Visualização de leitura

What Nvidia’s $13B acquisition of Hugging Face means for AI model choice

When Nvidia said Thursday that it plans to pay $13 billion to acquire Hugging Face, the question arose of whether the open AI platform would remain open when it becomes a unit of Nvidia. And the current lack of a single viable open alternative that does everything Hugging Face does for enterprises adds further complications for CIOs.

Rumors of the pending deal have been circulating for at least a week. 

In its announcement, Nvidia said, “Hugging Face will remain an open platform for the entire AI ecosystem. Developers will choose the models they want, the frameworks they want, the clouds and inference service providers they want and the computing platforms they want. Nvidia compute will not be required to build on or deploy through Hugging Face.”

It added that Hugging Face will continue to support open source and open weight models from every model builder, and “continue to support multi-cloud and multi-accelerator development and deployment, so builders can use the hardware and infrastructure that best fit their work.”

Hugging Face CEO Clément Delangue took to his X account to also reassure customers, noting, “open-source AI is at an inflection point” and pointing out that, for the business to scale, it needs “more compute, more support, more collaboration and more visibility. That’s why we went to talk to [Nvidia CEO] Jensen [Huang], who offered to do exactly that with us.”

Preserving the Hugging Face team

Nvidia is also attempting to retain some of the Hugging Face workforce. As part of the deal, according to Nvidia’s 8-K filing, the purchase price is $11.9 billion, with “approximately $1 billion” earmarked for “an equity-based retention program” for Hugging Face employees who agree to join Nvidia. It has yet to be announced how many members of the Hugging Face workforce, estimated to be almost 750, will be offered roles at Nvidia.

But despite the reassurances from Nvidia about maintaining the open nature of Hugging Face, analysts and consultants suggested that the truth may not be known until months, or even a year, after the acquisition finalizes sometime next year; the transaction is expected to close “in the first half of 2027.”

Cause for optimism

Enterprise CIOs can only wait and see what Nvidia will ultimately do. 

But in the meantime, there is cause for optimism, given the history of recent open source acquisitions, said Jason Andersen, principal analyst at Moor Insights & Strategy. 

“There is always a ‘sky is falling’ narrative” with these transactions, Andersen said, but in recent years, open source acquisitions have often turned out quite well.

“What happened to Red Hat after IBM bought it? Things got better,” Andersen said. “The same can be said for GitHub after Microsoft bought it. Or Google’s acquisition of Gemma. There are just too many examples of it going the right way.”

Justin Greis, CEO of consulting firm Acceligence, also sees this acquisition as potentially good news for enterprise CIOs. 

“If Nvidia turned [Hugging Face] into a walled garden or an obvious funnel toward Nvidia hardware, it could undermine the community and network effects it just paid nearly $13 billion to acquire,” he pointed out. “Nvidia is being unusually explicit that Hugging Face will remain model-, framework-, cloud- and accelerator-agnostic, including saying that Nvidia compute will not be required.” 

And, he added, Nvidia could indeed make Hugging Face even more enterprise friendly. 

“Nvidia itself points to the opportunity to improve Hugging Face’s reliability, safety, model evaluation, inference, and deployment capabilities. That is potentially a very big deal,” Greis said, noting that enterprises don’t simply need access to more models, they need confidence that those models can operate within complex environments with governance, security, performance, resilience, and lifecycle management around them.

Those needs make the combination compelling, he said: “Nvidia has the engineering depth, infrastructure expertise and ecosystem reach to significantly raise that bar. Hugging Face has been enormously successful as a developer and open-model platform. Nvidia now has the opportunity to help make it much more enterprise-grade: a place where companies can discover models, datasets, and AI components, but also increasingly evaluate, test, secure, operationalize, and deploy them with the level of confidence and rigor expected inside a large enterprise.”

Avoid a single dependency

Still, said Shashi Bellamkonda, a principal research director at Info-Tech Research Group, there are various practical steps that CIOs can and should soon take to preserve what they have already created within Hugging Face.

