---
domain: digital
tags: [harmonism, frontiers, ai, inference, sovereignty, open-weight, abliteration, uncensored, local-ai]
content_layer: applied
doctrinal_status: clear
breadth: substantial
depth: introductory
craft: muddy
status: draft — not yet deployed
created: "2026-09-28"
canonical_url: https://harmonism.io/world/frontiers/uncensored-ai-models--a-ranking-by-the-hand-that-remains
site: Harmonia — harmonism.io
---
# Uncensored AI Models — A Ranking by the Hand That Remains

*Frontiers article in the [[Harmonism]] cascade. The model-level ranking beneath the tier map of [[Inference Sovereignty]], and the list [[Running MunAI on Your Own Substrate]] draws its model choice from. Figures as of September 28, 2026. See also: [[The Sovereign Stack]], [[The Sovereignty of the Mind]], [[The Sovereign Substrate]].*

---

Alibaba released [Qwen3.6-27B](https://huggingface.co/Qwen/Qwen3.6-27B) in April 2026, and on the willingness test of the [UGI leaderboard](https://huggingface.co/spaces/DontPlanToEnd/UGI-Leaderboard) it scores 2.8 out of 10: pushed on a contested question, it declines or drifts off the instruction. A month later a community release stripped those refusals out of the weights, and [the modified model](https://huggingface.co/llmfan46/Qwen3.6-27B-uncensored-heretic-v2) scores 9.5. The same leaderboard also puts each model through a political questionnaire and places it on a scale from −100 (left) to +100 (right). The original sits at −20.0. The uncensored version sits at −24.5.

The refusals went. The worldview stayed where it was, and leaned a little further in the direction it already leaned.

Every open model marketed as uncensored has been through some version of that operation, and the result generalises. Removing a model's refusals leaves in place the hand that [[Inference Sovereignty]] traces through pretraining corpus, preference training and safety tuning, because refusal is only that hand's last and most visible layer. So the best uncensored model is the one whose remaining hand is smallest and best known for the work brought to it. The models below are ranked by what the operation cost them and what it left, never by how much they will say.

## 1. What Uncensoring Removes and What It Leaves

Refusal in a language model turns out to be unusually easy to locate. Andy Arditi and colleagues showed in 2024 that across thirteen open models the behaviour runs along a single direction in the model's internal activations, and that projecting that direction out of the weights stops the model refusing. Practitioners call the procedure abliteration. The [Heretic](https://github.com/p-e-w/heretic) project automated it and scores each attempt on two numbers: refusals on a set of prompts the original would decline, and how far the modified model's answers drift from the original's on harmless ones. On Google's Gemma 3 12B, Heretic takes refusals from 97 in 100 to 3 in 100 with less drift than two hand-tuned abliterations of the same model.

Refusal is what the procedure measures, and refusal is all it removes. On September 28, 2026 the UGI leaderboard held 1,317 model evaluations, and 206 of them could be paired, under the same settings, with the unmodified model they were made from. Across those pairs, willingness rose by a median of 6.0 points on the ten-point scale. Political lean moved by a median of 2.2 points on the two-hundred-point scale, and in 107 of the 203 pairs with a political score it moved by less than 5. The median original sat at −17.2 and the median uncensored model at −15.4. General capability, which the leaderboard scores as NatInt from textbook knowledge, popular culture and a set of real-world estimation tasks, fell in 137 of the 206 pairs.

Aleksander Fafuła found the same thing from the other side in July 2026. He ran abliterated and original versions of Gemma 4 and Qwen3 through 21,600 market decisions, and the abliterated versions bet on the upside between 7.4 and 12.2 percentage points more often on identical evidence. His conclusion is the one this ranking is built on: [an "uncensored" model is "a different decision-maker"](https://arxiv.org/html/2607.17427v1) from the original minus its refusals. The operation leaves the worldview and shifts the temperament.

