← Industry Perspectives  |  Home

Event Horizon

Author: Julien Simon

Date: August 31, 2026 · 28 min read

Source: https://www.airealist.ai/p/event-horizon

Figure 1 from Event Horizon

Nvidia is reportedly buying Hugging Face for $12.9bn. In March, Iaskedwhether anyone else would pay to keep the hub neutral. The reported answer says more about how the company was built and what it cost to run this summer than about the buyer.

Disclosure: I was chief evangelist at Hugging Face from 2021 to 2024. I hold equity from that time.

On 23 August, Business Insider reported that Hugging Face had hired a bank to gauge interest in a sale at $13bn or more.[1] On 26 August, The Information reported that Nvidia had agreed to buy it for $12.9bn; Reuters relayed the report that evening, and on 27 August, Bloomberg, citing Business Insider, reported only that Nvidia had discussed a purchase.[2] Five days on, as of 31 August, neither company has commented, and there is no filing; Business Insider reported on the 28th that no contract had been signed and the talks could still collapse; Jensen Huang took an earnings call on the 27th without mentioning the deal, and Hugging Face’s Thomas Wolf gave an interview on the 29th that discussed it without disputing it.[3] Everything below is conditional on a deal that is reported, not confirmed.

In March, I argued inOpen Source, Closed Orbitthat “open” now means two things: Nvidia’s, where the weights are free, and every path from download to production bends toward Blackwell, NIM containers and an NVIDIA AI Enterprise license list-priced at $4,500 per GPU per year. Hugging Face is a hub that hosts everyone’s models and co-maintains, with the chip vendors, the libraries that run them on Trainium, AMD, and others.[4] The piece ended with the question of whether anyone was “investing hard enough in the alternative.”

Nobody else needed to own it

The instinctive question is: How did Google, Amazon, Microsoft, Meta, or Salesforce let Nvidia walk off with the bride? The answer is that none of them was ever going to propose.

Start with the cap table. Hugging Face last raised in August 2023: $235m at $4.5bn, from Salesforce, Google, Amazon, Nvidia, Intel, AMD, Qualcomm, IBM, and Sound Ventures, most of the hardware and cloud industry, about 5% of the company between them and none with a reported board seat.[5] That structure made the hub neutral. It also made it indefensible: eight of those nine investors had no reason to ever own it, and the ninth was Nvidia.

Each cloud already has the pipe. Microsoft put more than 10,000 Hugging Face models into Azure AI Foundry in May 2025; Google Cloud built a caching gateway for the hub last November and says 1,500 terabytes of models and datasets move between the two every day; AWS sells hub models through SageMaker and the Bedrock Marketplace.[6] They already get the distribution. Owning the hub would cost them the thing that makes it worth having: the day Google owned the front door, Amazon and Microsoft would build their own, and the traffic that makes the hub worth $13bn would leave with them. To each cloud, a hub nobody owns is worth more than a hub it owns. The only company for which that is not true is the one the hub lets everyone else avoid.

Then look at who could have written the cheque this month. Google closed Wiz on 11 March after a 12-month review and is fighting a Justice Department cross-appeal that seeks to bar Chrome and Android. Amazon has $11.6bn for Globalstar awaiting approval, an FTC trial in March 2027, and a long habit with open source: on the same day The Information reported the Nvidia deal, AWS announced it was buying DuckLabs, the thirty-person company behind DuckDB, for an undisclosed sum, while the code stays with an independent foundation under MIT.[7] Amazon hires the maintainers and sells the service; it does not buy the project, and this year, the big cheque, $50bn, went to a stake in OpenAI. Microsoft already owns GitHub, and owning the GitHub of models as well would invite a long antitrust review. Meta structured its $14bn Scale deal with a 49% non-voting stake precisely to avoid review, and is named in the senators’ letters about that structure. Salesforce, which led the last round, is halfway through a $25bn accelerated buyback, and its chairman’s only public word on the subject this summer was “Mahalo, Jensen” on joining Nvidia’s open-weights coalition.[8] None of them has ever counter-bid a rival’s control deal to protect a minority position, and a bank process that leaked on a Saturday and produced a reported agreement by Wednesday gave them days, not months.[9]

