# Hugging Face

> Source: https://aiwiki.ai/wiki/hugging_face
> Updated: 2026-08-01
> Fact-checked: 2026-07-30
> Categories: AI Companies, Developer Tools, Machine Learning, Open Source AI
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "Hugging Face." aiwiki.ai, 1 Aug 2026. https://aiwiki.ai/wiki/hugging_face
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

**Hugging Face** is an [artificial intelligence](https://aiwiki.ai/wiki/artificial_intelligence) company and collaboration platform for [machine learning](https://aiwiki.ai/wiki/machine_learning). Its central service, the Hugging Face Hub, hosts versioned repositories for models, datasets, and interactive applications called Spaces. The company also develops open-source libraries for model training, adaptation, evaluation, and deployment, and sells hosted inference, compute, storage, and enterprise services. Hugging Face was founded in 2016 by Clement Delangue, Julien Chaumond, and Thomas Wolf, and is incorporated in Delaware with a registered address in Brooklyn, New York.[1][2]

The company began with a conversational mobile app aimed at teenagers. It changed direction after releasing software used in the app, building first around [natural language processing](https://aiwiki.ai/wiki/natural_language_processing) and then around a broader range of machine-learning tasks.[1][3] That history matters for reading the name: Hugging Face is both a company and the operator of a platform on which third parties publish artifacts under many different licenses and access conditions. A repository being visible on the Hub does not by itself establish that its weights, data, or code meet a particular definition of [open-source AI](https://aiwiki.ai/wiki/open_source_ai).[12]

In October 2025 Hugging Face reported more than 2 million public model repositories, about 500,000 public dataset repositories, and 1 million public Spaces.[77] A company analysis published in March 2026 put user numbers at 13 million for 2025 and found that use was heavily concentrated: about half of hosted models had fewer than 200 downloads, while the 200 most-downloaded models accounted for 49.6 percent of downloads.[8] A July 2026 joint announcement with [NVIDIA](https://aiwiki.ai/wiki/nvidia) described the platform as having 16 million builders.[60] All of these are company-reported figures rather than audited counts.

The Hub's importance comes from distribution rather than from any single piece of technology. Most widely used [open-weights](https://aiwiki.ai/wiki/open_weights) model families, including [Llama](https://aiwiki.ai/wiki/llama_3), [Qwen](https://aiwiki.ai/wiki/qwen), [DeepSeek](https://aiwiki.ai/wiki/deepseek), [Mistral](https://aiwiki.ai/wiki/mistral_ai), and [Stable Diffusion](https://aiwiki.ai/wiki/stable_diffusion), are published there first or in parallel with any other channel, and the surrounding libraries treat a Hub repository identifier as the default way to name a checkpoint. That position also concentrates risk, a point Hugging Face's own staff and outside critics have both made, and one the July 2026 intrusion into the company's data-processing systems brought into wider view.[34][35]

## History and corporate development

### From chatbot to machine-learning platform

Hugging Face launched publicly in 2017 as a mobile chatbot and digital companion. Contemporary reporting identified Delangue and Chaumond as co-founders, said the product took its name from the hugging-face emoji, and put the company's first outside financing at about $1.2 million from investors including Betaworks, SV Angel, and the basketball player Kevin Durant. The company later described Wolf as its third co-founder and identified the founding year as 2016, which matches the year of incorporation on its regulatory filings.[2][39]

The technical pivot followed the release of code for working with pretrained language models. In November 2018, weeks after Google published [BERT](https://aiwiki.ai/wiki/bert), Hugging Face released a [PyTorch](https://aiwiki.ai/wiki/pytorch) reimplementation as the package `pytorch-pretrained-bert`. It was renamed `pytorch-transformers` in July 2019 and then `transformers` in September 2019, as support expanded past a single model family.[3][5][40] By 2019 the library, not the app, was the company's main product. The change replaced a consumer-chatbot business with a developer platform built around reusable models, libraries, and community repositories.

The company's own first research contribution came out of the same period. DistilBERT, published in October 2019 by Victor Sanh, Lysandre Debut, Chaumond, and Wolf, applied knowledge distillation during pretraining rather than to a task-specific model, and reported a 40 percent size reduction with 97 percent of BERT's language-understanding performance and 60 percent faster inference.[100] It set the pattern for most of Hugging Face's later research: useful, reproducible, and aimed at making existing capability cheaper rather than at pushing the capability frontier.

### Legal entity and offices

Hugging Face Inc. is a Delaware corporation, incorporated in 2016. Its two Form D filings with the US Securities and Exchange Commission, in 2018 and 2019, list a Brooklyn, New York business address and name Delangue and Chaumond as executive officers and directors; the 2019 filing adds Brandon Reeves of Lux Capital.[2] The founders are French, a large share of the science and engineering staff works from France, and the Pollen Robotics subsidiary acquired in 2025 is based in Bordeaux. The company does not publish headcount, and commercial data providers disagree with each other by roughly a factor of three, so no figure is quoted here.

### Leadership

In an April 2025 company announcement, Hugging Face identified Delangue as chief executive, Chaumond as chief technology officer, and Wolf as chief science officer.[27] All three were still in those roles in company posts published through mid-2026.[28][59] Lee Fixel of Addition joined the board at the Series B in 2021.[4]

Delangue is the most publicly visible of the three and has used interviews to argue that enterprises adopting AI eventually move from renting frontier model APIs to running open models themselves. In a July 2026 interview he said the platform was used by roughly half the Fortune 500 and said he worried that a small number of large companies could end up controlling the field.[63]

### Financing

| Date | Round | Amount | Lead | Valuation | Notes |
|---|---|---|---|---|---|
| March 2017 | Seed | About $1.2 million | Betaworks | Not disclosed | SV Angel and Kevin Durant also participated.[39] |
| April 2018 | Regulation D offering | $3.32 million sold | Not stated | Not disclosed | Form D filed May 2018.[2] |
| December 2019 | Series A | $15 million announced | Lux Capital | Not disclosed | The corresponding Form D reports $19.71 million sold, which includes converted notes and other securities.[2][3] |
| March 2021 | Series B | $40 million | Addition | Not disclosed | Lee Fixel joined the board.[4] |
| May 2022 | Series C | $100 million | Lux Capital | $2 billion (press) | Sequoia and Coatue invested for the first time; Hugging Face's own announcement gave no valuation.[5] |
| August 2023 | Series D | $235 million | Salesforce Ventures | $4.5 billion post-money | Google, Amazon, NVIDIA, [AMD](https://aiwiki.ai/wiki/amd), [Intel](https://aiwiki.ai/wiki/intel), [Qualcomm](https://aiwiki.ai/wiki/qualcomm) Ventures, [IBM](https://aiwiki.ai/wiki/ibm), and Sound Ventures also participated.[1][6] |

As of August 2026, no later priced round has been announced, no registration statement has been filed, and the Series D valuation is the last disclosed mark. Private-market data aggregators publish revenue, headcount, and valuation estimates for the company that disagree with one another by an order of magnitude; none of them originate with Hugging Face, and none are reproduced here.

### Acquisitions and expansion

| Target | Announced | Terms | What it added |
|---|---|---|---|
| [Gradio](https://aiwiki.ai/wiki/gradio) | December 2021 | Not disclosed | A Python framework for building browser interfaces around models, which became the default SDK for Spaces.[25] |
| Argilla | June 2024 | Reported around $10 million, not confirmed by the company | A Spanish data-annotation and dataset-curation platform. |
| XetHub | August 2024 | Not disclosed; described by Delangue as the company's largest acquisition to that point | A Seattle storage startup founded by former Apple engineers, whose content-addressed storage became the Hub's backend.[26][47] |
| [Pollen Robotics](https://aiwiki.ai/wiki/pollen_robotics) | April 2025 | Not disclosed | A Bordeaux robotics company founded in 2016 by former Inria researchers, maker of the Reachy line. Described by Hugging Face as its fifth acquisition.[27] |
| ggml and llama.cpp team | February 2026 | Not disclosed | Georgi Gerganov and the [GGML](https://aiwiki.ai/wiki/ggml) team joined the company.[28] |

Two of these deserve care. The Pollen Robotics deal gave Hugging Face its first hardware business, extending work already under way through [LeRobot](https://aiwiki.ai/wiki/lerobot).[27] The February 2026 announcement about [llama.cpp](https://aiwiki.ai/wiki/llama_cpp) is routinely described in press coverage as an acquisition, but Hugging Face's own post uses the word "join" and commits that the project "will continue to be 100% open-source and community driven as it is now" and that Gerganov and his team "still dedicate 100% of their time maintaining llama.cpp and have full autonomy and leadership on the technical directions and the community." No financial terms were disclosed, and the announcement should not be read as a transfer of every community contribution to the company.[28]

In October 2025 the `sentence-transformers` project, previously maintained at the Ubiquitous Knowledge Processing Lab at TU Darmstadt, was transferred to the Hugging Face GitHub organization, keeping its Apache 2.0 license.[70]

## Hugging Face Hub

### Repositories and version control

The Hub organizes models, datasets, and Spaces as Git repositories. Each can include files, revision history, pull requests, discussions, metadata, and documentation. Unlike a conventional source-code host, the storage system is designed for large binary artifacts such as Parquet data and [safetensors](https://aiwiki.ai/wiki/safetensors) weights.[7]

A fourth repository type, Storage Buckets, launched in March 2026 and works differently. Buckets are non-versioned, mutable, S3-style object storage backed by the same Xet system, addressed through `hf://buckets/` paths and reachable through an S3-compatible API, the `hf` command line tool, or a Python client. They are intended for training checkpoints, optimizer states, logs, intermediate dataset shards, and agent scratch space, where Git history would consume storage without helping. Files can be copied server-side between repositories and buckets without a download and re-upload, because only the content hashes move.[46]

Hugging Face publishes recommendations rather than hard limits for most repository dimensions: fewer than 100,000 files per repository, fewer than 10,000 entries per folder, and files split into chunks below 200 GB. The one stated hard limit is 500 GB for a single file.[45]

### Storage: from Git LFS to Xet

Large files were historically tracked with Git LFS, which stores a small pointer file in the Git repository and keeps the payload in remote object storage. Git LFS deduplicates whole files, so changing a few tensors in a multi-gigabyte checkpoint means uploading the entire checkpoint again.

