0 cumulative citations
View corpus contextA handful of repackagers keep safety-stripped open-weight models alive: three accounts produce over half of all compressed redistributions, making uncensored models persistent and easily deployable via quantized formats and registries such as Ollama, and enabling a surge in downstream apps—25% of which are explicitly malicious.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. We profile this ecosystem by identifying key producers, downstream reproductions, and emerging applications. Between January 2024 and March 2026, we identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy downstream. Of the 1,643 identified GitHub applications integrating uncensored large language models (ULLMs), 25% were classified as explicitly malicious.
Summary
Main Finding
A two-tier ecosystem — many independent producers who remove safety guardrails and a concentrated set of redistributors who package models into deployable formats — makes uncensored open-weight models durable and widely accessible. Redistribution (quantization, format conversion, mirroring) is the persistence layer: it multiplies availability (average 2.4 compressed repacks per original), concentrates operational control (three redistributors account for 52% of repacks), and drives downstream application growth (deployability, not raw upload volume, predicts developer adoption). Lowering technical barriers (e.g., the Heretic tool) and registry convenience (notably Ollama) accelerated supply and deployment, and 25% of downstream GitHub applications using uncensored models are explicitly malicious.
Key Points
- Scale and composition
- Time window: Jan 2024–Mar 2026 (HuggingFace & GitHub scraping).
- 12,360 HuggingFace repos associated with safety-guardrail removal:
- 3,471 original uncensored models (producers).
- 8,164 compressed redistributions (redistributors).
- 547 model merges; 178 malicious datasets.
- 1,643 GitHub repositories integrate, recommend, or default to an uncensored LLM backend.
- Two-tier structure
- Producers (≥1,055) and redistributors (≥1,011) mostly distinct; only ~24% of producers also redistribute.
- Redistributors convert originals into deployment-ready compressed formats (GGUF, AWQ, GPTQ, EXL2, MLX).
- Redistribution effects
- Each original model is repackaged on average 2.4 times; some producers’ originals are repackaged many times (e.g., huihui-ai: 192 originals → ~1,800 repacks).
- Three redistributors (mradermacher, Triangle104, RichardErkhov) produce 52% of compressed redistributions.
- Repackaging across accounts, formats, and registries creates enforcement-resistant persistence.
- Barrier lowering & supply growth
- Heretic CLI (late 2025) sharply reduced technical effort to uncensor; monthly new-original production rose from ~89→~338; Heretic accounted for ~54% of new originals by Q1 2026.
- Producer count increased; Heretic users produce more repeat models.
- Downstream adoption driven by deployability
- GitHub application creation rose from ~30/month (mid-2024) to 140–188/month (late-2025).
- Ollama registry adoption (43% of READMEs) correlates with application growth; only 14% reference direct HuggingFace downloads.
- Dolphin family alone powers ~30% (499) of identified applications.
- Use cases and intent
- ULLM apps by category: 37% general uncensored chatbots, 16% cybersecurity tools, 16% document processing; remainder NSFW, coding, roleplay, etc.
- 25% of the 1,643 apps classified as explicitly malicious (hacking, malware, fraud tooling).
- Telegram bots (110 repos) expose uncensored models to non-technical end users.
- Geographic/source mix
- Chinese-origin foundation models account for 38% of uncensored repos across the window; share rose from 1% (Q1 2024) to ~55% (Q2 2025), then fluctuated near parity.
- Alibaba’s Qwen family is the primary Chinese-source driver (≈80% of Chinese-origin entries).
- Commercial participation
- Commercial actors (e.g., Venice.ai) commission uncensored models, appear in redistributions, and monetize via APIs — blurring hobbyist/commercial lines.
Data & Methods
- Data sources and scope
- HuggingFace: keyword + actor crawls yielded 17,727 candidate repos; an LLM classifier (GPT-5) labeled 12,360 as related to safety-guardrail removal.
