NVIDIA will acquire Hugging Face for US$12.93 billion (roughly $17.96 billion), as part of its efforts to invest more in open-source AI and grow relationships with developers using the platform’s software, as well as increase its influence in the open-source AI space, which is growing capabilities almost rivalling frontier models from OpenAI and Anthropic.
The payment will include a US$11.9 billion payment as well as a US$1 billion retention program for staff joining NVIDIA.
The company also wants to become less reliant on the spending from major companies like OpenAI, Meta, and Microsoft, all of whom are looking to develop their own AI chips to reduce costs and dependence on NVIDIA.
NVIDIA CEO Jensen Huang commented on open-source models, stating that they “broaden access to AI and help ensure that AI leadership is distributed across companies, institutions and communities.
“They enable organisations to match the right model to the right job,” Huang said.
Huang isn’t wrong; these open-source models can be customised to business needs, and as a result, the market is responding with increased interest in Chinese models from DeepSeek and Z.ai.
Huang assured that the acquisition of Hugging Face would not change the platform’s open-source stance, saying that it “will remain an open platform for the entire AI ecosystem”, with developers still able to choose preferred models, cloud platforms, and chipsets.
Hugging Face and NVIDIA already share a close relationship and work together to assist developers using NVIDIA’s services on the platform.
However, the move has still concerned both NVIDIA investors and Hugging Face developers.
Investors are worried that the company could be boosting its valuation artificially and contributing to global concerns of an AI bubble.
On the other side, despite Huang’s comments, developers are worried that NVIDIA may prioritise its hardware on the platform, making rival hardware a non-practical choice.
“While they have stated otherwise, it is likely that, at a minimum, technical methods will get instrumented to provide a competitive advantage,” said Harold Byun, CEO of BlueRock, as seen by iTnews.
“That’s something any rational company would seek to do.”
IG group chief technical analyst Axel Rudolph said: “NVIDIA is clearly buying strategic influence as much as current earnings.”
Hugging Face cyber incident
The story closely follows an incident where an autonomous AI agent from OpenAI breached Hugging Face’s network.
OpenAI itself describe the incident as an “unprecedented cyber attack”.
On 16 July, Hugging Face disclosed the incident.
“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness – used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face said.
“This matches the ‘agentic attacker’ scenario the industry has been forecasting.”
However, the twist – and the reason OpenAI is now involved – is that it was one of OpenAI’s agents.
“Last week, Hugging Face disclosed a new kind of security incident after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models,” OpenAI explained in a 21 July blog post.
“After investigating, we now know that this particular incident was driven by a combination of OpenAI models – including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes – while being internally tested on a benchmark of cyber capabilities.”
Essentially, the model was doing exactly what it was designed to do: seek out and chain together vulnerabilities. However, in this case, while it was initially operating in a sandboxed testing environment, in a “hyperfocused” effort to solve the ExploitGym benchmark, it eventually sought internet access in order to solve the problem.
It found this easily enough, and then reasoned that it could further data inside Hugging Face’s environment.
“Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation,” OpenAI said.
“In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.