China open source AI regulation

China's Hugging Face Clones Are a Hedge Against Washington, and Open-Weight Access Is Stronger Without Them

ModelScope and MoArk are growing because Chinese developers fear a US cutoff; the cheapest fix for both governments is leaving model-sharing open.

China's Hugging Face Challengers People of Internet Research · China ~170,000 ModelScope models Alibaba's platform, per Rest of Wo… ~20,000 MoArk models OSChina's platform, per Rest of Wo… 3M+ Hugging Face models The global hub blocked in China si… $12.9B Nvidia deal value $11.9B to holders plus up to $1.0B… peopleofinternet.com
China's Hugging Face Challengers People of Internet Research · China ~170,000 ModelScope models ~20,000 MoArk models 3M+ Hugging Face models $12.9B Nvidia deal value peopleofinternet.com

Key Takeaways

On September 29, 2026, Rest of World reported that Alibaba's ModelScope, with about 170,000 models, and OSChina's MoArk, with about 20,000 commonly used models, are competing to become China's domestic Hugging Face. Beijing blocked the U.S.-based hub in 2023, yet Chinese developers still often reach it by VPN. That is the odd part of the story: a block that is not enforced against the people who matter most.

The case for the walls

The strongest argument for China's approach is a security one. A state that regulates generative AI wants to know where models and training data come from, and a foreign hub it cannot supervise is a channel it cannot audit. China's Interim Measures for the Management of Generative AI Services, effective August 15, 2023, require providers of services with "public opinion attributes or social mobilization capacity" to complete security assessments and algorithm filings. Regulators may also ask providers to explain training data sources and algorithmic mechanisms. Domestic hubs fit that regime easily, because a platform inside the jurisdiction can be held to it.

There is a second argument, and it comes from Washington. Rest of World reports that the Trump administration has reportedly discussed banning Chinese models from platforms like Hugging Face. We have not independently verified those discussions. If they are real, Chinese labs have good reason to fear losing access to the world's main distribution channel. Rebecca Arcesati of the Mercator Institute told Rest of World there is "a real concern in China that access to [U.S.-based platforms] could be disrupted at any point." Building a fallback is rational risk management.

What the market is actually showing

The evidence so far says that regulation did not create demand for the domestic hubs. Developers pick the platform with the most models, and Hugging Face hosts more than 3 million. ModelScope reportedly has 250 million users, so it has real scale. But independent developer Chen Yunfei told Rest of World that domestic platforms "need to convince us why we should use them." ModelScope and MoArk do offer faster downloads and compatibility with domestic chips, and those are genuine product advantages. A hub that wins on speed and chip support serves developers well. A hub that wins because the alternative is blocked serves them less well.

The tolerance of VPN workarounds is a quiet admission of this. According to Rest of World, Beijing lets AI labs bypass the block to share Chinese models with the world, because total isolation would starve the domestic industry of global connections. Chinese open-weight models gain influence abroad only if they are published where the world's developers already look. A fully sealed system would give up that influence.

The acquisition raises the stakes

On September 2, 2026, Nvidia entered into a definitive agreement to acquire Hugging Face. The price is about $11.9 billion to stockholders plus up to $1.0 billion in employee retention equity, and closing is expected in the first half of 2027. The filing makes the deal subject to "required regulatory approvals" without naming the agencies. Rest of World reports that Nvidia flagged regulatory risk in its filing, which we have not independently confirmed in the filing text we reviewed. Adweek reports that Jensen Huang has said Hugging Face will "remain an open platform for the entire AI ecosystem." That neutrality pledge is the best protection against the fragmentation both capitals seem to be edging toward.

Why proportionate policy points the other way

A US ban on Chinese models on Hugging Face would be a poor trade. Open weights can be inspected, tested and fine-tuned, which makes them easier to scrutinize than closed APIs. Removing them from the main hub would not stop their use. It would push downloads to mirrors and to ModelScope, where US researchers have less visibility into what is being distributed. Targeted measures, such as disclosure of provenance and security evaluation of specific high-risk releases, address real concerns without cutting off a global commons. Blanket exclusion by origin is the weaker tool.

Beijing's side of the ledger has a matching lesson. The 2023 Measures are aimed at public-facing services, and the formal block is only loosely enforced against developers. That gap suggests regulators know that hard isolation would cost them. The proportionate course is to make the tolerated practice explicit, with a clear, published rule for how researchers may share models abroad, rather than relying on unspoken forbearance that can change without notice.

The lasting result may be two or more parallel hubs. That is not inherently bad. Competition between ModelScope, MoArk and Hugging Face can improve download speeds, tooling and hardware support. The risk is a forced split, where each side's developers lose access to the other's work because of political decisions rather than technical ones. Governments that care about both security and innovation should keep model-sharing channels open and put their regulatory effort into evaluation and disclosure.

What to watch

Two things will decide how this plays out. The first is whether Washington's reported discussions become a formal measure. The second is how regulators in the relevant jurisdictions treat the Nvidia deal ahead of its expected 2027 close. Until then, Chinese developers will keep both options open: a domestic hub for chip-native work and a VPN for everything else.

Sources & Citations

  1. CAC: Interim Measures for the Management of Generative AI Services (2023)
  2. NVIDIA Form 8-K, Hugging Face acquisition (Sept 2, 2026)
  3. Rest of World: The open-source AI platforms vying to become China's Hugging Face
  4. Adweek: Nvidia confirms purchase of Hugging Face