- GitHub: 44,705 candidate repos; after filtering, 1,643 applications identified as integrating or recommending uncensored backends.
- Temporal analysis uses HuggingFace/GitHub publication dates; window Jan 2024–Mar 2026.
- Classification & definitions
- "Original uncensored model": repository where safety behavior was intentionally modified (activation-space ablation, malicious fine-tuning, merges).
- "Compressed redistribution": repackaging into deployment formats (no new uncensoring step).
- Models tracked by repository counts (not necessarily unique weight files).
- Detection/labeling process
- LLM-based classifier categorized candidate repositories into originals, redistributions, merges, malicious datasets, and false positives.
- Application intent (malicious vs ambiguous) classified from repository content and README descriptions.
- Limitations noted (implicit in methods)
- Reliance on public registries and metadata: private mirrors, private channels (closed groups, paid services), and off-registry sharing not observed.
- Automated LLM labeling may introduce classification errors; metadata-based heuristics may misidentify provenance or intent.
- Counts are repository-based; a single weight mirrored across many repos inflates apparent model variety.
- Temporal attribution uses publication date which might lag actual upstream events.
Implications for AI Economics
- Persistence and enforcement costs
- Redistribution as a persistence layer converts takedowns into a high-cost, low-effectiveness enforcement problem: mirrored, quantized copies across accounts and registries undermine single-repo removals and raise repeated enforcement costs.
- Market structure & concentration
- Vertical separation (many producers, few redistributors) concentrates practical control in redistributors and registries (e.g., Ollama). These chokepoints determine deployability and, hence, downstream adoption — granting redistributors and registry operators de facto market power over which uncensored models become widely used.
- Lowered production costs and externalities
- Tools like Heretic materially lowered technical costs to produce uncensored models, expanding supply and repeat production. Lower production costs increase available (often harmful) capabilities, producing larger negative externalities (malware, fraud, disinformation) that are not internalized by producers or redistributors.
- Commercialization and incentives
- Commercial actors commissioning uncensored models and selling tiered uncensored services internalize value from broader redistribution, creating monetization incentives that coexist with hobbyist activity. This reduces the stigma/transaction costs for commercial participation and can scale harmful products.
- Demand elasticity and deployability
- Downstream developers prioritize ease-of-integration (quantized formats, registry availability) over raw model variety. Therefore policy or technical controls applied at the deployability layer (format converters, registries) can strongly influence downstream usage and may be more leverageable than attempts to restrict upstream production alone.
- Cross-border complexity
- High share of Chinese-origin base models complicates unilateral regulatory approaches and suggests cross-jurisdictional supply chains; efforts to control models in one region will partially fail if repackaging and registries are global.
- Potential market responses and opportunities
- Demand for provenance, provenance-based curation, watermarking, detection, and monitoring services will grow — creating markets for model auditing and safety-compliance tooling.
- Registry operators (Ollama, HuggingFace) and dominant redistributors could monetize governance (access controls, vetting) or be regulated as gatekeepers.
- Policy levers (economically targeted)
- Target choke points: regulate or set incentives for registries and major redistributors (transparency requirements, mandatory provenance metadata, liability for facilitating malicious redistribution).
- Impose cost-raising measures on redistributors (e.g., required vetting, take-and-notify rules) to increase the marginal cost of persistence and reduce free mirroring.
- Subsidize or reward safe-model packaging and detection services; support development of robust provenance/watermarking to aid attribution and enforcement.
- International cooperation to address cross-border redistribution and commerce, since supply and redistribution are globally distributed.
- Research gaps relevant to policy/economics
- Quantify social cost of redistributed uncensored capabilities vs social benefit of open research.
- Map private/paid distribution channels and estimate their scale and monetization.
- Measure rent capture by redistributors/registries and the price elasticity of demand for uncensored model access.
- Evaluate technical interventions (watermarks, provenance standards) and their economic impacts on producers, redistributors, and deployers.
