Europe still needs to do more to provide real artificial intelligence reassurance
Artificial intelligence CEOs seem to have concluded that there is a risk of loss of control over their models. Anthropic’s chief executive Dario Amodei has called for an industry slowdown; some of his peers agree. For the European Union, this may offer some vindication of its legislative approach. EU law already obliges frontier AI companies to assess loss-of-control risks. The implication is that the EU has protection in place and cannot be surprised.
That confidence is misplaced. The AI Act (Regulation (EU) 2024/1689) contains binding rules that are progressively entering into force. But they are insufficient for all AI risks, and close to impossible to enforce with the EU’s current means.
Most recently, the European Commission gained powers to investigate general-purpose AI providers, order corrective measures and fine providers up to 3% of worldwide revenues if they fail to tackle systemic risks. Most other rules, covering AI applications, are still to take effect and are mostly for national authorities to enforce. From 2 December 2027, national authorities will start to supervise standalone high-risk applications, such as algorithms that screen job candidates. From 2 August 2028, this responsibility will extend to AI embedded in regulated products, such as software designed to examine MRI scans for tumours.
Whether or not one believes rogue agents could seize the internet within a year, AI is already changing people’s lives: how they are hired, whether they get credit, how they are informed, whether they can believe what they see.
The AI Act was built as a product-safety law. If the standards are met, a product can be marketed. But AI is not a traditional product for which the risks can be assessed and managed. AI operates in dynamic environments that are not fully predictable; AI can take actions that are not necessarily pre-coded.
For example, in May 2026, OpenAI’s agents ran a dormant German wiki for two months, which might sound trivial, but nobody outside OpenAI knew, until researchers found it in September. In July, AI agents breached the Hugging Face AI community platform. The United Kingdom’s AI Security Institute watched its test agents invent fake identities to get malicious code approved.
No product conformity check would have caught these incidents. In any case, none of these AI agents are designated high-risk, so can be deployed free of AI Act safety obligations. Rules apply upstream on the providers of the models agents run on, and compliance is demonstrated through a voluntary code. The EU requires providers to assess the risk of loss of control over a model but does not require providers to report it, unless it causes serious harm.
For most high-risk applications, to which AI Act rules apply directly, compliance relies on companies assessing themselves against standards written by industry bodies. So far, none of these standards have been published in the EU Official Journal, so companies cannot yet plan for what they must demonstrate when the rules apply from December 2027.
It is also unclear who would spot breaches. The EU AI Office, which since August 2026 supervises frontier models and has investigative and fining powers, is still building up. With a current staff of about 145, it is far smaller than the Commission’s competition enforcement arm, which employs nearly 900. Meanwhile, at sub-EU level, more than 2,000 market surveillance authorities, built for traditional products, must police AI applications that even their developers do not fully understand.
This framework was built to learn-by-doing but the AI Act relies on pre-deployment checks by companies, verified by under-resourced authorities. It should be reinforced by improving supervision and post-deployment reporting. For example, the AI Office could routinely spot-check providers’ evidence on a risk basis.
Most importantly, the EU needs a liability regime to help manage risk emerging downstream, and under which those harmed by AI can claim compensation. The Commission proposed an AI Liability Directive but withdrew it in October 2025 to cut red tape. What remains is the Product Liability Directive (Directive (EU) 2024/2853), which from 9 December 2026 will cover death, injury, property and lost data caused by any product, including AI. It will, however, not tackle the harms AI may cause most often: a job denied (for example, women downgraded by a recruitment algorithm because of gender) or credit refused. For these, victims must show in national courts that something went wrong inside an opaque AI application.
AI developers who do not fear liability costs have little reason to invest in avoiding such harms. Europe should neither downplay the importance of rules nor be complacent about the security its framework provides. A harmonised EU AI liability regime, combined with more ex-post supervision, would fill gaps and cut legal uncertainty.
Related Stories
AI News
Technologies, Math Research Get Lift from CAREER Awards
18 minutes ago
AI News
Novo partners with Anthropic to speed up drug development with Claude
48 minutes ago
AI News
Quebec artificial intelligence institute vandalized by multiple people
48 minutes ago
AI News
'Defeated' GPT-6 Astra model spent several hours just farming potatoes after being blown up by a Creeper in Minecraft — OpenAI offering gets further than any other AI system in 141
1 hour ago
AI News
Anthropic and Microsoft Researchers Weigh Limits of Artificial Intelligence at Berkman Klein Panel
1 hour ago
China's open-weight AI models are now just 4 months behind frontier US offerings, Mozilla report claims
2 hours ago
AI News
Survey: Americans Concerned About AI’s Effect on Human Connection and Thinking
2 hours ago
AI News
Berlin-based Integral raises €18 million to deliver AI-run accounting, tax and payroll services to SMEs
3 hours ago