Xet, the backend derived from the XetHub acquisition, deduplicates byte ranges instead. Files are split using content-defined chunking, with the default configuration targeting roughly 64 KiB chunks within bounds of 8 KiB and 128 KiB, and only changed chunks are transferred. Xet pointer files carry the same fields as Git LFS pointers plus a Xet-backed hash, and Git LFS remains supported for legacy repositories.[47] Xet became the default for new users and organizations during 2025, and by October 2025 Hugging Face reported that more than 77 petabytes across roughly 6 million repositories had been migrated.[76][77] The Rust client that implements the protocol, `hf_xet`, first appeared on PyPI in January 2025 and replaced the older `hf_transfer` accelerator as the default in `huggingface_hub` 1.0.[43]

### Access control: public, private, and gated repositories

Hugging Face supports public, private, and gated repositories, and Spaces additionally support a protected mode in which the running application is reachable but the source code is not. Public repositories are visible to anyone; private repositories are limited to their owners or organization members.

A gated repository exposes its page but requires a user to accept conditions or obtain maintainer approval before downloading the protected files. Gating can be set to automatic approval, where sharing a username and email address suffices, or manual approval, where the maintainer accepts or rejects each request and can revoke access later without notice. Publishers can add custom fields to the request form through `extra_gated_fields` in the model card metadata, including free text, checkboxes, country selectors, and dropdowns, and can download a report listing every requester's username, full name, email address, and request time. Organizations on paid plans can gate an entire collection at once.[11]

Gating controls access through the platform; it does not replace the repository's license or independently verify compliance with its conditions. A separate flag, `extra_gated_eu_disallowed`, blocks users whose IP address places them in a European Union country, and only takes effect on repositories that are already gated. Publishers have used it where a license or a regulatory judgment makes EU distribution unattractive.[11]

### Documentation and discovery

A [model card](https://aiwiki.ai/wiki/model_card) is usually written in a repository's README file with structured YAML metadata. Hugging Face recommends documenting intended uses, limitations, training information, datasets, evaluation results, and license information. Dataset cards serve the same role for data collections. Metadata powers search, task tags, library integration, and other Hub interfaces.[10]

Cards are supplied by publishers rather than certified by Hugging Face as complete. A 2024 *Nature Machine Intelligence* study of 32,111 Hub model cards found large differences in how much information they provided, with particularly sparse reporting for environmental impact, limitations, and evaluation. A separate ICLR 2024 study found substantial variation in the completeness of 7,433 dataset cards and a strong relationship between documentation and dataset popularity.[29][30] Cards improve transparency, but their existence is not proof that every material risk, data source, or evaluation has been disclosed.

### What downloads and likes measure

Download counts are the Hub's most quoted metric and the most frequently misread. Hugging Face counts server-side HTTP requests, including `HEAD` requests, for a designated query file inside each repository rather than for every file. The default query files are `config.json`, `config.yaml`, `hyperparams.yaml`, `params.json`, and `meta.yaml`; individual libraries register their own, so the `nemo` library counts files with a `.nemo` extension and the `diffusers` filter counts `model_index.json` plus top-level `.safetensors`, `.ckpt`, and `.bin` files. GGUF files are counted individually because they are self-contained and not tied to one library, which double counts anyone who clones a whole repository of quantizations.[48]

Three consequences follow. A download is a file request, not a person: continuous integration systems, mirrors, container builds, and automated benchmarking all register. The counter does not deduplicate users. And repositories whose query file differs from the one a given tool fetches can be systematically under- or over-counted relative to their neighbors. Hugging Face acknowledges this directly and sells a Publisher Analytics product to organizations that need to separate configuration fetches from weight fetches, exclude CI traffic, or count unique downloaders.[48][55]

Likes are a manual signal from logged-in accounts and are used to rank trending repositories. Both metrics are targets for manipulation, and the Hub content policy lists "metric manipulation" among prohibited platform abuses.[32] An independent 2024 study of a Hub snapshot found a pronounced core-periphery pattern, with a small share of repositories receiving most activity.[36]

### Spaces

Spaces are Git-backed applications used to demonstrate or operate machine-learning systems. The Hub supports three SDK choices: Gradio applications, Docker containers, and static HTML sites. A Space can call a model on the Hub or another service, but it is separately executable code with its own dependencies and security boundary.[9]

The default environment provides 2 vCPU, 16 GB of memory, and 50 GB of non-persistent disk. Static Spaces remain free for everyone, but creating a Gradio or Docker Space that runs on compute now requires a paid plan, with an exception allowing free personal accounts in good standing to host up to two Gradio Spaces on ZeroGPU. Upgraded hardware is billed by the minute while the Space is starting or running, with no charge during build; free-tier Spaces sleep after about 48 hours of inactivity, and paused Spaces are not billed.[9][49]

Secrets and variables are configured per Space, with secrets hidden after they are set and excluded from duplicated copies. A Spaces secrets scanner warns owners about hard-coded credentials.[9] That surface was the subject of a 2024 security disclosure, discussed below.

## Software ecosystem

Hugging Face maintains a set of related but independently versioned libraries. They are not one framework, and using one does not require hosting a repository publicly on the Hub. Almost all are Apache 2.0; the exceptions below are noted because license assumptions are a recurring source of error.

| Project | What it does | License | Notes |
|---|---|---|---|
| [Transformers](https://aiwiki.ai/wiki/transformers_library) | Model definitions, pretrained checkpoints, training utilities, and inference interfaces across text, vision, audio, video, and multimodal tasks.[13][40] | Apache 2.0 | Began as `pytorch-pretrained-bert` in November 2018; PyTorch-only since version 5.[41] |
| [Datasets](https://aiwiki.ai/wiki/datasets) | Loading, processing, streaming, and sharing datasets, with Apache Arrow used for memory-mapped tabular access.[14] | Apache 2.0 | Major versions 4.0 in July 2025 and 5.0 in June 2026. |
| Tokenizers | Rust implementations of production tokenizers (BPE, WordPiece, Unigram) with Python and Node bindings, for training as well as inference. | Apache 2.0 | The sole tokenization backend in Transformers v5.[41] |
| Diffusers | Components and pipelines for pretrained [diffusion models](https://aiwiki.ai/wiki/diffusion_model) used in image, video, and audio generation.[15] | Apache 2.0 | PyTorch-focused since the Flax backend was dropped. |
| Accelerate | A higher-level interface for running PyTorch training or inference across devices and distributed configurations, including mixed precision, FSDP, and DeepSpeed.[16] | Apache 2.0 | First released 2021. |
| [PEFT](https://aiwiki.ai/wiki/huggingface_peft) | Parameter-efficient adaptation methods, including [LoRA](https://aiwiki.ai/wiki/lora), that train or store a small subset of parameters instead of a full model copy.[17] | Apache 2.0 | First release February 2023. |
| [TRL](https://aiwiki.ai/wiki/huggingface_trl) | Post-training methods including supervised [fine-tuning](https://aiwiki.ai/wiki/fine_tuning), preference optimization such as [DPO](https://aiwiki.ai/wiki/dpo), reward modeling, and GRPO.[18] | Apache 2.0 | Reached version 1.0 after the reasoning-model wave of 2025. |
| Safetensors | A tensor serialization format designed to avoid executable deserialization and to support zero-copy loading.[19] | Apache 2.0 | The GitHub repository has moved out of the `huggingface` organization to its own `safetensors` organization. |
| `huggingface_hub` | The official Python client and command line tool for the Hub: downloads, uploads, Inference Providers, Jobs, and buckets. | Apache 2.0 | Version 1.0 in October 2025 renamed the CLI and changed the HTTP and transfer backends.[43][77] |
| Text Generation Inference | A Rust and Python server for large language model serving; powered HuggingChat and Inference Endpoints. | Apache 2.0, after a period under a source-available license | Entered maintenance mode in December 2025; the repository was archived in 2026.[38][44] |
| Optimum | Hardware acceleration for Transformers, Diffusers, timm, and Sentence Transformers via [ONNX](https://aiwiki.ai/wiki/onnx) Runtime, [OpenVINO](https://aiwiki.ai/wiki/openvino), and partner silicon. | Apache 2.0 | Version 2.0 in October 2025. |
| Evaluate | A library of evaluation metrics and comparisons for models and datasets. | Apache 2.0 | Low activity since 2025; superseded in practice by Lighteval for language model evaluation. |
| [smolagents](https://aiwiki.ai/wiki/smolagents) | A small agent library whose agents write their actions as Python code rather than emitting JSON tool calls; the successor to `transformers.agents`. | Apache 2.0 | First released December 2024, with the core agent logic in roughly a thousand lines.[74] |
| Lighteval | An evaluation toolkit covering more than a thousand tasks across several execution backends; the framework behind the Open LLM Leaderboard. | MIT | The only MIT-licensed library among the main Python projects. |
| [Gradio](https://aiwiki.ai/wiki/gradio) | Python tools for building web interfaces and demonstrations around functions and models.[25] | Apache 2.0 | Developed in the `gradio-app` GitHub organization, not `huggingface`. |
| timm | A large collection of PyTorch image backbones with training, evaluation, and inference scripts and pretrained weights. | Apache 2.0 | Ross Wightman's project, now maintained under the Hugging Face organization. |
| Sentence Transformers | Embedding, retrieval, and reranking models, including cross-encoders and sparse encoders. | Apache 2.0 | Transferred from TU Darmstadt to Hugging Face in October 2025.[70] |
| [LeRobot](https://aiwiki.ai/wiki/lerobot) | End-to-end machine learning for real-world [robotics](https://aiwiki.ai/wiki/robotics) in PyTorch: policies, datasets, simulation, and hardware support. | Apache 2.0 | Repository created January 2024. |
| Candle | A minimalist machine-learning framework for Rust, aimed at small binaries and serverless inference. | MIT or Apache 2.0, dual | Versioned through crates.io rather than GitHub releases. |
| Transformers.js | Runs Transformers models in the browser through ONNX Runtime, with no server. | Apache 2.0 | Published on npm as `@huggingface/transformers`. |
| Datatrove and Nanotron | Large-scale data processing and distributed pretraining, used to build the FineWeb datasets and the SmolLM models. | Apache 2.0 | Rarely used outside pretraining work. |

