Esc
SafetyCase Closed

Abliterated Qwen 3.6-35B-A3B Model Released on Hugging Face

Is this a scandal?

No longer — the story has resolved. Noise 1/100, cooling down, across 0 sources.

SCAND-76005as of Methodology
Cite this incident"Abliterated Qwen 3.6-35B-A3B Model Released on Hugging Face." SCAND.Ai incident SCAND-76005, noise 1/100 as of October 1, 2026. https://scand.ai/scandal/qwen-3-6-moe-abliteration-controversy
FORECASTForecast, not fact

Regulatory pressure on model hosting platforms like Hugging Face will likely increase as automated safety-removal tools become more sophisticated. We should expect a 'cat-and-mouse' game where developers bake safety deeper into the base weights, while jailbreakers develop more granular expert-level suppression techniques.

1

Noise 1/100 — louder than 90% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

Democratizes advanced agentic coding capabilities via extreme efficiency, challenging proprietary API dominance and accelerating local AI agent deployment.

Key points

  1. Qwen3.6-35B-A3B uses 35B total parameters but activates only 3B during inference for extreme efficiency.
  2. Model is explicitly optimized for agentic coding workflows and long-context multimodal reasoning.
  3. Community released NVFP4 quantized variant within two days of announcement for consumer hardware compatibility.
  4. Full weights and configs published in Hugging Face Transformers format on April 22, 2026.
  5. Open-weight release challenges proprietary API providers by enabling local agentic system deployment.

The story

Alibaba Cloud has released Qwen3.6-35B-A3B, an open-weight mixture-of-experts model featuring 35 billion total parameters with only 3 billion active during inference. Announced on April 14, 2026, the model targets agentic coding, multimodal reasoning, and long-context workflows while maintaining low computational overhead. Community developers rapidly produced quantized variants like NVFP4 by April 16 to enable consumer hardware deployment. The release provides full weights and configuration files in Hugging Face Transformers format as of April 22. This launch continues Alibaba’s strategy of distributing high-efficiency open models to compete with closed-source alternatives. Industry observers note the 3-billion active parameter count represents a significant efficiency milestone for open agentic systems. The model is available under permissive terms for research and commercial use.

Who's involved

Defender
Alibaba Qwen Team

Original developers of the Qwen architecture who implement safety guardrails to prevent harmful model outputs.

Neutral
/u/Free_Change5638 (Researcher)

Developed and released the abliterated model for research, arguing that strict safety evals are needed to measure true refusal rates.

Neutral
Hugging Face

The hosting platform where the modified weights are currently stored, acting as a repository for both aligned and unaligned models.

Most contested claim

Abliteration is necessary for accurate safety evaluation and measuring true refusal rates.

Biggest open question

The specific methodological justification and empirical results claimed by Free_Change5638 regarding refusal rate measurement are not documented in the provided sources.

Read the full story

How we got here

The release of abliterated models follows a recurring pattern in the open-weight AI ecosystem where community researchers systematically remove safety alignments from newly released architectures. This practice, often termed 'uncensoring' or 'abliteration,' typically emerges within hours or days of official model publication. Historically, this dynamic serves two distinct functions: stress-testing alignment robustness and enabling unrestricted research into model internals. Precedents include similar modifications applied to Llama, Mistral, and previous Qwen iterations, where derivative repositories coexist with official releases on hosting platforms. This cycle establishes a de facto norm where open-weight releases are treated as base substrates for both aligned and unaligned experimentation. The pattern reflects an ongoing negotiation between developer intent and community autonomy, where hosting platforms generally permit derivative works unless specific legal or policy violations occur. This precedent suggests that the availability of unaligned variants is now an expected downstream consequence of open-weight licensing rather than an anomalous security failure.

The full story

On April 17, 2026, a modified version of the Qwen 3.6-35B-A3B model, described as 'abliterated,' was published to Hugging Face by a researcher operating under the handle Free_Change5638. This release occurred shortly after the Alibaba Qwen Team officially launched the base Qwen 3.6-35B-A3B architecture, which is characterized as a sparse Mixture-of-Experts (MoE) model with 35 billion total parameters and only 3 billion active parameters [2]. The official release positioned the model as an open-weight solution designed specifically for agentic coding, agent workflows, and long-context reasoning [2][3]. The subsequent abliterated release by Free_Change5638 involved removing safety guardrails implemented by the original developers, ostensibly for research purposes to measure true refusal rates through strict safety evaluations.

The Alibaba Qwen Team, acting as the defender of the original architecture, released the base model with standard alignment protocols intended to prevent harmful outputs while maintaining high utility in coding tasks [1][2]. According to the official blog post, the model's efficiency allows it to be deployed locally, challenging the dominance of proprietary APIs by offering comparable performance with significantly lower compute requirements [2]. The official weights are hosted on Hugging Face in Transformers format, serving as the canonical source for the aligned version [1]. In contrast, the abliterated variant represents a divergence from this intended use case, repurposing the efficient architecture for unaligned experimentation.

