Cycode’s Hugging Face integration gives security teams visibility, context, and control over the AI models your teams build, publish, and pull.
Hugging Face crossed over 3,000,000 public models on its hub in August 2026. Developers are pulling models from Hugging Face, fine-tuning what they find, wrapping models into services, and publishing new ones back to the organization.
Establishing security visibility, governance, and guardrails over those models is an escalating challenge.
Cycode’s Hugging Face integration closes that gap. It connects Cycode to the registry your teams already use and brings every model your organization publishes into the same inventory as the models Cycode detects in your code. Cycode provides visibility into each model’s license, access, lineage, and community signals to inform governance decisions and provides the controls to enforce them.
Understanding AI Model Governance
Security teams know how to reason about a dependency in an open-source library. There is source code, a version, a changelog, and years of tooling built to scan it. AI models are different. A model is a large binary artifact with real potential risks that security teams that only have visibility into code can’t see.
Loading a model can run code. Many model files are saved with Python’s pickle serialization, which can execute arbitrary code when the file is deserialized. A developer who pulls the wrong model can run someone else’s code on their workstation or inside your pipeline without ever calling a malicious function.
Licenses travel downstream. A fine-tuned model inherits obligations from the model it was built on. A non-commercial or research-only license two levels up the lineage can end up inside a product you ship to customers.
Lineage carries risk forward. Derivatives stack fast. Qwen-based models from Alibaba Cloud alone account for over 150,000 derivatives on Hugging Face. Whatever a base model carries, including tampered weights or undisclosed training data, flows into everything built on top of it.
There are too many models to trust blindly. More than 4 out of 5 AI models on Hugging Face have fewer than 200 lifetime downloads. A model with a familiar name may be one person’s abandoned experiment or a lingering malicious model.
Your own models can leak. A model fine-tuned on internal data and set to public by mistake exposes what it learned. And private models your teams publish and serve may never appear in a repository at all, so a code-only view will never find them.
Cycode discovers and unifies every AI model in one governed inventory
The Hugging Face integration extends Cycode’s ADLC Security coverage. It connects to your Hugging Face organizations, inventories the AI models your organization publishes, and enriches the models Cycode finds in your code with critical security context. The result is a unified inventory of AI Models that security can then see, manage, and act on.
Visibility: see every AI model, including Shadow AI
Cycode creates a unified inventory of every AI model with its source and authorization status.
- One list, wherever the model came from. Models detected in your code and models published by your Hugging Face organizations land in the same inventory.
- Shadow AI, surfaced. See what teams published and pulled without asking, including private organization models that never show up in a repository. If a model exists in your org, it exists in your inventory.
- Public or private, at a glance. Know whether each model is public on Hugging Face or private to your organization, so an internal model that went public is easy to spot.
- One provider at a time. Filter the inventory by namespace to review everything published by a single provider or organization.
Governance: manage models with the full picture
Cycode automatically enriches models with information from Hugging Face that security teams would otherwise have to hunt for on the Hugging Face Hub.
- Critical governance data. License, public or private visibility, and download access, including whether the author must approve each request before anyone can download the model.
- Enrich models found in code. When a model your scanners find in a repository is also published to a connected Hugging Face organization, it picks up the same enrichment.
- Where it came from. Base models show what a model was derived from, so you can trace license and trust questions up the lineage.
- What it is made of. Parameter count, parameters by precision, and the file types in the model’s repository. That last field tells a reviewer at a glance which serialization formats a model ships with.
- Whether anyone relies on it. Downloads, likes, the number of Hugging Face Spaces that use the model, and whether the author published benchmark results. Together they separate a widely used model from a one-off.
- The warning signs. Models that were disabled on Hugging Face are flagged, so a model pulled upstream does not stay in use downstream.
Guardrails: turn governance decisions into enforceable controls
Seeing every model is the start. The value is being able to make transparent governance judgements on each one and enforce decisions.
- A clear status for every model. Mark each model as Not reviewed, Authorized, or Unauthorized, directly from the inventory list with clarity from enrichment data.
- Enforcement without chasing. Unauthorized models raise violations automatically, and every status change is recorded in the audit log, so governance decisions are traceable when an auditor or an executive asks.
- Connect with ease. The integration uses a read-only token and syncs only the organizations you select.
- Stay in sync. Cycode pulls every model when you initially connect, then refreshes daily to add and remove models.
Manage and Secure AI Models with Cycode
AI models are now part of the software supply chain. They carry licenses, lineage, and risk the same way dependencies do, and they are growing faster than any review process built for human-paced development. Treating them as a blind spot is no longer an option.
Cycode’s Hugging Face integration brings models into the same inventory, the same context, and the same controls as the rest of your ADLC. Every model visible. Every decision informed. Every call on the record. Request a demo to see it in action.
