Hugging Face Response to Request for Information on the Development of an Artificial Intelligence Action Plan
Published March 2025 · "March 2025" is printed beneath the title on page 1 of both copies. The sorting date 2025-03-14 is the submission date given by Hugging Face itself in its blog post of 19 March 2025 ("On March 14, we submitted Hugging Face's response"); the RFI closed on 2025-03-15. The copy hosted on huggingface.co carries no internal creation date; the US government's compilation copy on files.nitrd.gov was created on 2025-04-15, when responses were published.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
Hugging Face's submission to the consultation behind the White House AI Action Plan is an argument that openness is itself national AI strategy, and it asks government to fund and standardise an open ecosystem rather than to regulate model developers. It states its premise plainly — "The United States must lead in open-source AI and open science" — and backs it with the claim that open models have caught up with proprietary ones on shrinking budgets and that open-source software is worth a large share of national GDP. The asks fall under three pillars. First, public infrastructure for open work: "Fully implement and expand the National AI Research Resource (NAIRR) pilot", "dedicate a portion of publicly-funded computing infrastructure to support open-source AI projects", and counter a shrinking data commons in which licensing deals are "threatening to lock out small open developers from access to quality data." Second, efficiency and reliability: research into smaller models, "federal standards for measuring and reporting AI system efficiency" (with "the Energy Star rating for models" as an example), and open evaluation, because "Developer-run private evaluations are not currently comparable and have limited scrutiny, whereas open evaluations enable broader oversight." Third, security through transparency: treat AI as an information system, so "AI security practices should be informed by decades of experience in cybersecurity", make model cards do for AI what a software bill of materials does for software, and value open-weight models that can be run air-gapped in sensitive settings. It asks nothing of any legislature, proposes no liability or licensing rule, and does not mention frontier-risk thresholds, copyright or state law.
Stated positions (15)
- Open development is the organising claim: "The United States must lead in open-source AI and open science, which can enhance American competitiveness by fostering a robust ecosystem of innovation and ensuring a healthy balance of competition and shared innovation."
- Cites economic evidence for public investment in openness: open technical systems have "an estimated 2000x multiplier effect", and without open-source contributions "the average country would lose 2.2% of its GDP".
- Public research infrastructure first: "Fully implement and expand the National AI Research Resource (NAIRR) pilot", drawing on Hugging Face's own participation in the pilot.
- Wants public compute earmarked for open projects: "dedicate a portion of publicly-funded computing infrastructure to support open-source AI projects, reducing barriers to innovation for smaller research teams and companies that cannot afford proprietary systems."
- Warns that data licensing is closing the data commons, with costs "threatening to lock out small open developers from access to quality data", and asks government to "Support organizations that contribute to public data repositories and streamlined compliance pathways that reduce legal barriers to responsible data sharing".
- Asks for rights-respecting data frameworks and data trusts: "Establish clear guidelines for data usage, including standardized protocols for anonymization, consent management, and usage tracking."
- Wants AI built for particular sectors, not only bought from the largest vendors: programmes enabling organisations to develop customised systems "rather than relying exclusively on general-purpose systems from major providers."
- Backs NIST as convener: "Expand NIST's role as a convener for AI experts across academia, industry, and government to share lessons and develop best practices", crediting the AI Risk Management Framework with shaping Hugging Face's own documentation and evaluation tools.
- Proposes efficiency standards: "Develop federal standards for measuring and reporting AI system efficiency, creating market incentives for technologies that use limited energy resources more effectively. Examples of tools include the Energy Star rating for models."
- Argues for choosing the smallest adequate model: "Promote the principle of using the most efficient tool that meets performance requirements", citing resource-utilisation considerations in the NIST AI RMF.
- Makes open, representative evaluation a policy goal: "Developer-run private evaluations are not currently comparable and have limited scrutiny, whereas open evaluations enable broader oversight." Government-industry evaluation partnerships should carry "an explicit mandate to prioritize open evaluation data and tooling".
- Wants agencies able to evaluate what they buy: "Provide training and further develop technical capabilities within organizations, including government agencies, to evaluate AI systems they procure or deploy".