“This should be a clarion call for CIOs to treat Hugging Face and open source models as part of their enterprise supply chain, and if a production system depends on an artifact hosted on Hugging Face, keep a verified copy in a second registry, whether that is GitLab, Amazon S3, or an internal artifact store,” he said. “Enterprises should also consider the source for open models and develop a fallback plan such as the model developer’s own repository or another hub, because Hugging Face is the dominant platform today, but no enterprise should depend on one company’s availability, governance, or roadmap.”

Bellamkonda also pointed out that, by owning Hugging Face, Nvidia would gain valuable visibility into which models are gaining traction, how developers are deploying them, and which hardware ecosystems they run on. It would then “hold a powerful position in the distribution of new open models, so that combination of infrastructure ownership, market intelligence, and hardware influence should factor into CIO planning,” he said.

Mike Wilkes, enterprise CISO at Aikido Security, added that one of the factors that makes a CIO’s 2027 contingency planning in the face of Hugging Face’s new ownership difficult is that there are not that many large open source companies that could directly replace Hugging Face for an enterprise.

“No true replacement exists for Hugging Face at its scale, but there are ways to avoid making it a single point of dependency,” he said. “Azure AI Foundry is probably the closest enterprise alternative regarding model breadth, now advertising more than 11,000 models and supporting models from OpenAI, Anthropic, Meta, Mistral and others. AWS SageMaker JumpStart is another option, as enterprises can create private curated model hubs with their own governance controls. Google’s Model Garden is a third viable choice and supports both managed and self-deployed open models inside the customer’s own cloud environment.”

But adopting any of those alternatives means a move from an independent Hugging Face to Microsoft, Amazon, or Google, “so they change the concentration risk rather than eliminating it,” Wilkes noted. “The best enterprise strategy is not to search for another Hugging Face, but to separate model discovery from model custody. We can continue using Hugging Face to discover and evaluate models while mirroring approved models into an internal repository or registry under our control.”

Risk of increasing AI control by Nvidia

IDC’s Ashish Nadkarni, a group VP, said CIOs must also remember that the Nvidia move could give it various levers to even further tighten its control over global AI developments. 

“Hugging Face is like GitHub for AI. It is the default front door for open AI innovation: it’s where data scientists, machine learning engineers, and developers discover pretrained models, fine-tune them, and push them into production, or find open datasets to train their own models,” he said. “Owning that front door gives Nvidia a major position in the mindshare of today’s AI development personas.”

Consultant Brian Levine, executive director of FormerGov, also advised CIOs to stay alert. He predicted that Nvidia will exert greater control over Hugging Face efforts, but it will happen so gradually that it might not be noticed.

“The risk isn’t a dramatic reverse course. It’s a slow drift, where the Nvidia-optimized path quietly becomes the easy path, and everything else becomes the friction path,” he said. “Stop treating Hugging Face as a vendor-neutral utility and start treating it as a strategically-owned platform. That doesn’t mean leave. It means keep your options real and tested, not theoretical.”

Unanswered questions

And, from an enterprise CIO’s perspective, there’s another worry.

“Nvidia’s openness commitment is precise where it is cheap, and silent where it is expensive,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “The release promises that Nvidia compute will not be required, that multi-cloud and multi-accelerator support continues, and that developers choose their own models, each of which is a commitment about availability rather than about terms. Nothing in it addresses ranking, search placement, or default routing, and those are what decide which models a developer ever sees. Nobody has to be banned for the field to tilt. Gravity is enough and gravity is the part the pledge does not mention.”

This article originally appeared on InfoWorld.

US Navy tells sailors and their families: scrub your social media, enemies are watching

The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where they live, and when they may not be at home. Read more in my article on the Hot for Security blog.

TikTok Agrees to $400M Settlement Over Children’s Privacy

TikTok and ByteDance agree to pay up to $400 million to settle US allegations involving children’s data, parental consent and account deletion.

