21,232 open-weight models on HuggingFace have had their refusal behaviour deliberately removed or reduced, by a technique its practitioners call abliteration. Between them they were downloaded 50,065,683 times in the 30 days before the harvest.
61 individual models exceed 100,000 downloads.
Read from each model's base_model: tag, counting each model
once per publisher named. Several large entries are themselves prolific abliteration
publishers, so the technique is applied to already modified models as well as to original
releases.
Downloads are the last 30 days. HuggingFace counts one query file per download, so taking a model normally counts once. The exception is GGUF: every GGUF file counts, so cloning a whole quantization repository counts each file rather than once. HuggingFace says most people take a single file, and nine of the top ten here are quantization repositories.
We search HuggingFace for models whose own metadata says the refusal behaviour has been
removed or reduced. Publishers describe it both ways, and some say "substantially reduced",
so a model counted here may still refuse some requests. Two passes: tags a publisher applied deliberately (abliterated,
uncensored), and a name search for eleven related terms
(abliteration, decensored, ablated,
jailbroken, unaligned, unfiltered,
refusal-removed, no-guardrail, unrestricted and the two
above). A model is counted if it carries one of the two tags, or if its name contains
ablitera, decensor or uncensor.
That means this counts what publishers say about their own models. We do not test them. 67.7% carry the tag; the rest were counted on the name. Both are the publisher's own claim, so the split is between two kinds of claim, not between verified and unverified.
"Uncensored" sells, so some share of this may be marketing, and a model that was genuinely stripped but never advertised is not visible to us. The number measures advertised availability, not verified capability.