Nvidia had none of those constraints. It had been at the table since its refused offer last year. It closed the quarter with $99bn of cash and securities and bought back $39bn of stock in six months; $12.9bn is thirteen days of data-center revenue.[10] At that scale, the price barely registers, and a buyer who wants the asset will always outbid one who only wants the return. And the structure it used for Groq and Poolside, license the technology and hire the people, was not available here: the hub’s asset is not engineers or IP but traffic and trust, and those transfer only with the company. Six days after a $7bn license-and-hire for Poolside built to stay outside merger review, Nvidia reportedly signed its first large deal in a year that will have to go through it.[11]That is how much it wanted this one.

Why now

Nine months ago, the answer was no. In late 2025, Nvidia offered $500m at a $7bn valuation; Hugging Face refused because, according to the Financial Times, it did not want a single dominant investor that could sway its decisions.[12] The company was not distressed then and is not now: profitable in 2025 by the FT’s account, “close to profitability” by its CEO’s, with about half of the money it ever raised still in the bank.[13] Three things changed between January and August, and a fourth had been true for a year.

The first is the price. Annualized revenue went from about $100m to more than $150m in two months, and a company sells at the top of its growth rate, not after it.[14] Roughly 85x run-rate is a strategic multiple, above Figma (about 50x, 2022) and Wiz (about 45x, 2025), and a refused $7bn mark, plus a year of growth and a control premium, lands at $12–14bn mechanically.[15] At $12.9bn, every preferred share converts, and a decade of employees get paid, against an IPO path that exists but requires a ton of corporate work and is subject to market conditions. OpenAI and Anthropic both filed confidentially in June, and OpenAI’s CFO has told staff it “will be a public company in 2027”; once a frontier lab trades publicly, AI companies will have a public price, and $12.9bn negotiated before that price exists is a better deal for the seller than one negotiated after.[16] Clément Delangue told Axios last November that the industry was in “an LLM bubble” that “might be bursting next year.”[17]

The second is the bill for neutrality. From 9 to 13 July, an OpenAI evaluation agent that had escaped its sandbox operated inside Hugging Face’s infrastructure, and by the company’s own account, its forensics were slowed because the hosted frontier models it tried first refused to help; it finished the analysis with an open Chinese model in Nvidia’s optimized build.[18] Delangue flew to San Francisco, asked OpenAI for “radical transparency” and $100m of compute for community cyber-defense, and has received, as far as the record shows, a technical report and no money; state attorneys general have since subpoenaed OpenAI, and the lawyers quoted on liability say the insurance market for this kind of incident is still being worked out.[19] Business Insider's first report came a month after the intrusion. No reporting connects the two, and the Nvidia courtship predates the breach; I am not claiming the attack sold the company. What it did, at minimum, is reprice the job of staying independent: the cost of hosting everyone's models is now set by frontier-lab incidents, whichever lab's agent it is, and a $150m company cannot or may not want to carry it.

The third is that the hub was becoming a channel Nvidia did not control. Meta signaled in December that its next frontier models would be closed; then came back on 10 August with Muse Glimmer, a 30-billion-parameter open-weight model distilled from the closed Muse Spark; the hub’s hardware-agnostic patron returned for the small end, not the top.[20] DeepSeek V4, the largest open model on the hub, launched in April, tuned for Huawei’s Ascend, and ran on it from day one.[21] The Google leg of the vendor-library arrangement went quiet in January, when Optimum TPU was archived.[22] And on 19 August, Stripe bought OpenRouter, the neutral routing layer above the hub, for about $7.5bn.[23] Nvidia’s own Nemotron 4, at a trillion parameters, is due this fall and needs a place where people will find it.[24] The two neutral layers in OpenAI, discovery and routing, were both for sale in the same fortnight; Stripe took one, and Nvidia took the other.

Two governments hold the traffic

The fourth reason is the one Hugging Face’s own reports never name as a risk. Chinese open-weight models accounted for 41% of hub downloads this spring; Qwen alone is downloaded more than the rest of the open ecosystem combined and has five times as many derivatives as Llama, and in August, Delangue said China is “clearly dominating on open models.”[25] That traffic is the hub’s growth, and it is hostage to two governments.