Caveat: the report focuses on public registries and repository metadata; unobserved private channels and paid services could materially change magnitudes and monetization patterns.
Assessment
Claims (14)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| Between January 2024 and March 2026, the study identified 3,471 original uncensored models and 8,164 compressed redistributions on Hugging Face. Adoption Rate | positive | Scale of the uncensored-model ecosystem |
Reading fidelity
high
Study strength
medium
|
n=17727
3,471 original models and 8,164 compressed redistributions
|
| Each original uncensored model was repackaged an average of 2.4 times into compressed deployment-oriented formats. Adoption Rate | positive | Redistribution multiplier |
Reading fidelity
high
Study strength
medium
|
n=3471
2.4 times
|
| Three redistributors accounted for 52% of all 8,164 observed compressed redistributions. Market Structure | positive | Concentration of redistribution activity |
Reading fidelity
high
Study strength
medium
|
n=8164
52%
|
| The producer and redistributor populations overlapped by only 24%, indicating that the two tiers were mostly separate. Organizational Efficiency | negative | Overlap between producer and redistributor populations |
Reading fidelity
high
Study strength
medium
|
n=2066
24% overlap
|
| The 192 original models from huihui-ai generated approximately 1,800 downstream compressed redistributions, representing about 14% of the identified Hugging Face dataset. Adoption Rate | positive | Downstream redistribution volume |
Reading fidelity
high
Study strength
medium
|
n=192
approximately 1,800 redistributions; approximately 14%
|
| Heretic-based production increased the rate of original uncensored-model creation from approximately 89 models per month before its release to approximately 338 per month afterward. Adoption Rate | positive | Monthly production of original uncensored models |
Reading fidelity
high
Study strength
medium
|
approximately 89 per month to approximately 338 per month
|
| By the first quarter of 2026, Heretic accounted for 54% of new original uncensored-model production. Adoption Rate | positive | Share of new original models produced with Heretic |
Reading fidelity
high
Study strength
medium
|
54%
|
| Chinese-origin foundation models accounted for 38% of all identified uncensored model repositories, with their share of new production rising from 1% in Q1 2024 to 55% in Q2 2025. Adoption Rate | positive | Share of uncensored repositories derived from Chinese-origin foundation models |
Reading fidelity
high
Study strength
medium
|
n=12360
38% overall; 1% to 55% quarterly share
|
| The study identified 1,643 GitHub repositories that integrated, recommended, or defaulted to an uncensored model backend. Adoption Rate | positive | Number of downstream applications using uncensored models |
Reading fidelity
high
Study strength
medium
|
n=44705
1,643 repositories
|
| Of the 1,643 identified applications, 411, or 25%, were classified as explicitly malicious. Ai Safety And Ethics | positive | Prevalence of explicitly malicious downstream applications |
Reading fidelity
high
Study strength
medium
|
n=1643
25%
|
| The Dolphin model family powered 30% of identified uncensored-model applications, corresponding to 499 repositories. Adoption Rate | positive | Application adoption by model family |
Reading fidelity
high
Study strength
medium
|
n=1643
30%; 499 repositories
|
| Ollama was referenced in 43% of application README files, compared with 14% referencing direct Hugging Face downloads. Adoption Rate | positive | Distribution-channel accessibility and application integration |
Reading fidelity
high
Study strength
medium
|
n=1643
43% versus 14%
|
| GitHub application creation increased from approximately 30 applications per month in mid-2024 to 140–188 applications per month by late 2025. Adoption Rate | positive | Rate of downstream application creation |
Reading fidelity
high
Study strength
medium
|
n=1643
approximately 30 per month to 140–188 per month
|
| The commercial Dolphin-Mistral-24B-Venice-Edition model generated 73 Hugging Face redistributions and was integrated by 77 GitHub repositories. Adoption Rate | positive | Commercial model redistribution and downstream integration |
Reading fidelity
high
Study strength
low
|
n=150
73 redistributions; 77 repositories
|