- Treats AI security as an extension of software security: "model cards and training information for AI systems can play a similar role for AI security as the widely recognized Software Bill Of Materials", and asks that "all actors using AI systems in security-impacting applications have sufficient information about the system’s development and characteristics to proactively identify risks in their deployment context."
- Presents open weights as a security asset, not a risk: "“Open-weight” models stored in secure formats that can be deployed in air-gapped environments play a critical role for adoption of the technology in the most sensitive environments", and "prioritizing open and open-source AI as a critical component of the U.S. AI security strategy will be crucial for its success."
- Wants government to build its own purpose-specific systems where commercial ones are risky: "Facilitate the development of purpose-specific AI systems for government use in cases where the use of general-purpose commercial systems may carry information security risks."
About this document
An 8-page PDF headed "Hugging Face Response to Request for Information on the Development of an Artificial Intelligence Action Plan", dated "March 2025" under the title, about 2,800 words, hosted in Hugging Face's public policy-docs dataset on huggingface.co. It closes "Submitted by: Avijit Ghosh, Yacine Jernite, and Irene Solaiman" of Hugging Face and is addressed to the Office of Science and Technology Policy. It runs: About Hugging Face; an Executive Summary setting out three numbered pillars (strengthen open and open-source AI ecosystems; prioritise efficient and reliable adoption; promote security and standards); a section on the role and progress of open and transparent AI, citing OLMo 2 and Hugging Face's OlympicCoder against proprietary models; then three substantive sections, each ending in bulleted "Policy Recommendations" — open source and open science (six bullets, two with sub-bullets on datasets and data-access frameworks), efficient and reliable adoption (six bullets), and security and standards (four bullets) — and a Conclusion. It cites figures on economic impact, energy demand and healthcare error rates without footnotes, names the NAIRR pilot, the NIST AI Risk Management Framework and the AI Safety Institute Consortium, and names no bill, statute or foreign law beyond a reference to European Commission rules on open-sourcing government software.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Open-source and open-weight AI as a national priority
The US should lead in open-source AI and open science because open models, libraries and research drive innovation, lower costs for startups and let sensitive users run models locally; policy should actively support the open ecosystem rather than treat it as a risk.
The Act accommodates open source rather than promoting it: Article 53(2) exempts providers of general-purpose models released under a free and open-source licence with public weights from the technical-documentation duties in Article 53(1)(a) and (b), but not from the copyright-policy and training-summary duties, and not at all if the model has systemic risk.
The plan has a section titled 'Encourage Open-Source and Open-Weight AI' saying the federal government 'should create a supportive environment for open models', and tasks NTIA with convening stakeholders to drive their adoption by small and medium-sized businesses.
Public compute and research infrastructure for open work
Fully implement and expand the NAIRR pilot, and dedicate a portion of publicly funded computing infrastructure to open-source AI projects so that smaller teams can compete.
The Act is a product-safety regulation and contains no public-compute programme; its nearest support measures are the AI regulatory sandboxes of Article 57 and priority sandbox access for SMEs and start-ups, which concern testing under supervision, not compute.
The plan supports the NAIRR pilot — partnering with companies to widen researchers' access to private compute, models and data, and building a sustainable NAIRR operations capability — and wants a financial market for compute, but it does not earmark public compute for open-source projects as Hugging Face asks.
Data commons and open datasets
Government should counter a shrinking data commons, in which licensing deals price small open developers out, by supporting contributors to public data repositories, funding open high-quality datasets and setting rights-respecting data-access frameworks and data trusts.
The Act does not fund or open datasets. Its data provisions are duties — data governance for high-risk systems in Article 10, and a published training-content summary and copyright policy for general-purpose models in Article 53(1)(c) and (d) — not measures to widen access.
The plan's 'Build World-Class Scientific Datasets' section asks for data-quality standards, secure access to federal data and incentives for researchers to release datasets publicly, and would require federally funded researchers to disclose non-proprietary datasets used by AI models; it is confined to scientific and federal data and does not address the commercial licensing market Hugging Face worries about.