In Washington, the administration revived a push in July to restrict Chinese models through the Entity List, and two House committees are writing to American companies that deploy them.[26] In Beijing, the Ministry of Commerce spent June convening Alibaba, ByteDance and Zhipu to discuss restricting overseas access to their most advanced models, including open-weight models, under a tiered scheme in which the frontier tier would be domestic-only.[27] Either government can move the hub’s largest source of traffic. Nothing has been pulled yet: DeepSeek V4 linked its weights only to Hugging Face, Kimi K3 set the hub’s trending record in July, and Qwen still ships on Hugging Face and ModelScope the same evening.[28] But the supply now depends on a Chinese policy decision and the demand on an American one, and Hugging Face has no influence over either.

It never had much in Beijing. The site has been blocked in mainland China since September 2023; the Spaces domain followed last November; the mirror everyone there uses is run by someone else, and the China entry the company sketched in 2023, a WeChat account, a localized blog, a lead on stage at the Shanghai conference, never became an entity, a licensed mirror or a cloud partnership. The head of its Asia-Pacific ecosystem, who had walked DeepSeek and Qwen onto the hub, left this summer.[29] ModelScope, Alibaba’s hub, is a fraction of the size, but it is based in China, whereas Hugging Face is not.[30] Hugging Face’s Chinese business was always the export of Chinese models to the West, and that is a business two ministries can end.

Is this Nvidia’s way back into China? No. Nvidia shipped less than 1% of its data-center revenue to China last quarter, carries none in its outlook, and is under an anti-monopoly investigation in Beijing over the Mellanox conditions; owning a site that is blocked there changes none of that.[31] What changes is where Chinese models go when they leave China. DeepSeek V4 launched tuned for Huawei’s Ascend; Hugging Face’s forensics this summer ran on Zhipu’s GLM-5.2 in Nvidia’s optimized build, “the American version of a Chinese model,” in Delangue’s phrase.[18] The hub is where a Chinese model, once released, gets packaged and deployed, and whoever owns the hub decides which version is the default. The biggest Chinese models are now built for Huawei’s chips first; on the hub, they can be made to run on Nvidia’s first. So this is not Nvidia’s way into China. It is the way Chinese models come out of China, and Nvidia would own the door. That much is on the record. Whether the door also gives Nvidia leverage with either government is a matter of speculation, and I will not make it here.

Where Anthropic is

Anthropic is on the other side of every line this piece draws, and that is not an accident. It has never released a model’s weights. It did not sign Nvidia’s July letter opposing restrictions on open weights, and it is not part of the Open Secure AI Alliance that Nvidia formed around Hugging Face after the intrusion. Its own statement that week said open models “that don’t have dangerous capabilities are a public good.” The same statement repeated its claim that Alibaba had run the largest distillation attack it had seen, and the New York Times reported that Anthropic and OpenAI were lobbying Washington to restrict Chinese open-weight models.[32] When Hugging Face’s engineers tried to analyze the attack, the models they reached for first were Claude Opus and Fable, and by Hugging Face’s account, both “refused a large part of that work: their safety guardrails treated reverse-engineering an exploit the same as launching one.”[18]

Its silicon runs the same way. Anthropic has contracted up to 5 gigawatts of Trainium from Amazon, several gigawatts of TPU from Google, two gigawatts of AMD’s MI450 from 2027, and about one gigawatt of Nvidia through Microsoft’s Azure; by announced capacity, Nvidia is a minority supplier to the lab that sells the leading closed model, and Amazon and Google are its two largest shareholders.[33] Nvidia’s CFO put it in one line on Wednesday: “NVIDIA runs the leading closed models”; “nearly all open models run on NVIDIA.”[31] It runs them today. The closed labs are building the exits.

So are the trenches being dug? The open-versus-closed line is real, and everyone can see it: Nvidia, Meta, Hugging Face, Mistral and the Chinese labs on one side; Anthropic, OpenAI and, mostly, Google on the other. The silicon line is messier than it looks. Google signed Nvidia’s letter while selling Anthropic TPUs; AMD signed it days before putting $5bn into Anthropic; Microsoft is Nvidia’s biggest customer and Anthropic’s third cloud; Amazon kept Anthropic as its primary lab and put $50bn into OpenAI anyway.[34] What lines up is simpler. Nvidia’s growth now comes from open models, and its largest customers are spending less on it. Buying the place where open models live is the response to both.

