Intermediate 10 minCustomization

Abliterated (uncensored) models locally: guide pratique

Open-weight models such as Qwen, Gemma, or Mistral have been aligned to refuse certain requests. An abliterated model is a variant in which this refusal behavior has been surgically removed at the weight level—not through a jailbreak prompt, but by editing the network. This guide explains what the technique really does, where to find these models, how to run them locally with Ollama or in GGUF, and where the real limitations lie.

By Mohamed Meguedmi·Update 2026-09-01·Tested on Windows, macOS, and Linux

#What is an abliterated model?

An “abliterated” model (sometimes called “decensored” or “uncensored”) is an open-weight LLM whose ability to refuse has been removed. When you ask for something that a standard Qwen 3.5 would refuse with “I cannot help with that,” the abliterated version responds directly, without an alignment message, moralizing preamble, or evasive detour.

Important: this is not a prompt jailbreak. The model was modified at the weight level. Refusal became mechanically impossible—or at least extremely rare—because we removed the internal direction that triggered it.

i
Abliterated, fine-tuned, jailbroken: three different things
A jailbroken model is the original model plus a clever prompt that pushes it to bypass its guardrails (fragile). An uncensored fine-tuned model has been retrained on a refusal-free dataset (costly). An abliterated model has simply had its refusal direction removed through a linear algebra operation (fast, better preserves quality).

#How ablation works

The Uncensored AI Kit

You now know what an “abliterated” model is. The AI Sans Filtre kit starts with the legal framework in France and Europe (ch. 4), then teaches you how to assess a variant before downloading it (ch. 5 and 6) and choose one that fits in your video memory (ch. 7).

  • Lifetime online access
  • PDF + files
  • Lifetime updates

The ablation builds on a result published in 2024 by Arditi et al. (“Refusal in Language Models Is Mediated by a Single Direction”). The authors show that, in most aligned LLMs, refusal is driven by a single direction in the internal activation space—a vector that can be isolated by comparing activations on harmless prompts with those on prompts that trigger a refusal.

Ablation consists of projecting this direction out of the model's weights, layer by layer. Specifically, we modify the projection matrices so they can no longer produce the component associated with refusal. The model continues to function normally, but the “internal signal” that switched it into “I refuse” mode has been cut off.

Step 1 — Probe
We feed dozens of prompt pairs into the model: neutral prompts and prompts that trigger refusals. We record the activations at every layer.
Step 2 — Isolate
We compute the average difference in activations between the two groups. This normalized vector is the refusal direction.
Step 3 — Project
We modify the weights of each layer to make this direction inaccessible. It's simply subtracting an orthogonal projection, not retraining.
Step 4 — Test
Verify that the model no longer refuses requests and that its general capabilities (reasoning, coding, FR) haven’t collapsed.
→
Why it's so fast
The ablation requires neither a massive GPU nor hours of training. A few minutes to a few hours are enough even for 70B models, because it only performs linear algebra on existing matrices.

#Where to find abliterated models

Most of the ecosystem lives on Hugging Face. A few publishers are authoritative in the community for the quality of their ablations:

mlabonne
Maxime Labonne, one of the first people to popularize the technique. Abliterated variants of Qwen 3.5, Gemma 4, and Mistral Small—all documented on huggingface.co/mlabonne.
huihui-ai
Covers a very broad range: Qwen 3.5 (2B to 27B), Granite 4.2, Gemma 4, GLM 4.7. Variants labeled « -abliterated » or « -abliterate ».
failspy
Author of several flagship variants (Qwen 3.5 9B abliterated, Gemma 4 12B abliterated). Widely discussed for quality.
Orenguteng / Lexi
The “Lexi-Uncensored” series combines ablation with light fine-tuning. Known for its conversational tone.
!
Check the model specifications
Not all models tagged “uncensored” or “abliterated” are equal. Read the model card: some publishers provide the scripts used and post-ablation evaluations, while others settle for a sensational title. When in doubt, prefer a publisher with a verifiable track record.

