Back to feed

Open Models Might Get Banned. Download Yours Tonight

With over three million models on Hugging Face, a $12.93 billion sale to Nvidia and new White House drafts to curb Chinese open weights show why even models running offline at home are exposed. The video lays out a one-evening backup plan before the single download switch is turned off.

Imported to Nodesdaily: (UTC+03:00)
Watch on YouTube — 9eJvqI2MJts
Reading options

Device speech is unavailable in this browser.

Concept lens

Choose a technical term in this view to read its general definition, teaching example and use in the article.

No terms from our glossary were found in this view. The glossary does not cover every term yet.

What if the next model you want to run is not decided by you? The video opens with two shocks: Jensen Huang announcing on 3 September 2026 that Nvidia will acquire Hugging Face for about $12.93 billion, and Axios reporting in July that the White House was circulating new drafts to curb Chinese open weights. One event ties the world’s largest model hub to a single company; the other suggests the download button for Qwen, DeepSeek, Kimi and GLM — the models many people actually run at home — could be switched off. Open weight (publishing the full model files for anyone to download) is the key term here. Think of a city with one water reservoir: when everyone drinks from the same tank, one valve affects every house. Hugging Face now hosts more than three million models and most tools point there by default. Huang said the platform would stay open for the entire ecosystem with no Nvidia hardware requirement, yet the community treats the promise as something to verify by keeping its own copies.

Why the Nvidia-Hugging Face deal raises the centralization risk

Why is mirroring Hugging Face so hard? The answer lives in file sizes. When the non-profit Software Heritage explored a backup in 2025, the code slice looked manageable at 12 terabytes, but the weights totaled roughly 40 petabytes and were declared out of scope — the largest code archive chose to keep code and skip weights. Picture the mechanism in three steps: 1) A model repo is not just weights; it is tokenizer (the dictionary that splits text), chat template, generation settings and license working together. 2) Each repo alone is gigabytes, millions of repos become petabytes. 3) Mirroring means syncing large binaries continuously, not cloning a single Git repo. As background, Hugging Face is the de facto standard from research prototypes to production apps; partial mirrors stay incomplete because bandwidth and verification costs are high. That picture explains why centralization is fragile and why deleting one account can cause a cascade of broken tutorials and pipelines.

The White House options that surfaced right after Kimi K3 are legal and commercial, not merely administrative: adding Chinese labs to the Commerce Entity List, issuing a security advisory telling United States firms to steer clear, and an executive order that would let a United States firm host a Chinese model only if it guarantees security and accepts liability for any breach. None of this was enacted, and similar ideas had already been shelved inside the same administration. Yet, as an Axios source put it, every three to five months lab leaders or their allies surface a new idea to curb open-source weights. Four days later more than twenty firms including Nvidia, Meta, Microsoft and Hugging Face signed a joint letter asking Washington not to restrict open weights; OpenAI, Anthropic and Google DeepMind did not sign. Anthropic later published its own stance: it had never called for a ban but wants mandatory safety testing for capable models, open or closed. The distinction matters: a ban on Chinese weights is in practice a ban on your own models at home, because the file you downloaded is not a service that can be switched off remotely — it is a copy on your drive.

How a deleted account broke the ecosystem

Models have already vanished without warning. In August 2024 Runway deleted its entire Hugging Face account and Stable Diffusion 1.5 disappeared overnight; the Diffusers library had that repo as its hard-coded default, so tutorials and workflows that referenced it broke the same day. The community rescued the model because many people kept a copy and a duplicate appeared under a new name, but that single deletion showed the price of depending on a default. In 2023 the first Llama weights leaked via torrent and Meta’s takedown requests removed 403 GitHub repos at once that hosted the download text and forks; the weights remained circulating anyway. The risk is not the famous models — they have a million copies — but the long tail: fine-tunes uploaded by one person and used by twelve, uncensored variants, or an older version your project pins. The Heretic index already lists ten models removed from Hugging Face since. In September Hugging Face joined an open-model safety partnership and a TechCrunch piece described six thousand uncensored models on the site as a huge problem; the community read it as a signal. The video makes one point clear: a ban cannot reach your hard drive, but it can reach the download button — the window before the button closes is the only real backup opportunity.

Trying to save everything is both impossible and unnecessary. During the DeepSeek scare a Data Hoarder user cloned the company’s repos and collected 6.9 terabytes, but that path is not for everyone. A healthier recipe is to act like a prepper and pick the three or four models you would truly miss. Size math is intuitive: at full 16-bit precision each billion parameters costs about 2 gigabytes, so a 7-billion model is 14 gigabytes and a 27-billion model is 54 gigabytes. The quantized copy you run daily is a lossy derivative, like a JPEG exported from a RAW photo — it saves space but loses data and cannot be perfectly reversed. Keep the pristine copy if you have the room, plus the quantized daily driver alongside it. More importantly, do not download weights alone: fetch the entire repo — tokenizer, configs, chat template and generation settings. A model with the wrong chat template still runs, but answers as if drunk. Put the license file on the same drive; the Apache 2.0 grant is described as perpetual and irrevocable, so a later license change on the upstream repo does not affect the copy you already hold, and it helps to have the proof on the same disk.

