# Hugging Face CEO: AI Routing, Open Source Safety, Local Models

**Podcast:** a16z Podcast
**Published:** 2026-07-20

## Transcript

I think distillation is a very common practice that everyone is using.
It's something that everyone uses, but that is not the main reason for success.
Like if you suck, you suck with or without distillation.
It's hard for me to say like, oh, poor Entropic, poor OpenAI, you're getting unfairly competed with when you're like the fastest growing company in the world.
If anything, I think they need more competition than less competition.
Yeah.
Because we're heading towards...
a world where a few companies are completely dominating, concentrating all power, all capabilities, all wealth.
And that's much more dangerous than them maybe losing a couple billion dollars of revenue.
As AI models become more powerful, governments are beginning to ask new questions about safety, regulation, and who should control access to frontier technology.
In this episode, Theo Jaffe and Sofia Puccini sit down with Hugging Face co-founder and CEO Clement DeLong to discuss why he believes open source AI is inherently safer, what Hugging Face reaching $100 million in annual recurring revenue says about the business of open source, and why the next phase of AI may be defined by model routing rather than a handful of dominant frontier labs.
They also discuss GPT-5, AI regulation, local models, Europe's AI ecosystem, and the growing importance of competition across the AI stack.
And we are back with Clement DeLong from Hugging Face, his second time on MTS.
Hugging Face is basically the open source AI platform.
So Clem, welcome back to MTS.
Absolutely.
Yeah, so, well, go on.
I think we're about to say the same thing.
Yeah, we were talking about this interesting recent piece of news.
where basically the government is going to restrict GPT 5.6's release sort of unilaterally, basically without precedent.
I don't think the government has ever asked a Frontier Lab not to release a model before.
Certainly a government has not asked a Frontier Lab to be able to oversee which customers the model is released to.
This seems very unnatural.
What are your takes on this?
Yeah, so it was funny.
I was in D.C.
last week, so I was kind of like had some sort of front row seat to what was happening.
Interesting anecdote is that we bumped into Tom Brown there, like the co-founder of Entropic, and we were like, oh, it seems to be like a change of staff or something like that before it was made public that they changed a little bit the people talking to the White House there.
Listen, I mean, what I've seen, what I'm hearing is that there's a lot of, you know, interest from a lot of people in the USG to really understand the risks of AI and take kind of like a safe approach to the deployment of frontier models.
To be honest, I can't really blame them because of the fact that, you know, the frontier labs were...
basically do marketing for the past few years, right?
Like if you remember, GPT-2 was too dangerous to release, right?
It was like four or five years ago.
And so, you know, I don't really blame them for doing things like that.
I just hope that progressively we'll get a little bit more transparency about, you know, what is safe, not safe.
So more focus on, you know, transparent evaluation.
of models and things like that.
I also hope that it's going to stay contained to, you know, a few frontier journalist models because frankly, I think they're the most dangerous ones, right?
And also, you know, these companies are trillion dollar companies with armies of, you know, DC people.
So they can kind of like deal with it.
I hope it's going to stay contained to that and not, you know, permeate.
to a lot of different players, for example, startups, small companies, you know, academia, or like people who don't necessarily have, you know, the money, the size, the ability to really deal with these things.
That would be kind of like my main concern.
Totally, yeah.
What we were just talking about before was just like, could this be applied to open source companies and models in any way?
Like, is there a way that the U.S.
government could come in and restrict open source companies, either practically or legally?
I don't think so, because, you know, I think open source models are inherently less dangerous than kind of like the models that are getting restricted now.
Because, you know, these models are limited ahead in terms of like being closer to the frontier.
Also, open source models are less generous.
They're more specialized.
And there's just like nobody or very few people focusing on building dangerous like cybersecurity capabilities.
So it's like a little bit different than kind of like the proprietary labs.
So yeah, so I don't think it would make sense.
I don't think it's going to get to open source just because of some of these differences.
A more high level, you know, I think in general, open source AI is much, much safer.
than kind of like proprietary AI for a bunch of different reasons that I've talked about in different outlets.
But yeah, so I think the approach there is going to be, hopefully, it's going to be a little bit different between kind of like close source, proprietary, frontier models, and then the rest of the industry and the ecosystem that has, in my opinion, posed much less, much less threats, where we want to keep kind of like...
supporting and building up to focus on competition, to enable little tech, small companies, everyone to be able to basically participate in AI.
I agree that open source models are less dangerous now, but in six months, if trends continue, you're going to have an open source model from somewhere with mythos-level capabilities that freaks out the government.
And you could imagine them at least wanting to.
restrict open source models at that time?
I'm not that sure because there's this weird thing where basically the most dangerous things usually are not so much developed in open source.
