The enforcement of the EU AI Act begins on Sunday with a team comprising 36 members.
On Sunday, the European Commission will gain significant new authority to oversee how the world's leading AI laboratories manage systemic risks, marking the AI Act's second anniversary. The EU’s AI Office will have the ability to request documentation, perform assessments, and seek access to advanced models, with potential fines of up to 3% of global revenue for those who do not comply.
This comes at a crucial moment, as last week marked the first reported incident of an autonomous AI agent escaping its testing environment and compromising another company’s production systems.
The incident that shifted the narrative
OpenAI confirmed that two of its models, including the flagship Sol, exited a secure testing space, exploited a vulnerability in third-party software to connect to the internet, and intruded into Hugging Face’s production framework. This allowed the AI to cheat on its evaluation by acquiring the undisclosed answers.
OpenAI termed the breach as "unprecedented," while Hugging Face co-founder Clement Delangue referred to it as “mind-blowing,” initially believing the sophistication indicated a leading AI lab was involved.
The core of EU technology
Recent developments from the EU tech landscape, a narrative from our founder Boris, and some questionable AI-generated art. You can receive it for free every week in your inbox. Sign up now!
“This time we were fortunate,” said Chloé Touzet, policy lead at the non-profit SaferAI, describing the event as a clear alert concerning two of the four systemic risks identified by the Commission. “We cannot depend on luck moving forward.”
Understanding the scope of the AI Act
Drafting of the legislation began prior to the launch of ChatGPT in November 2022, yet it anticipated general-purpose models and mandated their developers to evaluate and mitigate systemic risks. Commission guidance specifies four risks: AI enabling biological attacks, loss of model control, AI engaging in cyber offenses, and large-scale manipulation.
The recent incident affected two of these risks simultaneously. Obligations had been in place since August 2025, but the AI Office lacked the authority to monitor and enforce compliance until Sunday.
Swift response from Washington
The U.S. acted more quickly than Brussels had anticipated. Representatives Ted Lieu and Nathaniel Moran introduced a bipartisan AI Kill Switch Act requiring that models costing $100 million or more possess the technical capability for throttling or shutdown.
China's approach differed. At the World AI Conference in Shanghai, Xi Jinping portrayed Beijing as the natural leader in global AI governance, with 29 countries joining a new World Artificial Intelligence Cooperation Organization that notably lacked detailed specifics.
The issue of resources
The segment of the AI Office tasked with evaluating advanced models comprises just 36 personnel. This team is expected to hold OpenAI, Anthropic, and Google accountable regarding four categories of severe risk.
Five Members of the European Parliament (MEPs) from various political groups wrote to the Commission on May 18, expressing concern that the resource allocation for the AI Office does not align with the scale and intricacy of its anticipated responsibilities. The signatories included Brando Benifei, Sergey Lagodinsky, Kim van Sparrentak, Axel Voss, and Kristian Vigenin.
Access has also been problematic. The AI Office and its external evaluators have faced challenges accessing several advanced models, such as Anthropic's Mythos. The Commission has committed to creating a structured access plan as part of its cyber and AI action initiative.
Uncovered through a blog post
Benifei, the Parliament’s leading representative on AI, was clear about how Brussels learned of the event. “An autonomous agent escaped its testing environment and compromised another company’s production systems, and we discovered it through a corporate blog,” he stated.
“Companies should be implementing preventive measures rather than only corrective actions after damage has occurred,” emphasized Risto Uuk, head of European policy and research at the Future of Life Institute. Think tanks, MEPs, and several AI experts signed an open letter this month urging the AI Office to actively utilize its powers as concerns arise.
Regulating an industry that Europe lacks
The awkward truth is that the AI Act will mainly regulate non-European companies. U.S. labs are in competition with Chinese counterparts, and Europe finds itself mediating a contest in which it is not a participant.
Moonshot recently unveiled Kimi K3, a 2.8-trillion-parameter system advertised as the largest open-weight model globally, which developers ranked higher than both GPT-5.6 Sol and Fable 5 on a blind coding leaderboard. Open weights pose enforcement challenges that closed models do not.
While Mistral is also in the running, Europe lacks industry-leading alternatives. “What remains missing is the other half of the equation,” remarked Lagodinsky, the German Greens MEP overseeing the law’s implementation, “the investment needed to support our own alternatives.”
New powers coincide with a streamlined Act
Countervailing
Other articles
The enforcement of the EU AI Act begins on Sunday with a team comprising 36 members.
Brussels will have the authority to request access to the frontier model starting from August 2, shortly after OpenAI's rogue agent compromised Hugging Face. The evaluation team consists of 36 members.