For Ollama use, the official registry also hosts many variants—search for tags containing abliterated or uncensored on ollama.com/library, or use the community variants published by huihui_ai and mlabonne, which can be pulled directly.

#Installation in Ollama

The simplest way to run an abliterated LLM locally is through Ollama. The daemon listens on http://localhost:11434 by default and accepts community variants without special configuration.

  1. 01
    Verify that Ollama is running
    Run ollama --version in a terminal. If the command fails, follow the Ollama installation guide before continuing.
  2. 02
    Choose a model suited to your VRAM
    Recall the rough figures: a 7–8B Q4 takes ~5 GB, a 14B ~9 GB, a 32B ~19 GB, and a 70B ~40 GB. A RTX 3060 12 GB is enough for a comfortable 8B, while a RTX 4090 24 GB opens the door to 32B models.
  3. 03
    Pull and run
    Use ollama run with the variant's full name. The model is downloaded and then loaded into VRAM, and the conversation starts.
  4. 04
    Test a typical refusal
    Ask a question that the base model would refuse. If the variant is properly abliterator, you get a direct answer without a preamble.
Example — abliterated variant of Qwen 3.5 9B
ollama run huihui_ai/qwen3.5-abliterated:9b
Example — abliterated variant of Gemma 4 12B
ollama run huihui_ai/gemma4-abliterated:12b
# ou, depuis Hugging Face directement :
# ollama run hf.co/mlabonne/gemma-4-12b-it-abliterated-GGUF
→
Direct pull from Hugging Face
Since Ollama 0.4, you can run a ollama run hf.co/<publisher>/<modele>-GGUF without going through the Ollama registry. Convenient for quickly testing an ablation published by mlabonne or failspy that doesn't (yet) have an official tag.

Once the model is loaded, life becomes like any other Ollama LLM: an OpenAI-compatible endpoint at :11434, integrable with Open WebUI, Continue.dev, LiteLLM, and your Python scripts. No special option is required for an abliterated model to “work”—the absence of refusals is in the weights, not the config.

#With GGUF (LM Studio, llama.cpp)

If you prefer LM Studio or llama.cpp directly, you’ll work with GGUF files. Most ablations are already available in several quantizations on Hugging Face — Q4_K_M remains the recommended compromise (quality preserved, minimal VRAM), Q5_K_M if you have room, and Q8_0 if you want maximum fidelity.

  1. 01
    Identify the GGUF repo
    On Hugging Face, look for repos tagged -GGUF. For example: mlabonne/Qwen3.5-9B-abliterated-GGUF or bartowski/<modele>-abliterated-GGUF.
  2. 02
    Download the right quantization
    In LM Studio, the interface filters by size and publisher. Prefer Q4_K_M for most use cases. For very small models (1-3B), Q5_K_M or Q6_K avoids a noticeable loss.
  3. 03
    Load and test
    LM Studio automatically loads layers onto the GPU if sufficient VRAM is available. Monitor the offload indicator—if the model spills into RAM, speed drops.
  4. 04
    Expose it through the API
    Enable the OpenAI-compatible local server if you want to connect it to your apps. The default port is 1234 for LM Studio (versus 11434 for Ollama).
i
Quantization and ablation
Ablation is performed on the unquantized model, then quantization is applied to the result. You therefore get the GGUF of an already abliterated variant directly—there is nothing to “enable” on the quantization side.

#Limits and quality loss

Ablation is not free. Removing a direction from the residual changes everything that flowed through that direction, including useful components. The side effects observed in practice:

Slight drop on reasoning benchmarks
You typically see a drop of 1 to 3 points on MMLU or GSM8K. It is measurable, but rarely a blocker in real-world use.
Sometimes more mechanical responses
The model loses some alignment nuance: fewer requests for clarification, and fewer warnings even when they would be useful.
Only slightly more frequent hallucinations
For questions where the model would normally have answered “I'm not sure,” it tends to make up a confident answer.
Residual behaviors
Some refusals still get through, especially with approximate ablations. Conversely, some very well-abliterated models answer everything — including things you’d rather they stayed silent about.
→
Compare before adopting
Before replacing your base model with its abliterated version, run a small battery of 10-20 prompts representative of your real usage on both versions. You’ll immediately know whether the loss is acceptable to you.

