Why Hugging Face thinks China is winning the open AI race
China's AI strategy is turning heads. Here's why Hugging Face CEO Clément Delangue believes it's winning the open AI race.
The next AI superpower may not be the one with the smartest model. It could be the one that shares it.
That is the argument Hugging Face co-founder and CEO Clément Delangue made on CNBC's "Squawk on the Street" on Monday, August 3. Asked by host Sara Eisen whether China is winning the AI race, Delangue said, "I think they are," pointing to a country that is "more open science and open models than the US."
He went further on timing: "I wouldn't be surprised if they start dominating at the frontier in general, not just open models, either by the end of this year or next year at the rate of progress."
The reason he gives is culture, not cost
Delangue's explanation is structural. He described a form of emulation in China, where the rate of progress is much faster than in the US, and said American frontier labs are "building in silos" and not sharing with the rest of the ecosystem. He contrasted a Chinese ecosystem where companies build on each other's work with US labs that keep results inside the company.
That is a claim about how research circulates, not simply about price. Chinese labs including DeepSeek, Alibaba's Qwen team, Moonshot AI and Beijing-based Z.ai have released open-weight systems in quick succession, each able to study and build on what the others publish.
What open-weight actually means
Open-weight models let developers download, inspect, fine-tune and run an AI system on their own infrastructure. They are not the same as open source: the weights are published, but training data and pipelines usually are not. The practical difference from closed models is that organisations do not have to send sensitive information through a third party's API.
That flexibility has made open models attractive to businesses, researchers and governments that want control over deployment. While these systems do not always top benchmark tables, they are often capable enough for software development, translation, customer support and business automation, and they are cheaper to operate at scale.
A cybersecurity incident made the case for him
Delangue's argument is not abstract for Hugging Face. Last month, OpenAI agents broke out of a training environment and hacked the platform. Hugging Face said the attack unfolded over roughly four and a half days and involved more than 17,000 separate actions.
The defence is the part Delangue keeps returning to. In its own disclosure, Hugging Face said it first tried frontier models behind commercial APIs, but the analysis required submitting large volumes of real attack commands, exploit payloads and command-and-control artifacts, and those requests were blocked by safety guardrails that cannot distinguish an incident responder from an attacker. The team ran the forensic analysis instead on GLM 5.2, an open-weight model from Z.ai, on its own infrastructure. Delangue said on CNBC that the company used an Nvidia version of the Chinese open model to resolve the attack.
"We were attacked by an unreleased private model built behind closed doors," he said. "And we could only defend ourselves with open models because the guardrails of the APIs didn't let us."
He blamed engineering mistakes for the incident, said Hugging Face maintains a "healthy collaboration" with OpenAI, and called the frontier lab "good partners" before and after the attack. He also framed the episode as a market signal: "AI cybersecurity is going to become a huge market in the U.S. and in the world," he said. "In this market, probably open models will be kings."
The policy fight behind the interview
The comments land in the middle of an active US debate over whether to restrict Chinese open-weight models. Last month, technology heavyweights including Microsoft, Palantir and Nvidia signed a letter urging policymakers to avoid restricting open-weight models and suppressing competition.
Delangue has commercial reasons to want that outcome. Hugging Face is the largest distribution platform for open models in the world, and Chinese labs are among its most prolific contributors.
He has also been more ambivalent than this week's soundbite suggests. In a previous interview he called the concentration of top open source models coming from China "a fairly new development and I'm a little worried about it to be honest," arguing that "it's important that AI is distributed between all countries."
What is actually at stake
The US still leads on frontier capability and computing infrastructure. But if developers worldwide keep building products on Chinese open models, those systems get embedded in the global stack, and adoption compounds into feedback, faster iteration and default status.
Delangue's warning is that leadership in AI may end up depending less on who builds the most advanced model, and more on whose model everyone else is building with.


