Read

4 MIN

Date

Category

They Jailbroke China's Best AI in 41 Hours.

Alibaba published Qwen3.8-27B on 14 August at three in the afternoon. Forty-one hours later a stranger had published the same model with the refusals cut out of the weights, and that copy now gets 2.8 million downloads a month. The panic around it is wrong in a specific way, and what is left when you remove the panic is more useful than the panic was.

They Jailbroke China's Best AI in 41 Hours.
Champ Smith
Champ Smith

Champ Smith

Operator & AI Cystems Builder

I build the custom AI Cystems that run businesses for the operators who own them — leads routed, content shipped, calls handled. I work from a finca in Málaga, where the intelligence lives in the walls.

Alibaba published the weights for Qwen3.8-27B on 14 August at three in the afternoon, UTC. Apache-2.0, free to download, free to use commercially. Forty-one hours and twenty-two minutes later, an account called huihui-ai published the same model with the refusals cut out of it.

Both timestamps are public and you can check them yourself. Hugging Face — Qwen/Qwen3.8-27B shows 7.4 million downloads a month for the clean model. Hugging Face — huihui-ai/Huihui-Qwen3.8-27B-abliterated shows 2.8 million for the stripped copy, in the format that is easiest to run.

That gap is the whole story, and it is not the story going around.

What was actually removed

The technique is called abliteration. It comes out of a 2024 paper showing that refusal in a language model is mediated by a single direction in the residual stream. Find that direction, project it out of the weights, and the model stops saying no. No retraining, no new data, a few hours on a rented GPU. The huihui-ai card is unusually honest about the tradeoff: only layers 18 to 51 were touched, specifically to preserve more of the original quality.

Preserve more of it, because the operation costs you some. This is the part the panic gets backwards. Abliteration is subtractive. It deletes a refusal circuit. It does not add capability, knowledge, or skill. Published measurements of the technique show degradation across standard benchmarks after ablation alone, worst on truthfulness and on math. You can recover most of it with a fine-tune afterward, and most people do not bother.

So the uncensored model is a slightly worse version of the same model that will not decline. Whatever it can tell you about breaking into a network, the original could tell you too, on the third rephrasing. The refusals were a speed bump, and removing the speed bump did not build a road.

The numbers, before anyone quotes the marketing

Alibaba's own card claims Qwen3.8-27B beats Claude Opus 4.6 Max on SWE-bench Pro, 61.7 to 53.4. On Terminal Bench 2.1 the same card has it losing, 73.0 to 78.2. Those are self-reported, on evaluations the vendor chose.

Independently, the Artificial Analysis — Qwen3.8 27B listing scores it 34 on their intelligence index. That is first place among open-weight models between 4 and 40 billion parameters, which is a genuine achievement for something you can hold in a file. It is not first place overall. The best open weights, GLM-5.3 and Kimi K3, sit at 44. Frontier closed models sit at 53. The UK AI Security Institute put the gap on offensive cyber capability at four to seven months, narrowing.

It is a very good small model. It is not a frontier model, and nothing was jailbroken into being one.

What is true and worth your attention

Three things survive the noise.

The first is a design fact, and it is permanent. Alibaba spent real money on safety training and it lasted forty-one hours. Once you publish weights, the refusal layer is an accessory, not a property. Anyone selling you an AI product on the grounds that the model refuses to misbehave is selling you something they do not control. Guardrails live in the architecture around the model, in what the thing is allowed to touch and what gets checked before it acts. They have never lived in the weights, and now everybody can see it.

The second is that the bottom of the market is falling out, on purpose. Qwen has passed Llama to become the most-downloaded open model family, and the count of derivative repositories built on top of it dwarfs every alternative. That is not an accident of quality. It is a strategy to commoditise the layer everyone else is trying to sell. It is working.

