Nvidia has agreed to buy Hugging Face, the platform millions of developers use to find, share and test AI models, in a deal worth $12.9bn. It is Nvidia’s second-largest acquisition ever, and it hands the world’s most valuable chipmaker control of one of the biggest distribution points for open-source AI. For most businesses, this will register as background tech news. It shouldn’t. If your team uses any AI tool built on an open-source model, there is a reasonable chance Hugging Face sits somewhere in that tool’s supply chain, and its ownership just changed.
Nvidia’s biggest AI platform bet doubles down on open-source
The deal, confirmed on 3 September 2026, sees Nvidia pay around $11.9bn to Hugging Face’s investors, with up to $1bn more offered in stock-based incentives to retain staff. It ranks second only to Nvidia’s $20bn purchase of chipmaker Groq’s assets in December, and dwarfs its previous largest acquisition, the near-$7bn purchase of Mellanox in 2019. The deal is expected to close in the first half of 2027, subject to regulatory approval. Nvidia CEO Jensen Huang described Hugging Face as remaining “an open platform for the entire AI ecosystem,” and the company has said developers will not be required to use Nvidia hardware or services to access it. Nvidia is already Hugging Face’s biggest single contributor, having published over 500 of its own models and 250 open datasets on the platform, so the acquisition formalises a relationship the two companies had built for years rather than starting one from scratch.
Hugging Face already touches more businesses than most realise
Hugging Face works a bit like an app store or a GitHub for AI. It hosts more than three million AI models, half a million datasets and a million applications, used by upwards of 18 million developers and more than 200,000 companies. Very few of those users are AI companies themselves. Most are ordinary businesses whose software vendors quietly built a feature on top of a model hosted there. That is what makes this deal relevant well beyond the AI industry: Hugging Face is closer to plumbing than to a product most staff would ever open directly.
The ownership change matters more for your AI supply chain than your AI budget
We have covered before why unmanaged AI tools have become a genuine compliance question under Cyber Essentials v3.3, which now treats any cloud service processing company data, including AI tools staff use daily, as explicitly in scope. Hugging Face was also the platform breached earlier this year when a rogue AI agent escaped its testing environment. This incident showed how much sits on infrastructure most businesses never think to ask about. In Dr Logic’s experience, the businesses caught out by incidents like this are rarely the ones using AI deliberately. They are the ones who never mapped which tools their staff and software vendors actually rely on.
Nvidia’s ownership stake does not change what Hugging Face does today, and its stated commitment to keeping the platform open is a reasonable signal of intent. What it does change is who ultimately controls the roadmap, pricing and access decisions for a platform a large share of the AI tooling market depends on indirectly. That is worth a line in your next vendor risk review, whether or not your business has ever heard of Hugging Face before this week.
What to do with this news
Treat this as a prompt to check your own AI tool inventory, not a reason to change anything today. Nvidia’s deal has not closed yet, and Hugging Face’s day-to-day operation is unaffected for now. The useful step is confirming which of your business tools rely on open-source models, and whether that dependency was ever formally logged as part of your Cyber Essentials or supplier risk assessment.
Do you know what’s underneath your AI tools?
Most businesses can’t name every model or platform their software depends on, and that gap is exactly what modern compliance frameworks now expect you to close.



















































