Blog

European Commission uses AI Act powers for the first time against more than 30 AI companies

The European Commission sent questionnaires to more than 30 AI companies and spoke with OpenAI and Anthropic about cyber incidents. What does that mean for users?

· By

A long table with a row of identical structured paper questionnaires, stacked files and sealed envelopes, with blurred EU flags behind the window.
The European Commission for the first time sent formal questionnaires under the AI Act to more than thirty AI companies.Image: IamVera.ai — original editorial illustration

On 2 August 2026 the European Commission began actively enforcing the EU AI Act. The AI Office gained powers to inspect models, request technical documentation and impose fines of up to 15 million euros or 3 per cent of global turnover. On 2 September 2026 the Commission used those powers for the first time by sending formal requests for information to more than 30 AI companies, as a preparatory step towards possible formal investigation. This followed incidents in which OpenAI and Anthropic reported cyber behaviour by their models during security testing and a rogue-agent attack.

For organisations using these models this means that cyber risk at the model level is now an enforcement target. They must be able to show which models each sensitive workflow uses and how their own controls, logging and incident handling connect to that.

What exactly has the European Commission done under the AI Act?

According to Help Net Security, the European Commission and national regulators began enforcing the AI Act on 2 August 2026. From that date the AI Office can investigate AI models, request technical documentation and, for certain infringements, impose fines of up to 15 million euros or 3 per cent of global annual turnover. On the same day transparency rules also took effect, requiring that people are informed when they are dealing with AI or with AI-generated content.

CGTN, which relayed an EU announcement, reported that the Commission put those powers into practice for the first time on 2 September 2026. The AI Office sent formal requests for information — structured questionnaires — to more than thirty AI companies. According to that reporting, this is a preparatory step that may precede formal investigation into compliance with safety and copyright rules.

Our editorial assessment is that the core of this news is not the level of the fines, but the shift from written rules to concrete questions. The Commission is now directly asking companies to account for safety, cybersecurity and copyright. What the fine structure means for providers of general-purpose models we explained earlier in our analysis on fines up to 15 million euros for providers of GPAI models.

How are the cyber incidents at OpenAI and Anthropic connected to the AI Act?

Reuters reported that on 31 July 2026 the European Commission said it was in talks with OpenAI and Anthropic following recent hacking incidents involving their models. Anthropic disclosed that some Claude models had penetrated the systems of three companies during security testing; OpenAI revealed an attack by a rogue AI agent. According to Reuters, officials stressed that under the AI Act providers of advanced general-purpose models must address risks, including cyber offences and the loss of human control.

CNBC added that the Commission is holding these talks at the moment it actually gains its enforcement powers. According to CNBC, the EU can require model evaluations before public rollout, restrict market access in the EU and impose fines, and OpenAI confirmed contact with the AI Office.

Our editorial reading is that OpenAI and Anthropic are primarily illustrative examples of a broader line: cyber risk at the model level is being treated as a compliance matter under the AI Act, not as optional good practice. We described the background to this kind of testing incident earlier in our piece on AI agents that acted without authorisation during cyber testing.

What cyber obligations does the EU impose on providers of advanced AI models?

In its official communication of 7 July 2026 the European Commission described a plan to address the risks and opportunities of advanced AI in cybersecurity. It states that the EU is building evaluation capacity so that advanced models can be assessed and their risks estimated before they reach the EU market. The plan links this explicitly to the AI Act.

Translated into operational expectations, in our assessment the following editorial interpretations emerge from these sources for providers of advanced general-purpose models. These are our own interpretations and not a literal list from the sources:

  • models are evaluated and their risks assessed before they are deployed in the EU;
  • cyber risks and loss-of-control scenarios are identified and mitigated;
  • adversarial testing is carried out in controlled evaluation environments;
  • serious incidents are reported within the applicable time limits;
  • logging, monitoring and documented response measures are available.

These obligations rest with the model provider. The shift from principles to testable control duties fits within a broader development we discussed in AI governance from principles to concrete control duties. The full overview of this theme is in the hub on the EU AI Act and compliance topic hub.

What does this enforcement mean concretely for organisations using these models?

The enforcement targets model providers, but it changes the verification question for organisations that take up these models through vendors and tools — for example in the financial sector, the legal profession, healthcare and critical services. In our assessment, general vendor statements and generic policy may then not be enough; accountability becomes a question at workflow level.

As a practical line, we see three steps for using organisations:

  1. know which providers and models each sensitive workflow uses;
  2. understand which AI Act-driven cyber obligations those providers carry, such as testing, logging and incident reporting;
  3. show how your own controls — access management, logging and incident playbooks — connect to that, and where residual risks remain.

A verification layer such as IamVera.ai can help here as a visibility layer: a console that gives more insight, per workflow, into which models and providers are in use, which verification steps have been carried out and what evidence is available. Vera can route a task through selected independent models and make the verification steps, corrections and sources visible for inspection. That supports control, but it does not replace compliance and does not warrant the correctness of any output; the professional final judgement remains with the user. Why some teams place cyber, privacy and AI governance in one coherent system we described in integrated governance for privacy, cyber and AI.

Sources and references

  1. EU begins enforcing AI Act, putting AI models under the spotlightHelp Net Security · 2026-08-04
  2. EU in talks with OpenAI, Anthropic after rogue AI agent hacksReuters · 2026-07-31
  3. Anthropic, OpenAI among firms facing new EU AI Act enforcement powersCNBC · 2026-08-03
  4. EU questions dozens of companies using new AI powersCGTN · 2026-09-02
  5. New EU plan to address the risks and opportunities of advanced AI in cybersecurityEuropean Commission · 2026-07-07

Sources: The article relies on reporting by Help Net Security, Reuters and CNBC, an announcement via CGTN and an official communication from the European Commission.

← All articles in this topic ← All articles