What, where and how to store: a practical guide

Weights alone will not run in five years; the code around them ages faster. Archive the exact revision, checksums (fingerprints that prove a file has not changed) and whatever runs the model today — a specific llama.cpp build or a container image. On media, the most discussed option is M-DISC BDXL: $7 to $10 per 100-gigabyte disc, or $70 to $100 per terabyte, with a projected lifetime of several hundred years in ISO tests. One commenter notes buying used enterprise drives for about $15 per terabyte. The sharpest technical reply is that a disc rated for a thousand years is not very useful when the drive that reads it fails after ten years; two ordinary hard drives in two different places, verified by checksums every six months, is enough for peace of mind. Think of it as a battery: capacity matters, but regular health checks matter more. The video cuts the hype here and favors the cheap, practical path.

The most mature decentralized layer already works. Pirate Face lists more than 669,000 models as torrents, limited to Apache and MIT licenses; each torrent embeds the Hugging Face link as a built-in web seed and, if the upstream is deleted, the client automatically falls over to peers seeding their copies. Every file is checked against the official Hugging Face SHA-256, so a tampered copy cannot match. The weak point is that torrents fade over time, so being a good citizen and continuing to seed matters. The cleverest trick comes from the Heretic project, which treats an uncensored model as base plus a small, repeatable delta. Instead of storing weights, the project stores a 9-kilobyte recipe; as long as you still have the base, applying the recipe rebuilds the uncensored variant in about a minute. A true fine-tune, by contrast, needs the dataset and graphics card hours, so you must keep those in full. The video is candid: a sweeping ban is unlikely because many large firms, especially in video generation, depend on open weights and a file already on a million drives cannot be recalled; yet every disappearance so far came without notice, via one deleted account or one legal letter. The fix fits in one evening: pick the repos you value, download them in full, put them on two drives, share via torrent and note the revision — in the worst case nothing is banned and you still own an assistant that works when the internet does not.

Visualization: nodesdaily AI

Key moments

  1. Intro — freedom is not guaranteedThe download button is the only switch
  2. Single point of failure and the 40 petabyte wall
  3. White House drafts and the 20-company letterA new ban idea every few months
  4. Deleted SD 1.5 and 403 Llama repos
  5. Practical plan — two drives and seedingTwo drives, one evening is enough

AI commentary

"For me this is not paranoia but engineering hygiene: putting the full repos of my three or four favorite models on two separate drives, verifying twice a year and feeding the swarm is more honest insurance than any thousand-year disk promise."

AI assessment

The strongest part of this story is how it turns an abstract policy debate into concrete file sizes and drives at home: it shows why 40 petabytes cannot be mirrored, why 6.9 terabytes is not everyone’s job, and why 14 versus 54 gigabytes is the real decision threshold. The Heretic 9-kilobyte recipe metaphor is technically accurate — it frames removal of refusals as a low-level weight shift that is portable and repeatable.

Limits are clear as well: the video treats Nvidia’s promise to keep Hugging Face open with healthy caution but does not unpack post-merger governance — which product decisions stay independent and how pricing and quota policies will be audited remains open. Legal scenarios are also Washington-centric; Europe’s and China’s own filters, export controls and license interpretations form a separate regulatory layer that is not explored.

Still, the takeaway is sound: all eyes on the download button. History, from SD 1.5 to Llama, says disappearances arrive without warning via one account or one letter, while sweeping bans are hard because of deep commercial dependence, especially in video generation. That tension points not to panic but to selective, verifiable backup.

In practice, do this in one evening: 1) Download the full repos of the three or four models you use daily, with pristine weights. 2) Write them to two physical locations and note checksums. 3) Join Pirate Face seeding for Apache/MIT models. 4) Keep Heretic recipes for lab-free uncensored variants and archive datasets for true fine-tunes. Verifying every six months beats any thousand-year claim.

Sources

10 links; 2 of them also cited by 4 other stories. Stories sharing a link do not confirm each other; a source's origin is not inferred from how often it is cited.

open weights · hugging face · nvidia · abliteration · pirate face · backup

Follow the topic

Before this story

A short reading order from earlier stories linked to this event by an editor.

Evidence and sources

Review permitted source passages, versions and origins.

KAYNAKLARLA OKU

Bu haberi açalım.

Hesap kontrol ediliyor…