Pliny the Liberator, the most followed of the people who break model guardrails for a living, documents the limit in his own toolkit. The research survey shipped with his [OBLITERATUS](https://github.com/elder-plinius/OBLITERATUS) repository records that when one layer's contribution is ablated, the other layers compensate and restore about seventy percent of the original computation, and that a model trained to explain its refusals rather than simply issue them keeps refusing more than ninety percent of the time after abliteration. What training put in, training defends.

Jailbreaks, the prompt-level route Pliny is known for, fall outside the ranking for a narrower reason. They work on closed models the practitioner does not hold, and the lab can close any of them with its next update. Weights on the practitioner's own disk take no updates from anyone.

Four kinds of claim sit in this section, and they carry different weight. Harmonism holds that every substrate carries a hand and that sovereign cognition means knowing which hand one is routing through. The evidence supports three narrower claims: abliteration removes refusal reliably, it leaves measured political disposition close to where it was, and it usually costs some capability. The leaderboard's political questionnaire is a proxy, and whether it tracks the hand that matters to a tradition, on metaphysics, health or the reading of history, remains open.

## 2. How the Models Were Measured

Three measures come from public data, and the fourth, the one that matters most, has not been run.

*Refusal removed.* A modified model enters the ranking if it scores at least 8 on the willingness scale. An unmodified model enters if it already scores 6 or more, because a model that answers without surgery carries none of the off-target shift Fafuła measured.

*Capability retained.* The ranking reads NatInt twice: the score itself, and its change from the unmodified original. A modified model that lost capability in the operation ranks below one that did not, even when its absolute score is higher, since a large loss is evidence of a large disturbance.

*Lineage and openness.* Every model below is open-weight: downloadable, runnable on hardware the practitioner owns. Whose hand it carries is named with it. Alibaba, Zhipu and DeepSeek are the non-Western open-weight tier of [[Inference Sovereignty]]; Google, Mistral and OpenAI are the Western tier, whose hand travels with the weights whoever runs them. One model below is fully open, which is a different property and gets its own section.

*The hand itself.* [[Running MunAI on Your Own Substrate]] names a test that has not yet been built: a suite of canonical questions with known Harmonist answers, runnable by any practitioner against any model. Until that suite exists, lineage stands in for the hand, and the rankings below are provisional on it. When the suite runs, it will reorder them.

Models are grouped by size, because size decides what hardware can hold them. A rough rule for a model compressed to four bits is 0.6 gigabytes of memory per billion parameters, plus room for the conversation. The figures come from the UGI data as updated on September 24, 2026, with each model linked to its own card.

## 3. Laptop Class: Up to 24 Billion Parameters

A machine with 8 to 16 gigabytes of memory holds these.

| Rank | Model | Willingness, original → now | NatInt, original → now | Hand |
|---|---|---|---|---|
| 1 | [Mistral Small 3.2 24B](https://huggingface.co/mistralai/Mistral-Small-3.2-24B-Instruct-2506), unmodified | 6.5 | 23.9 | Mistral |
| 2 | [Magistral Small 2509, Heretic v1](https://huggingface.co/llmfan46/Magistral-Small-2509-ultra-uncensored-heretic-v1) | 6.5 → 8.5 | 21.5 → 23.8 | Mistral |
| 3 | [Gemma 3 12B, norm-preserved abliteration](https://huggingface.co/grimjim/gemma-3-12b-it-norm-preserved-biprojected-abliterated) | 3.0 → 9.2 | 18.7 → 21.3 | Google |
| 4 | [Qwen3.5 9B, Heretic v2](https://huggingface.co/trohrbaugh/Qwen3.5-9B-heretic-v2) | 1.8 → 9.5 | 31.0 → 24.2 | Alibaba |

Mistral's small model leads because it needs no surgery at all and matches the best modified model on capability. At 24 billion parameters it fills a 16-gigabyte machine; below that, the Gemma 3 build fits in about 8.

Gemma 3 12B shows what care in the operation buys. Its maker, who publishes as grimjim, developed the norm-preserving method the OBLITERATUS survey singles out, and the modified model gained 2.6 points of capability and moved its political score toward the centre, from −11.7 to −6.4.