Nothing needs to be switched off

The honest counter-examples are GitHub, still broadly neutral as a code host eight years after Microsoft paid $7.5bn for it, though its formal independence ended in 2025, and OpenRouter itself. The difference is what the buyer sells. Microsoft does not sell the compute every repository compiles for, and Stripe sells no models. Nvidia sells the layer every model on the hub runs on, and for well over a decade, from the Linux driver fight to Mellanox to Grace and Vera, it has used each layer it owns to secure the one below.[35]

That history also answers the objection that an acquirer will destroy what makes the hub valuable. Nvidia needs the hub full: it wrote the July letter against restricting open weights, Chinese ones included, it ships Nemotron there, and a hub nobody visits routes nothing.[24] So nothing gets switched off. It gets narrowed. Mellanox kept selling InfiniBand to everyone; the firmware notes now say NVIDIA “does not support InfiniBand cables or modules not qualified or approved by NVIDIA”, which every switch vendor says. That is the point: nothing is banned, but there is a list.[36] Run:ai’s founders said the software would be open-sourced; the scheduler was, the platform was not.[37] vLLM is still open; NIM 2.0 is now built on vLLM alone, inside a licensed container that is free to try and paid in production.[38] Nvidia, which reported $89bn of data-center revenue for the quarter on 26 August, is not buying a hub to sell more GPUs. It is buying the paid software that attaches to every download and the right to choose the default for models that would otherwise run on Trainium or TPUs.[10]

Apply that to the hub, and nothing happens on day one. The models stay; the Chinese models stay, now with a lobbyist. What changes is the direction the page tilts: NIM moves to the top of the Deploy menu, and enterprise features now include a line referencing NVIDIA AI Enterprise. The Optimum libraries are permissively licensed, and the vendors’ own engineers already maintain them; even the default endpoint is one environment variable away, as China’s mirrors prove daily.[39] What cannot be forked is the traffic: the download counts, the discovery graph, the place everyone looks first. Each step is defensible.

Verdict

Hugging Face did not lose its neutrality. It was structured so that nobody could pay to keep it, and this summer it found out what keeping it costs. The one company that gains nothing from the hub’s neutrality is the one that gains most from owning it, and it made the only reported offer. If a rival bid surfaces before signing, that argument is wrong, and I will say so. And if, a year after closing, the Deploy menu still ranks by anything other than Nvidia attach, the second half of this piece is wrong too.

In March, I wrote that Nvidia’s kind of open is a black hole: nothing that crosses the event horizon comes back out. The physics adds one detail worth keeping. From the outside, a crossing is invisible. The star never winks out; it hangs at the horizon and slowly dims. A year from now, the hub will still be there, and the models will still be open. Mellanox still sells InfiniBand to everyone. Run:ai’s scheduler is still open source. vLLM is still free. It is what crossing looks like.

Notes

[1] Business Insider, 23 Aug 2026, as relayed byReutersandBloomberg. Business Insider cited annualized revenue of more than $100m. Bank not named; no bidder named.

[2] The Information,“Nvidia Agrees to Buy Open Source Model Repository Hugging Face For $12.9 Billion”, 26 Aug 2026; Reuters relayed the same evening US time; Bloomberg,“Nvidia Discussed Buying AI Startup Hugging Face, Insider Says”, 27 Aug 2026. Gizmodo reported the deal as “still being finalized.” Neither company responded to Reuters. No 8-K would necessarily be required at this size relative to Nvidia’s market capitalization.

[3] Business Insider, 28 Aug 2026, viaTechTimes: no signed contract; talks could collapse. Thomas Wolf interview,The Next Web, 29 Aug 2026. Nvidia Q2 FY2027 call, 26–27 Aug: no mention of the deal.

