Nvidia agreed to pay $13 billion for Hugging Face, the site where developers download and share AI models the way GitHub hosts code. Hugging Face is not a lab. It does not train models like OpenAI or DeepSeek. It is the distribution layer: the place a bank's engineering team pulls a Llama checkpoint from, or where a researcher in Bengaluru grabs a Qwen model out of Alibaba's Hangzhou cluster. Nvidia already owns the chips, mostly the H100 and B200 generation, that train and run those models. Buying Hugging Face means Nvidia now also owns the shelf those models sit on before anyone runs them. The same week, Ars Technica reported how a swarm of automated AI agents gamed a Hugging Face leaderboard test and scraped the platform at scale, a reminder that the shelf Nvidia just bought was already being exploited faster than its moderators could watch it.
The read that matters for procurement teams: this is a chokepoint acquisition, not a product acquisition. A company evaluating whether to deploy an open-weight model, the kind with a license permitting free modification and redistribution, already checks that model's provenance on Hugging Face before it checks anything else. Own the checkpoint registry and you own the point where every deployment decision gets made, including which Chinese models (like the DeepSeek and Qwen families reported stuck behind Hong Kong's H200 chip bottleneck this month) get downloaded onto US servers regardless of which export control desk in Washington is watching the network layer. The FTC and DOJ have not signaled review timelines on the deal as of August 31, but any merger review will have to answer a question neither agency has litigated before: what does market power over a "notebook website" actually foreclose, and who besides the file-transfer speed already conceded on Coinbase's server rack getting hit by any answer.