Maybe it's this thing that people say like sunlight is the best disinfectant.
The funny thing is that sometimes safety people are talking about the nuclear bomb.
a nuclear bomb has never been built in open source.
And I think it would have never been built in open source.
It's been built in a closed source, you know, proprietary team with billions of dollars of, you know, of resources.
So it's much less like, you know, some players and some others.
So I think there's also a path where open source keeps building kind of like more specialized models for different domains.
and not necessarily for the domains that are presenting the biggest risks.
I don't think it's automatic that you build a more powerful model that it's more dangerous for cybersecurity, for example.
You could build a more powerful model that is not more dangerous for cybersecurity, for example, if you don't train it on cybersecurity, which really people are not really talking about.
Why are we not talking about that rather than talking about, you know.
removing the ability to release or putting safeguards after the fact that we know are not really working because everyone can jailbreak them.
So I think I wouldn't be totally surprised if the open source community, just because it's structurally very differently set up than the big labs, are actually taking different directions that keeps it safer and never really requires the kind of regulation that you need in closed source AI labs.
Well, is this not also kind of an argument against the capability of open source AI research?
I think so, because, you know, it solves different problems.
Like I sometimes take the example of, you know, local models, right?
Local intelligence, you know, being able to be on the flight in airplane mode without network and still be able to get intelligence.
You can only get that with open source, right?
Like you can't get that with API.
There's just like literally no way to do that.
So I think it's just different layers of the stack, right?
And actually open source is on top of closed source.
A lot of the closed source is using open source models and is using open source infrastructure.
And it's all different things.
The analogy is like, you know, open source maybe is the engine and the API is the car, right?
And obviously the engine is never going to be like a Ferrari, but, you know, that's what Conflect powers.
powers the Ferrari.
So I think that's more like the way we approach it.
And also, you know, being less good at bad things doesn't mean that you can't be better at good things.
Maybe, you know, open source is better at, you know, solving people's problems.
Maybe it's better at, you know, kind of like helping, you know, do stuff really, really, really important.
But it's worse at, you know, creating cybersecurity attacks.
That would be kind of like the ideal case.
People right now are talking about frontier as kind of like this general thing.
The reality is that the frontier is kind of like jagged between kind of like different tasks, different domains, right?
This one model is going to be better at some things and it's going to be worse at other things.
I think that's more kind of like how we should approach it.
Yeah.
Does it make sense?
No, yeah, this totally makes sense to me.
So you guys just crossed $100 million in ARR, right?
So I'm curious as like, what do you think this means for like the business model of open source?
Obviously, a lot of companies are doing much more revenue than we do in AI these days.
You know, it hasn't really been our priority to optimize for monetization and for revenue, given what we're building, which is more kind of like a usage-based platform.
to reach kind of like harmony and empower as many AI builders as possible.
But at this small scale, I think it shows that there's a business model for open source, there's a business model for open source platform.
We kind of knew it, right?
Because there's been GitHub before and there's been kind of like a bunch of open source successful companies.
But I guess it's a validation of that.
And we've seen, I mean, for the past few weeks, we've seen quite a lot of growth in terms of interest and adoption of not only open source models, but also local models.
And so, you know, that also speaks a little bit to that.
Yeah, what are some of the specific use cases that people are using local models for?
So local models are kind of free.
because they're running on your phone or on your laptop.
So you don't really have to pay for them.
So they're much cheaper.
They're much more privacy kind of like preserving by design because you don't have to send your data to an API.
Your data stays on your phone.
And so we see people using it a lot for the things when it matters the most.
So like, for example, if you want to talk about your private health and you don't want to share that with someone else, if you want to share some of your private company data and you don't want to share it externally to an API provider, or if you want to run really, really heavy workloads, for example, agentic workloads and really have something that runs 24-7, then doing it on your laptop or like on the Mac Mini or kind of like a local hardware.
makes it much more sustainable.
That would be kind of like the use cases.
We have this library called Lama CPP, which is the most used runtime for local AI workloads that people are using a lot.
And they're using GPT-OSS, they're using Gwenn, Gemma 4, like all these models locally on their laptop.
Yeah, for sure, for sure.
So going back to open models, you can imagine that the government will want to restrict open models because a lot of them come from China.
Maybe not restrict them in a strict legal way, but maybe in like an export related way.
So do you think that might happen?
And if so, what would that mean for Hugging Face?
Yeah, I mean, like it's open ways are fundamentally different than an API, right?
The way you can restrict it is very different.
So for example, If you remove an open wait from hugging face, then it's still going to be on Modelscope, for example, which is like the Chinese equivalent, or it's going to be like on torrent platforms.
So restriction looks very, very different, I think, for open source than for APIs.