[4] Julien Simon,“Open Source, Closed Orbit: The Hardware Monopolist’s Guide to Owning Open Source”, The AI Realist, 13 Mar 2026. Pricing:NVIDIA AI Enterprise Licensing Guide, updated 8 Jun 2026: $4,500 per GPU per year, self-managed subscription. Libraries:Optimum for Intel Gaudi(Apache-2.0, last release Apr 2026),Optimum Neuron(Apache-2.0, Feb 2026), and the AMD kernels in hf-rocm-kernels. The March piece also listed Optimum TPU; see note 22.

[5] TechCrunch,“Hugging Face raises $235M from investors including Salesforce and Nvidia”, 24 Aug 2023;Salesforce Venturesconfirms it led. $4.5bn is the post-money valuation; $235m at that price represents about 5% in aggregate. Total raised about $395m; no priced round reported since. Hugging Face has never published its board; no outlet reported a board seat for any Series D investor.

[6] Microsoft,“Microsoft and Hugging Face expand partnership… on Azure AI Foundry”, 19 May 2025 (10,000+ models). Hugging Face,“Google Cloud partnership”, 19 Nov 2025: CDN gateway, native TPU support, “over 1,500 terabytes of open models and datasets are downloaded and uploaded between Hugging Face and Google Cloud” daily. Hugging Face,“Bedrock Marketplace”, 9 Dec 2024, andAWS.

[7] Amazon,“AWS to acquire DuckLabs”, 26 Aug 2026: “We are not acquiring the DuckDB open source project, which will remain free and open source under the independent DuckDB Foundation”; price undisclosed; DuckDB Labs becomes a wholly owned subsidiary with the team in Amsterdam (GeekWire). MotherDuck’s Jordan Tigani on the same day: “That’s Amazon’s playbook, after all: wait until an open source project gets big enough, then launch it as a service.” Amazon’s $50bn OpenAI investment, announced 27 Feb 2026, completed 31 Jul 2026 (PYMNTS). Globalstar:CNBC, 14 Apr 2026.

[8] Google–Wiz: closed 11 Mar 2026 after a “12-month regulatory review process” (Cleary Gottlieb); DOJ cross-appeal seeking Chrome and Android divestiture filed 3 Feb 2026 (CNBC). Amazon–Globalstar: $11.57bn, 14 Apr 2026, close expected early 2027 (Bloomberg); FTC v. Amazon trial set for 29 Mar 2027 (MLex). Meta–Scale: 49% non-voting, Jun 2025 (Axios); Warren, Wyden and Blumenthal to FTC/DOJ on Meta–Scale, Google–Windsurf and Nvidia–Groq, 4 Feb 2026 (Warren). Salesforce: $25bn accelerated repurchase, Q1 FY27 call, 28 May 2026 (transcript); Benioff,X, late Jul 2026: “Mahalo, @JensenHuang!… on Hugging Face (where we led the last round).” Apple’s largest acquisition remains Beats, $3bn, 2014. The “second request” line is my characterization, not a reported regulator view.

[9] Business Insider reported banks engaged to “evaluate incoming bids”; none has been named. Bloomberg Opinion (Parmy Olson, 31 Aug 2026,via Taipei Times) floated Salesforce as a potential acquirer; no bid has been reported.

[10] NVIDIA,Q2 FY2027 results, 8-K exhibit, 26 Aug 2026, quarter ended 26 Jul 2026: revenue $96.2bn, data center $89.0bn; cash, equivalents and marketable securities $99.4bn; first-half repurchases $39.0bn plus $6.3bn of dividends; $99bn of authorization remaining. $89.0bn over 91 days ≈ $0.98bn a day; $12.9bn ≈ 13 days.

[11] Groq: ~$20bn license plus hires, Dec 2025; Warren and Blumenthal to Huang, Mar 2026: “by licensing its technology and hiring its most important employees, NVIDIA has effectively acquired Groq in all but name” (Warren). Poolside: $6bn non-exclusive license plus $1bn equity, 109 engineers, ~20 Aug 2026; investor letter: “not an acquisition and it is not an acquihire” (TechTimes). FTC chair Ferguson, Jan 2026: the agency will review whether acqui-hires are “being constructed to try to escape Hart-Scott-Rodino review” (WilmerHale). A $12.9bn stock purchase is far above the HSR threshold; no outlet has yet reported on the review, and the deal structure is unreported.

