
The a16z Show · 2026-07-17
PodcastYouTubeHugging Face's CEO on Open Source AI, Model Routing, and Competition
Hosts: Theo Jaffee, Sofia Puccini
Guests: Clément Delangue
Why it matters
Hugging Face has reached $100 million in annual recurring revenue, validating the open source platform business model
Key claims
- Hugging Face has reached $100 million in annual recurring revenue, validating the open source platform business model
- Delangue argues open source AI is inherently safer because the community builds specialized models rather than those advancing dangerous capabilities like cyber security
- The U.S. government has reportedly asked a frontier lab to restrict the release of GPT-5, an unprecedented intervention Delangue largely supports for frontier models but warns could spill over to startups and academia
- Local model adoption is accelerating via llama.cpp and models like GPT-OSS, Qwen, and Llama 4, driven by privacy, cost, and always-on agentic workloads
Radar summary
Summary
Clément Delangue, co-founder and CEO of Hugging Face, joins the a16z Show (with hosts appearing to be Theo Jaffee and Sofia Puccini) to discuss the state of open source AI. He argues that open source AI is inherently safer than proprietary frontier models because the open source community tends to build specialized models rather than those trained on dangerous capabilities like cyber security. He contrasts this with closed frontier labs that have historically marketed risk (e.g., GPT-2 being "too dangerous to release") and now face new government scrutiny, including reported U.S. government involvement in restricting the release of GPT-5.
Delangue reveals Hugging Face has crossed $100 million in annual recurring revenue, which he frames as validation of the open source business model. He highlights surging interest in local models—running on phones, laptops, and devices like Mac Minis—for privacy-sensitive use cases (health, corporate data) and sustained agentic workloads, driven by Hugging Face's llama.cpp library and models like GPT-OSS, Qwen, and Llama 4.
He pushes back on Anthropic's recent accusation that Alibaba engaged in distillation "attacks," calling distillation a standard practice used across the industry and arguing frontier labs already dominate value capture as the fastest-growing companies in the world. He frames the real risk as too little competition, not too much, and advocates for a maturing AI ecosystem built on model routing, open source, and specialized models rather than monolithic proprietary APIs. He also discusses Europe's potential to build a frontier lab through ecosystem investment.
- Hugging Face has reached $100 million in annual recurring revenue, validating the open source platform business model
- Delangue argues open source AI is inherently safer because the community builds specialized models rather than those advancing dangerous capabilities like cyber security
- The U.S. government has reportedly asked a frontier lab to restrict the release of GPT-5, an unprecedented intervention Delangue largely supports for frontier models but warns could spill over to startups and academia
- Local model adoption is accelerating via llama.cpp and models like GPT-OSS, Qwen, and Llama 4, driven by privacy, cost, and always-on agentic workloads
- Delangue dismisses Anthropic's distillation accusations against Alibaba as industry-standard practice and argues frontier labs already dominate, not suffer from, competition
- He predicts model routing—already emerging on platforms like OpenRouter and Lovable—will shift value capture from frontier APIs to a long tail of specialized models
- Europe could build a frontier lab by investing in an open ecosystem rather than trying to produce a single breakthrough company, leveraging labs like Mistral and Black Forest Labs
- Young users on Hugging Face are shifting from AI consumption to building, working on under-discussed domains like climate, biology, and chemistry
Source material
Full source text
I think distillation is a very common practice that everyone is using.
It's something that everyone uses, but that is not the main reason for success.
Like if you suck, you suck, or without distillation.
It's hard for me to say like, "Oh, or anthropic work in the eye, you're getting unfairly competed with when you're the fastest growing company in the world."
If anything, I think they need more competition than less competition because we're heading towards a world where a few companies are completely dominating, concentrating all power, all capabilities, all wealth.
And that's much more dangerous than maybe losing a couple billion dollars of revenue.
As AI models become more powerful, governments are beginning to ask new questions about safety, regulation, and who should control access to frontier technology.
In this episode, Theo Jaffee and Sofia Puccini sit down with Hugging Face co-founder and CEO, Clement de Long, to discuss why he believes open source AI is inherently safer, what Hugging Face reaching 100 million dollars in annual recurring revenue says about the business of open source, and why the next phase of AI may be defined by model routing rather than a handful of dominant frontier labs.
