Uncensored Open-weight Models: Redistribution as the Persistence Layer
A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. We profile this ecosystem by identifying key producers, downstream reproductions, and emerging applications. Between January 2024 and March 2026, we identified 3,471 original uncensored models on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy
Lineage graph
Paper → model → repo connections mined from source citations (Tier-1 exact match).
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- FuzzyOverlapping authors or contributors · 62%black-forest-labs/FLUX.1-dev →
“Shared author/contributor keys: labs”
- FuzzyOverlapping authors or contributors · 62%black-forest-labs/FLUX.1-schnell →
“Shared author/contributor keys: labs”
- FuzzyOverlapping authors or contributors · 62%nari-labs/Dia-1.6B →
“Shared author/contributor keys: labs”
- FuzzyOverlapping authors or contributors · 62%black-forest-labs/FLUX.1-Kontext-dev →
“Shared author/contributor keys: labs”
- PossiblePossibly related (embedding) · 61%OpenAI models autonomously hacked into machine learning company Hugging Face: ‘Unprecedented’ - Washington Examiner →
- PossiblePossibly related (embedding) · 59%OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know →
- PossiblePossibly related (embedding) · 58%Safety and alignment in an era of long-horizon models →
- PossiblePossibly related (embedding) · 58%Open-Weight AI Models: Why Companies Stop Renting - bereaonline.com →