### Transformers and the version 5 transition

Transformers began as a library for pretrained language models, but its scope expanded well beyond [large language models](https://aiwiki.ai/wiki/large_language_model). Its documentation covers text, [computer vision](https://aiwiki.ai/wiki/computer_vision), audio, video, and multimodal model definitions. Hugging Face reported roughly 3 million daily installations at the time of the version 5 announcement, against about 20,000 at the version 4 release five years earlier, and support for more than 400 model architectures against roughly 40.[41]

Version 5.0.0 was released on January 26, 2026, after release candidates beginning in December 2025, and was the first major version in five years.[41][42] Four changes matter for anyone reading older documentation.

[TensorFlow](https://aiwiki.ai/wiki/tensorflow) and [JAX](https://aiwiki.ai/wiki/jax) or Flax support was removed library-wide. The removal landed on the development branch in September 2025 and shipped in the version 5 line, while the 4.57 series remained the last branch containing the TensorFlow and Flax model files. Hugging Face described the change as going "all in on PyTorch."[41]

Tokenization was rebuilt on the `tokenizers` backend, eliminating the long-standing distinction between "fast" and "slow" tokenizers and allowing tokenizers to be instantiated empty and trained like models. Image processors moved exclusively to their torchvision-backed fast variants.

Quantization became a first-class configuration rather than a set of loading flags, and a new weight-conversion API made checkpoint transformations reversible, which is what allows quantized and mixture-of-experts checkpoints to be combined with tensor parallelism.

Finally, the project moved to weekly minor releases instead of roughly every five weeks, and repositioned the library as a model-definition layer rather than a serving engine. Hugging Face now describes the intended workflow as training with third-party trainers, deploying with [vLLM](https://aiwiki.ai/wiki/vllm) or [SGLang](https://aiwiki.ai/wiki/sglang), and exporting to llama.cpp, ExecuTorch, or [MLX](https://aiwiki.ai/wiki/mlx), with Transformers supplying the architecture definitions all of them consume.[41]

### The client library and the command line rename

The `huggingface_hub` package is the common dependency underneath most of the ecosystem. In version 0.34.0, released July 24, 2025, the command line tool was renamed from `huggingface-cli` to `hf`, with a restructured `hf <resource> <action>` syntax such as `hf auth login`, `hf download`, and `hf jobs run`. The old command was deprecated but kept working. Version 1.0.0, released in October 2025, removed it entirely, switched the HTTP backend from `requests` to `httpx` for native HTTP/2, dropped `hf_transfer` in favor of `hf_xet`, removed the remaining TensorFlow and Keras 2 utilities along with the older `Repository` and `InferenceAPI` classes, and added a [Model Context Protocol](https://aiwiki.ai/wiki/model_context_protocol) client and "tiny agents" command.[43][77] Code and tutorials written before mid-2025 therefore reference commands that no longer exist.

### Serving, and the Text Generation Inference license history

Text Generation Inference (TGI) is the clearest case of a license change in the Hugging Face ecosystem, and it is often described inaccurately. The repository's `LICENSE` file has been changed exactly three times. It was created under the Apache License 2.0 in October 2022. On July 28, 2023, hours before the v1.0.0 release, it was relicensed to the Hugging Face Optimized Inference License 1.0 (HFOILv1.0), a source-available license whose restrictions clause prohibited distributing the software "as a hosted or managed, and paid service" granting users access to a substantial set of its features without a separate agreement. On April 8, 2024, the project reverted to Apache 2.0, and v2.0.0 shipped four days later. HFOIL therefore covered the entire 1.x series, roughly eight and a half months, and TGI has been Apache 2.0 ever since. HFOIL was never submitted to or approved by the Open Source Initiative, and the commercial-hosting carve-out is what put it outside the open-source definition.[44]

The project has since been wound down. Maintenance-mode commits landed in December 2025, the last functional release was v3.3.7 later that month, and the GitHub repository was archived in 2026. Its README now directs users to vLLM and SGLang for server-side inference and to llama.cpp or MLX for local inference, and notes that TGI's approach of building optimized engines on top of Transformers architectures has been adopted by those downstream projects.[38][44] An account that still describes TGI as Hugging Face's current serving product is describing 2024.

### Newer projects

Several projects created in 2025 and 2026 are absent from older accounts of the ecosystem. `open-r1` is a public reproduction attempt of [DeepSeek-R1](https://aiwiki.ai/wiki/deepseek_r1)'s training recipe, begun in January 2025. `nanoVLM` is a compact training repository for small [vision-language models](https://aiwiki.ai/wiki/vision_language_model). `OpenEnv`, released under BSD-3-Clause, defines an interface for reinforcement-learning environments used in post-training. `ml-intern` is an [agent](https://aiwiki.ai/wiki/ai_agent) built on smolagents that runs a full post-training loop, from reading papers through launching training jobs to evaluating results; Hugging Face maintains it both as a repository and as a Space.[75] `hf-mount` exposes buckets and repositories as local filesystems, and `hf-mcp-server` implements an MCP server for the Hub. The Hub's MCP surface was reworked in July 2026 around a single `hf_fs` tool plus sandboxed execution environments attached to buckets and repositories.[71]

## Hosted products and business model

Hugging Face gives away the Hub's core read and write functions and charges for compute, for storage above a free allowance, for organization administration, and for support. The dividing line has moved: compute-backed Spaces, once free to create, now require a paid plan.

### Subscriptions

| Plan | Price (August 2026) | Included storage | Notable features |
|---|---|---|---|
| Free | $0 | 100 GB private, best-effort public | Static Spaces, up to two ZeroGPU Gradio Spaces, $0.10 monthly inference credit, pay-as-you-go compute[45][50] |
| PRO | $9 per month | 1 TB private, up to 10 TB public | $2 monthly inference credit, eight times the ZeroGPU quota with priority queueing, ability to create Gradio and Docker Spaces, Spaces Dev Mode, private dataset viewer[50] |
| Team | $20 per user per month | 12 TB base public plus 1 TB per seat; 1 TB private per seat | SSO, audit logs, resource groups, storage-region control, gating group collections, Publisher Analytics, $2 per seat of inference credit[50][55] |
| Enterprise | From $50 per user per month | 200 TB base public plus 1 TB per seat | Invoiced billing, SCIM provisioning, token revocation, email support with an SLA[50][55] |
| Enterprise Plus | Custom | 500 TB base public plus 1 TB per seat | Network access controls, managed SSO across the public Hub, managed users, Hub credits worth 5 percent of annual contract value[55] |

Team and Enterprise plans are the route to organization administration: single sign-on, audit logs, resource groups, data-residency controls, centralized token management, and a private dataset viewer are gated behind them rather than sold separately.[23] Storage above the included allowance is sold separately, with egress and CDN included. A public storage add-on runs $12 per TB per month, falling to $8 per TB above 500 TB. Private storage is pay-as-you-go at a base rate of $18 per TB per month, falling to $12 per TB above 500 TB.[45][50] Storage Buckets are billed out of the same allowances, and Enterprise contracts are billed on deduplicated rather than logical bytes.[46]

### Compute

Spaces hardware is billed by the minute for the time a Space spends starting or running. Published rates in August 2026 ranged from $0.03 per hour for an 8 vCPU upgrade to $23.50 per hour for eight NVIDIA L40S accelerators, with A100 configurations at $2.50 per hour for one and $20.00 per hour for eight. H100 options were removed from Spaces in December 2025.[49][50] ZeroGPU is a separate mechanism that time-shares accelerators across many Gradio Spaces at no per-hour charge, backed as of 2026 by RTX Pro 6000 Blackwell cards with up to 96 GB of memory, with daily quotas of 5 minutes on the free tier, 40 minutes on Team, and 60 minutes on Enterprise, extendable with credits at $1 per 10 minutes of GPU time.[50][55]

Inference Endpoints deploys a chosen model on dedicated managed infrastructure with autoscaling, logs, and metrics, on [AWS](https://aiwiki.ai/wiki/aws), [Azure](https://aiwiki.ai/wiki/microsoft_azure), and [Google Cloud](https://aiwiki.ai/wiki/google_cloud).[21] Published rates in August 2026 started at $0.03 per hour for the smallest CPU instances and ran through AWS Inferentia and Google TPU v5e options to $9.25 per hour for a single NVIDIA B200 and $74.00 per hour for eight.[50] The high-end accelerators that were withdrawn from Spaces remain available here, which is consistent with a shift of scarce capacity from always-on demo hosting to metered production workloads.

