The Commonplace
Home Three-study pilot Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

A handful of repackagers keep safety-stripped open-weight models alive: three accounts produce over half of all compressed redistributions, making uncensored models persistent and easily deployable via quantized formats and registries such as Ollama, and enabling a surge in downstream apps—25% of which are explicitly malicious.

Uncensored Open-weight Models: Redistribution as the Persistence Layer
10a Labs, :, Juliette Garcia, Hailey May, Bobby McKenzie, David Pham, Matthew Swain, Joshua Valdez, Corie Wieland, Zachary Yahn · September 04, 2026
arxiv descriptive medium evidence 7/10 relevance Full text usable extracted full text Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

Arxiv

Latest observation:

  1. 10a Labs unresolved corpus identity
  2. : unresolved corpus identity
  3. Juliette Garcia unresolved corpus identity
  4. Hailey May unresolved corpus identity
  5. Bobby McKenzie unresolved corpus identity
  6. David Pham unresolved corpus identity
  7. Matthew Swain unresolved corpus identity
  8. Joshua Valdez unresolved corpus identity
  9. Corie Wieland unresolved corpus identity
  10. Zachary Yahn unresolved corpus identity
Public scraping of HuggingFace and GitHub shows that a concentrated set of redistributors (three accounts account for 52% of compressed redistributions) converts many safety-stripped models into persistent, deployable artifacts, driving downstream application growth—including explicitly malicious tooling—via registries and quantized formats like Ollama and GGUF.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. We profile this ecosystem by identifying key producers, downstream reproductions, and emerging applications. Between January 2024 and March 2026, we identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy downstream. Of the 1,643 identified GitHub applications integrating uncensored large language models (ULLMs), 25% were classified as explicitly malicious.

Summary

Main Finding

A two-tier ecosystem — many independent producers who remove safety guardrails and a concentrated set of redistributors who package models into deployable formats — makes uncensored open-weight models durable and widely accessible. Redistribution (quantization, format conversion, mirroring) is the persistence layer: it multiplies availability (average 2.4 compressed repacks per original), concentrates operational control (three redistributors account for 52% of repacks), and drives downstream application growth (deployability, not raw upload volume, predicts developer adoption). Lowering technical barriers (e.g., the Heretic tool) and registry convenience (notably Ollama) accelerated supply and deployment, and 25% of downstream GitHub applications using uncensored models are explicitly malicious.

Key Points

  • Scale and composition
    • Time window: Jan 2024–Mar 2026 (HuggingFace & GitHub scraping).
    • 12,360 HuggingFace repos associated with safety-guardrail removal:
    • 3,471 original uncensored models (producers).
    • 8,164 compressed redistributions (redistributors).
    • 547 model merges; 178 malicious datasets.
    • 1,643 GitHub repositories integrate, recommend, or default to an uncensored LLM backend.
  • Two-tier structure
    • Producers (≥1,055) and redistributors (≥1,011) mostly distinct; only ~24% of producers also redistribute.
    • Redistributors convert originals into deployment-ready compressed formats (GGUF, AWQ, GPTQ, EXL2, MLX).
  • Redistribution effects
    • Each original model is repackaged on average 2.4 times; some producers’ originals are repackaged many times (e.g., huihui-ai: 192 originals → ~1,800 repacks).
    • Three redistributors (mradermacher, Triangle104, RichardErkhov) produce 52% of compressed redistributions.
    • Repackaging across accounts, formats, and registries creates enforcement-resistant persistence.
  • Barrier lowering & supply growth
    • Heretic CLI (late 2025) sharply reduced technical effort to uncensor; monthly new-original production rose from ~89→~338; Heretic accounted for ~54% of new originals by Q1 2026.
    • Producer count increased; Heretic users produce more repeat models.
  • Downstream adoption driven by deployability
    • GitHub application creation rose from ~30/month (mid-2024) to 140–188/month (late-2025).
    • Ollama registry adoption (43% of READMEs) correlates with application growth; only 14% reference direct HuggingFace downloads.
    • Dolphin family alone powers ~30% (499) of identified applications.
  • Use cases and intent
    • ULLM apps by category: 37% general uncensored chatbots, 16% cybersecurity tools, 16% document processing; remainder NSFW, coding, roleplay, etc.
    • 25% of the 1,643 apps classified as explicitly malicious (hacking, malware, fraud tooling).
    • Telegram bots (110 repos) expose uncensored models to non-technical end users.
  • Geographic/source mix
    • Chinese-origin foundation models account for 38% of uncensored repos across the window; share rose from 1% (Q1 2024) to ~55% (Q2 2025), then fluctuated near parity.
    • Alibaba’s Qwen family is the primary Chinese-source driver (≈80% of Chinese-origin entries).
  • Commercial participation
    • Commercial actors (e.g., Venice.ai) commission uncensored models, appear in redistributions, and monetize via APIs — blurring hobbyist/commercial lines.

