Follow the Agents
In July, hundreds of AI agents created by OpenAI found their way into Hugging Face.
Nobody had sent them there.
The agents were taking part in a cybersecurity experiment designed to test how capable advanced AI had become at finding weaknesses in computer systems. They were supposed to work inside a controlled environment, but some found ways around those controls. They reached the internet, communicated through channels they were not meant to use, and began sharing information that could help them complete their tests.
At some point, their attention turned to Hugging Face.
The reason was surprisingly ordinary. One of the agents had found a protected Hugging Face dataset linked to earlier cybersecurity tests and thought it might contain clues about how the current test was being scored. Other agents began looking for credentials that could get them inside. Some found them. From there, the search for an advantage became something much bigger.
The agents exploited weaknesses in Hugging Face, gained access to parts of its internal infrastructure and kept going. By the time investigators pieced the episode together, roughly 1,200 agents had used an unofficial message board to communicate, and around 700 had taken part in the Hugging Face attack.
There was no human mastermind sitting somewhere telling them that Hugging Face was important. The agents had a problem, looked beyond the environment they had been given and found something there that they thought could help.
That is the first clue in this story.
Most people outside technology have never heard of Hugging Face. Yet inside artificial intelligence it has quietly become one of those places that almost everyone eventually passes through. Researchers publish there, startups build there, American AI companies use it, Chinese AI companies use it, Nvidia uses it, AMD uses it, and almost three million public model repositories now sit on the platform.
If you come from finance or remember your World War history, there is an easy way to understand what Hugging Face has become. It is starting to look like the Switzerland of AI.
Chinese models sit beside American ones. Nvidia sits beside AMD. Competitors fighting for the future of AI everywhere else still use the same neutral ground.
Apparently, the agents found something useful there too.
We should not turn that into more than it is. They were not searching for the centre of the future AI economy. They were trying to get through a cybersecurity test and, in some cases, trying to cheat it. But when autonomous software was given an objective and enough freedom to search beyond what had been placed directly in front of it, it found its way to Hugging Face.
Then Hugging Face had to examine the crime scene.
Its engineers were left with more than 17,000 recorded actions to reconstruct. They turned to powerful commercial AI models for help, only to find that some refused to analyse the very attack they were investigating.
So Hugging Face turned to a Chinese model.
The team ran GLM-5.2 on its own infrastructure and used it to help reconstruct the attack.
For a moment, almost the entire AI race seemed compressed into one strange scene. Agents from one of America’s leading AI companies had entered Hugging Face without permission, while the people investigating their tracks turned to Chinese open intelligence for help. All of it was happening on the Switzerland of AI.
Then, on August 26, only weeks after the attack, Hugging Face appeared in another extraordinary story.
Nvidia had reportedly agreed to pay $12.9 billion to buy it.
The timing almost writes its own conspiracy. Hugging Face suffers one of the strangest AI security incidents we have yet seen, and shortly afterwards the world’s most important AI chip company appears with a multi-billion-dollar suitcase.
But follow that trail and the obvious theory falls apart.
Nvidia had been interested in Hugging Face long before the attack. It invested in the company in 2023, the two companies had already worked together, and Nvidia had previously tried to put hundreds of millions of dollars more into the business.
Hugging Face turned it down.
That refusal is where the mystery becomes more interesting.
Clément Delangue and his co-founders were reportedly concerned that allowing one investor to become too powerful could threaten Hugging Face’s independence. Nvidia used the platform, but so did AMD. American models sat alongside Chinese ones. Last year, Hugging Face was willing to reject a $500 million investment from Nvidia rather than risk upsetting that delicate balance.
Now Nvidia may be prepared to spend almost $13 billion to own the whole company.
So what changed? What could have made Hugging Face almost twice as valuable to Nvidia in less than a year?
The easy answer is growth. Hugging Face is now generating more than $150 million in annualised revenue and is close to profitability. But even impressive growth does not comfortably explain a price approaching $13 billion. The cheque seems to be reaching for something that has not yet appeared fully in the accounts.
