🚀NEW COURSEVibe Coding AI Apps with Claude Code 🤖✨Enroll now
← All papers  /  Sep 4, 2026
Safety

Uncensored Open-weight Models: Redistribution as the Persistence Layer

First page
Uncensored Open-weight Models: Redistribution as the Persistence Layer
The curator’s take

10a Labs profiles the ecosystem that strips safety guardrails from open-weight models, and shows that redistribution rather than original production is what keeps those models available after an upstream takedown.

Ask this paper

Key points
01

Scale: Between January 2024 and March 2026 the authors identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times.

02

Concentration: Three actors account for 52% of all 8,164 compressed redistributions, so the redistribution layer has a small number of load-bearing nodes.

03

Why removal does not work: Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, a model persists regardless of whether the original is taken down, and becomes easier to deploy downstream.

04

Downstream use: Of 1,643 GitHub applications integrating uncensored LLMs, 25% were classified as explicitly malicious.

Abstract

A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. We profile this ecosystem by identifying key producers, downstream reproductions, and emerging applications. Between January 2024 and March 2026, we identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy downstream. Of the 1,643 identified GitHub applications integrating uncensored large language models (ULLMs), 25% were classified as explicitly malicious.

Every Monday
Get next week’s papers.
Subscribe on Substack