The third is what did not happen. There is no evidence for the idea that this is a plan to turn the West's own downloads into a Trojan horse, and it is worth saying plainly that Anthropic, the lab with the most commercial reason to want open weights restricted, has publicly never asked for a ban. The real geopolitics here is boring and commercial: make the model free, own the dependency.

What I would do about it

Nothing, for the uncensored copy. It is measurably worse, it adds no capability we want, and we audit other people's exposure for a living.

The clean model is a different conversation. Per Hugging Face — Qwen/Qwen3.8-27B, it is a 27-billion-parameter file that reads images and video, handles 262,000 tokens of context, runs offline on hardware you already own, and costs nothing per call. That is a real tool for one specific job: work on client data that is not allowed to leave your building. Not because it is better than Claude. Because it is yours.

That is the shift worth budgeting for. Not a smarter model. A model with no invoice and no upstream.

Sources: Hugging Face — Qwen/Qwen3.8-27B; Hugging Face — huihui-ai/Huihui-Qwen3.8-27B-abliterated; Arditi et al., arXiv:2406.11717; Labonne — Uncensor any LLM with abliteration; Artificial Analysis — Qwen3.8 27B; UK AI Security Institute — open-weight models on cyber; Anthropic — position on open-weight models.

Read

4 MIN

Date

Category

I share ideas, lessons, and practical insights from my work.

Related
Articles.

Sep 15, 2026

Three Founders Say Their AI Beat Bridgewater Last Year

Signal

Three Founders Say Their AI Beat Bridgewater Last Year

A three-person company on the Isle of Man says its trading AI returned 51.15% in 2025, ahead of Bridgewater and D.E. Shaw. It was built without a Transformer and without venture capital, and it is now planning to open its models to the public.

Sep 10, 2026

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

Signal

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

$1.03 billion, no product, no revenue. Four months after walking out of Meta, the man who helped make ChatGPT possible got the largest seed round in European history to prove language was the wrong bet. Why it matters, and the honest caveats.

Sep 9, 2026

Sam Altman Admits He Still Works the Old Way.

Cystems

Sam Altman Admits He Still Works the Old Way.

The man who built Claude Code made sure nobody on his team can. Two companies people put on opposite sides of AI, and the same lesson from both ends: the tool changed, and the job has to change with it.

Sep 3, 2026

The Signal Was Already in the Stream

Signal

The Signal Was Already in the Stream

Google Research just built a glucose model with only 0.72 million parameters, and it beats every bigger model that came before it. It reads the continuous glucose monitor people already wear and predicts diabetes risk, insulin resistance and beta-cell dysfunction, with no new blood test. The lesson is bigger than health: the signal you want is usually already in a stream you are already collecting. You are just reading it as spot values.

Sep 15, 2026

Three Founders Say Their AI Beat Bridgewater Last Year

Signal

Three Founders Say Their AI Beat Bridgewater Last Year

A three-person company on the Isle of Man says its trading AI returned 51.15% in 2025, ahead of Bridgewater and D.E. Shaw. It was built without a Transformer and without venture capital, and it is now planning to open its models to the public.

Sep 10, 2026

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

Signal

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

$1.03 billion, no product, no revenue. Four months after walking out of Meta, the man who helped make ChatGPT possible got the largest seed round in European history to prove language was the wrong bet. Why it matters, and the honest caveats.

Sep 15, 2026

Three Founders Say Their AI Beat Bridgewater Last Year

Signal

Three Founders Say Their AI Beat Bridgewater Last Year

A three-person company on the Isle of Man says its trading AI returned 51.15% in 2025, ahead of Bridgewater and D.E. Shaw. It was built without a Transformer and without venture capital, and it is now planning to open its models to the public.

Sep 10, 2026

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

Signal

Yann LeCun Quit Meta to Prove ChatGPT Wrong.

$1.03 billion, no product, no revenue. Four months after walking out of Meta, the man who helped make ChatGPT possible got the largest seed round in European history to prove language was the wrong bet. Why it matters, and the honest caveats.