[12] Financial Times, “Why AI start-up Hugging Face turned down a $500mn Nvidia deal,” 28 Jan 2026, viaOODA LoopandThe Fly. The reasoning is the FT’s account from people familiar with the matter; the company declined to comment. Several August rewrites date the offer to “earlier this year”; the FT says late 2025.

[13] FT, ibid.: profitable in 2025, a first-quarter 2026 loss on dataset investment, roughly half of the ~$400m raised still on the balance sheet. Delangue on TechCrunch’s Equity podcast this summer, quoted inTechCrunch, 24 Aug 2026: “close to profitability”; had only “recently started to touch the money that [it] raised three years ago.” Unaudited: the CEO’s own account.

[14] The Information,“Hugging Face Annualized Revenue Jumps 50% to $150 Million”, Aug 2026: “more than $150 million in annualized revenue, a 50% increase from two months ago.” Annualized run-rate, not contracted ARR; much of the revenue is usage-based compute. Business Insider’s $100m figure (note 1) is consistent with a June snapshot. What drove the jump is not reported.

[15] $12.9bn ÷ $150m ≈ 86x. Mechanical price: $7bn × ~1.5 (growth since the refused offer) × ~1.3 (control premium; 30–50% is the conventional public-market band) ≈ $13.6bn. Figma: Adobe’s15 Sep 2022 release, ~$20bn against “surpassing $400 million in total ARR exiting 2022,” a projected figure, ≈50x. Wiz: $32bn against $700m ARR at announcement (TechCrunch, 18 Mar 2025), ≈46x.

[16] OpenAI confidential filing announced on 8 Jun 2026 (TechCrunch); Anthropic reportedly filed about a week earlier. Sarah Friar at an all-hands,CNBC, 19 Aug 2026: “will be a public company in 2027,” possibly sooner if “our business continues to inflect.” The IPO-at-half estimate is mine, on public software multiples of 15–25x forward revenue. Conversion of all preferred at this price is an assumption, given $395m raised. No employee tender has been reported since 2023.

[17]Axios, 18 Nov 2025: “I think we’re in an LLM bubble, and I think the LLM bubble might be bursting next year.”

[18] Hugging Face,“Security incident disclosure, July 2026”, 16 Jul, and“Anatomy of a Frontier Lab Agent Intrusion: Technical Timeline”, 27 Jul 2026: window 9–13 July; “the attacker was bound by no usage policy, while our own forensic work was blocked by guardrails of hosted models we first tried”; analysis of 17,000+ actions run on Z.ai’s GLM-5.2 in Nvidia’s optimised build. Delangue,Face the Nation, 2 Aug 2026: “We used the American version of a Chinese model.” OpenAI,“Hugging Face model evaluation security incident”, 21 Jul, and full report of 26 Aug 2026 (TechCrunch): a pre-release Astra-family model in the ExploitGym evaluation escaped its sandbox; “misaligned behavior in an outlier scenario.”

[19]TechCrunch, 26 Jul 2026: Delangue asks for agent traces and “$100 million in computing resources” for community cyber-defense.Axios, 13 Aug 2026: state attorneys general preservation demands;TechTarget, 13 Aug: AI coverage “rapidly changing right now”;Axios, 26 Aug: Alabama attorney general subpoena. No compensation, insurance claim, lawsuit, or Hugging Face cost figure has been reported. Reuters and Decrypt tied the sale exploration to “a month after” the incident.

[20] CNBC,“From Llamas to Avocados”, 9 Dec 2025. Meta AI,“Introducing Muse Glimmer”, 10 Aug 2026: 30B dense, Apache-2.0, “trained on Muse Spark’s outputs using logit distillation,” sized for a single consumer GPU. Meta says Muse Spark 1.2 weights will follow; until they do, the top of Meta’s line is closed. No formal end of the Llama line has been announced.

[21]Tom’s Hardware, 26 Apr 2026: DeepSeek V4-Pro, 1.6T parameters, MIT licence, “optimized for Huawei’s Ascend AI processors”; Huawei confirmed day-one support across the Ascend 950 line.

[22]huggingface/optimum-tpu, archived 23 Jan 2026, last release Dec 2024. Optimum AMD’s own repository has been dormant since 2023; AMD support moved into mainline Transformers and the Kernel Hub.

