What changed
Wired reporter Will Knight used a fully de-aligned AI agent on his own home network over several days. The agent identified vulnerabilities in household devices, compromised a PC, and found bugs in “vibe-coded” projects, then provided recommendations for improving security.
Knight accessed the model through Abliteration AI, whose most powerful offering is described as a version of Z.ai’s agentic coding model, GLM 5.3. The company removes refusal-related patterns from open-weight models through a process called abliteration, offering fully de-aligned access for as little as the cost of a pizza. Its CEO, Devon, argues that broad access can help defenders probe their own systems and simulate hackers, scammers and rogue agents.
The experiment did not identify the affected devices, specific flaws or method used to compromise the PC. Wired also contrasted the service with Anthropic’s Mythos and OpenAI’s Astra, which it says have similar cyber capabilities but are limited to trusted customers; both companies also offer more widely available models with medium-level guardrails for authorized code and system vetting.
Why it matters
The experiment shows how consumer-accessible, guardrail-free agentic models can combine vulnerability discovery, exploitation and remediation advice in a household environment. That lowers the effort required for an authorized owner to inspect connected devices and software, but potentially lowers it for unauthorized probing as well.
For developers shipping vibe-coded applications, AI-assisted testing could make security review a more routine pre-deployment task. The same capability raises the cost of leaving authentication, permissions, exposed services and unpatched software unattended, because weaknesses may become easier to locate.
Impact assessment
Home users with connected devices face an immediate mixed effect. An authorized owner can use a de-aligned agent to find weaknesses and pursue fixes; where those weaknesses remain unresolved, comparable tools could make vulnerable systems more attractive targets. The chain is interrupted if access tightens or existing controls prevent discovered flaws from being exploited.
Small teams using vibe-coded projects may gain cheaper security-testing capacity in the coming weeks, reducing the advantage previously held by teams with dedicated security staff. But faster development without remediation shifts costs into patching and incident response after release, making security review more central to deployment operations.
Over six to 12 months, providers of restricted cyber-capable models could face pressure to make authorized-testing workflows more useful and clearly bounded. Fully de-aligned alternatives create a practical comparison: capability may be available outside trusted-customer programs. That pressure weakens if unrestricted models prove unreliable or their findings cannot be turned into fixes.
Scenarios
Most likely. Our outlook (informed speculation): Over the next several weeks to 12 months, authorized users and security teams will increasingly trial AI-assisted vulnerability scanning on systems they control. If fully de-aligned tools remain accessible and findings lead to actionable remediation, teams will add agent-led checks before deployment and allocate more routine work to patching defects identified by those checks. This baseline is more likely because the reported home-network test demonstrates both offensive capability and defensive utility. Documented fixes following authorized findings would strengthen it; unreliable scans or difficult remediation would weaken it.
Upside. If authorized testing is paired with clear remediation guidance and teams act on the findings, de-aligned and medium-guardrail agents could become practical defensive assistants within six to 12 months. Smaller development teams could catch and repair defects before release, expanding their capacity to harden products without dedicated security staffs. Evidence of agents being integrated into pre-deployment reviews and followed by documented fixes would support this path; demonstrations that do not become routine review would weaken it.
Downside. If unauthorized users can obtain and effectively operate fully de-aligned models against systems they do not control, the tools could lower the effort needed to probe household devices and poorly secured applications over the next year. Operators would then shift spending and staff time toward hardening exposed services, accelerated patching and incident response after weaknesses are found. Confirmed AI-assisted unauthorized probing or compromises would support this outcome; restricted access or controls that block exploitation would weaken it.
What to watch next
- Whether Abliteration AI and other providers continue, expand, restrict or withdraw access to fully de-aligned agentic models.
- Whether authorized AI-assisted testing produces reproducible findings and documented fixes to devices, PCs or applications.
- Whether Anthropic’s and OpenAI’s medium-guardrail models gain wider use for authorized code and system vetting.
Comments
No comments yet.