The a16z Show - Hugging Face's CEO on Open Source AI, Model Routing, and the Future of Competition
Episode Date: July 20, 2026As governments weigh new restrictions on frontier AI models, one question is becoming increasingly important: what role should open source play in the future of artificial intelligence? Theo Jaffee an...d Sofia Puccini speak with Hugging Face CEO Clément Delangue about AI regulation, open source safety, model routing, and why he believes competition—not consolidation—is essential for the industry's future. They discuss GPT-5, government oversight of frontier models, Hugging Face surpassing $100 million in annual recurring revenue, local AI, China's open-source ecosystem, Europe's AI ambitions, and why routing workloads across specialized models could fundamentally reshape where value is created in AI. Resources: Follow Clément Delangue on X: https://x.com/ClementDelangue Follow Theo Jaffee on X: https://x.com/theojaffee Follow Sofia Puccini on X: https://x.com/schisofrenia Follow MTS on X: https://x.com/mtslive Stay Updated:Find a16z on YouTube: YouTubeFind a16z on XFind a16z on LinkedInListen to the a16z Show on SpotifyListen to the a16z Show on Apple PodcastsFollow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Transcript
Discussion (0)
I think distillation is a very common practice that everyone is using.
It's something that everyone uses, but that is not, you know, the main reason for success.
Like if you suck, you suck with or without distillation.
It's hard for me to say like, oh, poor entropy, poor open AI, you're getting unfairly competed with
when you're like the fastest growing company in the world.
If you think, I think they need more competition than less competition.
Yeah.
Because we're heading towards a world where.
where a few companies are completely dominating,
concentrating all power, all capabilities, all wealth.
And that's much more dangerous than them
maybe losing a couple of billion dollars of revenue.
As Aeon models become more powerful,
governments are beginning to ask new questions about safety, regulation,
and who should control access to frontier technology.
In this episode, Theo Jaffe,
Jaffe and Sophia Puccini sit down with Hugging Face co-founder and CEO Clement DeLong
to discuss why he believes open source AI is inherently safer, what Hugging Face reaching
$100 million in annual recurring revenue says about the business of open source, and why
the next phase of AI may be defined by model routing rather than a handful of dominant frontier
labs. They also discussed GPT-5, AI regulation, local models, Europe's AI ecosystem, and the growing
importance of competition across the AI stack.
And we are back with Clement DeLong from Hugging Face, his second time on MTS.
HuggingFace is basically the open source AI platform.
So Clem, welcome back to MTS.
Absolutely.
Yeah, so, well, go on.
I think we're about to say the same thing.
Yeah, we were talking about this interesting recent piece of news where basically the government
is going to restrict
GPT 5.6's release
sort of unilaterally
basically without precedent.
I don't think the government
has ever asked
a frontier lab
not to release a model before.
Certainly a government
has not asked a frontier lab
to be able to
oversee which customers
the model is released to.
This seems very unnatural.
What are your takes on this?
Yeah, so it was funny.
I was in D.C. last week,
so it was kind of like had
some sort of Fron Rossi to what was happening.
Interesting anecdote is that we bumped into Tom Brown there,
like the co-founder of Frenchopic.
We were like, oh, it seems to be like a change, change of staff
or something like that before it was made public
that they changed a little bit the people talking to the White House there.
Listen, I mean, what I've seen, what I'm hearing is that there's a lot of,
you know, interest from a little bit of,
from a lot of people in the in the USG to really understand the risks of AI
and take kind of like a safe approach to the deployment of Frontier models.
To be honest, I can't really blame them because of the fact that, you know,
the Frontier Labs were basically doing marketing for the past few years, right?
Like if you remember GPT2 was too dangerous to release, right?
it was like what, like four, four or five years ago.
And so, you know, I don't really blame them for doing things like that.
I just hope that progressively will get a little bit more transparency about, you know,
what is safe, not safe, so more focus on, you know, transparent evaluation of models and things like that.
I also hope that it's going to stay contained to, you know, a few frontier journalist model.
because frankly, I think they're the most dangerous ones, right?
And also, you know, these companies are a trillion-dollar companies
with armies of, you know, D.C. people.
So they can kind of like deal with it.