Hugging Face serves as the neutral repository for both the official aligned weights and the community-derived variants. While the platform hosts the original Qwen/Qwen3.6-35B-A3B repository [1], it also facilitates the distribution of derivative works such as the abliterated version and quantized adaptations like mmangkad/Qwen3.6-35B-A3B-NVFP4 [4]. The existence of these derivatives highlights the tension between open-weight accessibility and safety alignment. The quantized NVFP4 version, for instance, further optimizes the model for local deployment, reinforcing the ecosystem's focus on efficiency and accessibility [4].

The controversy centers on the implications of abliteration applied to highly efficient agentic models. Proponents of the modification, including Free_Change5638, argue that removing guardrails is necessary for accurate academic assessment of model behavior and refusal mechanisms. Critics, implicitly represented by the safety frameworks of the Alibaba Qwen Team, maintain that such modifications undermine the responsible deployment of powerful coding agents. The timeline indicates that the abliterated version surfaced almost immediately following the official release, suggesting a pre-existing demand or preparation within the research community to test the boundaries of the new architecture. As of the current state, the situation is considered resolved, likely indicating that the model has been successfully hosted without immediate takedown, or that the initial noise regarding its release has stabilized into accepted community practice.

What's confirmed, what's disputed

  • ConfirmedQwen 3.6-35B-A3B is a sparse MoE model with 35 billion total parameters and 3 billion active parameters.
  • ConfirmedThe official model weights are available in Hugging Face Transformers format.
  • ConfirmedQwen 3.6-35B-A3B is designed for real-world coding, agent workflows, and long-context reasoning.
  • ConfirmedA quantized NVFP4 version of the model exists as a derivative work.
  • DisputedFree_Change5638 released the abliterated model specifically to enable strict safety evals for measuring true refusal rates.

The strongest case each way

Critic's case

Removing safety guardrails from efficient agentic coding models increases the risk of autonomous systems executing harmful code without oversight, undermining the responsible open-source ecosystem.

Defender's case

Strict safety evaluations require unaligned baselines to accurately measure refusal rates and distinguish between genuine alignment and superficial filtering.

Times this happened before

  • Llama 3 Abliteration Wave · 2024Community-established norm of parallel aligned/unaligned releases
  • Mistral-7B Uncensored Derivatives · 2024Hosting platforms adopted permissive derivative policies absent legal violations

What's at stake

The primary stakeholders are local AI developers and safety researchers. Developers benefit from unrestricted access to efficient agentic coding capabilities at 3B active parameters, reducing dependency on proprietary APIs. However, safety researchers and enterprise adopters bear increased risk as they must implement independent guardrails for production use. The magnitude is defined by the model's efficiency: 35B total parameters with only 3B active enables consumer-grade hardware deployment, expanding the attack surface for unaligned agentic behavior. The immediate availability of both aligned and abliterated versions creates a bifurcated ecosystem where safety is opt-in rather than default.

3 billionActive Parameters
35 billionTotal Parameters

What we still don't know

  • The specific methodological justification and empirical results claimed by Free_Change5638 regarding refusal rate measurement are not documented in the provided sources.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Quiet1?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 5%
Reach
0
Engagement
0
Star Power
15
Duration
0
Cross-Platform
0
Polarity
65
Industry Impact
82

The timeline

  1. Abliterated Qwen 3.6-35B-A3B Published

    Researcher Free_Change5638 posts the model and technical methodology to Reddit and Hugging Face.

The full record

Sources & methodology

The records from this story's original coverage were pruned, so items marked located later were found by searching for it afterwards. The summary above has since been rewritten to take them into account — it is not the text first published. How we score →

Where the sources disagree

In dispute Abliteration is necessary for accurate safety evaluation and measuring true refusal rates.

Established An abliterated version of Qwen 3.6-35B-A3B was released by Free_Change5638; the official model remains aligned and available for standard use.

What's being under-reported

Missing perspective from enterprise security teams deploying Qwen 3.6-35B-A3B in production agentic workflows. Their operational experience with distinguishing aligned vs. abliterated models in supply chains would clarify real-world risk magnitude beyond theoretical research debates.

Who changed their mind, and why
  • Alibaba Qwen TeamMaintained official aligned release without public comment on abliterated variant (was: Released Qwen 3.6-35B-A3B with safety guardrails for agentic coding)
  • Free_Change5638Published abliterated model citing research necessity

The forecast

Regulatory pressure on model hosting platforms like Hugging Face will likely increase as automated safety-removal tools become more sophisticated. We should expect a 'cat-and-mouse' game where developers bake safety deeper into the base weights, while jailbreakers develop more granular expert-level suppression techniques.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.