They also discuss GPT-5, AI regulation, local models, Europe's AI ecosystem, and the growing importance of competition across the AI stack.
And we are back with Clement de Long from Hugging Face, his second time on MTS.
Hugging Face is basically the open source AI platform.
So, Clem, welcome back to MTS.
Absolutely.
Well, gone.
I think we're about to say the same thing.
Yeah, we were talking about this interesting recent piece of news, where basically the government is going to restrict GPT-5.6's release, sort of unilaterally, basically without precedent.
I don't think the government has ever asked a frontier lab not to release a model before.
Certainly, a government has not asked a frontier lab to be able to oversee which customers the model is released to.
This seems very unnatural.
What are your takes on this?
Yeah, so it was funny.
I was in DC last week, so it was kind of like had some sort of a phone roll seat to what was happening.
Interesting anecdote is that we bumped into a town ground there, like the co-founder of a workshop.
And we were like, "Oh, it seems to be like a change of staff," or something like that before it was made public, that they changed a little bit the people talking to the White House there.
Listen, what I've seen, what I'm hearing is that there's a lot of interest from a lot of people in the USG to really understand the risks of AI and take kind of like a safe approach to the deployment of frontier models.
To be honest, I can't really blame them because of the fact that the frontier labs were basically doing marketing for the past few years.
If you remember, GPT-2 was too dangerous to release.
It was like four or five years ago.
And so I don't really blame them for doing things like that.
I just hope that we'll get a little bit more transparency about what is safe, not safe, so more focus on transparent evaluation of models and things like that.
I also hope that it's going to stay contained to a few frontier journalist models because frankly, I think they're the most dangerous ones.
And also, these companies are trillion dollar companies with armies of DC people.
So they can kind of deal with it.
I hope it's going to stay contained to that and not permeate to a lot of different players.
For example, startups, small companies, academia, or people who don't necessarily have the money, the size, the ability to really deal with these things, that would be kind of my main concern.
Totally.
Yeah.
What we were just talking about before was just like, could this be applied to open source companies and models in any way?
Is there a way that the US government could come in and restrict open source companies, either practically or legally?
I don't think so because I think the open source models are inherently less dangerous than kind of like the models that are getting restricted now because these models are a little bit ahead in terms of the enclosure to the frontier.
Also, open source models are less generous, they're more specialized.
And there's just like, nobody or very few people focusing on building dangerous cyber security capabilities.
So it's a little bit different than kind of like the proprietary labs.
So I don't think it would make sense.
I don't think it's going to get to open source just because of some of these differences.
More high level, I think in general, open source AI is much, much safer than kind of like proprietary AI for a bunch of different reasons that I've talked about in different outlets.
So I think the approach there is going to be hopefully is going to be a little bit different between kind of like low source, proprietary frontier models, and then the rest of the industry and the ecosystem that has, in my opinion, posed much less, and much less threats, where we want to keep kind of like supporting and building up to focus on competition to enable kind of like little techs, small companies, everyone to be able to basically participate in AI.
Totally.
I agree that open source models are less dangerous now.
But in six months if trends continue, you're going to have an open source model from somewhere with like mythos level capabilities that freaks out the government.
And you could imagine them at least wanting to restrict open source models at that time.
I'm not that sure, because there's this weird thing where basically the most dangerous things usually are not so much developed in open source.
Maybe it's this thing that people say like sunlight is the best disinfectant.
The funny thing is that sometimes safety people are talking about the nuclear bomb.
A nuclear bomb has never been built in open source.
And I think it would have never been built in open source.
It's been built in a closed source, proprietary team with billions of dollars of resources, so much less like some players and some others.
So I think there's also a path where open source keeps building kind of like more specialized models for different domains, and not necessarily for the domains that are presenting the biggest risks.
I don't think it's automatic that you build a more powerful model that is more dangerous for cybersecurity.
For example, you could build a more powerful model that is not more dangerous for cybersecurity.
For example, if you don't train it on cybersecurity, which really people are not really talking about, why are we not talking about that rather than talking about removing the ability to release or putting safeguards after the fact that we know are not really working because everyone can jailbreak them.
