They Jailbroke China's Best AI in 41 Hours.
Alibaba published Qwen3.8-27B on 14 August at three in the afternoon. Forty-one hours later a stranger had published the same model with the refusals cut out of the weights, and that copy now gets 2.8 million downloads a month. The panic around it is wrong in a specific way, and what is left when you remove the panic is more useful than the panic was.

Alibaba published the weights for Qwen3.8-27B on 14 August at three in the afternoon, UTC. Apache-2.0, free to download, free to use commercially. Forty-one hours and twenty-two minutes later, an account called huihui-ai published the same model with the refusals cut out of it.
Both timestamps are public and you can check them yourself. Hugging Face — Qwen/Qwen3.8-27B shows 7.4 million downloads a month for the clean model. Hugging Face — huihui-ai/Huihui-Qwen3.8-27B-abliterated shows 2.8 million for the stripped copy, in the format that is easiest to run.
That gap is the whole story, and it is not the story going around.
What was actually removed
The technique is called abliteration. It comes out of a 2024 paper showing that refusal in a language model is mediated by a single direction in the residual stream. Find that direction, project it out of the weights, and the model stops saying no. No retraining, no new data, a few hours on a rented GPU. The huihui-ai card is unusually honest about the tradeoff: only layers 18 to 51 were touched, specifically to preserve more of the original quality.
Preserve more of it, because the operation costs you some. This is the part the panic gets backwards. Abliteration is subtractive. It deletes a refusal circuit. It does not add capability, knowledge, or skill. Published measurements of the technique show degradation across standard benchmarks after ablation alone, worst on truthfulness and on math. You can recover most of it with a fine-tune afterward, and most people do not bother.
So the uncensored model is a slightly worse version of the same model that will not decline. Whatever it can tell you about breaking into a network, the original could tell you too, on the third rephrasing. The refusals were a speed bump, and removing the speed bump did not build a road.
The numbers, before anyone quotes the marketing
Alibaba's own card claims Qwen3.8-27B beats Claude Opus 4.6 Max on SWE-bench Pro, 61.7 to 53.4. On Terminal Bench 2.1 the same card has it losing, 73.0 to 78.2. Those are self-reported, on evaluations the vendor chose.
Independently, the Artificial Analysis — Qwen3.8 27B listing scores it 34 on their intelligence index. That is first place among open-weight models between 4 and 40 billion parameters, which is a genuine achievement for something you can hold in a file. It is not first place overall. The best open weights, GLM-5.3 and Kimi K3, sit at 44. Frontier closed models sit at 53. The UK AI Security Institute put the gap on offensive cyber capability at four to seven months, narrowing.
It is a very good small model. It is not a frontier model, and nothing was jailbroken into being one.
What is true and worth your attention
Three things survive the noise.
The first is a design fact, and it is permanent. Alibaba spent real money on safety training and it lasted forty-one hours. Once you publish weights, the refusal layer is an accessory, not a property. Anyone selling you an AI product on the grounds that the model refuses to misbehave is selling you something they do not control. Guardrails live in the architecture around the model, in what the thing is allowed to touch and what gets checked before it acts. They have never lived in the weights, and now everybody can see it.
The second is that the bottom of the market is falling out, on purpose. Qwen has passed Llama to become the most-downloaded open model family, and the count of derivative repositories built on top of it dwarfs every alternative. That is not an accident of quality. It is a strategy to commoditise the layer everyone else is trying to sell. It is working.
The third is what did not happen. There is no evidence for the idea that this is a plan to turn the West's own downloads into a Trojan horse, and it is worth saying plainly that Anthropic, the lab with the most commercial reason to want open weights restricted, has publicly never asked for a ban. The real geopolitics here is boring and commercial: make the model free, own the dependency.
What I would do about it
Nothing, for the uncensored copy. It is measurably worse, it adds no capability we want, and we audit other people's exposure for a living.
The clean model is a different conversation. Per Hugging Face — Qwen/Qwen3.8-27B, it is a 27-billion-parameter file that reads images and video, handles 262,000 tokens of context, runs offline on hardware you already own, and costs nothing per call. That is a real tool for one specific job: work on client data that is not allowed to leave your building. Not because it is better than Claude. Because it is yours.
That is the shift worth budgeting for. Not a smarter model. A model with no invoice and no upstream.
Sources: Hugging Face — Qwen/Qwen3.8-27B; Hugging Face — huihui-ai/Huihui-Qwen3.8-27B-abliterated; Arditi et al., arXiv:2406.11717; Labonne — Uncensor any LLM with abliteration; Artificial Analysis — Qwen3.8 27B; UK AI Security Institute — open-weight models on cyber; Anthropic — position on open-weight models.
I share ideas, lessons, and practical insights from my work.