I hope it's going to stay content to that
and not, you know, permeate to a lot of different players.
For example, startups, small companies, you know, academia,
or like people who don't necessarily have, you know, the money, the size,
the ability to really deal with these things,
that that would become like my main concern.
Totally, yeah.
What we were just talking about before was just like,
could this be applied to open source companies and models in any way?
Like, is there a way that the US government could come in
and restrict open source companies either practically or legally?
I don't think so because, you know,
I think open source.
models are inherently less dangerous
than kind of like the models that are getting restricted now
because, you know, these models are led to head
in terms of like being closer to the frontier.
Also open source models are less generally, they're more specialized.
And there's just like nobody or very few people focusing on
building dangerous like cybersecurity capabilities.
So it's like a little different than Canflare.
like the proprietary labs.
So I don't think it would make sense.
I don't think it's going to get to open source
just because of some of these differences.
A more high level, you know,
I think in general, open source AI is much, much safer
than kind of like proprietary AI
or a bunch of different reasons that I've talked about
in different outlets.
But yeah, so I think the approach there
going to be hopefully it's going to be a little bit different between kind of like
close source proprietary frontier models and then the rest of the industry and the
ecosystem that has in my opinion pose much less enter much less threats where we
want to keep kind of like you know supporting and and building up to focus on you know
competition to enable kind of like little tech small companies if everyone to be able
to basically participate in the AI.
I agree that open source models are less dangerous now,
but in six months, if trends continue,
you're going to have an open source model
from somewhere with like mythos level capabilities
that freaks out the government.
And you could imagine them at least wanting
to restrict open source models at that time.
I'm not that sure because there's this weird thing
where basically the most dangerous things
usually are not so much developed in open source.
You know, maybe it's this thing that people say, like,
sunlight is the best disinfectant.
You know, like, funny thing is that sometimes safety people
are talking about the nuclear bomb.
Nuclear bomb has never been built in open source,
and I think it would have never been built in open source.
It's been built in a close source, you know,
proprietary team or billions of dollars of, you know,
of resources.
So it's much less alike, you know, some players and some others.
So I think, I think there's also a path where open source keeps building kind of like more
specialized models for different domains and not necessarily for the domains that are presenting
the biggest risks.
You know, I don't think it's automatic that you build a more powerful model that it's more
dangerous for cybersecurity.
For example, you could build a more powerful model that is.
not more dangerous or cybersecurity.
For example, if you don't train it on cyber security,
which really people are not really talking about,
why are we not talking about that versus then talking about,
you know, removing the ability to release
or putting now like safeguards after the fact
that we know are not really working because everyone can jail break them.
So I think I wouldn't be totally surprised if the open source,
you know, community just because it's structurally very differently
set up than the big labs are actually taking different directions that tips it kind of like safer
and never really requires the kind of regulation that you need in kind of like a close source AI
labs. Well, is this not also kind of an argument against the capability of open source AI research?
I think so because, you know, it solves different problems. Like I sometimes take the example of,
you know, local models, right? Local intelligence, you know, being able to be on a flight,
in airplane mode without network
and still be able to get intelligence.
You can only get that with open source.
You can't get that with the API.
This just kept like literally no way,
no way to do that.
So I think it's just different layers of the stack, right?
And actually open source is on top of closed source.
A lot of the closed source is using open source models
and he's using open source infrastructure.
And it solves different things.
The analogy is like, you know,
open source maybe is the engine and gene.
API is the car, right?
And obviously the engine is never, never going to be like a Ferrari.
But, you know, that's what kind of like powers the Ferrari.
So I think that's more like the way we're approached.
And also, you know, being less good at bad things doesn't mean that you can't be better
at good things.
Maybe, you know, open source is better at, you know, solving people's problems.
Maybe it's better at, you know, kind of like helping, you know, do stuff really, really important.
But it's worse at, you know, creating cybersecurity attacks.
That would be kind of like the ideal case.
People right now are talking about frontier as kind of like this general thing.
The reality is that the frontier is kind of like jagged between kind of like different tasks, different domains.
Right.
This one model is going to be better at.
some things and it's going to be worse
to do other things. I think that's more
kind of like how we should approach it.