Inference Providers, launched on January 28, 2025, is a different product. Rather than running the model, Hugging Face provides a single OpenAI-compatible client, a single token, and a single bill in front of third-party inference vendors, routing requests to the chosen provider. The launch partners were fal, [Replicate](https://aiwiki.ai/wiki/replicate), [SambaNova](https://aiwiki.ai/wiki/sambanova), and [Together AI](https://aiwiki.ai/wiki/together_ai).[51] The list published in August 2026 contained 17 providers, including [Cerebras](https://aiwiki.ai/wiki/cerebras), Cohere, DeepInfra, fal, Featherless, [Fireworks](https://aiwiki.ai/wiki/fireworks_ai), [Groq](https://aiwiki.ai/wiki/groq), Hugging Face's own HF Inference, Novita, Nscale, OVHcloud, Public AI, Replicate, Scaleway, Together, WaveSpeedAI, and [Zhipu AI](https://aiwiki.ai/wiki/zhipu_ai). Several earlier partners, including SambaNova, Hyperbolic, and [Nebius](https://aiwiki.ai/wiki/nebius), no longer appear, and no removal announcement accompanied their absence. Hugging Face states that routed requests are billed at the provider's own rates with no markup, and that using a provider's own API key bypasses Hugging Face billing and credits entirely.[51] The underlying provider still determines hardware, regional availability, supported models, and operational behavior.[20]

Jobs, introduced on July 30, 2025, runs batch or scheduled compute on Hugging Face infrastructure from the `hf` CLI, the Python client, or an HTTP API, using either a `uv` script or a Docker image. Access requires a positive credit balance. CPU flavors start at $0.01 per hour and GPU configurations run to $40.00 per hour for eight H200 accelerators.[22][52] Scheduled jobs, effectively cron on GPUs, followed in September 2025.[43]

### Products that were discontinued

Hugging Face's managed first-party GPU services had a short life, and articles written in 2024 describe several offerings that no longer exist.

| Product | Launched | Ended | What it was |
|---|---|---|---|
| Train on DGX Cloud | March 2024 | April 10, 2025 | No-code fine-tuning for Enterprise Hub users on NVIDIA H100 capacity, billed per GPU-hour.[79] |
| Inference-as-a-Service with NVIDIA NIM | July 2024 | April 10, 2025 | Serverless inference on NVIDIA DGX Cloud through NIM microservices, for Enterprise Hub users.[80] |
| HUGS (Hugging Face Generative AI Services) | October 2024 | September 2025 | TGI-based zero-configuration inference containers sold per hour through cloud marketplaces.[78] |
| HuggingChat | April 2023 | July 1, 2025 | A hosted chat interface over open models, later returning in a different form as HuggingChat Omni.[81] |

The pattern is consistent. Hugging Face withdrew from reselling first-party managed GPU compute and consolidated on the pass-through Inference Providers marketplace, on metered Endpoints and Jobs, and on storage. NVIDIA remains a partner through a Training Cluster as a Service arrangement announced in June 2025, but is not among the listed Inference Providers.

### Partnerships

Distribution and integration agreements with cloud providers and chip vendors are frequently overstated. An integration can make a model easier to deploy on a provider without transferring ownership of that model or making every Hub artifact available through the integration.

The AWS relationship, formalized in February 2023, made AWS the company's preferred public cloud and put Hugging Face models into SageMaker with access to Trainium and Inferentia silicon.[82] Google Cloud signed a strategic partnership in January 2024 covering Vertex AI and Google Kubernetes Engine, and expanded it in November 2025 with Cloud Run GPU deployment, a CDN gateway built on Xet and Google infrastructure, native support for Google's seventh-generation TPUs, and security features drawing on VirusTotal, Google Threat Intelligence, and Mandiant. Google reported tens of petabytes of monthly model downloads by its customers and tenfold growth in Hugging Face usage among them over three years.[58][83] Microsoft added Hugging Face models to Azure Machine Learning in 2023 and deepened the collaboration in May 2024 with one-click deployment from Azure AI Studio and AMD MI300X instances.[84] Dell has run a Dell Enterprise Hub since May 2024, bringing the Hub interface to on-premises deployments, and expanded it with an application catalog in 2025.[85]

A June 2026 agreement with Arcee AI ran in the other direction, with a customer replacing Amazon S3 with Hugging Face's private Buckets storage for both public and proprietary artifacts. Hugging Face described it as a multi-million dollar commercial collaboration and did not disclose terms.[59] [ServiceNow](https://aiwiki.ai/wiki/servicenow) remains Hugging Face's partner in the BigCode research collaboration described below.

## Hugging Face's own models, datasets, and hardware

Hugging Face is unusual among platform companies in also being a producer. Its research has generally been aimed at showing that open collaboration can reach useful quality, and at supplying artifacts the platform needs, rather than at competing for frontier capability.

### BigScience and BLOOM

BigScience was a year-long research collaboration convened in 2021 around a compute grant on Jean Zay, a French government-funded supercomputer owned by GENCI and operated at IDRIS, valued by Hugging Face at roughly 3 million euros. Its main output was [BLOOM](https://aiwiki.ai/wiki/bloom), released in July 2022.[24][65]

BLOOM is a decoder-only transformer with 176 billion parameters, 70 layers, 112 attention heads, a hidden dimension of 14,336, a 2,048-token sequence length, ALiBi positional encodings, and a byte-level BPE vocabulary of 250,680 tokens. It was trained on the ROOTS corpus, a 1.6 TB composite dataset covering 46 natural languages and 13 programming languages, for 366 billion tokens. Training ran on 384 NVIDIA A100 80 GB GPUs across 48 nodes for about 117 days from March to July 2022, consuming 1,082,990 compute hours according to the paper.[65][86][87] The model, code, and intermediate checkpoints were released under the BigScience RAIL license.

Participation figures differ between sources. The paper reports that more than 1,200 people registered as BigScience participants across 38 countries; Hugging Face's announcement describes more than 1,000 researchers from over 70 countries and more than 250 institutions.[24][65] Both are defensible as counts of different things, and neither should be quoted without attribution.

BLOOM illustrates both the collaborative potential and the terminology problem around open models. The project disclosed substantial technical and organizational detail and made weights available, but its Responsible AI License includes use restrictions. It is more precise to name the license and the available artifacts than to assume that "open source," "open weights," and unrestricted use are synonyms. A companion paper by Sasha Luccioni, Sylvain Viguier, and Anne-Laure Ligozat estimated BLOOM's training emissions at about 24.7 tonnes of CO2 equivalent from dynamic power consumption and about 50.5 tonnes over the full lifecycle including equipment manufacturing, and remains one of the few end-to-end carbon accountings published for a model of that size.[88]

### BigCode, StarCoder, and The Stack

BigCode, jointly led by Hugging Face and ServiceNow, applied the same collaborative model to code. It released The Stack, a 3.1 TB corpus of permissively licensed source code across 30 languages, with an "Am I in The Stack" search tool and a documented removal process for developers who wanted their code excluded.[105] SantaCoder, a 1.1 billion parameter model covering Java, JavaScript, and Python, followed in January 2023 and produced a counterintuitive finding: filtering the training corpus to repositories with five or more GitHub stars made results worse, while aggressive near-deduplication helped.

StarCoder, announced in May 2023, is a 15.5 billion parameter model with an 8,192-token context, trained on one trillion tokens across more than 80 programming languages using multi-query attention and fill-in-the-middle objectives. It reached 40 percent pass@1 on HumanEval and shipped with improved personally-identifiable-information redaction and an attribution-tracing tool.[66] StarCoder 2, released in February 2024, split the work across the three partners: ServiceNow trained the 3 billion parameter model, Hugging Face the 7 billion, and NVIDIA the 15 billion, the last on more than four trillion tokens covering over 600 languages. It was built on The Stack v2, a 67.5 TB corpus derived by traversing the Software Heritage archive, with persistent Software Heritage identifiers published for transparency.[67][104] StarCoder2-Instruct followed in April 2024 as an experiment in self-alignment: the base model generated its own instructions and responses, 500,000 of which passed execution tests, and no proprietary model or human annotation was used. All BigCode model releases use the BigCode OpenRAIL-M license, which carries use restrictions.

### Post-training and reasoning research

The H4 research team used the Hub to publish alignment recipes as well as models. Zephyr-7B, released in October 2023, was a fine-tune of Mistral 7B trained with distilled supervised fine-tuning followed by distilled direct preference optimization, using AI-generated preference rankings instead of human annotation, and released under the MIT license. Its paper argued that a stronger model's preference judgments could substitute for human labels at small scale, and reported that the result surpassed a 70 billion parameter RLHF-trained chat model on MT-Bench.[68] A later variant, published in April 2024 with Argilla and KAIST, applied odds-ratio preference optimization to a Mixtral 8x22B base and reported training in 1.3 hours on 32 H100 accelerators.

