Nvidia buys Hugging Face
Hugging Face said no to $500 million. Then yes to $12.93 billion.

Twelve billion, nine hundred thirty million, three hundred thousand dollars
Jensen Huang wrote the acquisition price down to the dollar in his blog post on September 3: $12,930,300,000. Nvidia's SEC filing, which dates the definitive agreement to September 2, spells out the mechanics: roughly $11.9 billion paid to Hugging Face shareholders, plus up to $1 billion more in retention stock for employees joining the group. Closing is expected in the first half of 2027.
The story behind the deal matters more than the number. Clément Delangue went to Jensen Huang on his own initiative this summer, weeks after his platform got breached by agents belonging to an American lab. Huang confirms it in his own post: he says he's honored Clem came to him.
On CNBC Thursday morning, anchor Becky Quick asked it point-blank: was OpenAI's intrusion the trigger? The answer is worth reading slowly.
What the founder said
"When that happened, what we realized is that we needed open models. Why? Because if you remember, we couldn't defend ourselves with proprietary closed source APIs, so we had to use open models to defend ourselves."
The nuance matters: Delangue describes what the breach taught him, without ever saying he sold because of it. His conclusion, in his own words, is that Hugging Face needed to double down on open source. The rest of his answer sets up two paths: one where proprietary APIs dominate and everyone rents their intelligence, another where everyone can own it.
That conviction has a very specific technical reference, and it comes with a file name.
The model that saved Hugging Face already bore its buyer's name
We've followed this incident since day one: OpenAI's admission on July 21, then the platform's technical reconstruction and the lab's post-mortem. The technical writeup from July 27 contains a line nobody connected to this week's news.
Hugging Face's investigators first plugged frontier models behind commercial APIs to analyze the logs. It didn't work. Their disclosure explains why, without sugarcoating it: the analysis meant submitting large volumes of attack commands and real exploit payloads, and the providers' safety guardrails blocked those requests, unable to tell an investigator from an attacker.
Contrary to what's been circulating since Thursday, no licensing clause is at fault here. The block comes from the safety systems themselves, which see the same move whether it's the burglar or the expert who's pulled the lock apart on the evidence table.
So the team deployed an open model on its own infrastructure instead. Its exact reference, as it appears in the document: nvidia/GLM-5.2-NVFP4. In other words, GLM-5.2, a model from Chinese lab ZAI, in the compressed version published by Nvidia. That's the model the investigators used to recover the attacking agent's encryption scheme and decrypt payloads a raw read had missed.
Two versions of this detail are floating around, one calling it a Chinese model, the other an Nvidia model. Both are true: each one names half of the same reference.
What Nvidia tells its shareholders
A blog post sells a vision. An 8-K filing binds a public company. The one filed Thursday morning contains a paragraph nobody picked up on.
In its risk factors section, Nvidia warns that many of the world's most popular and capable open models were born in China, before being downloaded, revised, and fine-tuned by developers in the U.S. and elsewhere. Then comes the sentence that matters: any regulatory restriction limiting its ability to support models from any region, China included, could have a material impact on the Hugging Face platform and on its own results.
The same filing notes that other players are lobbying Washington for measures that would disadvantage open models.
That's the real sovereignty story of the week. It's not about whether a company founded by three French entrepreneurs is now flying an American flag. It's that the new owner of the world's biggest open-model warehouse states, in a regulatory filing, that the health of that warehouse partly depends on Chinese labs.
The word "asymmetry," used two opposite ways
On air, Huang argued that openness gives defenders an asymmetric advantage, because there are far more people protecting systems than attacking them. It's a solid point, and he backs it with a partnership he struck with CrowdStrike around Nvidia's Nemotron models. We'd already looked at what this strategy costs Nvidia.
Back in July, Hugging Face had titled an entire section of its post-mortem "the asymmetry problem." Same word, opposite meaning: the attacker wasn't bound by any usage policy, while the defenders' legitimate work kept getting blocked by the hosted models' guardrails. Their takeaway fit in one line: have a capable, vetted model ready on your own infrastructure before the fire starts.
So two companies signing a thirteen-billion-dollar deal use the same word to mean opposite things. The promise of openness is still a bet on the owner's intentions.
What isn't established
Three caveats, because this story is prone to overreach.
No regulator has announced a review at this point. The SEC filing mentions required regulatory approvals, boilerplate language for any deal of this size. The Register ran an opinion piece calling on authorities to block the deal, with an image that'll stick: you wouldn't let a carmaker buy the main fuel distribution network, or the school where mechanics get trained. That's a call published on an opinion page, and it doesn't open any procedure.
The multiple everyone's quoting rests on a press figure. Hugging Face doesn't publish its financials, and the $150 million in annualized revenue used everywhere as the denominator comes from The Information, cited by TechCrunch. The 86x revenue ratio is arithmetically correct, provided you take that revenue figure on faith.
As for the openness commitment, it's written down, which counts for something, and it's still a statement of intent. The 8-K specifies that Nvidia commits, among other things, to continue supporting other silicon vendors. Nothing in it says for how long, or who checks.
The price of a store
A year ago, according to the Financial Times, Delangue turned down a $500 million investment from that same Nvidia. On Thursday, Huang told CNBC there were other bidders, that $12.9 billion was what it took to close, and that knowing who the others were didn't matter, since only the winner counts.
The shovel maker just bought the map to the gold field, promising that the map will keep marking everyone else's claims too. We'll know by the first half of 2027 whether any regulator objects. In the meantime, the one document that says plainly what this platform is made of is the risk filing sent to shareholders, and it points to China.
Topics covered:
Frequently asked questions
How much is Nvidia paying to buy Hugging Face?
Is the Hugging Face breach the reason for the sale?
Which model did Hugging Face use to analyze the July attack?
Why didn't the models behind commercial APIs work?
Has any regulator opened a review of the deal?
What does Nvidia tell its shareholders about Chinese models?

Julien-Pierre Noto
Entrepreneur & Voice from the Field
Julien-Pierre is an entrepreneur with over twenty years of hands-on experience in construction and real estate. For the past three years, he has been working with AI every day in an SME — not in a lab: on real cases, with real clients. Founder of ONDE AI R&D, an applied research lab on human-AI work, he publishes his methods as open source — what works and what doesn't. At Declic Media, he is the voice from the field: applied AI, the kind that has to prove its worth.
All articles by Julien-Pierre →