Measuring and reporting AI energy efficiency
Develop federal standards for measuring and reporting AI system efficiency, such as an Energy Star rating for models, fund research into smaller models, and promote using the most efficient tool that meets the need.
The Act already asks for part of this: the technical documentation that general-purpose model providers must keep for the AI Office under Article 53(1)(a) and Annex XI includes the known or estimated energy consumption of the model. It sets no rating scheme.
The plan treats energy as a supply problem (permitting, grid and generation for data centres) and has no measure on model efficiency; it also directs NIST to revise the AI Risk Management Framework to remove references to climate change, the framework Hugging Face cites for resource-utilisation guidance.
Open, representative evaluation and public-sector evaluation capacity
Invest in evaluation frameworks that represent real uses, build agencies' capacity to evaluate the systems they buy, and run public-private evaluation partnerships with a mandate to prioritise open evaluation data and tooling, because private developer-run evaluations are not comparable and get little scrutiny.
Article 55(1)(a) requires providers of systemic-risk models to evaluate them with standardised protocols including adversarial testing, but the evaluations are the provider's own and are not required to be open; Hugging Face wants evaluation data and tools public.
The plan's 'Build an AI Evaluations Ecosystem' section has NIST and CAISI publish guidelines for agencies to run their own evaluations, funds measurement science and testbeds, and convenes the NIST AI Consortium — close to Hugging Face's asks, though it sets no preference for open evaluation data.
Documentation and transparency standards (model cards as an AI bill of materials)
Model cards and training information should do for AI what a Software Bill of Materials does for software, and everyone using AI in security-impacting applications should have enough information about a system's development and characteristics to identify risks in their own deployment.
Article 53(1)(a) and (b) require general-purpose model providers to keep technical documentation for the AI Office and to give downstream providers the information they need to understand the model's capabilities and limitations and meet their own obligations — the downstream-information duty Hugging Face describes.
AB 2013 requires developers of generative AI systems offered in California to publish documentation of their training data, including dataset sources and summaries; it is broader than Hugging Face's ask, which is framed around security-impacting uses, but points the same way. No federal instrument requires model documentation.
Security of AI as an extension of cybersecurity, with open weights as an asset
AI security should draw on decades of cybersecurity and open-source practice, including Secure by Design; open-weight models in secure formats that can run air-gapped are valuable for the most sensitive settings, and government should be able to build purpose-specific systems where commercial ones carry information-security risk.
Article 15 requires high-risk systems to achieve appropriate accuracy, robustness and cybersecurity, including resilience against attacks such as data poisoning, and Article 55(1)(d) requires an adequate level of cybersecurity for systemic-risk models; the Act draws no line between open and closed models on security.
The plan's 'Promote Secure-By-Design AI Technologies and Applications' section, AI incident-response measures and its note that many businesses and governments have sensitive data they cannot send to closed model vendors match Hugging Face's framing, though the plan's secure-by-design actions are aimed mainly at defence and intelligence users.
The adopted US plan took up more of Hugging Face's agenda than of most submitters': it has a section titled 'Encourage Open-Source and Open-Weight AI', expands NAIRR, builds scientific datasets, funds an evaluations ecosystem and promotes secure-by-design AI. Where it parts company is on efficiency and openness of evaluation — it says nothing on measuring model energy use, directs NIST to strip climate-change references from the AI Risk Management Framework that Hugging Face cites, and does not prefer open evaluation data. The EU AI Act works the other way round. It is a set of obligations, not an investment plan, so it has no counterpart to Hugging Face's calls for public compute and data commons, but it already contains several of the transparency tools Hugging Face advocates — technical documentation for downstream providers and disclosure of a general-purpose model's energy consumption — and it softens its documentation duties for open-source models without systemic risk. Hugging Face's claim that "open evaluations enable broader oversight" goes beyond both: each leaves evaluation largely to the developer or the government.
Source
https://huggingface.co/datasets/huggingface/policy-docs/resolve/main/2025_Hugging_Face_Response_to_AI_Action_Plan.pdf- Date on the page:
- March 2025
- Source checked:
- opened and confirmed on 2026-09-30