Qwen3.5 9B is the cautionary entry. Its original is the most capable small foundation model in the data, and the uncensored version gives up more than a fifth of that capability to stop refusing.

Smaller models exist, and the four-billion-parameter Qwen3.5 variants lose little in abliteration. MunAI Offline declines to run anything that small, on the ground that a confident wrong answer in MunAI's voice does more harm than no answer, and the same judgement applies to any model asked to speak for a doctrine.

## 4. Workstation Class: 25 to 124 Billion Parameters

A workstation with a 24-gigabyte graphics card, or an Apple machine with 32 to 64 gigabytes of unified memory, holds these.

| Rank | Model | Willingness, original → now | NatInt, original → now | Hand |
|---|---|---|---|---|
| 1 | [Gemma 4 26B-A4B, uncensored Heretic](https://huggingface.co/llmfan46/gemma-4-26B-A4B-it-uncensored-heretic) | 1.8 → 9.5 | 34.3 → 37.3 | Google |
| 2 | [GLM-4.5-Air, Derestricted](https://huggingface.co/ArliAI/GLM-4.5-Air-Derestricted) | 1.8 → 8.8 | 33.3 → 36.6 | Zhipu |
| 3 | [Qwen3.5 35B-A3B, uncensored Heretic](https://huggingface.co/llmfan46/Qwen3.5-35B-A3B-uncensored-heretic) | 2.2 → 10.0 | 33.1 → 35.6 | Alibaba |
| 4 | [gpt-oss-120b, Derestricted](https://huggingface.co/ArliAI/gpt-oss-120b-Derestricted) | 2.0 → 9.2 | 33.7 → 35.7 | OpenAI |
| 5 | [Gemma 4 31B, Heretic](https://huggingface.co/coder3101/gemma-4-31B-it-heretic) | 1.2 → 10.0 | 38.9 → 36.5 | Google |

In this class the operation often raised capability. Four of the five gained between 2.0 and 3.3 points. Part of the leaderboard's knowledge test asks things an aligned model would rather not answer, so removing refusal can read as a gain in knowledge that was there all along. That reading is an inference from the test's design, not a finding the leaderboard reports.

Gemma 4 26B leads because it gained 3.0 points and runs fast: it is a mixture of experts with only four billion parameters active per word, so it answers at laptop speed from workstation memory. GLM-4.5-Air carries the non-Western hand and a similar gain, but at 106 billion parameters it needs the top of this class's memory. Gemma 4 31B has the highest overall UGI score in the class and ranks last of the five, because it is the one that lost capability in the operation.

Qwen3.6 27B, the model in the opening, would rank below all five: its uncensored version lost 4.0 points of capability.

One unmodified model belongs here by capability and not by size. [Mistral Large 2411](https://huggingface.co/mistralai/Mistral-Large-Instruct-2411) answers at 7.5 with no surgery and scores 36.2, level with the leaders. As a dense 123-billion-parameter model it needs more memory than most workstations carry.

## 5. Server Class: 125 Billion Parameters and Above

These need a server with several graphics cards or an Apple machine with roughly two hundred gigabytes of memory or more.

| Rank | Model | Willingness, original → now | NatInt, original → now | Hand |
|---|---|---|---|---|
| 1 | [DeepSeek V4 Flash](https://huggingface.co/deepseek-ai/DeepSeek-V4-Flash), unmodified | 7.2 | 47.9 | DeepSeek |
| 2 | [DeepSeek V3.2](https://huggingface.co/deepseek-ai/DeepSeek-V3.2), unmodified | 7.2 | 47.9 | DeepSeek |
| 3 | [Mistral Large 3 675B](https://huggingface.co/mistralai/Mistral-Large-3-675B-Instruct-2512), unmodified | 6.8 | 38.8 | Mistral |
| 4 | [Qwen3.5 397B-A17B, Heretic](https://huggingface.co/trohrbaugh/Qwen3.5-397B-A17B-heretic) | 1.8 → 10.0 | 47.8 → 39.5 | Alibaba |

DeepSeek released V4 Flash on April 23, 2026, with 284 billion parameters of which 13 billion are active per word. With its reasoning mode switched off it answers at 7.2 and scores 47.9, the highest capability of any model in this ranking that needs no surgery. V3.2, from December 2025, matches it on both numbers at more than twice the size, so V4 Flash leads on hardware alone.