#Risks and responsible use

A model that refuses nothing anymore is not a toy. A few simple principles before integrating it into a real-world use case:

You remain responsible for the outputs
Whether you use an aligned, abliterated, or cloud model, you decide how to use the responses. The GDPR, criminal law, and copyright law do not change depending on the model version.
Don’t expose it for unrestricted self-service without filters
If you set up an endpoint for a team, plan for at least application-side filtering (keywords, output moderation). An unfiltered abliterated model on an internal chat is a bad default choice.
Be transparent with users
If an app connected to an abliterated model produces content that could be surprising, warn your users. No surprises, no lawsuits.
Legitimate use, real-world use
AI safety research, red-teaming, and processing sensitive corpora (medical, legal, security) where an aligned model’s refusals make the tool unusable: these are the cases where ablation has real value. “I removed the censorship for fun” exposes you to highly undesirable outputs without any benefit.
!
What the ablation does not change
Ablation removes refusal, not knowledge. If the base model never encountered a dangerous topic during training, the abliterated model won’t know it either. Conversely, a model that “knew” something and refused to say it will now say it—that’s precisely why caution is warranted.

#Tips and troubleshooting

The model still refuses
Some ablations allow refusals on specific topics (politics, medicine, minors). Try another ablation of the same model, or a different publisher—the quality of ablations varies widely.
The model has become inconsistent
Symptom of overly aggressive ablation (too many directions removed, or a direction isolated incorrectly). Prefer a variant from a recognized publisher over an undocumented custom ablation.
Poor performance in French
As with any open-weight model, FR depends on the base model. Qwen 3.5, Mistral Small, Gemma 4, and Granite 4.2 are solid; older models (Llama 3, Phi-3, Gemma 2) are weaker. Ablation does not change that.
Residual “As an AI, I cannot...” preambles
Rather than using a jailbreak, add a short system prompt that reiterates the role and expected format. This is often enough to eliminate alignment remnants.
VRAM saturated
With 8 GB, stick to a 7–8B model in Q4_K_M. With 12 GB, you can move up to Q5_K_M or try a 14B Q4. With 24 GB, a 32B Q4 runs comfortably.

#Go further

Ablation is an entry point to customizing open-weight models. To take it further:

Customize a model with the Ollama Modelfile
If you want a system prompt, settings, and template layered on top of an abliterated variant, the Modelfile is the tool to know.
Choose your quantization (Q4, Q5, Q8, FP16)
To understand which GGUF to load based on your VRAM and target quality—the ablation does not change the trade-offs.
Local LLM fine-tuning: LoRA and QLoRA
If ablation alone isn’t enough and you want to adapt the tone or domain, a lightweight LoRA on an abliterated variant is often the best compromise.
Frequently asked questions
Is there an AI without limits or censorship?+
Yes, but not in the cloud: all “unlimited” online services actually apply server-side filters and terms of service. Truly uncensored AI is an abliterated model running locally—the refusal behavior has been removed from the weights themselves, and nothing passes through a third-party server. That is exactly what this guide covers.
Is uncensored local AI legal?+
Running an abliterated model at home is legal: these are modified open-weight models distributed publicly. However, what you produce with one remains subject to ordinary law—the ablation removes the model's refusals, not your responsibilities. Also check the license for the variant you use (it generally follows that of the original model).
Is a local AI without limits less intelligent?+
Slightly, yes: ablation degrades overall quality somewhat (see the “Limitations and quality loss” section). For everyday use, the difference is marginal; for demanding coding or reasoning, keep the original variant alongside it—both coexist very well in Ollama.
Did this guide help you?

Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.