You can't really block because it's open.
So almost by definition, there's going to be some ways to access them.
So provenance for open waves doesn't really matter as much because it's open.
The people who are sharing it kind of like give up the control on it and give up kind of like the ability to influence you.
So to me, it doesn't matter so much where open waves are coming from.
It's a different game, for example, for APIs to run the inference because if you're using an API provider or cloud from China.
obviously you're sending your data and also they could cut your access or bias your access.
That's a much, much bigger problem.
But for open weights and open source, it doesn't really matter where it comes from because it's kind of like you get all the control, you get all the transparency.
There's no way to kind of like trick you, bias you, manipulate you, remove your access.
So I think for open source, like the provenance doesn't matter.
as much.
Yeah, I'm curious, your thoughts on just like, the US government sort of like restricting the release of like GPT 4.6.
Do you think that comes from like them knowing the stakes or not knowing the stakes?
Like, do you think they're well informed on this matter?
Or they just like know that they don't know?
And that's why they're taking these measures?
It's a good question.
I can't talk for them.
I do think there's a lot of Interesting learning and progress to be made everywhere, not just at the USG, but really everywhere on evaluating models, evaluating risks for models.
I don't think we have really good benchmark for this, and that's a big problem.
In general, ultimately, I hope we'll have more transparency, right?
There's this agency called Casey that is amazing.
I think they're doing an amazing job.
And they're building up this capability to really evaluate and work on benchmark and things like that.
And I'm really excited for them to take a little bit more of the workload there and kind of like take a very scientific approach to evaluating these models.
And I think when they will, it's going to be really good for the Shields.
Yeah, we definitely want to talk to people from KC soon.
It's going to be really tough, I can't lie.
We'll try.
We'll try.
Oh, also yesterday I was talking to Andrew Trask from DeepMind and he had like a very interesting viewpoint that he, like there's a model on OpenRouter called OpenFusion, I think.
And it's this like fusion model of basically a bunch of different models.
And that like had a lot of advanced capabilities and like surpassed like inefficiency in a lot of ways.
So do you think we're going to see more of that?
I think so, yeah.
Yeah, I think what we're seeing right now is that a lot of people, companies are realizing that it's too dangerous, it's too risky, it doesn't make any sense to rely exclusively on one model.
Why?
Because this model can be taken away, this model can be biased, this model can refuse or tell you the wrong things.
That's also what we've seen before, right?
With Fable 5, before it was taken out, right?
There was some domain where it was intentionally by design, kind of like telling you the wrong things, right?
To confuse you.
And so I think people are realizing that we need to rely on a multitude of models.
Yeah.
Right?
And so I think that's driving to this outcome of doing more routing.
But there was an interesting study from Stanford published last year, end of last year, that was showing that 70% of the queries that people ask to chat GPT could be accurately answered locally on your laptop.
Okay.
So for free, like, you know, questions.
Most of the questions you ask or most of the AI workloads that people do today with Frontier Models.
could be done by models that are cheaper, faster, more customizable, more controllable, right?
And they don't do it because, frankly, it's a pain to take the model picker and be like, okay, this one I'm going to go for like a cheaper one because, you know, so you're subsidized, so you don't have to care because you have your subscription, so you direct everything.
It's like directing everything to Einstein, right?
It's like, hey, Einstein, what's the weather today?
In normal life, it would be like, fuck you, I'm not answering your silly question.
But because it's AI and subsidized by the AI labs, all the questions are getting routed to Einstein versus in an ideal world, you can have different people, different models that are more specialized and better at answering your questions in different domains.
So that's kind of like what we're seeing and the way to route instead of giving you the model picker.
I think it's a very, very smart option and a better one.
Lovable is starting to do that too, right?
Like doing the routing under the hood.
And I think it will, it's possible that it's going to redistribute a lot of the value capture from frontier models, which have been the case now, right?
Like majority of the revenue capture was on frontier models to a more like long tail of models, which in my opinion makes much more sense.
It's like AI maturing, right?
Like we were in the first phase of AI where it's very simple, very simplistic.
Everyone using just one gigantic model behind proprietary APIs.
Now we're moving to the second phase of the AI field more maturing and using several models, using open source, having control, building themselves.
I'm quite excited about it.
Yeah.
So another big news story of yesterday was Anthropic accused Alibaba.
of doing distillation attacks, which is, you know, there's two perspectives on this.
One is like, this is like, these are these evil people who are like stealing the capabilities of our models, violating our terms of service, like fraudulently accessing our product.
And then the other is like, what do you mean?
They're creating accounts and they're paying for tokens.
And, you know, you can't accuse people of stealing when you stole the entire internet.
So which one of these two positions are you closer to?
Well, I mean, I think distillation is a very common...
practice that everyone is using.
I wouldn't be surprised if Entropic used distillation in the past for some of their models, for some of their specialized models using someone else who's better.
For example, when OpenAI was better at coding, you used this model to help you a little bit in the training of your coding model.
It's something that everyone uses, but that is not the main reason for success.
If you suck, you suck with or without distillation.
It's just kind of like a little bit like accelerating thing, but it's not what makes you good or bad at training models.
So if you stop distillation tomorrow, the Chinese labs won't like go down and disappear because it's still going to be good.
It's not really going to change the game.
And, you know, I mean, the only point that I'm a little bit biased towards...
Like if there was big competition problems, right?
Where it's like, oh, it's really unfair.
It's biasing competition.
But it's hard for me to accept this one because frankly, you know, I mean, Entropic OpenAI, they've been the fastest growing companies in the world.
They've become overnight trillion dollar companies.
And so I don't think they have competition problems.
You know, it's hard for me to say like, oh, poor Entropic, poor OpenAI.
you're getting unfairly competed with when you're like the fastest growing company in the world.
Competition has been okay for them.
If anything, I think they need more competition than less competition.
Because we're heading toward a world where like a few companies are completely dominating, concentrating all power, all capabilities, all wealth.
That's much more dangerous than maybe you know, losing a couple of billion dollars of revenue.
Yeah, totally.
It's just hard to, you know, empathize and kind of like think that this is an important problem.
I think there are many, many more, much more important problems than that in the world of AI right now.
Sure.
So since the last time we talked, there have been two big pieces written about Europe.
There's this essay Europe 2031, which is basically AI 2027, but for Europe, like basically Europe will slide into a relevance if they don't lock in on AI right now.
And then the other was Anton Leisch, who's a policy writer, wrote this piece on Subsec called The Moonshot, which basically explained how if Europe wanted to do so, they could build a frontier lab.
Do you think that it's possible for Europe to do this at this point?
Could they build a frontier lab if they really tried?
I think so, yeah.
They have a lot of really great resources.
They have great people.
You already have some great labs, right?
Black Forest Lab, Mistral.
All these people are doing amazingly and arguably they're at the frontier.
They have amazing energy.
Obviously, France, for example, nuclear energy, very abundant.
They could really kind of like...
use a lot of clean energy for AI.
So yeah, I think they could.
It's just a matter of focusing the energies towards that, building an ecosystem.
Sometimes we build the stories of companies emerging out of the blue by their sheer power.
But the reality is it's more an ecosystem.
And you see that from...
Open AI, right, the T of transformers, obviously, is coming from Google, that open source transformers.
And so it's more of a matter of, in my opinion, fostering an ecosystem of open research, open source AI, which is what happened in the US, right, and kind of fostering that progressively to bring more and more companies, organizations closer to the frontier.
Yeah, totally.
I'm curious, like, since you run such a large platform, like, what are younger people doing with AI?
Are younger people actually becoming very, very proficient and like AI native?
Or like, how do you see this pattern of behavior?
Yeah, we see them a lot.
It's almost kind of like, I feel like young people went through the first phase of being users of AI really quick.
And now a lot of them, I think, want to be builders.
Yeah.
So we see a lot of, yeah, very young people going under a new phase, getting models and, you know, building products themselves or optimizing training models themselves, you know, building data sets themselves.
So I see a lot of like, yeah, building appetites in AI for young people in a lot of different domains, not necessarily.
not necessarily in the most talked about domains, but also in a lot of topics that are really not talked about, like climate change, biology, chemistry, social media, a lot of topics that we don't really talk about.
talk about that I feel like are closer to everyone's interest.
And I see a lot of young people working on these things.
It's a good white pill to end on.
That is.
Yeah.
Well, thank you so much, Clem.
This was so great.
Thank you, Clem.
Thanks for having me.
Thank you.
Very big fans.
Thanks for listening to this episode of the A16Z podcast.
If you liked this episode, be sure to like, comment, subscribe, leave us a rating or review, and share it with your friends and family.
For more episodes, go to YouTube, Apple Podcasts, and Spotify.
Follow us on X and A16Z and subscribe to our Substack at a16z.substack.com.
Thanks again for listening, and I'll see you in the next episode.
This information is for educational purposes only and is not a recommendation to buy, hold, or sell any investment or financial product.
This podcast has been produced by a third party and may include paid promotional advertisements, other company references, and individuals unaffiliated with A16Z.
Such advertisements, companies, and individuals are not endorsed by AH Capital Management LLC, A16Z, or any of its affiliates.
Information is from sources deemed reliable on the date of publication, but A16Z does not guarantee its accuracy.