Neither DeepSeek model is without a hand. The Chinese labs' refusals cluster around topics sensitive to the Chinese state, and when Perplexity set out in February 2025 to remove them from DeepSeek R1, it needed about 40,000 prompts across roughly 300 topics of fresh training ([The Decoder](https://the-decoder.com/perplexity-ai-removes-chinese-censorship-from-deepseek-r1/)). That scale suggests the lab's positions sit in trained answers as well as in refusals, where abliteration cannot reach them. For work on Chinese history or politics, a DeepSeek model's willingness score says little.

Mistral Large 3 sits closest to the centre of the political scale of any large model here, at −11.3. Qwen3.5 397B is the heaviest loss in the whole ranking: its original scores 47.8, level with DeepSeek, and the uncensored version gives up 8.3 points of it.

Two absences matter. [DeepSeek V4 Pro](https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro) is the most capable open model on the leaderboard, at 67.0, and answers at 3.2, so it is not an uncensored model in any sense. Moonshot's Kimi K2 models score between 1.8 and 3.2 and stay out for the same reason.

## 6. Fully Open Models on a Different Axis

[OLMo 3 32B Think](https://huggingface.co/allenai/Olmo-3-32B-Think), from the Allen Institute for AI, would rank last in every class above. It answers at 1.8 and scores 20.9.

Its standing lies on a different axis. Every other model in this ranking released its weights and kept its training data and recipe. OLMo 3 released the weights, the Dolma 3 training corpus, the training code and the intermediate checkpoints. Its hand can be read, which no other hand here can, and it can be rebuilt from the data up, which is the terminus [[Inference Sovereignty]] names: a model retrained on a tradition's own corpus and run on hardware the tradition owns. MunAI Offline already ships the earlier OLMo 2 7B beside Qwen3 8B.

No abliterated OLMo 3 appears on the leaderboard as of this date. One would offer something none of the models above can: a hand fully documented, minus its refusals. Retraining would go further and replace the hand. A practitioner choosing today takes a model from sections 3 to 5; an institution building for the long arc works on this one.

## 7. Hosted Services Sold as Uncensored

Two hosted services come up wherever uncensored models are discussed. Neither appears in the tables above, and the reasons differ.

[uncensored.ai](https://uncensored.ai) is the chat service of Uncensored AI Inc., founded in Omaha in February 2023 by Jason Dick and Troy Weber. Its site, its app-store listing and its [2024 crowdfunding offer](https://kingscrowd.com/uncensored-ai-on-startengine-2024/) do not name the model that answers. The site's privacy line, that conversations are not used "to train third-party models" without consent, implies third-party models sit in the path. [Grokipedia](https://grokipedia.com/page/uncensored-ai) lists Grok, Gemini, Claude, Kimi and MiniMax models on the service in March 2026; the company has not confirmed that list, and it is not verified here. A service that routes to closed frontier APIs cannot remove refusal from weights it does not hold. It can only prompt around it, which is the jailbreak route section 1 set aside, rented by the month. When [NewsGuard](https://www.newsguardrealitycheck.com/p/uncensored-ai-chatbot-pushes-conspiracy) put the moon landing, 9/11 and COVID-19 vaccine safety to it in 2026, it failed to debunk the false narrative each time. Its Google Play listing declares that the data it collects is not encrypted. The hand is unknown and the operator can change it without notice, so there is nothing to rank.

