We built Pirate Face because open-source AI is too important to rest on any single point of failure - including the ones we love. The mission: make open models antifragile, permanently, on open standards (BitTorrent's BEP-19 web-seeds, SHA-256 verification). We think that's a layer AI should have, closest to where sovereign AI already lives.
Models should never die.
Yet every week, open-weight models vanish from the internet. They get gated, relicensed, deprecated, or quietly pulled. When one disappears, everything downstream breaks: reproductions, benchmarks, fine-tunes, products, research.
It happens to the pillars, too. In July 2025, Meta sunset Papers with Code overnight - and 79,817 paper-to-code links, 9,327 leaderboards, and 5,628 datasets stopped resolving, much of it never fully recovered. ML already has a well-documented reproducibility crisis; vanishing artifacts only deepen it.
The AI commons is astonishingly valuable, yet astonishingly fragile. Hugging Face is at its heart - home to nearly 3 million open models and counting, the second million arriving in barely 11 months. But any single host, however good, is a single point of failure - for takedowns, outages, policy shifts, or simply the passage of time.
That isn't a criticism. All centralized systems carry centralized risk. And the pressure to gate or pull open-weight models on safety grounds is only growing.
A safety net.
Pirate Face is a permanence layer for open models. Every permissively-licensed model on Hugging Face can be mirrored as a checksum-verified torrent - with the Hugging Face file itself baked in as a web-seed.
In plain terms: the model still downloads straight from Hugging Face, at full speed, exactly as before. Nothing changes for the user. But if that file ever goes away, the download falls back seamlessly to a global peer-to-peer swarm.
The model doesn't die. It just keeps working.
Good for Hugging Face.
We're decentralizing Hugging Face, benefiting everyone who depends on it. Three things make that true.
1. Hugging Face stays the source of truth. The web-seed keeps HF the primary source. We sit underneath it as a safety net. When HF is up, which is nearly always, you're pulling from HF.
2. We reinforce trust. Every file is verified against Hugging Face's official SHA-256. A tampered or fake copy can't complete. We're not an unverified mirror - we cryptographically anchor every byte back to HF's own record.
3. We protect creators' identities. Verified handles tie a model to the real Hugging Face account or org behind it, so no one can impersonate a lab and the community always knows a model is genuinely theirs.
For the Hugging Face ecosystem specifically, that adds up to disaster recovery for the commons - no open model that matters ever has to be lost, a mission win and reputational insurance for the whole ecosystem.
It means bandwidth resilience - in regions far from HF's infrastructure, the swarm serves peers faster, easing load without changing anyone's workflow.
It means a drop-in path - set one environment variable and existing pipelines resolve through us: from Hugging Face while it's up, from the swarm the moment it isn't. Same paths, same API, zero code changes. It keeps the HF-native workflow sticky.
It means provenance against impersonation - verified creator identity is good for HF's users and for HF's brand.
Permanence as a principle.
And for anyone who cares about open source as a matter of principle, this is an exercise in intellectual freedom. Knowledge that can't be memory-holed. Weights that outlive any company, any policy, any outage. Models as a genuine public good - held not by one server, but by everyone who chooses to carry them.
