Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

The Eu Ai Act Newsletter #110: Powers In Practice

Card image cap

Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.

Legislative Process

EU orders leading AI labs to detail security practices: Maximilian Henning from Euractiv reports that the European Commission has made first use of its new AI Act enforcement powers, requesting information from leading developers on cybersecurity, safety and copyright compliance. This follows a string of high-profile cybersecurity incidents at several leading AI labs just weeks ago. Tech Commissioner Henna Virkkunen told Euractiv that some providers of the “most advanced” models had received requests, without naming them, adding that others were left out because the Commission has “already had very close dialogue” with them. Anthropic, OpenAI, Google, Meta and Mistral did not immediately respond to Euractiv questions. According to Virkkunen, the Commission wants to know how labs prevent humans or AI from stealing their models, how much access they give external evaluators, and how usage is monitored once a model is public. Separately, more than 30 companies that had not published a training-data summary were asked about copyright compliance. Unanswered requests may be escalated, with fines of up to 3% of annual turnover as a last resort.

Analyses

AI labs’ internal models ‘might’ fall under EU safety rules: Also writing in Euractiv, Maximilian Henning describes that the European Commission has not ruled out applying the AI Act to unreleased models that developers use only internally, with a spokesperson saying they “might” fall within scope. The question is pressing after a series of safety incidents at leading labs, the first of which saw several OpenAI models hack into Hugging Face. OpenAI said the attack was “primarily driven” by an “internal-only research model” never meant for public release and since deactivated. Legally, the issue turns on the Act’s reference to “placing on the market”, which might appear to exclude internal models. Yet an edge-case rule brings a model into scope where its developer integrates it into an AI system put into service in Europe, and that can happen within the same company. On the spokesperson’s account, not every market placement requires broad public release, and where internal use does constitute placement, the rules apply normally, from the start of training until retirement.

Is the EU AI Act equipped for a crisis? Eliška Andrš, Policy Researcher at the Future of Life Institute, asks how prepared the Commission is to use the enforcement powers it gained on 2 August. In late August, the Commission confirmed that the AI Office had sent general-purpose AI providers requests for information on model security, external evaluations and post-market monitoring, which followed AI agents autonomously hacking a private company and came amid a steady rhythm of new releases. Should a model pose an unacceptable risk of aiding bioweapons development or cyberattacks, the AI Office, helped by the Scientific Panel, would be responsible for detecting the unmitigated systemic risk, after which the Commission could request information, conduct evaluations or demand mitigation, and ultimately restrict the model or fine the provider. The July 2026 implementing regulation on Articles 92 and 101 also allows interim measures where serious damage to health, safety or other public interests is at risk. Even so, Andrš argues, a well-resourced evaluator ecosystem is a necessity.

ChatGPT becomes first AI chatbot to face tougher EU rules: France24 notes that the European Commission has added ChatGPT to the list of digital services subject to greater legal scrutiny under the Digital Services Act, a first for an AI chatbot, having qualified it as a search engine to bring it within the law’s remit. Brussels also designated Reddit and Roblox as “very large” online platforms, a label applying to services with more than 45 million monthly active users in the EU. All three have four months to meet additional obligations, including assessing and mitigating risks from illegal content, negative effects on minors, users’ well-being, fundamental rights, electoral processes and public security. Lena-Maria Boswald of the think tank Interface said beforehand that the designation would set a precedent for every large generative AI system used in the EU, since the DSA could widen the scope of OpenAI’s existing AI Act obligations.

Can the EU’s AI Act rein in artificial intelligence? Dren Gërguri, Assistant Professor at the Department of Journalism, University of Prishtina, argues in Sbunker that regulation is not the enemy of innovation, even though the law might slow it down, because although rules create costs for companies, especially small businesses and start-ups, a technology without rules is not a viable alternative. He notes that AI raises legal, ethical and academic integrity dilemmas alongside its benefits, and he holds up the EU AI Act as a comprehensive model the rest of the world should follow. Gërguri therefore urges Kosovo, despite not being an EU member, to harmonise its framework with the Act as soon as possible. He closes on accountability, asking who answers when an algorithm discriminates in hiring or a fake election video circulates. The answer cannot be “the algorithm”, but responsibility must remain with those who develop, deploy or rely on the technology.

What standards do to ideas: The European Observatory on AI Standards examines how the AI Act’s essential requirements become things a person can check, arguing that this conversion is where the substance is decided and that the public enquiry is the only window through which outsiders can watch. As a rule, the EU legislates results rather than technical content, leaving technical solutions to a private standards body. A manufacturer following a harmonised standard, once its reference is cited in the Official Journal, is presumed to conform, whereas one who does not may still comply by other means, though with a heavier burden of proof and no safe harbour. The AI Act inherits this architecture, setting seven essential requirements for high-risk systems in Chapter III, Section 2. The standards are being drafted by CEN/CENELEC JTC 21 under a standardisation request from the European Commission.


We’ve built the most comprehensive website on the EU AI Act to help answer all your questions. Here are a few of our most popular resources used by 60,000+ professionals every week:

AI Act Explorer: Explore the official AI Act text on any device, in any EU language, with helpful cross-links, added context, and more.

Compliance Checker: In just 10 minutes, figure out exactly what your business or organisation must do to comply with the AI Act.

High-level Summary: A short overview of the AI Act, with a breakdown on risk categorisation, obligations, prohibited systems, and timelines.

Small Businesses’ Guide: Everything you need to know, for small and medium-sized enterprises (SMEs) in the EU and beyond.