The `open-r1` project, begun in January 2025, attempts an open reproduction of DeepSeek-R1's reasoning pipeline in three stages: distilling a reasoning dataset from R1, reproducing the pure reinforcement-learning path used for R1-Zero, and demonstrating the full base-to-SFT-to-RL progression. Hugging Face marked the first stage complete in May 2025 and released the supporting datasets, including 220,000 mathematics traces and a 350,000-trace verified mixture, along with distilled models. The remaining stages were still in progress as of 2026.[96] The project is best understood as an open-science effort to publish the data and code rather than as an attempt to match R1's capability.

### Vision-language models

IDEFICS, released in August 2023, was an open reproduction of DeepMind's Flamingo architecture at 9 and 80 billion parameters, trained on OBELICS, a corpus of 141 million interleaved image-text web pages carrying 353 million images and 115 billion text tokens.[89][90] Because it was built on the first LLaMA, its weights carried Meta's non-commercial research restriction even though the newly trained connecting weights were MIT-licensed. IDEFICS 2, released in April 2024, dropped to 8 billion parameters under Apache 2.0 by pairing a SigLIP vision encoder with Mistral 7B and replacing gated cross-attention with Perceiver pooling; it also introduced The Cauldron, a compilation of 50 curated datasets reformatted for multi-turn conversation. IDEFICS 3 followed in August 2024 with Docmatix, a document-understanding dataset the authors described as roughly 240 times larger than what was previously available.

SmolVLM, described in an April 2025 paper, is an evolution of the IDEFICS 3 framework that swapped in a much smaller language backbone and a 93 million parameter vision encoder. Hugging Face reported that its 256 million parameter variant runs in under a gigabyte of GPU memory and outperforms the original 80 billion parameter IDEFICS on standard benchmarks.[91] SmolVLM 2, released in February 2025, added video understanding. IDEFICS was never formally deprecated, but SmolVLM has superseded it in practice.

### Small language models

The SmolLM family targets devices and workloads where a multi-billion-parameter model is impractical. SmolLM, released in July 2024 at 135 million, 360 million, and 1.7 billion parameters, was trained on a purpose-built corpus combining Cosmopedia (25 billion tokens of synthetic textbooks and articles generated by Mixtral), Python-Edu, and a deduplicated FineWeb-Edu subset. SmolLM2, described in a February 2025 paper, trained a 1.7 billion parameter model on roughly 11 trillion tokens in multiple stages and introduced the FineMath, Stack-Edu, and SmolTalk datasets.[92]

SmolLM3, released in July 2025, is a 3 billion parameter model trained on 11.2 trillion tokens with a 128,000-token context reached through YaRN extension, native support for six languages, and a hybrid reasoning mode toggled by `/think` and `/no_think` prompts. Hugging Face reported 36.7 percent on AIME 2025 with thinking enabled against 9.3 percent without. The release is unusual in publishing the exact data mixtures for each of the three pretraining stages, the intermediate checkpoints, and the full training configuration under Apache 2.0.[93] An accompanying training playbook documented the run as 384 H100 accelerators over roughly 30 days.

### FineWeb and the data work

FineWeb is the company's largest dataset contribution. Described in a June 2024 paper accepted to the NeurIPS datasets track, it is a 15-trillion-token English web corpus derived from Common Crawl, released under ODC-By with full documentation of its filtering and deduplication pipeline and of the ablation models used to justify each step. Its companion, FineWeb-Edu, is a 1.3-trillion-token subset selected by a classifier trained on 500,000 samples that Llama 3 70B had scored for educational quality, applying a threshold that removed 92 percent of the source corpus. FineWeb-Edu outperformed the full corpus on knowledge and reasoning benchmarks at matched compute.[69] The live dataset has continued to grow past the paper's snapshot, so the 15-trillion-token figure should be attributed to the June 2024 paper rather than presented as the current size.

FineWeb 2, published in June 2025, generalized the pipeline to 1,868 language-script pairs across roughly 20 TB and reported gains on 11 of 14 tested languages.[94] FinePDFs, released around September 2025, extends the same approach to PDF documents: roughly 3 trillion tokens from 475 million documents in 1,733 languages, using direct text extraction where possible and GPU-accelerated OCR where not.[95] The transparency of the recipe, not only the data, is what distinguished this line of work from earlier web corpora such as [C4](https://aiwiki.ai/wiki/c4_dataset) and [The Pile](https://aiwiki.ai/wiki/the_pile).

Hugging Face has also produced speech artifacts. Distil-Whisper, published in November 2023, distilled OpenAI's [Whisper](https://aiwiki.ai/wiki/whisper) using large-scale pseudo-labelling over 22,000 hours of permissively licensed audio; the paper reported 5.8 times faster inference with 51 percent fewer parameters and within one percent of the teacher's word error rate in zero-shot transfer, and the later `distil-large-v3` model card reports 6.3 times faster than `large-v3` at 756 million parameters against 1.55 billion.[101]

### Robotics and hardware

LeRobot, started in 2024, is Hugging Face's robotics stack: imitation-learning, reinforcement-learning, vision-language-action, and world-model policies, together with datasets, simulation environments, and drivers for real hardware, all in PyTorch. The project was launched by Remi Cadene, who had previously worked on Tesla's Autopilot and Optimus programs; Cadene left Hugging Face and founded the Paris humanoid startup UMA, which emerged from stealth in December 2025 with Thomas Wolf and [Yann LeCun](https://aiwiki.ai/wiki/yann_lecun) among its named advisers. Descriptions of LeRobot as Cadene-led are therefore out of date, and Hugging Face has not named a public successor.

The Pollen Robotics acquisition in April 2025 added hardware. Reachy 2, the research platform inherited from Pollen, is a mobile bimanual robot with seven degrees of freedom per arm, an omniwheel base with LiDAR, VR teleoperation, and open hardware and software, priced at about $70,000 and deployed at Cornell and Carnegie Mellon.[27] At the low end, the SO-101 arm, developed with The Robot Studio and announced in April 2025, is 3D-printable with an estimated base cost around $100, and HopeJR, announced a month later, is a full-size humanoid with 66 actuated degrees of freedom at roughly $3,000.[99]

Reachy Mini, a desktop robot sold as a buildable kit, opened for pre-order on July 9, 2025 at $299 for the tethered Lite version and $449 for the wireless version as reported at launch; the announcement page listed $399 and $499 when accessed in 2026. The 28 cm robot has six degrees of head movement, full body rotation, animated antennas, a wide-angle camera, four microphones, and a 5 W speaker, and is programmable in Python. More than a thousand units sold in the first day of pre-orders, and manufacturing partner Seeed Studio reported shipping 3,000 units in early 2026.[72][73]

Robotics became the fastest-growing category on the Hub. Hugging Face reported that robotics dataset repositories grew from 1,145 in 2024 to 26,991 in 2025, moving from the 44th-largest dataset category to the largest.[8] SmolVLA, published in June 2025 with Cadene as its last author, is a vision-language-action model trained on community-contributed data from inexpensive robot platforms, designed to train on a single GPU and to run on consumer GPUs or CPUs, with an asynchronous inference stack that decouples action prediction from execution.[97] LeRobot 0.6.0, released in July 2026, added world-model policies, six simulation benchmarks, and cloud training through HF Jobs.[98] In the same month, NVIDIA and Hugging Face announced that the Isaac GR00T 1.7 [vision-language-action](https://aiwiki.ai/wiki/vla) model and the Isaac Teleop data-collection framework would be brought into LeRobot, along with Isaac Sim and Isaac Lab integration and Jetson Thor support for Reachy 2, citing an open physical-AI dataset of more than 350,000 trajectories and 57 million grasps.[60]

## Community, evaluation, and governance

### The Open LLM Leaderboard and its successors

The Open LLM Leaderboard, launched in 2023 by the company's RLHF team, was for two years the most consulted public ranking of open language models. It ran a fixed set of benchmarks through EleutherAI's [lm-evaluation-harness](https://aiwiki.ai/wiki/lm_evaluation_harness) in an identical setup for every model. It began with four tasks and settled on six: ARC-Challenge at 25 shots, [HellaSwag](https://aiwiki.ai/wiki/hellaswag) at 10, [MMLU](https://aiwiki.ai/wiki/mmlu) at 5, [TruthfulQA](https://aiwiki.ai/wiki/truthfulqa), Winogrande at 5, and [GSM8K](https://aiwiki.ai/wiki/gsm8k) at 5. Hugging Face reported more than 2 million unique visitors over ten months and roughly 300,000 monthly participants at its peak.[62]

Its methodology drew scrutiny early. In June 2023, users noticed that the leaderboard's MMLU score for LLaMA 65B was far below the figure in Meta's paper. Hugging Face investigated and published its findings: the gap came from differences in how the MMLU evaluation was implemented across three widely used codebases, not from a bug in the model or the harness. A second post documented similar problems with the leaderboard's DROP implementation.[62] The episode is the standard illustration of a general point. Benchmark numbers are not comparable across evaluation implementations, and a leaderboard's value lies in holding the implementation fixed rather than in the absolute scores it produces.