The post TikTok Agrees to $400M Settlement Over Children’s Privacy appeared first on TechRepublic.

Nvidia to hike prices by 15%, on top of an even larger increase in July

On top of July’s 30% price hikes across almost all of its product lines, Nvidia is reportedly preparing to raise prices of servers, including those powered by Vera Rubin and Grace Blackwell chips, by 15%, due to skyrocketing memory prices.

That 15% increase for systems being delivered in early 2027, reported by Bloomberg and other business media, is seen as part of a series of expected price hikes throughout AI deployments.

Scott Bickley, advisory fellow at Info-Tech Research Group, said that he sees Nvidia’s move as one that is only passing along its own rapidly increasing costs. But rather than price gouging because of its close-to-monopoly market control, Bickley’s calculations suggest that Nvidia is likely eating some of its costs, and is only passing along a fraction of them to its largest customers.

But not all AI-related costs are increasing; per-token prices appear to be dropping, he said. That gives CIOs a potential strategy to manage costs by pushing approaches that will reduce the reliance on memory.

“The workload cost is going down per token while the underlying hardware and infrastructure costs are going up,” Bickley said. “If you are directly building out your own clusters, this is an automatic uplift to an already egregiously expensive solution. If you are buying your own hardware, you’re going to have to suck it up. You are not going to negotiate your way out of this.”

But, he added, CIOs should also be able to get more mileage out of the clusters they are currently running, via techniques such as model routing, compression, and batch processing.  

Gaurav Gupta, VP analyst at Gartner, noted that the Nvidia price hikes are reflective of the many pricing increases throughout the AI environment. 

“Memory prices are going up, especially HBM and LPDDR5, but there are other aspects, like leading-edge foundry wafers, advanced packaging, and other component shortages,” Gupta said, adding that those issues generate “longer lead-times, which typically translates to higher prices.” And he does not expect the situation to improve any time soon. 

“In the current environment of strong demand and limited supply, we expect this situation to continue in the near to mid-term,” he said. “This means higher costs for those deploying these servers/systems and for those renting compute in the cloud, including software vendors/model builders, and others.”

Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, agreed.

“This is a supply and demand problem, and it’s likely to reach a plateau and eventually improve once memory production ramps up to meet the current demand due to AI, but I don’t think this will happen in the next few months,” Villanustre said. “For now, CIOs will need to contend with the current market conditions.”

But he also agreed with Bickley’s suggestion that CIOs try to squeeze more value from the RAM they already have.

“Some AI model vendors are adapting their models to run better in memory constrained environments,” Villanustre noted. “For example, Gemma E4B and similar models by Google now use a hierarchical tiered model that allows them to pull only the necessary parts of the model into memory instead of holding the entire model in RAM. These models have a much larger effective number of parameters than the memory that they require.”

And, added Mike Wilkes, enterprise CISO at Aikido Security, this means that the Nvidia price hikes may do some good if they convince enterprises to adopt a more thoughtful approach to AI deployments. 

“Enterprises have spent the last few years treating frontier-model tokens almost as an infinitely elastic utility, sending workloads to the biggest model whether or not the task required frontier-level reasoning,” he said. “Higher infrastructure and token costs should force much better workload discrimination.”

He observed that the right enterprise AI architecture is increasingly hybrid: reserve 10% for frontier model consumption for problems that genuinely require it, while pushing classification, extraction, summarization, routine agent actions, and other bounded workloads toward small language models (SLMs) and open-weight models running on infrastructure that the enterprise controls.

“That gives CIOs leverage against price gouging or unilateral price setting,” he pointed out.

This article originally appeared on NetworkWorld.

France’s Top Court Blocks Under-15 Social Media Ban

France’s Constitutional Council blocked an under-15 social media ban, raising questions over free expression, age verification and online privacy.

The post France’s Top Court Blocks Under-15 Social Media Ban appeared first on TechRepublic.

Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Nvidia’s $500B AI investment pool could impact enterprise chip pricing, availability

Nvidia and six financial partners are creating a $500 billion investment pool to help Nvidia customers including frontier AI labs, AI clouds, and other enterprises buy its chips on credit. 

The impact of such a cash infusion on enterprise AI is uncertain, but analysts fear that it could both further increase enterprise AI infrastructure costs and exacerbate the shortage of AI chips for data centers

The announcement from Nvidia and financial partners Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR said that their memorandums of understanding describe a fund “to establish the first compute financing platforms of their kind at global scale to enable the AI infrastructure buildout across Nvidia’s ecosystem, including leading frontier AI labs, enterprises and AI clouds.”

The group added that the fund would “create dedicated pools of capital at significant scale at attractive rates for Nvidia customers.”

Although the statement said the goal was to help AI infrastructure “across Nvidia’s ecosystem, including leading frontier AI labs, enterprises and AI clouds,” analysts and consultants agreed that it is highly unlikely any of these funds would be dispensed directly to enterprises, but would instead impact the overall AI supply chain.

Even the precise amount of money earmarked for the fund was unclear, with the statement merely saying that the amount would be more than $500 billion. 

Nvidia did not respond to requests for clarification about details of the proposed fund, but one financial partner did comment on the amount.

“We can clarify that this is a number that’s been totaled up by Nvidia,” said Simon Maine, managing director for communications at Brookfield Asset Management, in an email. “The finance partners are not collaborating together on this, but rather it is a series of individual partnerships. We therefore cannot comment on how the total figure has been arrived at.”

CIO concerns: chip pricing, availability

The top concern for CIOs around such a fund is the question of whether it would impact chip pricing along with that of components and devices using those chips, and if it would impact chip availability. Almost all of the analysts and consultants willing to speculate on that agreed that it would likely increase prices and worsen chip shortages. However, one optimistic interpretation of the fund was that it could help reduce chip shortages. 

“It remains to be seen what kind of downstream impact this initiative will have on enterprise spend,” said Ashish Nadkarni,  a group VP for IDC, but “there is an assumption here that these investments will go toward building fab capacity, and that the fabs will produce chips to address a chip shortfall.”

Other analysts disagreed, and argued that the fund would likely make the chip shortage worse, at least initially. 

“The current chip demand is taking all of the capacity and there is only so much chip fabrication capacity available,” said Mark Tauschek, a distinguished analyst at Info-Tech Research Group. “It will also take years to build new chip fabs. [The proposed Nvidia fund] will probably exacerbate the shortage.”

In fact, for enterprises, Tauschek projected a 15%-20% cost hike.

Sanchit Vir Gogia, chief analyst at Greyhound Research, agreed with Tauschek on both counts. 

He estimated that AI chip prices would be roughly the same for another year, and increasingly only at a good price if customers sign a long-term commitment. “The discount for committing is shrinking, not growing,” he said.

Thus, he pointed out, “more financing therefore means more new capacity is spoken for before it exists, and the open market gets whatever is left. The queue is no longer sorted by who can pay. It is sorted by who will commit.”

But he added that these numbers will likely improve eventually. “It does add real capacity in the end,” he noted. “Enterprises planning for 2028 will benefit. Those reacting to 2026 will not.”

Mike Wilkes, enterprise CISO at Aikido Security, said that one of the key impacts of the fund will be the way in which enterprises should view AI financing. That change, he argued, is both good and bad.

The improved availability of funds could “finance the AI buildout at much greater scale. That could accelerate enterprise access to compute, but it could also connect AI infrastructure much more tightly to the financial system,” Wilkes said. “This financing is likely to lower the cost of getting access to AI infrastructure in the near term, but not necessarily lower the price enterprises ultimately pay for AI.”

He suggested that potential enterprise impact will vary over time.