Yeah. Does it make sense?
No, yeah. This totally makes sense to me.
So you guys just crossed
$100 million in ARR, right?
So I'm curious as like, what do you think
this means for like
the business model of open source?
Obviously a lot of companies
are doing much more revenue than
we do in AI these days.
You know,
it hasn't really been our
priority to optimize for for monetization and for for revenue given what we're building
which is more kind of like a usage based platform to reach kind of like how many
and empower me as many AI builders as possible but you know at this at this
small scale I think it shows that you know there's a business model for open source
this business model for open source platform we kind of knew it right because there's
there's been GitHub before and there's been kind of like a bunch of open source
successful companies but I
I guess it's a validation of that.
And we've seen, I mean, for the past few weeks,
we've seen quite a lot of growth in terms of interest
and adoption of not only open source models,
but also local models.
And so, you know, that also speaks a little bit to that.
Yeah, what are some of the specific use cases
that people are using local models for?
So locomotals are
kind of free
because they're running on your phone or on your laptop
and so you don't really have to pay for them.
So they're much cheaper.
They're much more privacy
kind of like preserving by design
because you don't have to send your data to an API,
right? Your data stays on your phone.
And so we see people using it a lot
for the things when it matters the most.
So, like, for example,
if you want to talk about your private health
and you don't want to share that with someone else,
if you want to share some of your private company data
and you don't want to share it externally to an API provider,
or if you want to run really, really heavy workloads,
for example, agentic workloads
and really have something that runs 24-7,
then doing it on your laptop or like on the Mac Mini,
or kind of like a local hardware makes it much much more sustainable.
So that would be kind of like the use cases.
We have this library called Lama CPP,
which is the most used runtime for local AI workloads.
People are using a lot and they're using GPTOSS,
they're using Gwen, JMA4, like all these models locally on their laptop.
Yeah, for sure, for sure.
So going back to open models, you can imagine that the government will want to restrict open models because a lot of them come from China.
Maybe not restrict them in a strict legal way, but maybe in like an export related way.
So do you think that might happen?
And if so, what would that mean for Hugging Face?
Yeah, I mean, like it's so open, open ways are fundamentally different than an API, right?
The way you can restrict it is very different.
So, for example, you know, if you remove an open weight from HangingFace,
then it's still going to be on Modelscope, for example,
which is like the Chinese equivalent,
or it's going to be like on torrent platforms.
So like restriction looks very, very different, I think,
for open source than for APIs.
You can't really block because it's open.
So almost by definition, there's going to be some ways,
some ways to access them.
And also, provenance for open weights doesn't really matter as much.
Because because it's open, the people who are sharing it kind of like give up the control
and give up kind of like their ability to influence you.
So to me, it doesn't matter so much where open weights are coming from.
It's a different game, for example, for APIs to run the inference
because if you're using an API provider or a cloud from China,
obviously you're sending your data
and also they could
cut your access or bias your access
why that's a much, much bigger problem
but for open ways
and open source
it doesn't really matter where it comes from
because it's kind of like
you get all the control
you get all the transparency
there's no way to kind of like
trick you bias you
manipulate you remove your access
so I think for open source
like the provenance doesn't
doesn't matter
as much. Yeah, I'm curious. Your thoughts on just like the U.S. government sort of like restricting
the release of like GPD 4.6, do you think that comes from like them knowing the stakes or not
knowing the stakes? Like, do you think they're well informed on this matter or they just like know that
they don't know and that's why they're taking these measures? It's a good question. I can't talk
for them. I do think there's a lot of interesting learning and progress to me made everywhere,
not just at the USG,
but really everywhere on evaluating models,
evaluating risks or for models,
I don't think we have really good benchmark for this,
and that's a big problem.
In general, ultimately, I hope, yeah,
we'll have more transparency, right?
There's this agency called Casey.
Yeah.
That is amazing.
I think they're doing an amazing job
and they're building up these capability
to really evaluate.
and work on benchmark and things like that.
And I'm really excited for them to take a little bit more of the workload there
and kind of like take a very scientific approach to evaluating these models.
And I think when they when they were, it's going to be really good for the Shields.