Data & Methods

  • Data sources and scope
    • HuggingFace: keyword + actor crawls yielded 17,727 candidate repos; an LLM classifier (GPT-5) labeled 12,360 as related to safety-guardrail removal.
    • GitHub: 44,705 candidate repos; after filtering, 1,643 applications identified as integrating or recommending uncensored backends.
    • Temporal analysis uses HuggingFace/GitHub publication dates; window Jan 2024–Mar 2026.
  • Classification & definitions
    • "Original uncensored model": repository where safety behavior was intentionally modified (activation-space ablation, malicious fine-tuning, merges).
    • "Compressed redistribution": repackaging into deployment formats (no new uncensoring step).
    • Models tracked by repository counts (not necessarily unique weight files).
  • Detection/labeling process
    • LLM-based classifier categorized candidate repositories into originals, redistributions, merges, malicious datasets, and false positives.
    • Application intent (malicious vs ambiguous) classified from repository content and README descriptions.
  • Limitations noted (implicit in methods)
    • Reliance on public registries and metadata: private mirrors, private channels (closed groups, paid services), and off-registry sharing not observed.
    • Automated LLM labeling may introduce classification errors; metadata-based heuristics may misidentify provenance or intent.
    • Counts are repository-based; a single weight mirrored across many repos inflates apparent model variety.
    • Temporal attribution uses publication date which might lag actual upstream events.

Implications for AI Economics

  • Persistence and enforcement costs
    • Redistribution as a persistence layer converts takedowns into a high-cost, low-effectiveness enforcement problem: mirrored, quantized copies across accounts and registries undermine single-repo removals and raise repeated enforcement costs.
  • Market structure & concentration
    • Vertical separation (many producers, few redistributors) concentrates practical control in redistributors and registries (e.g., Ollama). These chokepoints determine deployability and, hence, downstream adoption — granting redistributors and registry operators de facto market power over which uncensored models become widely used.
  • Lowered production costs and externalities
    • Tools like Heretic materially lowered technical costs to produce uncensored models, expanding supply and repeat production. Lower production costs increase available (often harmful) capabilities, producing larger negative externalities (malware, fraud, disinformation) that are not internalized by producers or redistributors.
  • Commercialization and incentives
    • Commercial actors commissioning uncensored models and selling tiered uncensored services internalize value from broader redistribution, creating monetization incentives that coexist with hobbyist activity. This reduces the stigma/transaction costs for commercial participation and can scale harmful products.
  • Demand elasticity and deployability
    • Downstream developers prioritize ease-of-integration (quantized formats, registry availability) over raw model variety. Therefore policy or technical controls applied at the deployability layer (format converters, registries) can strongly influence downstream usage and may be more leverageable than attempts to restrict upstream production alone.
  • Cross-border complexity
    • High share of Chinese-origin base models complicates unilateral regulatory approaches and suggests cross-jurisdictional supply chains; efforts to control models in one region will partially fail if repackaging and registries are global.
  • Potential market responses and opportunities
    • Demand for provenance, provenance-based curation, watermarking, detection, and monitoring services will grow — creating markets for model auditing and safety-compliance tooling.
    • Registry operators (Ollama, HuggingFace) and dominant redistributors could monetize governance (access controls, vetting) or be regulated as gatekeepers.
  • Policy levers (economically targeted)
    • Target choke points: regulate or set incentives for registries and major redistributors (transparency requirements, mandatory provenance metadata, liability for facilitating malicious redistribution).
    • Impose cost-raising measures on redistributors (e.g., required vetting, take-and-notify rules) to increase the marginal cost of persistence and reduce free mirroring.
    • Subsidize or reward safe-model packaging and detection services; support development of robust provenance/watermarking to aid attribution and enforcement.
    • International cooperation to address cross-border redistribution and commerce, since supply and redistribution are globally distributed.
  • Research gaps relevant to policy/economics
    • Quantify social cost of redistributed uncensored capabilities vs social benefit of open research.
    • Map private/paid distribution channels and estimate their scale and monetization.
    • Measure rent capture by redistributors/registries and the price elasticity of demand for uncensored model access.
    • Evaluate technical interventions (watermarks, provenance standards) and their economic impacts on producers, redistributors, and deployers.

Caveat: the report focuses on public registries and repository metadata; unobserved private channels and paid services could materially change magnitudes and monetization patterns.