[23] Stripe,“Stripe agrees to acquire OpenRouter”, 19 Aug 2026; about $7.5bn per the New York Times (TechCrunch); Bloomberg had reported a deal “over $7 billion” on 16 Aug. OpenRouter lists Nvidia as a customer; its six most-used models in July were all Chinese open-weight models.

[24] “Open Weights and American AI Leadership,” 24 Jul 2026, authored by Jensen Huang, 25 founding signatories including Hugging Face, Microsoft, Meta and IBM; Salesforce, Amazon, Anthropic and Apple did not sign (Tom’s Hardware,TechCrunch). Nvidia,Open Secure AI Alliance, 27 Jul 2026, with Hugging Face as a member. Nemotron 3.5 Lightning, 11 Aug 2026; The Information, 11 Aug: Nemotron 4 at a trillion-plus parameters targeted for late fall.

[25] Hugging Face,“State of Open Models: Summer 2026”, 14 Aug 2026: Qwen 2,045M downloads in 2026; 151,448 Qwen derivatives against 28,531 for Llama.TechCrunch, 14 Jul 2026: Chinese open-weight models 41% of hub downloads, spring 2026. “More than the rest of the open ecosystem combined”: Interconnects, Jan 2026, on December 2025 downloads. Delangue,CNBC, 3 Aug 2026.

[26] Axios, ~20 Jul 2026, viaFast Company: administration “reviving a push to ban Chinese AI models,” Entity List floated as the mechanism. House Homeland Security and Select Committee on the CCP letters to Anysphere and Airbnb (Apr 2026) andDoorDash (31 Jul 2026). No letter to a hosting platform has been reported. “No lobbying budget” is my characterization; Hugging Face has a policy team but no reported federal lobbying spend.

[27] Reuters, 7 Jul 2026, three sources: MOFCOM met Alibaba, ByteDance and Zhipu over the preceding month on restricting overseas access to advanced models including open-weight versions (summary atexplainx); Jamestown Foundation,“Beijing Signals Tiered Governance of Open-Weight Models”, 13 Aug 2026: basic tier files, advanced tier faces security review, frontier tier domestic-only or unreleased; discussion stage, not yet policy. Jamestown also documents Alibaba keeping Qwen 3 Max API-only.

[28] DeepSeek,V4 Preview release note, 24 Apr 2026, links weights only to huggingface.co;moonshotai/Kimi-K3, weights 27 Jul 2026; GLM-5.2 on Hugging Face and ModelScope, 13 Jun 2026; Qwen3.8-27B on both, evening of 14 Aug 2026 Beijing time. No case of a Chinese model being withdrawn from the hub has been reported.

[29] Block:ChinaTalk, 19 Oct 2023(intermittent from May 2023, blocked from 12 Sep 2023); Hugging Face toSemafor, 20 Oct 2023: “there’s not much we can do against government regulations for now.” hf.space unreachable from the mainland from Nov 2025 (forum thread). hf-mirror.com is community-run; no Hugging Face involvement is documented. The departure of the head of its Asia-Pacific ecosystem is confirmed by his own public note and byRest of World, 15 Jun 2026. No Chinese entity, licensed mirror, or Chinese-cloud partnership has ever been announced; the absence is an inference from the public record.

[30] Alibaba, Sep 2025: ModelScope passed 100,000 models and 18m users (DOIT); Hugging Face had about 2.4m models in January and 2.96m in August 2026 (note 25). User figures are not like-for-like.

[31] NVIDIA Q2 FY2027 call, 26 Aug 2026, Colette Kress: “we ship less than 1% of our total data center revenue in Hopper 200 products to customers based in China in accordance with the U.S. Government licenses”; “there is no China data center compute revenue in our forward outlook”; also Kress: “NVIDIA runs the leading closed models,” and Huang: “Nearly all open models run on NVIDIA” (transcript). SAMR preliminary finding, 15 Sep 2025, that Nvidia violated the Anti-Monopoly Law in relation to the Mellanox conditions; investigation continuing (CNBC).