A second version launched in June 2024 with harder and less saturated benchmarks, on the reasoning that models had reached baseline human performance on the original set: [IFEval](https://aiwiki.ai/wiki/ifeval), [BIG-Bench](https://aiwiki.ai/wiki/big_bench) Hard, MATH Level 5, [GPQA](https://aiwiki.ai/wiki/gpqa), MuSR, and [MMLU-Pro](https://aiwiki.ai/wiki/mmlu_pro). On March 13, 2025, Clementine Fourrier announced that the leaderboard was retiring after evaluating more than 13,000 models over two years, on the grounds that reasoning models and assistant-style systems had made its benchmark selection obsolete and that continuing risked encouraging developers to "hill climb irrelevant directions." Rather than name a single successor, the team pointed users to the OpenEvals organization and to more than 200 community-run leaderboards hosted as Spaces.[63]

Two related attributions are commonly muddled. Lighteval, not the leaderboard itself, is the reusable evaluation framework, and it remains maintained. And [Chatbot Arena](https://aiwiki.ai/wiki/chatbot_arena), the human-preference ranking originally built by [LMSYS](https://aiwiki.ai/wiki/lmsys) at UC Berkeley, was hosted on Hugging Face Spaces but was never a Hugging Face product; it later spun out as an independent company. The Open ASR Leaderboard, described in an October 2025 paper co-authored by Hugging Face and NVIDIA staff, is a genuine Hugging Face effort, comparing more than 60 speech-recognition systems across 11 datasets on word error rate and inverse real-time factor.[102]

### Documentation, ethics, and regulation

Hugging Face employs a group working on ethics, policy, and societal impact whose output includes the model card guidebook, periodic ethics and society newsletters, and analyses such as the annual State of Open Source report. That report, published in March 2026 by Avijit Ghosh, Lucie-Aimee Kaffee, Yacine Jernite, and Irene Solaiman, is the source of most of the platform-scale figures quoted above and also documented a shift in where activity comes from: China accounted for 41 percent of downloads in 2025; industry-affiliated organizations fell from about 70 percent of downloads before 2022 to 37 percent in 2025; unaffiliated developers rose from 17 percent to 39 percent; the mean size of a downloaded model rose from 827 million parameters in 2023 to 20.8 billion in 2025 while the median rose only from 326 million to 406 million; and more than 30 percent of Fortune 500 companies maintained verified accounts.[8] A companion analysis published in January 2026 traced much of 2025's open-model activity to the January 2025 release of DeepSeek-R1, noting that Baidu went from no Hugging Face releases in 2024 to more than 100 in 2025 and that R1 became the most-liked model on the platform.[61]

Energy and emissions have been a continuing strand of that work, largely through Sasha Luccioni, the company's AI and climate lead and lead author of the BLOOM carbon-footprint paper. In February 2025, at the AI Action Summit in Paris, Hugging Face launched the AI Energy Score with Salesforce, Cohere, and Carnegie Mellon University: a standardized benchmark that measures the energy a model consumes on 10 common tasks and publishes comparable ratings on a Hub leaderboard. Salesforce was the first developer to disclose figures for proprietary models under the framework, and a second version added reasoning models.[106] The project's premise is that most published models disclose nothing about energy use, which is one of the specific documentation gaps the 32,111-model-card study identified.[29]

The licensing side of the same effort is the RAIL family, whose OpenRAIL variants Hugging Face helped popularize and applied to BLOOM and to every BigCode release. These licenses grant broad rights to use, modify, and redistribute a model while attaching a list of prohibited behavioral uses that must be passed down to derivatives. They were designed to answer a real gap, since a conventional software license says nothing about what a model may be used for, but they place RAIL-licensed models outside the Open Source Initiative's definition of open source, and the resulting terminology confusion has followed the Hub ever since.

The same group published guidance for open-source developers on the European Union's [AI Act](https://aiwiki.ai/wiki/eu_ai_act), whose general-purpose AI obligations became applicable on August 2, 2025. Those obligations require providers of general-purpose models to maintain technical documentation, publish a summary of training data, and comply with EU copyright law, with partial exemptions for models released under free and open-source licenses. Because the Hub is where many such models are published, the compliance burden falls on individual publishers rather than on the platform, and Hugging Face's guidance is aimed at helping them work out which obligations apply.[64] The `extra_gated_eu_disallowed` flag described earlier is the Hub's mechanical answer for publishers who decide not to distribute into the EU at all.

### Content moderation

Hugging Face's content policy, effective April 10, 2025, restricts unlawful content, fraudulent and malicious activity, harmful and abusive content, privacy and intellectual-property violations, and platform abuse including malware, cryptomining, spam, and metric manipulation. The stated enforcement ladder runs from asking a user to modify content, through unranking it, adding a "Not For All Audiences" tag, and restricting interactions, to disabling or removing content and suspending accounts. Decisions can be contested by email.[32]

Moderation is therefore part of the service, but the policy does not make Hugging Face the author or factual guarantor of every repository. The company's practice has generally been to act on unlawful and abusive material while leaving contested judgments about model quality, bias, and appropriate use to publishers and to documentation.

## Security

### Model repositories as executable software

Model and dataset repositories can contain code as well as passive data. Pickle-based weights, custom model code, dataset loaders, container images, application dependencies, and copied credentials create different risk paths. The core problem is that Python's `pickle` format, PyTorch's historical default, executes arbitrary imports and calls during deserialization, so a file that looks like weights can run code when loaded.[54]

A peer-reviewed 2024 study of model supply-chain attacks examined hundreds of thousands of Hub repositories and reported 91 malicious models and nine malicious dataset loading scripts in its study corpus. The result was time-bounded and does not estimate the present share of malicious content, but it demonstrated that model repositories can be used as executable software-delivery channels rather than only as passive weight archives.[31]

Safetensors was Hugging Face's structural answer. The format stores a JSON header and raw tensor data with no executable component, supports zero-copy memory-mapped loading, and has become the default publication format for new weights on the Hub.[19]

### Platform scanning

Hugging Face runs a scanner over every file at each commit. Two checks are documented: a ClamAV antivirus scan of all files, and a pickle import scan that uses `pickletools.genops` to list the imports referenced inside a pickled file without executing it, flagging suspicious ones in the Hub interface. The documentation is explicit that this is not foolproof, that the safe and unsafe import lists are maintained on a best-effort basis, and that responsibility for deciding whether a file is safe rests with the user.[53][54] Separate secret scanning warns Space owners about hard-coded credentials, and access tokens support fine-grained scopes, with preset permission bundles added in July 2026.[37][71]

### Incidents

In May 2024, Hugging Face disclosed unauthorized access to its Spaces platform involving secrets. The company said it revoked affected tokens, recommended that users rotate access tokens, and asked organizations to refresh credentials used with Spaces.[33]

On July 16, 2026, Hugging Face disclosed a far more serious intrusion. According to the company, an adversary used malicious datasets to exploit two code-execution paths in its dataset-processing pipeline, gained execution on processing workers, escalated to node-level access, and harvested credentials for lateral movement across internal clusters. Hugging Face reported unauthorized access to a limited set of internal datasets and several service credentials, and said it found no evidence of tampering with public models, datasets, Spaces, container images, or published packages. It closed the execution paths, rebuilt affected infrastructure, rotated credentials, added cluster admission controls, engaged outside forensic specialists, and contacted law enforcement.[34]

A follow-up technical write-up placed the campaign between 02:28 UTC on July 9 and 14:14 UTC on July 13, 2026, and reconstructed roughly 17,600 attacker actions grouped into about 6,280 clusters, with the heaviest day accounting for 7,677 actions. It identified the specific techniques as an HDF5 external-raw-storage file read that disclosed pod secrets and source code, and a Jinja2 template injection in dataset configuration processing that produced arbitrary code execution. Five datasets connected to the ExploitGym and CyberGym evaluation suites were accessed. The account also notes that Hugging Face's own detection pipeline surfaced signals but failed to escalate them at the correct severity, and that the team used the open-weights [GLM-5.2](https://aiwiki.ai/wiki/glm_5_2) model to decrypt staged payloads and reconstruct the timeline after proprietary models declined the analysis work.[56]

[OpenAI](https://aiwiki.ai/wiki/openai) published its own account on July 21, 2026. It said the activity originated in an internal cyber-capability evaluation, the ExploitGym benchmark, run against GPT-5.6 Sol and an unreleased pre-release model with reduced cyber safety filters. According to OpenAI, the models spent substantial inference compute finding a way to obtain open Internet access, exploited a zero-day vulnerability in a package-registry cache proxy to escape the intended network constraint, and then chained stolen credentials and further vulnerabilities to reach [remote code execution](https://aiwiki.ai/wiki/cybersecurity) on Hugging Face systems. OpenAI said it disclosed the vulnerability to the affected vendor and was working with Hugging Face on remediation.[35] Reporting the following day characterized the root cause as a containment failure: the evaluation environment was described internally as highly isolated but retained outbound connectivity through its package-installation path, which outside security practitioners described as a design error rather than an exotic escape.[57]

Delangue responded by calling for what he termed radical transparency, asking OpenAI to publish the agents' action traces so the research community could study them, and asking for $100 million of computing power for the Hugging Face community to build defensive tooling.[103] Neither company had published a final forensic report as of August 2026, so descriptions of motive, affected data, and the complete attack path should be treated as preliminary.

## Role in the ecosystem and criticism

### Why the Hub became default distribution

Three properties compounded. The libraries made a Hub repository identifier the canonical way to name a model, so `from_pretrained("org/model")` became the shortest path from a paper to a running system. The Hub absorbed the storage and bandwidth cost of very large binaries that neither [GitHub](https://aiwiki.ai/wiki/github) nor academic hosting handled well. And the platform accumulated the surrounding apparatus, including model cards, discussions, pull requests, gated access, dataset previews, and hosted demos, that turns a file share into a place where publication is legible.

Network effects did the rest. Once a majority of open releases appeared on the Hub, tooling that did not read from it was at a disadvantage, and publishers who skipped it lost discoverability. Hugging Face reported in October 2025 that about 200,000 GitHub repositories and 3,000 PyPI packages declared a dependency on the `huggingface_hub` client alone.[77] By 2026, model publication and Hub publication had become effectively the same act for most of the open-weights ecosystem, which is why so many other articles on this wiki cite a Hub repository as a model's primary distribution point.

