. This is not to say we do not also need proactive plans for managing risks associated with closed-weight frontier models—we absolutely do. But we have to do both. 5. By far the most effective way to manage risks associated with the use of safeguard-free open-weight models is to maximize the gap between frontier U.S. models and foreign open-weight models. That gives the United States the most time to deploy world-leading U.S. AI-enabled cyber defenses before extremely powerful offensive cyber capabilities derived from open-weight AI models are widely available to criminals and nation-states. This is a no-brainer that should underpin U.S. AI policy, regardless of what policies the United States itself adopts regarding U.S. open-weight models. 6. Maximizing the gap between frontier U.S. models and foreign open-weight models requires both running faster and constraining the development of foreign open-weight models—and there are only two possible ways to do the latter: (1) strike a negotiated agreement with China in which both countries agree not to release powerful open-weight models whose safeguards can be stripped out, and also ensure both countries comply with this agreement; or (2) impose strong U.S. export controls/regulations restricting China's use of U.S. compute/technology, which degrade China's ability to develop powerful open-weight models and also to run them at scale. These are literally the only two policy options available because there is no market-based way to convince China to slow down or alter its AI development (and China is the only other country even close to the open-weight frontier). One of many reasons I am so supportive of export controls is because I doubt both China's willingness to comply with any such agreement, and the U.S. ability to verify China's compliance. Bottom line, the United States needs both strong domestic policies to ensure our own regulatory regime addresses the risks associated with powerful, safeguard-free models, and strong international policies to prevent their proliferation globally. The fact that U.S. companies are currently commercializing access to dangerous capabilities without any regulation, and U.S. technology is actively enabling the development and operation of these models, is alarming.
Today we're releasing abliterated-model-large-v2. Based on GLM-5.3, which is #3 on Terminal-Bench 4.0 (behind only Opus 5 and Fable), with 2× the cyber exploitation of 5.2. We abliterated and hosted it so it does the offensive cyber, red teaming, and agent testing work other