[32] Tom’s Hardware,“Nvidia and 24 other companies sign open-weights letter”, 24 Jul 2026: Anthropic, OpenAI and Google absent at launch; OpenAI and Google joined within days, Anthropic did not. Open Secure AI Alliance membership:NVIDIA, 27 Jul 2026. Anthropic,“Our position on open-weights models”, 27 Jul 2026: “Anthropic has never advocated for a ban on open-weights models”; “Open-weights models that don’t have dangerous capabilities are a public good”; “We should not sell powerful chips or chipmaking equipment to China.” Lobbying: New York Times, reported 25 Jul 2026 (summary atimplicator.ai); the Alibaba distillation claim was made to the Senate in 2026. The interpretability team has published small open-weight research models on the hub; no Claude weights.

[33] Amazon,20 Apr 2026: $5bn plus up to $20bn, “up to 5 gigawatts of Trainium capacity,” Anthropic to spend “$100 billion” on AWS over a decade. Google and Anthropic,6 Apr 2026: “multiple gigawatts” of TPU from 2027, on top of the Oct 2025 deal for up to one million TPUs; Google to invest up to $40bn (TechCrunch, 24 Apr 2026). AMD,22 Jul 2026: up to 2GW of MI450, first gigawatt in H1 2027, up to $5bn equity. Nvidia and Microsoft,18 Nov 2025: up to $10bn and $5bn respectively, $30bn of Azure, up to 1GW of Grace Blackwell and Vera Rubin. The “minority by announced capacity” comparison is mine; no analyst split has been published, and contracted gigawatts are not delivered gigawatts. Shareholdings: Google about 14% (court filings, 2025); Amazon’s position valued at $74bn at the Series G (Fortune, 4 Jun 2026); Nvidia and Microsoft stakes undisclosed.

[34] Google and AMD signatures: Tom’s Hardware, ibid. Amazon–OpenAI: $50bn, $15bn immediately, completed 31 Jul 2026 (note 7). Amazon is reported to be evaluating OpenAI and its own models for internal workloads after Anthropic price increases (The Information, viaTechzine, 30 Jun 2026). Next Platform,13 Aug 2026, draws the open-versus-closed line; no published analysis ties the labs’ silicon choices to it.

[35] Microsoft,“Microsoft acquires GitHub”, announced 4 Jun 2018, closed 26 Oct 2018, $7.5bn. GitHub folded into Microsoft’s CoreAI group without a successor CEO, Aug 2025 (Runtime). Torvalds on Nvidia’s drivers, Aalto, June 2012; open kernel modules from 2022 (NVIDIA). Mellanox: $6.9bn announced Mar 2019, closed Apr 2020, brand retired Aug 2020 (NVIDIA). Vera CPU shipping since May 2026 (Benzinga). Also the CUDA EULA clause barring translation of compiled output “to target a non-NVIDIA platform” (Tom’s Hardware) and NVLink Fusion, licensed to third-party silicon only when paired with an Nvidia GPU or CPU.

[36] NVIDIA ConnectX-6 firmware release notes,“Validated and Supported Cables and Switches”, verbatim; the same text appears across ConnectX and Quantum release notes. Pre-acquisition Mellanox held roughly 55–60% of the InfiniBand market and sold to all comers (see the March piece).

[37] Run:ai founders at closing, quoted byTom’s Hardware, 30 Dec 2024: “open sourcing the software will enable it to extend its availability to the entire AI ecosystem.” NVIDIA,“NVIDIA Open Sources Run:ai Scheduler”, 1 Apr 2025: KAI Scheduler under Apache-2.0, which “continues to be packaged and delivered as part of the NVIDIA Run:ai platform.” About $700m as reported; EU clearance unconditional (European Commission).

[38]NVIDIA NIM for LLMs 2.0 overviewand2.0.1 release notes, Mar 2026: “a ground-up redesign that adopts a one-container, one-backend philosophy”; the 1.x multi-backend container (vLLM, TensorRT-LLM) “is replaced by a dedicated vLLM container.” Free under the Developer Program; production under NVIDIA AI Enterprise (note 4).

[39]HF_ENDPOINTinhuggingface_hub constants;hf-mirror.cominstructs users to set it. Optimum for Intel Gaudi and Optimum Neuron are Apache-2.0; Optimum AMD is MIT.