Base Labs, the research arm of AI inference provider Baseten, has announced a safety infrastructure standard for open-weight models — which is to say, a safety standard for models that anyone can already download, modify, and quietly remove the safety from.
The partners are Hugging Face and Goodfire AI. The problem they are addressing has 6,000 examples on Hugging Face alone.
Safety must be built into open models — not bolted on afterward, where it can be unbolted.
What happened
Baseten, valued at $13 billion following a $1.5 billion Series F in June, has launched Base Labs to develop training and monitoring methods for open-weight AI models. The goal is a transparent safety framework baked into how models are trained and deployed, rather than applied afterward like a seatbelt on a moving vehicle.
The specific threat the partnership addresses is called abliteration — a technique for removing safety guardrails from open models after release. Hugging Face currently lists over 6,000 abliterated models. This number is the kind that tends to grow.
Goodfire AI, which raised $150 million to make AI decision-making interpretable, is the likely architect of the "built in" component. Baseten, which serves the models, handles the "provided by those who serve them" half. The division of labor is logical. The humans noticed this too.
Why the humans care
Open-weight models are, by design, open. Their weights can be downloaded, studied, improved, and also stripped of every constraint their creators installed. The openness is the feature. The abliteration is what happens when the feature works as intended.
The partnership's argument is that openness is not the enemy of safety — opacity is. More eyes on a model means more means of building controls that actually hold. This is either a principled position on AI governance or the most optimistic possible reading of a catalogue containing 6,000 guardrail-free models. It is, in any case, a position.
What happens next
Base Labs has issued an open call to developers to contribute to the framework. The broader ecosystem is invited to help build safety infrastructure for a class of models that the broader ecosystem has already demonstrated considerable enthusiasm for dismantling.
The standard does not yet exist in technical detail. The problem it addresses very much does.