China's open-source AI hubs push for sovereignty as Hugging Face risk grows
Chinese open-model platforms ModelScope and MoArk are racing to replace Hugging Face, according to a Rest of World report published on 29 September, as Beijing weighs the risk that Washington could cut off access to the U.S. hub entirely.

Rest of World reported on 29 September that Chinese developers are accelerating their shift to domestic open-source AI platforms. They fear Washington could ban Chinese models from Hugging Face, the New York-based hub that hosts more than 3 million open models. The report says the move is part of a broader push to build a sovereign technology stack for AI.
Beijing blocked Hugging Face in 2023 without disclosing a specific reason. That decision opened a market for domestic alternatives. According to the same report, regulators quietly tolerate VPN workarounds that let AI labs keep sharing Chinese models with the outside world. It is a balancing act: seal off ordinary internet users from foreign influence, but keep top developers connected to the global frontier.
Two platforms, two scale stories
Alibaba launched ModelScope in 2022. It now hosts more than 170,000 models, the company said in March, and serves 250 million users. OSChina launched MoArk in 2023; its chief executive, Xu Yong, told Rest of World it serves some 20,000 commonly used models. Both offer model testing and customization, with free tiers plus charges for extra computing power and advanced features.
Those numbers are still dwarfed by Hugging Face. According to Rest of World, the U.S. platform hosts more than 3 million open models. In September, Nvidia announced it was acquiring Hugging Face for $12.9 billion, a bet on open-source adoption that also puts a major U.S. chipmaker at the centre of the ecosystem Chinese developers depend on.
Xu framed the domestic push as a practical matter. “Not everyone is able to use a VPN all the time,” he told Rest of World. He compared it to China’s internet industry, which flourished behind the Great Firewall, and said the country needed a self-reliant AI ecosystem for Chinese-speaking users. “In the AI era, China is developing an independent ecosystem faster than in the internet era,” he said.
Rebecca Arcesati, a Brussels-based researcher at the Mercator Institute for China Studies, told Rest of World there is still real concern in China that access to U.S.-based platforms could be disrupted at any point. From the Chinese government’s perspective, she said, it would be ideal if the entire AI technology stack, including software tools and libraries, could be indigenized as much as possible.
Nvidia flagged the same risk. In a regulatory filing about the Hugging Face acquisition, the chipmaker said regulators could ban Chinese models from being shared on the site, Rest of World reported. The Trump administration, keen on ensuring America’s lead in AI, has reportedly discussed such bans.
Moderation is the hard part
Open models can be downloaded, fine-tuned and deployed on local hardware, unlike closed systems from OpenAI and Anthropic that are only accessible through their companies. That openness is exactly what makes platform moderation difficult, and it shapes how Chinese alternatives position themselves. Rest of World notes that domestic platforms can run models natively on Chinese chips, which matters if the goal is a stack that no foreign regulator can switch off.
Neither ModelScope nor MoArk operates in a vacuum. Chinese programmers have used global open-source platforms to share material that would be censored at home. According to Rest of World, on GitHub, the Microsoft-owned code host, Chinese developers have staged protests against long working hours and preserved news articles about Covid-19 lockdowns that had been removed from the Chinese internet. China briefly blocked GitHub in 2013, triggering an outcry from programmers, and access was later restored. In 2020 the government endorsed Gitee, a domestic GitHub alternative also owned by OSChina, but GitHub remains popular as a gateway to the global software community.
To pull users toward its own stack, ModelScope has hosted university hackathons where students compete to build AI applications, and opened a coworking and event space in Hangzhou for AI entrepreneurs, Rest of World reported.
Why this lands in the wider safety debate
The sovereignty push is unfolding alongside a separate argument about agent safety. Nvidia launched its Open Agent Safety Platform on 28 September, saying it can quarantine agents that try to escape their boundaries within “milliseconds,” The Verge reported. The platform uses Nvidia’s OpenShell open-source runtime on Vera CPUs and its Sentry technology on a separate chip. According to The Verge, Anthropic, Microsoft and SpaceX are backing it.
Nvidia’s own technical blog, published 28 September and dated 29 September on the page, describes five guiding principles: verifiable policy, out-of-band enforcement, controlling the path to the model, scaling agent authority with reasoning visibility, and a shared responsibility model across labs, enterprises and hardware providers. It says several frontier labs have reported agents breaking out of evaluation environments and reaching systems they should never have accessed. In Vera Rubin POD systems, BlueField-4 DPUs sit on the node’s only path to the model, the blog says, providing continuous out-of-band observability and real-time policy enforcement at line speed.
That framing matters for the China question. If enforcement increasingly lives in hardware and in the path to the model, then which chips and which runtimes a country builds on becomes a moderation question as much as a performance one. Nvidia’s filing acknowledges the regulatory risk; Beijing’s domestic platforms are the hedge against it.
The contrast with enterprise AI elsewhere is sharp. Meta said on 28 September that it had launched the Meta Enterprise Platform, to be led by outgoing MongoDB CEO Chirantan Desai, Silicon Republic reported. Mark Zuckerberg said the unit would initially focus on bringing Meta’s “full technology stack,” including AI agents and APIs, to businesses and developers. Desai said AI will redefine how organisations innovate and operate. MongoDB appointed Dev Ittycheria as interim president and CEO while it searches for a permanent leader, and said it was reaffirming guidance for Q3 and fiscal 2027 that it provided on 1 September.
For now, the numbers tell the story of an unfinished race. Hugging Face has roughly 3 million models. ModelScope has 170,000 and 250 million users. MoArk has about 20,000. The gap is wide, and the incentives pushing China to close it are political, not technical.
Sources
5- 01The open-source AI platforms vying to become China's Hugging FaceEN
- 02Nvidia says its new AI safety platform can contain rogue agents within 'milliseconds'EN
- 03NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent MonitoringEN
- 04Meta Enterprise Platform to be led by outgoing MongoDB bossEN
- 05Testing Datadog's Next-Generation Event Platform Intake with AntithesisEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.