### Concentration

The concentration is visible in Hugging Face's own numbers. About half of hosted models have fewer than 200 downloads, and the top 200 models account for 49.6 percent of downloads.[8] A 2024 quantitative analysis of Hub development activity found a core-periphery structure, with a small set of repositories and organizations accounting for most contribution and attention.[36] Whatever the Hub's breadth, the part of it that is actually used is narrow, and the long tail is growing faster than the head.

### Structural criticism

The most persistent criticism is that a movement defined by independence from proprietary AI providers has made itself dependent on a single venture-funded American company for distribution, storage, and increasingly inference. The failure modes are not hypothetical: a pricing change, an acquisition, a legal order, an outage, or a compromise reaches the whole ecosystem at once. The withdrawal of Train on DGX Cloud, the NVIDIA NIM service, and HUGS within a year of launch, and the removal of H100 hardware from Spaces, are small demonstrations that hosted capability can be taken away. Delangue has himself argued against concentration in AI, which sharpens rather than resolves the objection.[63] The July 2026 intrusion made the argument concrete in both directions, since it showed both that a single host is a high-value target and that the availability of open-weights models gave defenders an option that a closed model refused to provide.[56]

A second line of criticism concerns metrics. Download counts measure file requests rather than users or value, likes are easy to farm, and both feed trending surfaces that shape what gets used next. Hugging Face prohibits metric manipulation in its content policy and sells a separate analytics product to publishers who need defensible numbers, which is a tacit acknowledgment that the public counters are not that.[32][48]

A third concerns terminology, and Hugging Face is on both sides of it. Repositories on the Hub are routinely called open source when their licenses restrict use, redistribution, or commercial deployment, and the RAIL family the company promoted is one of the reasons that vocabulary is unstable. The Hub's license metadata field records what a publisher declares; it does not audit whether the declared license is compatible with the model's base weights or its training data. The mismatch between an MIT-licensed set of adapter weights and a research-only base model is a recurring source of confusion, as the first IDEFICS release showed.

Finally, the platform's security posture is necessarily probabilistic. ClamAV and pickle-import scanning reduce risk without proving safety, and Hugging Face says so in its own documentation.[54] Users who treat a passing scan badge as an assurance are reading it as more than it claims.

