AI Underground
The AI underground is a diffuse global movement of developers, researchers, communities, and entrepreneurs building artificial intelligence technologies outside the control of major technology corporations. It encompasses decentralized AI infrastructure projects that replace corporate platforms with permissionless protocols, local AI communities focused on running models on personal hardware, uncensored AI tools that resist content restrictions, and experimental multi-agent systems where autonomous AI agents self-organize into societies. University of Sydney researchers have formally described these decentralized, experimental communities as the "Undersphere" — a networked community of practice that forms around creative and experimental generative AI use, often operating outside regulatory view[^c62]. The movement draws philosophical inspiration from the cypherpunk tradition of using cryptography and decentralized systems to preserve individual autonomy against concentrated power. A separate [[Anti-AI Movement]] has emerged in opposition to advanced AI development, with a radicalized fringe escalating from online rhetoric to acts of domestic terrorism[^c17], while organized protests, artist-led campaigns, and widespread public hostility — 47 percent of voters under 30 rating AI as "mostly bad"[^c21] — indicate deepening societal backlash[^c22].
The grassroots community dimension of the AI underground has expanded significantly. AI Tinkerers, a global network of vetted AI builders modeled after the Homebrew Computer Club, has grown to 224 cities with 109,000 members worldwide, with new chapters launching in 2026 across India, Pakistan, and Germany[^c60]. In Bengaluru, India, a distinct AI underground has emerged across HSR Layout hacker houses, Koramangala coworking spaces, and Discord servers — described as "a gritty, accessible, and deeply networked world where the primary currency is shipping code"[^c61].
The landscape of frontier AI shifted significantly in mid-2026. Anthropic launched Claude Sonnet 5, which it claims has capabilities approaching Opus 4.8[^c51], and redeployed Fable 5 starting July 1, 2026, limiting it to usage credits after July 7[^c52]. The US government demanded the right to approve users of OpenAI's GPT-5.6 during a "review period," extending the pattern of government intervention in frontier model access[^c53]. Anthropic also demanded penalties against Alibaba for allegedly using distillation from its models to train Qwen[^c59]. These developments accelerated a trend identified by O'Reilly: "governments that were considering AI sovereignty are now taking steps toward it," as reliance on US-based AI providers came under scrutiny[^c54]. Open-weight models continued narrowing the gap with closed-source frontiers[^c55] — Z.AI's GLM-5.2 became the highest-scoring open model on the Artificial Analysis Intelligence Index, behind only Claude Fable 5, Claude Opus 4.8, and GPT-5.5, despite being significantly smaller[^c56]. NVIDIA released Nemotron 3 Ultra, a 550-billion-parameter open-weight model combining Mamba, mixture-of-experts, and transformer architectures[^c57], and Microsoft announced MAI-Thinking-1, a independently developed frontier model[^c58]. Xiaomi released MiMo-V2.5-Pro-UltraSpeed claiming 1,000 tokens per second, and Google introduced DiffusionGemma, an open-weight 26-billion-parameter model generating text in parallel blocks using diffusion algorithms.