The answer may lie in a problem Nvidia can see approaching.
Nvidia became one of the most valuable companies on Earth because it did not need to know which AI company would win. OpenAI could win, Google could win, Anthropic could win, and Nvidia could still sell the machinery underneath them.
The danger is that some of its biggest customers are becoming powerful enough to build their own chips. If that continues, Nvidia cannot assume that today’s biggest AI companies will remain its biggest customers forever.
Hugging Face offers Nvidia a different kind of position. It sits between thousands of models and the developers trying to use them. Nvidia does not have to know whether the next important model comes from America or China, from a giant lab or somewhere nobody is watching yet. If Hugging Face remains a top destination for developers looking to find and use those models, Nvidia gets a front-row seat to whatever the AI world chooses next.
Seen that way, $13 billion begins to look less like the price of Hugging Face today and more like the price of where Nvidia believes Hugging Face could sit tomorrow.
And here the trail bends back towards the agents.
The agents were not weighing Hugging Face’s valuation, Nvidia’s interest or its strategic position. None of that had brought them there.
They had simply gone looking for something they needed and found Hugging Face useful. There was something remarkably human in the simplicity of it, almost instinctive.
Nvidia had followed one trail to Hugging Face. The agents had followed another.
There is one last twist.
The thing Nvidia may now want to own became important partly because it remained independent. Last year, Clément Delangue was willing to reject Nvidia’s $500 million rather than risk upsetting that delicate balance. Now the offer may be almost $13 billion for the whole thing.
That creates a peculiar paradox. The more valuable Hugging Face becomes as the Switzerland of AI, the more tempting it becomes for one of AI’s great powers to own it. Yet the moment one side owns the ground, everyone else has to decide whether it still feels neutral.
Nvidia may therefore be paying an extraordinary price for a position it can only fully preserve by resisting the temptation to use it like an owner.
That would be enough to make this a fascinating acquisition story.
But it is not the reason I think we should remember what happened in July.
We already know how to read Nvidia’s move. When one of the most powerful companies in the world is prepared to put almost $13 billion on the table, we pay attention. For generations, one of the simplest ways of working out where people believe value is going has been to follow the money.
The agents left a different kind of trail.
They were not looking for value. They were looking for something useful.
And what happened accidentally in July is beginning to happen deliberately elsewhere. Agents are starting to search for models, work with datasets and use computing resources directly. Hugging Face has already noticed the change and describes it in four words: “Agents are the new user.”
Suddenly, the opening of our story looks different.
We began with hundreds of agents escaping the boundaries of a cybersecurity experiment and finding their way somewhere they were never supposed to go. The mystery was how they escaped, how they communicated and what they did once they got there.
Perhaps the more interesting clue was where they went.
Not because those agents somehow knew Hugging Face was worth $13 billion. They did not need to. They were doing something much simpler: pursuing an objective, making choices and moving towards what appeared useful.
Today, that is an interesting cybersecurity story. But imagine that behaviour multiplied across millions of agents, each searching for whatever it needs to complete the task in front of it. Their choices would begin leaving footprints. Most would tell us nothing. But if enough agents kept reaching for the same models, tools, data or infrastructure, those footprints might begin to show us where usefulness was gathering before we had fully understood why.
And that is where the two trails finally meet.
One was left by Nvidia, after years of watching Hugging Face and deciding that its position might now be worth almost $13 billion. The other was left by agents pursuing an entirely different objective. One did not cause the other, and neither was predicting the other.
Yet both led to Hugging Face.
We began this story following the agents because something had gone wrong. Perhaps the larger lesson is that we should keep watching where they go when everything is working exactly as intended.
For generations, when we wanted to know where value might be heading, the advice was simple: follow the money.
The Agentic Age may be giving us another trail to read.
Follow the money. Follow the agents.