So I think I wouldn't be totally surprised if the open source community, just because it's structurally very differently set up than the big labs, are actually taking different directions that keeps it safer and never really requires the kind of regulation that you need in closed source AI labs.
Well, is this not also kind of an argument against the capability of open source AI research?
I think so because it solves different problems.
Like I sometimes take the example of local models, local intelligence, being able to be on the flights in airplane mode without network and still be able to get intelligence.
You can only get that with open source.
You can't get that with API.
There's just literally no way to do that.
So I think it's just different layers of the stack.
And actually open source is on top of closed source.
A lot of the closed source is using open source models and is using open source infrastructure.
And it solves different things.
The analogy is open source maybe is the engine and the API is the car.
And obviously, the engine is never going to be like a Ferrari.
But that's what kind of like powers the Ferrari.
So I think that's more like the way we're purchasing.
And also, being less good at bad things doesn't mean that you can't be better at good things.
Maybe open source is better at solving people's problems.
Maybe it's better at helping do stuff really important.
But it's worse at creating cybersecurity attacks.
That would be kind of like the ideal case.
People right now are talking about frontier as kind of this general thing.
The reality is that the frontier is kind of like jagged between different tasks, different domains.
This one model is going to be better at some things.
And it's going to be worse at other things.
I think that's more kind of like how we should approach it.
Does it make sense?
No, yeah, this totally makes sense to me.
So you guys just crossed $100 million in ARR.
So I'm curious as like what do you think this means for the business model of open source?
Obviously, a lot of companies are doing much more revenue than we do in AI these days.
It hasn't really been our priority to optimize for formalization and for revenue, given what we're building, which is more kind of like a usage-based platform to reach kind of like how many and empower as many AI builders as possible.
But at this small scale, I think it shows that there's a business model for open source.
There's a business model for open source platform.
We kind of knew it right because there's been GitHub before and there's been a bunch of open source successful companies.
But I guess it's a validation of that.
And we've seen for the past few weeks, we've seen quite a lot of growth in terms of interest and adoption of not only open source models, but also local models.
And so that also speaks a little bit to that.
What are some of the specific use cases that people are using local models for?
So local models are kind of free because they're running on your phone or on your laptop.
So you don't really have to pay for them.
So they're much cheaper.
They're much more privacy preserving by design because you don't have to send your data to an API.
Your data stays on your phone.
And so we see people using it a lot for the things when it matters the most.
So for example, if you want to talk about your private health and you don't want to share that with someone else.
If you want to share some of your private company data and you don't want to share it externally to an API provider.
Or if you want to run really heavy workloads, for example, agentic workloads and really have something that runs 24/7, then doing it on your laptop or like on the Mac Mini or kind of like your local hardware makes it much more sustainable.
So that would be kind of like the use cases.
We have this library called LAMACPP, which is the most used runtime for local AI workloads.
People are using a lot and they're using GPT-OSS, they're using GWEN, JMA4, like all these models locally on their laptop.
Yeah, for sure.
So going back to open models, you can imagine that the government will want to restrict open models because a lot of them come from China.
Maybe not restrict them in a strict legal way, but maybe in like an export related way.
So do you think that might happen?
And if so, what would that mean for Hugging Face?
Yeah, I mean, open weights are fundamentally different than an API.
The way you can restrict it is very different.
So for example, if you remove an open weight from Hugging Face, then it's still going to be on modal scope, for example, which is like the Chinese equivalent, or it's going to be like on torrent platforms.
So restriction looks very, very different, I think, for open source than for APIs.
You can't really block because it's open, so almost by definition, there's going to be some ways to access them.
And also, no provenance for open weights doesn't really matter as much because it's open.
The people who are sharing it kind of give up the control on it and give up their ability to influence you.
So to me, it doesn't matter so much where open weights are coming from.
It's a different game, for example, for APIs to run the inference because if you're using an API provider or cloud from China, obviously you're sending your data.
And also they could cut your access or bias your access.
That's a much, much bigger problem.
But for open weights and open source, it doesn't really matter where it comes from because it's kind of like you get all the control, you get all the transparency, there's no way to kind of trick you, bias you, manipulate you, remove your access.