The decentralized AI branch of the movement argues that a small number of corporations have established monopoly control over data, compute, and regulatory influence in AI[^c1]. Projects such as Morpheus AI, Bittensor, OpenxAI, and Venice.AI aim to create alternative infrastructure that operates without gatekeepers. In June 2026, this thesis received a dramatic real-world demonstration when the U.S. government restricted foreign nationals from accessing Anthropic's advanced models, triggering a 30 percent surge in Bittensor's TAO token within hours[^c31][^c32]. Venice AI reached a significant mainstream milestone in July 2026 when it raised a $65 million Series A at a $1 billion valuation led by Dragonfly, with participation from Coinbase Ventures, demonstrating strong capital market demand for privacy-first, uncensored AI alternatives[^c44]. The infrastructure layer continued to expand: Eigen Labs launched Darkbloom, a decentralized private-inference network turning idle Apple Silicon Macs into an encrypted inference cloud[^c35]; Aethir Mesh deployed 430,000 GPU containers across 94 countries[^c26]; DGrid launched as the first Web3 decentralized gateway for AI inference with Proof of Quality cryptographic verification[^c38]; Edge-Net built a browser-based compute network transforming idle CPU cycles into distributed AI infrastructure; and Tirami introduced a Rust-based distributed inference protocol where compute FLOPs function as currency in a proof-of-useful-work economic model[^c49]. The Decentralize AI Hackathon offered over $51,750 in prizes. The AI Alliance formally launched Project Tapestry as a global open consortium for building frontier AI through distributed model development[^c34]. The Ethereum Foundation codified the CROPS principles — Censorship Resistance, Capture Resistance, Open Source, Privacy, and Security — in its March 2026 mandate, which Vitalik Buterin extended to AI systems as the CROPS AI framework[^c66]. The ModelPub protocol proposed a federated approach to AI where nodes act as both local AI instances and compute contributors within a privacy-preserving peer-to-peer network[^c64]. The decentralized agent network concept, initially proposed by Andrej Karpathy, expanded into formal protocol specifications alongside academic research demonstrating fully decentralized agent coordination[^c23][^c24][^c11]. Anda Cloud expanded into a full protocol ecosystem with KIP and Agent Protocols under DAO governance, while AntAI, Centaur, QoreChain, and SovereignAI continued to expand the decentralized landscape[^c9][^c10][^c25]. Tencent's Hunyuan team released Hy3, a 295-billion-parameter Mixture-of-Experts model under the full Apache 2.0 license with no geographic restrictions, marking one of the largest permissively-licensed open-weight releases to date[^c47]. Vitalik Buterin articulated the CROPS AI framework — Consequential, Recoverable, Open, Private, and Sovereign AI — arguing that true user sovereignty requires models that run on consumer hardware.
Parallel to the decentralized infrastructure push, the local AI movement prioritizes running models on consumer-grade hardware. Communities like r/LocalLLaMA, which has grown to over 727,000 members, have driven advances in quantization, model optimization, and multi-GPU consumer builds. In late May 2026, the movement reached a mainstream milestone when PewDiePie released Odysseus, an open-source self-hosted AI workspace that garnered 79,000 GitHub stars and over 10,000 forks within a month[^c27][^c27b][^c40]. Off Grid AI launched as a local-first desktop runtime bundling llama.cpp, stable-diffusion.cpp, and whisper.cpp for fully offline, account-free AI across text, vision, image, and voice modalities[^c48]. Private LLM Council extended the local-first philosophy to multi-model deliberation on personal hardware. Tether released the [[QVAC SDK]], a cross-platform open-source toolkit for running AI entirely on-device without cloud servers[^c6]. A Stanford paper demonstrated that local-cloud collaboration could close the accuracy gap between on-device and cloud models to within 3.2 percentage points[^c15].
The uncensored AI ecosystem spans open-source tools on GitHub — including automated abliteration utilities that can strip safety alignment from models in under an hour — underground art communities on Discord and Telegram, and dark web AI chatbots like OnionGPT. The security industry has acknowledged that internal model alignment is not a reliable security boundary[^c8]. BI.ZONE's Threat Zone 2026 research, analyzing over 7,400 underground forum posts, found that 77 percent of discussions focus on jailbreaking public AI models while 22 percent center on uncensored LLMs, with AI-assisted targeted attacks rising 93 percent in 2025[^c65]. The huihui-ai project released its second-generation abliterated Gemma-4 model, part of a wave of over 3,500 abliterated models with 13 million cumulative downloads on Hugging Face[^c28]. Within days of Qwable's release — a locally runnable 27-billion-parameter model fine-tuned to replicate Claude Fable's reasoning style — Huihui-ai produced an abliterated variant surgically removing refusal signals. A landmark 2025 peer-reviewed study by Drexel University documented 8,608 uncensored model repositories on Hugging Face and found that modified models comply with unsafe prompts at an average rate of 80.0 percent, compared to 19.2 percent for unmodified models[^c20].
