EU says its AI Act can handle rogue AI risks

Flag of Europe (Wikimedia Commons, public domain)

EU says its AI Act can handle rogue AI risks

Tech chief Henna Virkkunen argues the bloc's rulebook already covers autonomous AI threats, even as key obligations slip to 2027 and 2028

The European Union thinks it has already written the rulebook for AI that goes off script. On October 9, 2026, EU Executive Vice-President Henna Virkkunen said the bloc’s AI Act offers robust protection against rogue AI risks.

Her argument rests on scope. The regulation covers AI models across their entire life cycle, not just at launch.

What the EU is actually claiming

Virkkunen’s case leans heavily on ongoing oversight. Under the AI Act, a scientific panel of 60 experts is tasked with continuously monitoring and evaluating AI models.

Concern has grown following recent leaks from firms like OpenAI and Anthropic, which showcased instances of AI systems bypassing controls.

The Act explicitly names the systemic risks it is watching. These include loss of control, cyber offense capabilities, and manipulation at large scale.

It also draws a line based on raw computing power. General-purpose AI models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk. Put plainly, the biggest models are treated as dangerous until their makers show otherwise.

Advertisement

Virkkunen also stressed that the law was built to adapt. According to her, it can stay relevant to emerging technologies without requiring immediate legislative changes.

Teeth, timelines, and a few delays

Enforcement sits with the European Commission’s AI Office. The office has been empowered to investigate AI models more decisively, including the authority to fine companies that fail to comply.

Those fines are not rounding errors. Penalties can reach up to €35 million or 7% of global turnover.

The office has already started knocking on doors. As of August 2026, it had sent requests to more than 30 AI providers seeking information on their safety and security practices, including transparency protocols.

Bans on certain AI practices have been in force since February 2025, and transparency obligations for AI providers kicked in during August 2026.

The heaviest obligations, though, are still on the horizon. Requirements for high-risk AI systems were pushed back by the 2026 Digital Omnibus regulation.

Standalone high-risk systems now face a December 2027 deadline. High-risk systems embedded in other products have until August 2028.

How we got here

The AI Act was introduced in 2024 and built around a risk-based framework. Rather than regulating all AI the same way, it sorts systems by how much harm they could plausibly cause.

Low-risk uses face lighter requirements, while the most dangerous practices are banned outright. High-risk systems and powerful general-purpose models sit in the middle, carrying the heaviest compliance load.

What this means for AI developers and investors

For companies building frontier models, the message is that the EU sees no need to wait for new laws before acting. The AI Office already has investigative powers, a compute threshold that captures the largest systems, and a long list of information requests outstanding.

Firms facing potential penalties of up to 7% of global turnover may be pushed to devote significant resources to compliance, which could reshape how AI products are developed and deployed in the region.

The other thing to watch is what the AI Office does with the answers from those 30-plus providers. Information requests are a starting point. Whether they lead to formal investigations or fines will show whether the Act’s teeth are as sharp as Brussels says.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
EU says its AI Act can handle rogue AI risks
EU says its AI Act can handle rogue AI risks

Tech chief Henna Virkkunen argues the bloc's rulebook already covers autonomous AI threats, even as key obligations slip to 2027 and 2028

Flag of Europe (Wikimedia Commons, public domain)

The European Union thinks it has already written the rulebook for AI that goes off script. On October 9, 2026, EU Executive Vice-President Henna Virkkunen said the bloc’s AI Act offers robust protection against rogue AI risks.

Her argument rests on scope. The regulation covers AI models across their entire life cycle, not just at launch.

What the EU is actually claiming

Virkkunen’s case leans heavily on ongoing oversight. Under the AI Act, a scientific panel of 60 experts is tasked with continuously monitoring and evaluating AI models.

Concern has grown following recent leaks from firms like OpenAI and Anthropic, which showcased instances of AI systems bypassing controls.

The Act explicitly names the systemic risks it is watching. These include loss of control, cyber offense capabilities, and manipulation at large scale.

It also draws a line based on raw computing power. General-purpose AI models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk. Put plainly, the biggest models are treated as dangerous until their makers show otherwise.

Advertisement

Virkkunen also stressed that the law was built to adapt. According to her, it can stay relevant to emerging technologies without requiring immediate legislative changes.

Teeth, timelines, and a few delays

Enforcement sits with the European Commission’s AI Office. The office has been empowered to investigate AI models more decisively, including the authority to fine companies that fail to comply.

Those fines are not rounding errors. Penalties can reach up to €35 million or 7% of global turnover.

The office has already started knocking on doors. As of August 2026, it had sent requests to more than 30 AI providers seeking information on their safety and security practices, including transparency protocols.

Bans on certain AI practices have been in force since February 2025, and transparency obligations for AI providers kicked in during August 2026.

The heaviest obligations, though, are still on the horizon. Requirements for high-risk AI systems were pushed back by the 2026 Digital Omnibus regulation.

Standalone high-risk systems now face a December 2027 deadline. High-risk systems embedded in other products have until August 2028.

How we got here

The AI Act was introduced in 2024 and built around a risk-based framework. Rather than regulating all AI the same way, it sorts systems by how much harm they could plausibly cause.

Low-risk uses face lighter requirements, while the most dangerous practices are banned outright. High-risk systems and powerful general-purpose models sit in the middle, carrying the heaviest compliance load.

What this means for AI developers and investors

For companies building frontier models, the message is that the EU sees no need to wait for new laws before acting. The AI Office already has investigative powers, a compute threshold that captures the largest systems, and a long list of information requests outstanding.

Firms facing potential penalties of up to 7% of global turnover may be pushed to devote significant resources to compliance, which could reshape how AI products are developed and deployed in the region.

The other thing to watch is what the AI Office does with the answers from those 30-plus providers. Information requests are a starting point. Whether they lead to formal investigations or fines will show whether the Act’s teeth are as sharp as Brussels says.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.