Uncensored Open-weight Models: Redistribution as the Persistence Layer
Between January 2024 and March 2026, 3,471 original uncensored models were identified on HuggingFace, each repackaged an average of 2.4 times; three actors account for 52% of all 8,164 compressed redistributions. Of the 1,643 identified GitHub applications integrating uncensored large language models (ULLMs), 25% were classified as explicitly malicious.
A rapidly expanding ecosystem of actors is removing built-in safety guardrails from open-weight AI models. The ecosystem includes key producers, downstream reproductions, and emerging applications. Once quantized and mirrored across separate accounts, formats, and registries such as Ollama, these models persist regardless of upstream removal and become easier to deploy downstream.
The redistribution of uncensored models through quantization and mirroring across multiple registries creates a persistence layer that resists upstream removal. The average repackaging rate of 2.4 times per original model indicates a systematic pipeline for distribution.
The concentration of redistribution among three actors (52% of compressed redistributions) suggests a small number of entities dominate the uncensored model distribution ecosystem, potentially enabling rapid propagation of modified models.
The persistence and ease of deployment of uncensored models may lower barriers for downstream applications, but also increases risks associated with malicious use, potentially affecting platform policies and enterprise adoption of open-weight models.
Observable next signals include monitoring the growth rate of new uncensored models on HuggingFace, tracking the emergence of additional redistribution actors, and assessing whether the proportion of malicious GitHub applications changes over time.