Assessment

Paper Typedescriptive Evidence Strengthmedium — Large-scale empirical scraping across HuggingFace and GitHub with clear counts and temporal coverage provides substantial descriptive evidence; however the analysis depends on keyword searches, an automated LLM classifier (GPT-5) for labeling, and repository-counts rather than independently validated ground truth (unique weights, human-verified labels), leaving room for classification error, selection bias, and undercounting of private/alternative distribution channels. Methods Rigormedium — The authors use a systematic crawl, an explicit keyword list (including multi-language terms), actor crawls, and a classifier to categorize tens of thousands of repositories and then present aggregated metrics and case studies; but key methodological details are missing (e.g., labeled validation set metrics for the classifier, sensitivity checks for keyword coverage, de-duplication rules, and how manual review was used), and counts are repository-based rather than weight-unique, which weakens some inferences. SamplePublic repositories scraped from HuggingFace model and dataset registries (17,727 candidate repositories identified via 43 high-signal and 12 context-dependent keywords plus crawls of 15 prolific producers), classified by an LLM (GPT-5) into 12,360 repositories associated with safety-guardrail removal (3,471 original uncensored models, 8,164 compressed redistributions, 547 model merges, 178 malicious datasets); GitHub scraped via model- and application-level keywords and actor crawls (44,705 candidate repos reduced to 1,643 repositories identified as integrating, recommending, or defaulting to uncensored model backends). Temporal window: January 2024 — early March 2026. Counts refer to repositories, not deduplicated unique weight files. Themesgovernance adoption innovation GeneralizabilityAnalysis limited to public HuggingFace and GitHub repositories and observable registries (e.g., Ollama); excludes private channels, paid marketplaces, and closed forums., Relies on keyword searches and an LLM classifier—risk of false positives/negatives and language/term coverage gaps (may undercount non-English ecosystems beyond Chinese/Japanese)., Repository counts may overstate distinct model weights (many repos can mirror the same weights) and understate off-platform replication., Findings reflect the Jan 2024–Mar 2026 window and may not hold after new tooling, takedowns, or platform policy changes., Platform-specific dynamics (e.g., Ollama registry effects) may not generalize to other distribution architectures or enterprise settings.

Claims (14)

ClaimDirectionOutcomeConfidence & EvidenceDetails
Between January 2024 and March 2026, the study identified 3,471 original uncensored models and 8,164 compressed redistributions on Hugging Face. Adoption Rate positive Scale of the uncensored-model ecosystem
Reading fidelity high
Study strength medium
n=17727
3,471 original models and 8,164 compressed redistributions
0.18
Each original uncensored model was repackaged an average of 2.4 times into compressed deployment-oriented formats. Adoption Rate positive Redistribution multiplier
Reading fidelity high
Study strength medium
n=3471
2.4 times
0.18
Three redistributors accounted for 52% of all 8,164 observed compressed redistributions. Market Structure positive Concentration of redistribution activity
Reading fidelity high
Study strength medium
n=8164
52%
0.18
The producer and redistributor populations overlapped by only 24%, indicating that the two tiers were mostly separate. Organizational Efficiency negative Overlap between producer and redistributor populations
Reading fidelity high
Study strength medium
n=2066
24% overlap
0.18
The 192 original models from huihui-ai generated approximately 1,800 downstream compressed redistributions, representing about 14% of the identified Hugging Face dataset. Adoption Rate positive Downstream redistribution volume
Reading fidelity high
Study strength medium
n=192
approximately 1,800 redistributions; approximately 14%
0.18
Heretic-based production increased the rate of original uncensored-model creation from approximately 89 models per month before its release to approximately 338 per month afterward. Adoption Rate positive Monthly production of original uncensored models
Reading fidelity high
Study strength medium
approximately 89 per month to approximately 338 per month
0.18
By the first quarter of 2026, Heretic accounted for 54% of new original uncensored-model production. Adoption Rate positive Share of new original models produced with Heretic
Reading fidelity high
Study strength medium
54%
0.18
Chinese-origin foundation models accounted for 38% of all identified uncensored model repositories, with their share of new production rising from 1% in Q1 2024 to 55% in Q2 2025. Adoption Rate positive Share of uncensored repositories derived from Chinese-origin foundation models
Reading fidelity high
Study strength medium
n=12360
38% overall; 1% to 55% quarterly share
0.18
The study identified 1,643 GitHub repositories that integrated, recommended, or defaulted to an uncensored model backend. Adoption Rate positive Number of downstream applications using uncensored models
Reading fidelity high
Study strength medium
n=44705
1,643 repositories
0.18
Of the 1,643 identified applications, 411, or 25%, were classified as explicitly malicious. Ai Safety And Ethics positive Prevalence of explicitly malicious downstream applications
Reading fidelity high
Study strength medium
n=1643
25%
0.18
The Dolphin model family powered 30% of identified uncensored-model applications, corresponding to 499 repositories. Adoption Rate positive Application adoption by model family
Reading fidelity high
Study strength medium
n=1643
30%; 499 repositories
0.18
Ollama was referenced in 43% of application README files, compared with 14% referencing direct Hugging Face downloads. Adoption Rate positive Distribution-channel accessibility and application integration
Reading fidelity high
Study strength medium
n=1643
43% versus 14%
0.18
GitHub application creation increased from approximately 30 applications per month in mid-2024 to 140–188 applications per month by late 2025. Adoption Rate positive Rate of downstream application creation
Reading fidelity high
Study strength medium
n=1643
approximately 30 per month to 140–188 per month
0.18
The commercial Dolphin-Mistral-24B-Venice-Edition model generated 73 Hugging Face redistributions and was integrated by 77 GitHub repositories. Adoption Rate positive Commercial model redistribution and downstream integration
Reading fidelity high
Study strength low
n=150
73 redistributions; 77 repositories
0.09

Notes