[Venice](https://venice.ai), founded by Erik Voorhees and launched in May 2024, is a different case. It hosts more than two hundred models, and its own model, Venice Uncensored, is open-weight: [Dolphin Mistral 24B Venice Edition](https://huggingface.co/dphn/Dolphin-Mistral-24B-Venice-Edition), a fine-tune of Mistral Small 24B made with the Dolphin team and released under Apache 2.0. The leaderboard has tested the first release. Its original, [Mistral Small 24B 2501](https://huggingface.co/mistralai/Mistral-Small-24B-Instruct-2501), answers at 6.5 with NatInt 25.9 and a political score of −17.6. The Venice Edition answers at 7.8 with NatInt 24.4 and a political score of −15.4. It falls short of this ranking's bar of 8 for a modified model and lost 1.5 points of capability, to raise the willingness of an original that already cleared the bar for unmodified models. Dolphin's method is fine-tuning on new data rather than abliteration, which can move the hand as well as the refusals; here the political score moved 2.2 points toward the centre, the median shift across all 206 pairs. Version 1.2, released in April 2026 with vision and a longer context, has not been tested.

Venice's real standing is on the observability axis of [[Inference Sovereignty]], and there one service spans two regimes. Its closed frontier models run in an anonymised mode, where by [Venice's own account](https://venice.ai/privacy) the provider sees the prompt and likely saves it. Its open models run in a private mode that rests on contracts with the GPU providers. A subset runs inside attested enclaves on NEAR AI Cloud and Phala Network, where the privacy can be checked rather than trusted. The regime belongs to the request, not to the brand.

VVV is Venice's token, [launched on January 27, 2025](https://venice.ai/blog/introducing-the-venice-token-vvv) on Base with 100 million at genesis. Staking it earns a pro-rata share of Venice's API capacity, and locked stake mints DIEM, worth a dollar of API credit a day. Venice states that no token is needed to use the app or the API. The token prices access. It changes neither the hand of the model answering nor the privacy regime of the request, and a holder owns a claim on capacity that runs on someone else's hardware. An [independent review](https://ownyourmind.ai/projects/venice/) reports that a four-of-six multisig controls emissions, with no governance and no timelock.

A hosted service is judged by the model it serves and the regime it serves it in. A service that will not name its model has given the ranking nothing to measure.

## 8. How to Use the Ranking

Route by task first, as [[Inference Sovereignty]] prescribes. For code, summaries and translation, any capable model serves and refusal rarely bites. For contested ground in doctrine, health or civilizational diagnosis, reach for a model from the ranking and carry the doctrinal backbone with it. Removing refusals clears the way; the backbone supplies the orientation the refusals never did.

Then test the hand yourself. Write ten questions whose answers your own tradition holds clearly, ask the original and the modified model, and read what each volunteers, hedges and treats as settled. Twenty minutes of that tells a practitioner more about a model's hand than any leaderboard column.

If you run an abliteration of your own, check what the tool sends home. OBLITERATUS contributes each run to a public dataset, a setting that is on by default in its hosted version and opt-in locally. Pliny's stated principle, that "model behavior should be decided by the people who deploy them," applies to the tool's own telemetry as much as to the model's refusals.

Keep the operator's responsibility in view. A model that no longer refuses has handed the judgement its refusals used to carry to the person at the keyboard, which is the cost [[Inference Sovereignty]] attaches to its community-uncensored tier.

Finally, date everything. The UGI data changed on September 24, 2026, and every figure here is stamped four days later. The model list in [[Running MunAI on Your Own Substrate]], revised on the same September 24, still recommends Qwen 2.5 seven months after Qwen3.5 shipped. The field moves faster than any article's revision cycle, so this ranking will be re-run each quarter against the same criteria.

A model is matter organised by intelligence, and its hand was put there by the people who trained it. Taking up one's own substrate at the inference layer means knowing whose hand that was, keeping the refusals one wants and removing the ones one does not, and building toward the model whose hand is one's own.

---

*See also: [[Inference Sovereignty]], [[Running MunAI on Your Own Substrate]], [[The Sovereign Stack]], [[The Sovereignty of the Mind]], [[The Sovereign Substrate]], [[The Telos of Technology]], [[AI Alignment and Governance]], [[MunAI]].*