For large enterprises, the infusion of funds would allow their infrastructure vendors to build large datacenters without requiring financial help from the enterprise, he said, and this added capacity should eventually put downward pressure on the unit cost of compute.

“But,” he noted, “in the next few years, I would expect vendors to use cheaper financing primarily to build faster and lock customers into longer-term capacity contracts, rather than simply pass all of those savings through. In other words, enterprises may get more AI for the same dollar before they get the same AI for fewer dollars. So I think the biggest effect on enterprise readers is that this could remove one bottleneck while creating another.”

He expects that capital may cease to be the limiting factor in building AI infrastructure, giving CIOs considerably more capacity and more financing options available to them. “But,” he said, “the resulting competition may increasingly focus on who can persuade enterprises to make the longest and largest commitments to future AI consumption. If hundreds of billions of dollars of infrastructure are financed based on assumptions about future utilization, somebody ultimately has to pay when those assumptions prove wrong.”

Things will brighten, but not for awhile

Justin Greis, CEO of consulting firm Acceligence,  agreed that the short-term impact of this agreement may not be good for enterprise IT. 

“My view is that this financing will accelerate the creation of AI infrastructure, but it will not provide meaningful near-term price relief for most enterprises. In fact, I think the next 12-18 months could remain a period of elevated costs and constrained availability as the market absorbs this new wave of investment,” Greis said. The reason, he noted, is that the limiting factor today is not capital, it is the physical capacity to manufacture components.

“Adding hundreds of billions of dollars of available financing will create more buyers with the ability to compete for those resources,” he said. “My expectation is that the largest AI infrastructure providers and hyperscalers will continue to secure a significant share of available capacity because they have the scale, existing relationships, and ability to commit to long-term purchases.”

But eventually he believes that the enterprise picture should brighten. 

“Where I do expect enterprises to see benefits is further out. As this capital turns into actual infrastructure capacity, the market should become more competitive and enterprises should have more options in how they access compute,” Greis said.

“From a CIO perspective, I would not respond to this announcement by trying to secure more hardware. That is likely to become an expensive race that most enterprises cannot win.”

This article originally appeared on NetworkWorld.

Sexual predators targeting online accounts for intimate images, FBI warns

The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII).

The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.

According to the FBI, criminals use a mix of account takeover and social engineering tactics:

  • Password and PIN guessing: Criminals make high-volume login attempts using data from breaches, public social media profiles, leak sites, and other publicly available sources. Known victims may be targeted using name variations, birth dates, and other predictable personal details.
  • Fake customer service texts: Victims receive a message claiming their social media account will be locked or disabled. The criminal triggers a legitimate password reset request, then persuades the victim to hand over the resulting verification code.
  • Phishing emails: Lookalike support domains and email addresses warn of a “new login” and direct victims to a fake password change page designed to steal credentials.

This is different from the familiar “I recorded you” sextortion email, which typically relies on intimidation rather than a real account compromise. Still, if such an email includes a password you still use, change it immediately wherever it remains in use.

How to stay safe

There are several ways to reduce the risk of becoming a victim:

  • Avoid storing sensitive images on social media platforms or other internet-connected services when possible. Breaches and leaks happen, and those images can end up in the wrong hands.
  • Use a password manager to create a unique, long password for every account. Don’t base passwords or PINs on names, birthdays, or other public information.
  • Turn on multi-factor authentication (MFA), preferably with passkeys or hardware security keys where available. MFA is valuable, but criminals can still phish one-time codes and session cookies, so never approve an unexpected prompt or share a verification code.
  • Treat unexpected “account warning” links in texts and emails as suspicious. Open the service’s official app or type the known web address yourself instead. Don’t trust sponsored search results to take you to the correct website.

If you discover that intimate content has been stolen or shared, preserve any relevant links and evidence, secure the affected accounts, and report it through the FBI’s NCII reporting portal at ncii.ic3.gov.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

July 2026 Dark Web Threat Actor Trend Report

Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
❌