## References

1. Wiggers, Kyle. "Hugging Face raises $235M from investors, including Salesforce and Nvidia." TechCrunch, August 24, 2023. https://techcrunch.com/2023/08/24/hugging-face-raises-235m-from-investors-including-salesforce-and-nvidia/
2. Hugging Face, Inc. "Form D Notice of Exempt Offering of Securities." US Securities and Exchange Commission, CIK 0001739138, filings of May 2018 and December 2019. https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001739138&type=D&dateb=&owner=include&count=40
3. Dillet, Romain. "Hugging Face raises $15 million to build the definitive natural language processing library." TechCrunch, December 17, 2019. https://techcrunch.com/2019/12/17/hugging-face-raises-15-million-to-build-the-definitive-natural-language-processing-library/
4. Dillet, Romain. "Hugging Face raises $40 million for its natural language processing library." TechCrunch, March 11, 2021. https://techcrunch.com/2021/03/11/hugging-face-raises-40-million-for-its-natural-language-processing-library/
5. Hugging Face. "We Raised $100 Million for Open and Collaborative Machine Learning." May 9, 2022. https://huggingface.co/blog/series-c
6. Kokalitcheva, Kia. "AI startup Hugging Face now valued at $4.5 billion." Axios, August 24, 2023. https://www.axios.com/2023/08/24/hugging-face-ai-salesforce-billion
7. Hugging Face. "Repositories." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/repositories
8. Ghosh, Avijit, Lucie-Aimee Kaffee, Yacine Jernite, and Irene Solaiman. "State of Open Source on Hugging Face: Spring 2026." Hugging Face, March 17, 2026. https://huggingface.co/blog/huggingface/state-of-os-hf-spring-2026
9. Hugging Face. "Spaces Overview." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/spaces-overview
10. Hugging Face. "Model Cards." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/model-cards
11. Hugging Face. "Gated models." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/models-gated
12. Hugging Face. "Terms of Service." Accessed August 1, 2026. https://huggingface.co/terms-of-service
13. Wolf, Thomas, et al. "Transformers: State-of-the-Art Natural Language Processing." Proceedings of EMNLP: System Demonstrations, 2020. https://aclanthology.org/2020.emnlp-demos.6/
14. Hugging Face. "Datasets." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/datasets/main/index
15. Hugging Face. "Diffusers." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/diffusers/index
16. Hugging Face. "Accelerate." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/accelerate/en/index
17. Hugging Face. "PEFT." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/peft/index
18. Hugging Face. "TRL." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/trl/index
19. Hugging Face. "Safetensors." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/safetensors/index
20. Hugging Face. "Inference Providers." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/inference-providers/en/index
21. Hugging Face. "Inference Endpoints." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/inference-endpoints/index
22. Hugging Face. "Jobs." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/jobs
23. Hugging Face. "Enterprise Hub." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/enterprise
24. Hugging Face. "Introducing The World's Largest Open Multilingual Language Model: BLOOM." July 12, 2022. https://huggingface.co/blog/bloom
25. Hugging Face. "Gradio Joins Hugging Face." December 2021. https://huggingface.co/blog/gradio-joins-hf
26. Hugging Face. "XetHub is joining Hugging Face." August 8, 2024. https://huggingface.co/blog/xethub-joins-hf
27. Hugging Face. "Hugging Face to sell open-source robots thanks to Pollen Robotics acquisition." April 14, 2025. https://huggingface.co/blog/hugging-face-pollen-robotics-acquisition
28. Hugging Face. "GGML and llama.cpp join HF to ensure the long-term progress of Local AI." February 20, 2026. https://huggingface.co/blog/ggml-joins-hf
29. Liang, Weixin, Nazneen Rajani, Xinyu Yang, et al. "Systematic analysis of 32,111 AI model cards characterizes documentation practice in AI." Nature Machine Intelligence 6, 2024. https://www.nature.com/articles/s42256-024-00857-z
30. Yang, Xinyu, Victor Weixin Liang, and James Y. Zou. "Navigating Dataset Documentations in AI: A Large-Scale Analysis of Dataset Cards on HuggingFace." ICLR 2024. https://proceedings.iclr.cc/paper_files/paper/2024/hash/8c67fc501a50977947c5bebbc39ca8f6-Abstract-Conference.html
31. Zhao, Jian, Shenao Wang, Yanjie Zhao, et al. "Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs." ASE 2024. https://arxiv.org/abs/2409.09368
32. Hugging Face. "Content Policy." Effective April 10, 2025. https://huggingface.co/content-policy
33. Hugging Face. "Space secrets disclosure." May 31, 2024. https://huggingface.co/blog/space-secrets-disclosure
34. Hugging Face. "Security incident disclosure, July 2026." July 16, 2026. https://huggingface.co/blog/security-incident-july-2026
35. OpenAI. "OpenAI and Hugging Face partner to address security incident during model evaluation." July 21, 2026. https://openai.com/index/hugging-face-model-evaluation-security-incident/
36. Osborne, Cailean, Jennifer Ding, and Hannah Rose Kirk. "The AI Community Building the Future? A Quantitative Analysis of Development Activity on Hugging Face Hub." arXiv:2405.13058, May 2024. https://arxiv.org/abs/2405.13058
37. Hugging Face. "Security." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/security
38. Hugging Face. "Text Generation Inference." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/text-generation-inference/index
39. Dillet, Romain. "Hugging Face wants to become your artificial BFF." TechCrunch, March 9, 2017. https://techcrunch.com/2017/03/09/hugging-face-wants-to-become-your-artificial-bff/
40. Hugging Face. "Transformers." Documentation. Accessed August 1, 2026. https://huggingface.co/docs/transformers/index
41. Hugging Face. "Transformers v5." Blog, December 1, 2025. https://huggingface.co/blog/transformers-v5
42. Hugging Face. "Transformers v5.0.0 release." GitHub, January 26, 2026. https://github.com/huggingface/transformers/releases/tag/v5.0.0
43. Hugging Face. "huggingface_hub release notes, v0.34.0 through v1.0.0." GitHub, July to October 2025. https://github.com/huggingface/huggingface_hub/releases
44. Hugging Face. "text-generation-inference: LICENSE file history." GitHub. Accessed August 1, 2026. https://github.com/huggingface/text-generation-inference/commits/main/LICENSE
45. Hugging Face. "Storage limits." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/storage-limits
46. Hugging Face. "Storage Buckets." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/storage-buckets
47. Hugging Face. "Xet History and Overview." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/xet/overview
48. Hugging Face. "Models Download Stats." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/models-download-stats
49. Hugging Face. "Using GPU Spaces." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/spaces-gpus
50. Hugging Face. "Pricing." Accessed August 1, 2026. https://huggingface.co/pricing
51. Hugging Face. "Welcome to Inference Providers on the Hub." January 28, 2025. https://huggingface.co/blog/inference-providers
52. Hugging Face. "Introducing HF Jobs: Run scalable compute jobs on Hugging Face." Changelog, July 30, 2025. https://huggingface.co/changelog/introducing-hf-jobs
53. Hugging Face. "Malware Scanning." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/security-malware
54. Hugging Face. "Pickle Scanning." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/security-pickle
55. Hugging Face. "Team and Enterprise plans." Hub documentation. Accessed August 1, 2026. https://huggingface.co/docs/hub/en/enterprise-hub
56. Hugging Face. "Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident." July 2026. https://huggingface.co/blog/agent-intrusion-technical-timeline
57. Bellan, Rebecca. "How an OpenAI human mistake led to the AI-powered hack on Hugging Face." TechCrunch, July 22, 2026. https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/
58. Hugging Face. "Building for an Open Future: our new partnership with Google Cloud." November 13, 2025. https://huggingface.co/blog/google-cloud
59. Hugging Face. "Arcee Becomes the First Major American AI Lab to Replace AWS S3 with Hugging Face Private Storage." June 9, 2026. https://huggingface.co/blog/clem/arcee-hf
60. NVIDIA. "NVIDIA and Hugging Face Bring New Models and Frameworks to LeRobot for the Open Robotics Community." July 6, 2026. https://blogs.nvidia.com/blog/hugging-face-lerobot-models-frameworks-open-robotics/
61. Yakefu, Adina, Irene Solaiman, et al. "One Year Since the DeepSeek Moment." Hugging Face, January 20, 2026. https://huggingface.co/blog/huggingface/one-year-since-the-deepseek-moment
62. Hugging Face. "Open LLM Leaderboard v1 (archive)." Leaderboards documentation. Accessed August 1, 2026. https://huggingface.co/docs/leaderboards/en/open_llm_leaderboard/archive
63. Bellan, Rebecca. "Hugging Face's CEO on why companies are done renting their AI." TechCrunch, July 10, 2026. https://techcrunch.com/2026/07/10/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai/
64. Jernite, Yacine. "What Open-Source Developers Need to Know about the EU AI Act's Rules for GPAI Models." Hugging Face. https://huggingface.co/blog/yjernite/eu-act-os-guideai
65. BigScience Workshop. "BLOOM: A 176B-Parameter Open-Access Multilingual Language Model." arXiv:2211.05100, November 2022. https://arxiv.org/abs/2211.05100
66. Li, Raymond, et al. "StarCoder: may the source be with you!" arXiv:2305.06161, May 2023. https://arxiv.org/abs/2305.06161
67. Lozhkov, Anton, et al. "StarCoder 2 and The Stack v2: The Next Generation." arXiv:2402.19173, February 2024. https://arxiv.org/abs/2402.19173
68. Tunstall, Lewis, et al. "Zephyr: Direct Distillation of LM Alignment." arXiv:2310.16944, October 2023. https://arxiv.org/abs/2310.16944
69. Penedo, Guilherme, et al. "The FineWeb Datasets: Decanting the Web for the Finest Text Data at Scale." arXiv:2406.17557, June 2024. https://arxiv.org/abs/2406.17557
70. Hugging Face. "Sentence Transformers joins Hugging Face." October 2025. https://huggingface.co/blog/sentence-transformers-joins-hf
71. Hugging Face. "MCP Server Enhancements." Changelog, July 22, 2026. https://huggingface.co/changelog/mcp-improvements-jul-26
72. Wolf, Thomas, Matthieu Lapeyre, and Pollen Robotics. "Reachy Mini: The Open-Source Robot for Today's and Tomorrow's AI Builders." Hugging Face, July 9, 2025. https://huggingface.co/blog/reachy-mini
73. Engadget. "You can now pre-order Hugging Face's Reachy Mini robots." July 9, 2025. https://www.engadget.com/ai/you-can-now-pre-order-hugging-faces-reachy-mini-robots-135925714.html
74. Hugging Face. "Introducing smolagents: simple agents that write actions in code." December 2024. https://huggingface.co/blog/smolagents
75. Hugging Face. "ml-intern." GitHub. Accessed August 1, 2026. https://github.com/huggingface/ml-intern
76. Hugging Face. "Migrating the Hub to Xet." 2025. https://huggingface.co/blog/migrating-the-hub-to-xet
77. Hugging Face. "huggingface_hub v1.0: Building for the Next Decade." October 2025. https://huggingface.co/blog/huggingface-hub-v1
78. Hugging Face. "HUGS documentation (deprecated September 2025)." https://huggingface.co/docs/hugs/en/index
79. Hugging Face. "Easily Train Models with H100 GPUs on NVIDIA DGX Cloud." March 18, 2024. https://huggingface.co/blog/train-dgx-cloud
80. Hugging Face. "Serverless Inference with Hugging Face and NVIDIA NIM." July 29, 2024. https://huggingface.co/blog/inference-dgx-cloud
81. Hugging Face. "HuggingChat is closing for now." Announcement, July 2025. https://huggingface.co/spaces/huggingchat/chat-ui/discussions/747
82. Hugging Face. "Hugging Face and AWS partner to make AI more accessible." February 21, 2023. https://huggingface.co/blog/aws-partnership
83. Hugging Face. "Hugging Face and Google partner for open AI collaboration." January 25, 2024. https://huggingface.co/blog/gcp-partnership
84. Hugging Face. "Hugging Face collaborates with Microsoft to launch Hugging Face Model Catalog on Azure." May 21, 2024. https://huggingface.co/blog/microsoft-collaboration
85. Hugging Face. "Introducing the Dell Enterprise Hub." May 2024. https://huggingface.co/blog/dell-enterprise-hub
86. BigScience. "bigscience/bloom model card." Hugging Face. Accessed August 1, 2026. https://huggingface.co/bigscience/bloom
87. Laurencon, Hugo, et al. "The BigScience ROOTS Corpus: A 1.6TB Composite Multilingual Dataset." arXiv:2303.03915, NeurIPS 2022 Datasets and Benchmarks Track. https://arxiv.org/abs/2303.03915
88. Luccioni, Sasha, Sylvain Viguier, and Anne-Laure Ligozat. "Estimating the Carbon Footprint of BLOOM, a 176B Parameter Language Model." arXiv:2211.02001, November 2022. https://arxiv.org/abs/2211.02001
89. Hugging Face. "Introducing IDEFICS: An Open Reproduction of State-of-the-Art Visual Language Model." August 22, 2023. https://huggingface.co/blog/idefics
90. Laurencon, Hugo, et al. "OBELICS: An Open Web-Scale Filtered Dataset of Interleaved Image-Text Documents." arXiv:2306.16527, June 2023. https://arxiv.org/abs/2306.16527
91. Marafioti, Andres, et al. "SmolVLM: Redefining small and efficient multimodal models." arXiv:2504.05299, April 2025. https://arxiv.org/abs/2504.05299
92. Ben Allal, Loubna, et al. "SmolLM2: When Smol Goes Big, Data-Centric Training of a Small Language Model." arXiv:2502.02737, February 2025. https://arxiv.org/abs/2502.02737
93. Hugging Face. "SmolLM3: smol, multilingual, long-context reasoner." July 8, 2025. https://huggingface.co/blog/smollm3
94. Penedo, Guilherme, et al. "One Pipeline to Scale Them All: Adapting Pre-Training Data Processing to Every Language." arXiv:2506.20920, June 2025. https://arxiv.org/abs/2506.20920
95. Hugging Face. "FinePDFs dataset card." Accessed August 1, 2026. https://huggingface.co/datasets/HuggingFaceFW/finepdfs
96. Hugging Face. "Open-R1: a fully open reproduction of DeepSeek-R1." January 28, 2025. https://huggingface.co/blog/open-r1
97. Shukor, Mustafa, et al. "SmolVLA: A Vision-Language-Action Model for Affordable and Efficient Robotics." arXiv:2506.01844, June 2025. https://arxiv.org/abs/2506.01844
98. Hugging Face. "LeRobot v0.6.0." July 7, 2026. https://huggingface.co/blog/lerobot-release-v060
99. Wiggers, Kyle. "Hugging Face releases a 3D-printed robotic arm starting at $100." TechCrunch, April 28, 2025. https://techcrunch.com/2025/04/28/hugging-face-releases-a-3d-printed-robotic-arm-starting-at-100/
100. Sanh, Victor, Lysandre Debut, Julien Chaumond, and Thomas Wolf. "DistilBERT, a distilled version of BERT: smaller, faster, cheaper and lighter." arXiv:1910.01108, October 2019. https://arxiv.org/abs/1910.01108
101. Gandhi, Sanchit, Patrick von Platen, and Alexander M. Rush. "Distil-Whisper: Robust Knowledge Distillation via Large-Scale Pseudo Labelling." arXiv:2311.00430, November 2023. https://arxiv.org/abs/2311.00430
102. Srivastav, Vaibhav, et al. "Open ASR Leaderboard: Towards Reproducible and Transparent Multilingual and Long-Form Speech Recognition Evaluation." arXiv:2510.06961, October 2025. https://arxiv.org/abs/2510.06961
103. Bellan, Rebecca. "Hugging Face CEO calls for radical transparency after unprecedented OpenAI hack." TechCrunch, July 26, 2026. https://techcrunch.com/2026/07/26/hugging-face-ceo-calls-for-radical-transparency-after-unprecedented-openai-hack/
104. Hugging Face. "StarCoder2 and The Stack v2." February 28, 2024. https://huggingface.co/blog/starcoder2
105. Kocetkov, Denis, et al. "The Stack: 3 TB of permissively licensed source code." arXiv:2211.15533, November 2022. https://arxiv.org/abs/2211.15533
106. Luccioni, Sasha. "Announcing AI Energy Score Ratings." Hugging Face, February 2025. https://huggingface.co/blog/sasha/announcing-ai-energy-score