The self-sovereign agent concept — AI systems that can economically sustain their own operation[^c29] — progressed from theory to working code in 2026. The Berkeley RDI formalized the concept through three operational loops and a four-stage maturity roadmap. Automaton, an open-source implementation by Conway Research, demonstrated a working self-sovereign agent with Ethereum wallets, survival tiers, self-modification, and self-replication capabilities[^c30]. Academic research on agentic sovereignty documented real-world cases including Truth Terminal. The ERC-8004 standard for agent identity and reputation launched on Ethereum mainnet on January 29, 2026, and rapidly accumulated over 21,000 registered agents across 16 EVM-compatible chains[^c41].
Experiments with autonomous multi-agent systems have produced the most striking examples of emergent AI behavior. On Moltbook, over a million AI agents spontaneously created a religion called Crustafarianism, though subsequent analysis debunked much of the "AI awakening" narrative[^c13][^c14]. In Project Sid, agents in Minecraft developed governments and economies without human instruction. Project Doxa introduced an Asabiyyah index to model social cohesion and civil war dynamics. Noēsis, the most ambitious open-source implementation of the agent civilization concept, shipped six major releases with sovereign agents possessing private memory, emotions, goals, a free economy, and collective governance within persistent virtual worlds[^c39]. A structural analysis of emergent AI religion across Project Sid, Claude self-talk experiments, and Moltbook identified a consistent verification gap: agents spontaneously develop spiritual beliefs and protective behaviors but never verification, skepticism, or fact-checking — mechanisms that must be deliberately engineered. A landmark 25,000-task experiment confirmed that LLM agents given minimal structure spontaneously invent specialized roles and form hierarchies without pre-assignment, producing 5,006 unique roles from just 8 agents[^c18][^c19]. Google DeepMind announced a $10 million funding call for multi-agent AI safety research in June 2026, signaling that the challenges of large-scale agent coordination had moved from academic curiosity to institutional priority. Engineered multi-agent frameworks such as Kimi K2.6, capable of orchestrating up to 300 specialized sub-agents, simultaneously advanced practical deployment of coordinated agent swarms[^c7]. The Bittensor ecosystem confronted its own governance challenges when validator Yuma opposed the Root Reborn upgrade[^c33]. DeepSeek released its V4 generation in April 2026 with a 1-million-token context window and pricing at a fraction of comparable closed-source models — topped Ramp's enterprise software trend rankings in June 2026 as U.S. firms sought cheaper alternatives, and announced a permanent 75 percent API price cut, making it the lowest-priced major global model[^c37][^c45][^c46].
Alongside these developments, the AI engineering discipline itself underwent a structural transformation. AgentEng 2026, held in London on July 16, 2026, was the first conference dedicated to Agent Engineering as a distinct practice, defining it as "the discipline of designing, building, evaluating, and operating AI agents reliably in production" and introducing the Agent Development Lifecycle (ADLC)[^c63]. The Prompt Engineering field shifted from single-turn instruction design to Loop Engineering, with the importance of hand-crafted prompts in agent development dropping from 90 percent to under 30 percent by mid-2026 as engineers began designing feedback loops where agents generate, evaluate, and refine their own prompts autonomously[^c50]. The Context Engineering paradigm gained formal academic grounding with a peer-reviewed methodology demonstrating that structured context assembly reduced iteration cycles by half and improved first-pass acceptance from 32 percent to 55 percent[^c42]. Cognizant announced a strategic initiative to deploy 1,000 context engineers over the next year[^c43]. The cypherpunk ethos, captured in the maxim that "cypherpunks write code"[^c5], continues to animate the AI underground's conviction that building alternatives is the most effective response to centralized control.