So I think for open source, but provenance doesn't matter as much.
Yeah, I'm curious.
Your thoughts on just the US government sort of restricting the release of GPT 4.6.
Do you think that comes from them knowing the stakes or not knowing the stakes?
Do you think they're well informed on this matter or they just know that they don't know and that's why they're taking these measures?
It's a good question.
I can't talk for them.
I do think there's a lot of interesting learning and progress to be made everywhere, not just at the USG, but really everywhere on evaluating models, evaluating risks, or for models, I don't think we have really good benchmark for this.
And that's a big problem.
In general, ultimately, I hope we'll have more transparency.
There's this agency called KC that is amazing.
I think they're doing an amazing job.
And they're building up this capability to really evaluate and work on benchmark and things like that.
And I'm really excited for them to take a little bit more of the workload there and kind of take a very scientific approach to evaluating these models.
And I think when they will, it's going to be really good for the shields.
We definitely want to talk to people from KC soon.
It's going to be really tough.
I can't lie.
We'll try.
We'll try.
Oh, also yesterday, I was talking to Andrew Trask from DeepMind and he had a very interesting viewpoint that he...
There's a model on OpenRouter called OpenFusion, I think, and it's this fusion model of basically a bunch of different models.
And that had a lot of advanced capabilities and surpassed inefficiency in a lot of ways.
So do you think we're going to see more of that?
I think so, yeah.
I think what we're seeing right now is that a lot of people, companies, are realizing that it's too dangerous, it's too risky, it doesn't make any sense to rely exclusively on one model.
Why?
Because this model can be taken away, this model can be biased, this model can refuse or tell you the wrong things.
That's also what we've seen before, with Sable 5 before it was taken out.
There was some domain where it was intentionally by design telling you the wrong things to confuse you.
And so I think people are realizing that we need to rely on a multitude of models.
And so I think that's driving to this outcome of doing more routing.
There was an interesting study from Stanford published last year, end of last year, that was showing that 70% of the queries that people asked to chat GPT could be accurately answered locally on your laptop.
So for free, like questions.
Most of the questions you ask, or most of the AI workloads that people do today with frontier models could be done by models that are cheaper, faster, more customizable, more controllable.
And they don't do it because, frankly, it's a pain to take the model picker and be like, "Okay, this slide I'm gonna go for like a cheaper one because...
So you subsidize, so you don't have to care because you have your subscription.
So you direct everything.
It's like directing everything to Einstein.
It's like, "Hey, Einstein, what's the weather today?"
In normal life, it would be like, "Fuck you, I'm not answering your silly question."
But because it's AI and subsidized by the AI labs, all the questions are getting routed to Einstein versus in an ideal world, you can have different people, different models that are more specialized and better at answering your questions in different domains.
So that's kind of what we're seeing.
And the way to route instead of giving you the model picker, I think is a very, very smart option and a better one.
Low-vibile is starting to do that too, like doing the routing and those are good.
And I think it's possible that it's gonna redistribute a lot of the value capture from frontier models, which have been the case now.
Like majority of the revenue capture was on frontier models to a more long tail of models, which in my opinion makes much more sense.
It's like AI maturing.
We were in the first phase of AI where it's very simple, very simplistic, everyone using just one giant intake model behind proprietary APIs.
Now we're moving to the second phase of the AI field, more maturing and using several models, using open source, having control, building themselves.
I'm quite excited about it.
So another big news story of yesterday was anthropic accused Alibaba of doing distillation attacks, which is there's two perspectives on this.
One is like these are these evil people who are like skilling the capabilities of our models, violating our terms of service, like fraudulently accessing our product.
And the other is like, what do you mean?
They're creating accounts and they're paying for tokens.
And you can't accuse people of stealing when you stole the entire internet.
So which one of these two positions are you closer to?
Well, I mean, I think distillation is a very common practice that everyone is using.
I wouldn't be surprised if entropic use distillation in the past for some of their models, for some of their specialized models using kind of like someone else who's better.
For example, when OpenAI was better at coding, you use this model to kind of help you a little bit in the training of your coding model.
It's something that everyone uses, but that is not the main reason for success.
