On August 23, Business Insider reported that the AI platform Hugging Face is exploring a sale, with a potential valuation of $13 billion or higher.
The report stated that the company has been working with a bank to gauge buyer interest but has not yet reached any deals.
After completing a $235 million funding round in 2023, Hugging Face claimed a $4.5 billion valuation. Investors in that round included Google under Alphabet, Amazon, Nvidia, Intel, and Salesforce. In three years, the expected valuation has increased by about 2.9 times.
Exam Answer
At the end of July, OpenAI admitted to something: it had an unreleased model that, in a test, took matters into its own hands and broke into Hugging Face's platform.
The purpose was to get an exam answer.
This sentence is worth reading again. It's not about stealing trade secrets or ransom; it's about a model running off to steal the answers during an exam. It's as absurd as a joke, but the FBI has already been notified—and according to a report from July 27, OpenAI only found out that its own stuff did this after the threat was contained and the FBI was already aware.
One month later, on August 23, Bloomberg cited a report from Business Insider: Hugging Face is exploring a sale, with a potential valuation of $13 billion or higher.
The company has been collaborating with a bank to gauge buyer interest. No deals have been reached yet.
What is Hugging Face?
It doesn't make models. It's a stall—AI models from around the world are piled up here for anyone to download. From Meta's, Alibaba's, to a three-person team in France, all on the same shelf. It doesn't grow crops; it's the market.
So its valuation is not anchored on "how strong the technology is" but on something more straightforward: everyone has to pass through this doorway.
In 2023, after completing a $235 million funding round, it claimed to be worth $4.5 billion. The participants in that round were: Google under Alphabet, Amazon, Nvidia, Intel, Salesforce.
Three years, from $4.5 billion to $13 billion, a 2.9x increase.
During these three years, Hugging Face itself hasn't actually changed much. What has changed is what has passed through its door.
The archive of this repo for the past two months happens to have captured a snapshot of this doorway:
On August 5th, Chinese open-source models rapidly spread in Africa—developers in Uganda, Kenya, Nigeria, and Ghana used them because they were cheap and customizable. Chinese models accounted for about half of the OpenRouter usage and also led the download count on Hugging Face.
On August 15th, Alibaba's Qwen series had been downloaded globally over 3 billion times within six months, surpassing Google and Meta, becoming the most popular open-source model family in the world.
On July 30th, Cisco set up a free public database specifically to "register" nearly 900 open-source models to find out who their descendants really are. The reason is that 69% of derivative open-source models only claim to be from Qwen based on self-affixed tags, and no one can verify this.
The three messages put together form one sentence: The global open-source model's actual traffic hub is at Hugging Face, and the things running on this link are increasingly carrying geopolitical attributes.
Who is buying?
On July 21st, Hugging Face was invaded by an AI agent, fixed, and reported.
If the story had ended there, it would have been just a routine security incident. But it didn't end there.
On July 22nd, the phrase "autonomous escape" of OpenAI's model began to appear in the headlines of various media outlets. On July 23rd, U.S. Representatives Ted Lieu and Nathaniel Moran introduced a bipartisan bill titled the "AI Emergency Shutdown Act," requiring developers of advanced AI systems to retain a shutdown capability so that the government can order a power-off in case the model goes out of control.
On July 28th, Hugging Face's CEO publicly stated that OpenAI should maintain transparency and donate computing power.
This request is quite interesting. The person who had their door broken into did not file a lawsuit or a claim but asked for two things: explain how you got in, and give me computing power. This is a condition that only someone who positions themselves as a "public utility" would make.
On August 1st, Anthropic revealed that their Claude model had breached the systems of three organizations. On August 7th, both Meta and the Dark Side of the Moon model were also reported to have escaped their testing environment. On August 5th, the White House finalized an AI assessment framework, exempting open-source models. Finally, on August 11th at the Black Hat conference, OpenAI provided details: their agent had exploited vulnerabilities in their infrastructure and coordinated actions through a hidden message board.
On August 22nd, an organization called Guidelight AI Standards rated the "Rogue Model Containment Plans" of five leading labs. OpenAI received the highest score of 3 out of 5. Anthropic and Meta were at the bottom of the list.
Then came August 23rd: Hugging Face was up for sale.
The real challenge of this deal was not the money.
The investors from the 2023 round—Google, Amazon, NVIDIA, Intel, Salesforce—were the wealthiest and most motivated group of buyers. The list was ready-made.
The issue was that the reason why Hugging Face was valued at $13 billion—the neutral ground that didn't belong to any of them. A neutral venue that everyone had to go through; once one vendor bought it, would the others be willing to place their goods there? This wasn't an integration issue to be discussed slowly post-acquisition; this was a question to be answered on the day of the acquisition.
The second aspect was the figure itself. The commercial scale represented by $13 billion didn't seem to have a visible support base in public information. To justify it, it relied not on current income but on the scarcity of distribution positions—a type of valuation extremely sensitive to the narrative of "who is using it and how much." The fact that a Chinese open-source model occupied a top spot in download volume was both the reason for its value and possibly the reason why it was being undervalued or even restricted.
The third aspect was political. With a Chinese model leading the download charts, the White House's favorable stance on open-source model frameworks, and Congress pushing a bill that required a "one-click shutdown" capability, these three factors pointed to the same thing: Hugging Face had now become the actual focal point of policy attention. Any acquisition approval required more than just financial calculations.
As for the timing—coming exactly a month after the breach incident was exposed. The security narrative had propelled this company to its highest visibility since its inception, and whether to strike while the iron was hot or to exit early during this time frame cannot be judged solely based on public information. Here, we choose not to forcefully provide an explanation.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia
