THE DEEP TAKE

Nobody in your company signed a contract with Hugging Face

Nvidia confirmed on Thursday that it is buying Hugging Face for $12.93 billion. The platform hosts more than 3 million models, 500,000 datasets and 1 million applications. More than 200,000 companies use it. Almost none of them have a commercial relationship with it.

That gap is the story. Hugging Face got into your estate the way npm did. An engineer wrote one line that pulls a model by name. The library resolved it. It worked. Nobody raised a purchase order. Nobody ran a vendor review. Nobody wrote a continuity clause. Your model supply chain has been a free public utility, and this week it became an asset on a chip vendor's balance sheet.

Jensen Huang made a specific commitment. Hugging Face stays open, and Nvidia compute will not be required to build or deploy through it. Take him at his word, because requirement was never the lever. Defaults are. The lever is which artifacts arrive pre-optimized, which runtime the quickstart shows, and which hardware the reference deployment assumes. Nvidia is already the platform's largest contributor, with more than 500 models and 250 open datasets published there. None of that needs a policy change to move your engineers.

The second shift is in your negotiating position. You buy GPUs, or you buy cloud instances priced off them. Now the same company owns the registry your AI teams pull from every day. That is not a conspiracy. It is a leverage question, and leverage questions are worth answering before a deal closes rather than after. Nvidia expects to close in the first half of 2027, subject to regulatory approval. Call it two quarters of certainty.

Three things are worth doing while that clock runs. First, find out whether Hugging Face is actually in your build. Grep CI for huggingface.co, HF_HOME and HF_TOKEN, and check which services fetch weights at deploy time instead of from an internal registry. Second, mirror the weights you depend on into storage you control, the way you vendored npm packages after 2018. Third, put a change-of-control clause in your AI platform contracts that names model resolution. A vendor who reroutes you through a paid tier should have to say so.

From the people who send this

CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you $150 to $200, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.

Or reply to this email with the word "briefing" and Ryan will set you up personally.

QUICK HITS

OpenAI shipped a model that finds its own zero-days

On September 2, OpenAI said Astra is the first of its models to reach the Critical cybersecurity tier of its Preparedness Framework. In evaluation it scored perfectly on ExploitBench. It chained flaws in a hardened operating system up to root. It escaped a browser sandbox and found two zero-days on its own. Full cyber capability is not shipping at launch. A small set of testers gets it first, then the Daybreak Blue program. Read that access model closely. Capability parity for defenders is now something a vendor grants by application. Ask your red team, your pentest firm and your MDR provider whether they have applied and what their timeline is.

A valid TLS certificate is not a vendor's signature

On August 28 an attacker announced a slice of Hetzner address space more specifically than Hetzner did. The hijacked route held for about 33 hours. Virtualizor servers that checked for updates in that window installed the attacker's package. The certificate raised no warning, because Let's Encrypt validated domain ownership over the hijacked path. Softaculous has shipped 3.2.9.9 with mitigation tooling and says it cannot produce a definitive victim list, so treat every instance as in scope. The wider lesson is cheap to act on. HTTPS proves who held the route at that moment, not who built the file. Ask every auto-updating appliance vendor whether packages are signed independently of transport.

The UK is about to get a veto over your suppliers

Amendments tabled on August 24 would let ministers designate a technology supplier as high risk. A designated supplier can then be barred from critical-sector organisations. The Cyber Security and Resilience Bill is now in the Lords. Size is no protection here, because the power covers suppliers of any size. If you run anything inside UK energy, water, health or transport, this is not a compliance obligation you can plan against. It is a designation risk you cannot. The response is contractual. Check whether your agreements let you exit and substitute when a supplier is designated, and who pays for the migration. Start with the contracts you renew this quarter.

THE NUMBER: $600,000

That is the value of the model credits an attacker burned on a stolen METR API key, disclosed August 31. The theft was three weeks old before anyone caught it. The logging was not the problem. Heavy model traffic is what METR's researchers generate all day, so the abuse looked like the work. The key had no spend ceiling. Most enterprises are now in that same position. An AI credential fails as money before it fails as data, and the detection signal is a spend shape nobody has baselined. Pull your model-provider keys this week and check two things: whether each key has a ceiling, and whether anyone gets an alert when it moves.

The hardest question in this issue is not technical, it is ownership. If you are working out who owns model provenance in your company, ask someone in the DoGood network who has already answered it.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT or security leader? Vendors pay $150 to $200 for a 30-minute briefing. Claim your invite or reply "briefing".