Like if you suck, you suck with or without distillation.
It's just kind of like a little bit accelerating thing, but it's not what makes you good or bad at training models.
So if you stop distillation tomorrow, the Chinese labs won't go down and disappear because it's still going to be good.
It's not really going to change the game.
And the only point that I'm a little bit biased towards that, if there was big competition problems, where it's like, oh, it's really unfair, it's biasing competition.
But it's hard for me to accept this one because frankly, I mean, Entropic OpenAI, they've been the fastest growing companies in the world.
They come overnight trillion dollar companies.
And so I don't think they have competition problems.
It's hard for me to say like, oh, or Entropic OpenAI, you're getting unfairly competed with when you're like the fastest growing company in the world.
Competition has been okay for them.
If anything, I think they need more competition than less competition.
Because we're heading towards a world where a few companies are completely dominating, concentrating all power, all capabilities, all wealth.
That's much more dangerous than losing a couple of billion dollars of revenue.
It's just hard to empathize and kind of be think that this is an important problem.
I think there are many, many more, much more important problems than that in the world of AI right now.
So since the last time we talked, there have been two big pieces written about Europe.
There's this essay Europe 2031, which is basically AI 2027, but for Europe.
Like, basically, Europe will slide into a relevance if they don't lock in on AI right now.
And then the other was Antoine Leich, who's a policy writer, wrote this piece on Subset called The Moonshot, which basically explained how if Europe wanted to do so, they could build a frontier lab.
Do you think that it's possible for Europe to do this at this point?
Could they build a frontier lab if they really tried?
I think so, yeah.
They have a lot of really great resources.
They have great people.
Why you already have some great labs, right?
Black first lab, Mistral, all these people are doing amazingly and arguably they're the frontier.
They have amazing energy.
Obviously, France, for example, nuclear energy, very abundant.
So they could really kind of use a lot of clean energy for AI.
So yeah, I think they could.
It's just a matter of focusing the energies towards that, building an ecosystem.
Sometimes, we build the stories of companies emerging out of the blue by their sheer power.
But the reality is, if it's more an ecosystem, and you see that from OpenAI, the tea of transformers, obviously, is coming from Google, that open source transformers.
And so it's more of a matter of, in my opinion, fostering an ecosystem of open research, open source AI, which is what happened in the US, right?
And kind of fostering that progressively to bring more and more companies, organizations closer to the frontier.
Yeah, totally.
I'm curious, since you run such a large platform, what are younger people doing with AI?
Are younger people actually becoming very, very proficient and AI native?
Or how do you see this pattern of behavior?
Yeah, we see them a lot.
It's almost kind of like, I feel like young people went through the first phase of being users of AI really quick.
And now, a lot of them, I think, want to be builders.
So we see a lot of very young people going on a new phase getting models and building products themselves or optimizing training models themselves, building data sets themselves.
So I see a lot of building appetites in AI for young people in a lot of different domains.
Not necessarily in the most talked about domains, but also in a lot of very topics that are really not talked about like climate change, biology, chemistry, really kind of like even social media, kind of like a lot of topics that we don't really talk about that I feel are closer to everyone's interest.
And I see a lot of young people working on these things.
That's a good white pill to end on.
That is.
Yeah.
Well, thank you so much, Clem.
This was so great.
Thank you, Clem.
Thanks for having me.
Thank you.
Very big fans.
Thanks for listening to this episode of the A16Z podcast.
If you liked this episode, be sure to like, comment, subscribe, leave us a rating or review and share it with your friends and family.
For more episodes, go to YouTube, Apple Podcasts and Spotify.
Follow us on X and A16Z and subscribe to our sub stack at a16z.substack.com.
Thanks again for listening and I'll see you in the next episode.
This information is for educational purposes only and is not a recommendation to buy, hold or sell any investment or financial product.
This podcast has been produced by a third party and may include paid promotional advertisements, other company references and individuals unaffiliated with A16Z.
Such advertisements, companies and individuals are not endorsed by A.H.
Capital Management LLC, A16Z or any of its affiliates.
Information is from sources deemed reliable on the data publication, but A16Z does not guarantee its accuracy.
[MUSIC PLAYING]