Nvidia has agreed to acquire Hugging Face for $12,930,300,000, in a deal announced by Nvidia founder and chief executive Jensen Huang on 3 September.

Hugging Face, used by more than 18 million developers, researchers and creators, hosts over 3 million models, 500,000 datasets and 1 million applications, with more than 200,000 companies using the platform to discover, evaluate, customise and deploy AI. Huang said Hugging Face will remain an open platform, with developers free to choose their preferred models, frameworks, clouds and computing hardware, and that Nvidia compute will not be required to build on or deploy through the site.

Nvidia said it is already the largest contributor of open models and data to Hugging Face, having released more than 500 models and over 250 open datasets on the platform. Huang framed the deal as an extension of an open letter he recently co-authored with other industry leaders on the importance of open-weight models to broadening access to AI and distributing AI leadership across companies and institutions.

Huang said Hugging Face co-founders Clem Delangue, Julien Chaumond and Thomas Wolf had built the platform into a vibrant home for the open model developer community over the past decade, and that Delangue had approached him about Nvidia becoming the company's next home. Huang said the acquisition would bring Nvidia's infrastructure and engineering resources to bear on improving the platform's reliability, safety, model evaluation and deployment capabilities, while preserving its open ecosystem. Hugging Face will keep its existing brand under the new ownership.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!