Yeah, we definitely want to talk to people from Casey soon.
Yeah.
It's going to be really tough.
I can't lie.
We'll try.
We'll try.
Yeah.
Oh, also yesterday I was talking to.
to Andrew Trask from Deep Mind,
and he had like a very interesting viewpoint that he,
like there's a model on open router called Open Fusion, I think,
and it's this like fusion model of basically a bunch of different models
and that like had a lot of advanced capabilities
and like surpassed like in efficiency in a lot of ways.
So do you think we're going to see more of that?
I think so, yeah, yeah.
I think what we're seeing right now is that the lot of people,
companies are realizing that it's too dangerous.
too risky, it doesn't make any sense to rely exclusively on one model.
Why? Because this model can be taken away. This model can be biased. This model can refuse or
tell you the wrong things. That's also what we've seen before, right? With Fabo 5 before
it was taken out, right? Is that there was some domain where he was intentionally by design
kind of like telling you the wrong things, right, to confuse you. And so I think people
are realizing that
that we need to rely on
a multitude of
of models.
Yeah.
Right?
And so I think that's driving
to this outcome
of doing more routing.
There was an interesting study
from Stanford published last year
end of last year that was showing that
70% of the queries that people ask to chat GPT
could be
accurately answered locally on your laptop.
Okay.
So for free.
Like, you know, questions, there are,
most of the questions you ask,
or most of the AI workloads that people do today with frontier models
could be done by models that are cheaper, faster,
more customizable, more controllable, right?
And they don't do it because, frankly, it's a pain
to take the piker, model piker,
it'd be like, okay, this one, I'm going to go for, like, a cheaper.
one because, you know, so you're subsidized so you don't have to care because you have
your subscription. So you direct everything. It's like directing everything to Einstein.
Right. It's like, hey, Einstein, what's, hey, Einstein. What's the weather today?
You know? In normal life, you would be like, fuck you. I'm not answering you silly question.
But because it's AI and subsidized by the, by the AI labs, all the questions are getting
routed to Einstein versus in an ideal world, you can have different people, different models that
are more specialized and better at answering your questions in different,
different domains.
So that's kind of like, yeah, what we're seeing.
And the way to route instead of giving you the model picker,
I think it's a very, very smart option and a better one.
Lovable is starting to do that too, right?
Like doing the routing under the hood.
And I think it will, it's possible that it's going to redistribute a lot of the value
capture from frontier models, which have been the case now.
right like majority of the revenue capture was on frontier models to a more like long tail of of models
which in my opinion makes much more sense it's like it's like a i maturing right like we're in the
first phase of the i where it's very simple very simplistic everyone using just one giant antique model
behind proprietary APIs now we're moving to the second phase of the i field more maturing and
using several models using open tools
having control building themselves.
I'm quite excited about it.
Yeah.
So another big news story of yesterday
was Anthropic accused
Alibaba of doing distillation attacks,
which is, you know,
there's two perspectives on this.
One is like, this is like,
these are these evil people
who are like stealing the capabilities
of our models, violating our terms of service,
like fraudulently accessing our product.
And then the other is like,
what do you mean?
They're creating accounts
and they're paying for tokens.
And, you know,
you can't accuse people
of stealing when you stole the entire internet.
So which one of these two positions are you closer to?
Well, I mean, I think distillation is a very common practice that everyone is using,
you know, I wouldn't be surprised if entropy used distillation in the past for some of their
models, for some of their specialized models using kind of like someone else who's better.
For example, you know, when open air was better at coding, like you use this model to kind
of like help you a little bit in the training of your, your, your, your, uh,
coding model.
It's something that everyone uses,
but that is not,
you know,
the main reason for success.
Like if you suck,
you suck with or without distillation.
It's just kind of like a little bit accelerating thing,
but it's not,
it's not what makes you good or bad at training models.
So if you stop distillation tomorrow,
the Chinese labs won't like go down and disappear
because it's still going to be good.
It's not really going to change the game.
And, you know, I mean, the only point that I'm a little bit, you know, biased towards that, like, if there was big competition problems, right, where it's like, oh, it's really unfair, it's biasing competition.
But it's hard for me to accept this one because, frankly, you know, I mean, anthropic open AI, they've been the fastest growing companies in the world.
They've become overnight trillion-dollar companies.
And so I don't think they have competition problems.
You know, it's hard for me to say like, oh, poor entropy, poor open AI,
you're getting unfairly competed with when you're like the fastest growing company in the world.
Competition has been okay for them.
If you think, I think they need more competition than less competition.
Yeah.
Because we're heading toward a world where like a few companies are completely dominating,
concentrating all power, all capabilities, all well.
that's much more dangerous than them maybe, you know,
losing a couple of billion dollars of revenue, you know.
Yeah, totally.
So it's just hard, yeah, it's just hard to, you know, empathize and kind of like the,
think that this is, this is an important problem.
I think there are many, many more, much more important problems
than that in the world of AI right now.
Sure. So since the last time we talked, there have been two big pieces written about Europe. There's this essay, Europe 2031, which is basically AI 2027, but for Europe. Like, basically Europe will slide into irrelevance that they don't lock in on AI right now. And then the other was Anton Leis, who's a policy writer, wrote this piece on subset called the Moonshot, which basically explained how if Europe wanted to do so, they could build a frontier lap. Do you think that,
It's possible for Europe to do this at this point?
Could they build a frontier lab if they really tried?
I think so, yeah.
Yeah, yeah.
They have a lot of really great resources.
They have great people.
Why, you already have some great labs, right?
Black Forest Lab, mistrial.
All these people are doing amazingly and arguably they're at the frontier.
They have amazing energy.
You know, obviously, France, for example, nuclear energy, very abundant.
So they could really kind of like use a lot of clean energy for AI.
So yeah, I think they could.
It's just a matter of kind of like focusing the energies towards that,
building an ecosystem.
It never, sometimes we build the stories of like companies emerging out of the blue
by their sheer power.
But the reality is if it's,
it's more an ecosystem, right?
And you see that from open AI, right?
The T of Transformers, obviously is coming from Google,
that open source transformers.
And so it's more of a matter of, in my opinion,
fostering an ecosystem of like open research,
open source AI,
which is what happened in the US, right?
And kind of like fostering that progressively
to bring more and more companies,
organizations closer closer to the frontier.
Yeah, totally.
I'm curious, like, since you run such a large platform,
like what are younger people doing with AI?
Are younger people actually becoming very, very proficient in, like, AI native?
Or like, how do you see this pattern of behavior?
Yeah, yeah.
We see them a lot.
Trying, it's almost kind of, I feel like young people went through the first phase
of being users of AI.
really quick.
And now a lot of them,
I think, want to be builders.
Yeah.
So we see a lot of, yeah, very young people
going on in your face getting,
getting models and, you know,
building products themselves
or optimizing training, training models themselves,
you know, building datasets themselves.
So I see a lot of like, yeah,
building appetites in AI for young people.
In a lot of different domains.
not necessarily
in kind of like the most talked about
domains but also in a lot of like
very
you know topics that are really not talked about
like climate change
you know biology
chemistry
you know really kind of like
social media
kind of like
like a lot of a lot of topics
that we don't really talk about,
that I feel like are closer to everyone's interest,
and I see a lot of young people working on these things.
It's a good white pill to end on.
That is.
Yeah.
Well, thank you so much, Clem.
This was so great.
Thank you, Clem.
Thanks for loving me.
Thank you.
Very big fans.
Thanks for listening to this episode of the A16Z podcast.
If you like this episode, be sure to like, comment, subscribe,
leave us a rating or review,
and share it with your friends and family.
For more episodes, go to YouTube,
Apple Podcasts, and Spotify.
Follow us on X and A16Z and subscribe to our Substack at A16Z.com.
Thanks again for listening, and I'll see you in the next episode.
This information is for educational purposes only
and is not a recommendation to buy, hold, or sell
any investment or financial product.
This podcast has been produced by a third party
and may include pay promotional advertisements,
other company references,
and individuals unaffiliated with A16.
Such advertisements, companies, and individuals are not endorsed by AH Capital Management LLC, A16Z, or any of its affiliates.
Information is from sources deemed reliable on the date of publication, but A16Z does not guarantee its accuracy.
