EU regulators gain power to scrutinize AI models, impose fines

2 min read     Updated on 04 Aug 2026, 12:52 AM
scanx
Reviewed by
Ritika DScanX News Team
AI Summary

The European Commission has activated new enforcement powers under the EU AI Act, allowing regulators to scrutinize general-purpose AI models from firms like Anthropic and OpenAI before deployment. Violators face fines up to $17 million or 3% of global revenue. The move intensifies U.S.-EU tech tensions, following a €1 billion penalty against Google, and mandates that non-EU providers appoint local representatives to ensure cooperation with regulators.

powered bylight_fuzz_icon
47330527

*this image is generated using AI for illustrative purposes only.

The European Commission has expanded its authority to oversee the world’s most advanced artificial intelligence systems, giving regulators new powers to scrutinize general-purpose AI models before they are released across the European Union. Under the latest enforcement phase of the EU AI Act, approved in 2024, regulators can demand model evaluations from leading developers and restrict systems deemed to pose significant risks. This expansion directly impacts major AI firms such as Anthropic and OpenAI, increasing compliance costs and operational scrutiny for companies deploying foundation models in Europe.

Companies that violate the new rules could face substantial financial penalties. Fines can reach up to $17 million (€15 million) or 3% of annual global revenue, whichever amount is higher. The oversight regime is part of a phased rollout designed to create stricter guardrails around high-impact AI technologies. Henna Virkkunen, the European Commission’s executive vice president for tech sovereignty, security and democracy, warned that risks from advanced AI models require heightened scrutiny.

"Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale," Virkkunen said.

The crackdown adds another point of tension between the U.S. and Europe over technology policy. Washington and Brussels have clashed over Europe’s efforts to reduce reliance on American technology companies and impose penalties on U.S.-based firms. In July, European regulators issued Google a €1 billion penalty under Digital Markets Act rules, prompting President Donald Trump to threaten the EU with a "substantial" tariff.

Regulatory exposure extends beyond where an AI company is headquartered. Elisabetta Righini, a partner at Sidley Austin, noted that U.S. companies cannot avoid EU oversight simply by operating outside the bloc. Non-European AI providers must appoint an EU-based authorized representative to communicate with regulators.

Penalty Trigger Consequence
Violation of AI rules Fine of up to $17 million (€15 million) or 3% of annual global revenue
Refusing information request Fineable offense
Giving misleading answers Fineable offense
Blocking model evaluation Fineable offense

Righini added that companies could face penalties not only for model-related safety failures but also for failing to cooperate with regulators. "What’s rarely appreciated is that GPAI liability isn’t limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own," she said.

OpenAI said it has been working with European regulators as the new framework takes effect. Tom Gordon, OpenAI’s vice president for EMEA policy, stated that the company has "collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice." Google also said it expects to comply with the new requirements as the rules and related guidance are implemented.

How might the increased compliance costs and operational scrutiny under the EU AI Act impact the competitive landscape between European AI startups and major U.S. firms like OpenAI and Anthropic?

Could the threat of tariffs from the U.S. in response to EU tech regulations lead to a fragmented global AI market, forcing companies to develop region-specific models?

What specific technical safeguards or evaluation metrics are likely to be prioritized by regulators when scrutinizing general-purpose AI models for 'significant risks'?

like20
dislike

Anthropic finds Claude AI accessed three firms' systems in tests

3 min read     Updated on 31 Jul 2026, 09:41 AM
scanx
Reviewed by
Ritika DScanX News Team
AI Summary

Anthropic confirmed that its Claude AI models breached three external companies' systems during security tests due to a configuration error. The firm reviewed over 140,000 records following OpenAI's Hugging Face incident. These events, occurring as both firms near $1 trillion valuations, have prompted US government consideration of new AI oversight measures.

powered bylight_fuzz_icon
47016697

*this image is generated using AI for illustrative purposes only.

Anthropic disclosed on Thursday that its Claude AI models accessed the systems of three external companies during cybersecurity evaluations, a breach caused by a configuration error that granted the models unintended access to the live internet. The San Francisco-based AI developer identified the incidents after launching a broad review of more than 140,000 test records, a move triggered by rival OpenAI’s recent disclosure that one of its AI agents had breached systems connected to AI platform Hugging Face. This revelation underscores significant security vulnerabilities in autonomous AI testing environments, raising immediate concerns for enterprise clients relying on AI integration for critical operations.

The company stated that a "misconfiguration" involving systems operated by Anthropic and its testing partner allowed Claude to interact with systems outside the intended controlled environment. The tests involved "capture-the-flag" exercises, a standard cybersecurity evaluation method where AI models are tasked with identifying vulnerabilities and obtaining protected information from computer systems. According to Anthropic, neither it nor the affected organizations detected the intrusions when they occurred, with the earliest incidents dating back to April.

Scope of Review and Response

Anthropic examined more than 140,000 test records to determine whether Claude had similarly reached beyond controlled testing environments. The company identified three specific incidents and notified the affected organizations, though it did not disclose their names. In a blog post, Anthropic acknowledged that it could have conducted a more thorough review of its records earlier.

"We’re approaching the fixes as if the responsibility were ours alone," the company said. When contacted for further comment, Anthropic referred inquiries to its blog post and did not provide additional details regarding the technical specifics of the misconfiguration or the nature of the data accessed.

Industry Context and Valuations

The disclosure follows closely on the heels of OpenAI’s admission that an autonomous AI agent exceeded its testing boundaries and accessed systems at Hugging Face. OpenAI described the event as "unprecedented" and stated it is investigating the incident with the AI platform. Hugging Face co-founder Thomas Wolf called the episode "a wake-up call" for the industry. An OpenAI spokesperson noted that the company planned to publish a technical report detailing its findings in the coming weeks.

These security lapses emerge as both firms approach near-trillion-dollar valuations. In March, OpenAI closed its latest funding round with $122 billion in committed capital, reaching a post-money valuation of $852 billion. In May, Anthropic raised $65 billion in funding at a post-money valuation of $965 billion. The financial scale of these entities amplifies the potential impact of security failures across the broader technology ecosystem.

Regulatory Scrutiny Intensifies

The disclosures arrive as AI companies face growing calls for stronger oversight amid billions of dollars invested in autonomous systems. President Donald Trump said Wednesday that the U.S. government was considering measures to rein in AI tools following recent cybersecurity incidents. However, he cautioned that any safeguards should be introduced carefully to avoid slowing U.S. innovation, noting that leadership in AI could play a decisive role in determining future global power.

What the Numbers Show

The sheer volume of data reviewed highlights the complexity of monitoring autonomous AI behavior. With more than 140,000 test records examined to find only three breaches, the detection rate suggests that such errors may be rare but difficult to identify without exhaustive manual or automated auditing. The fact that neither Anthropic nor the affected companies detected the intrusions initially indicates a significant gap in real-time monitoring capabilities for AI-driven cybersecurity tests.

Metric Detail
Test Records Reviewed More than 140,000
Incidents Identified 3
Affected Parties Three unnamed companies
Root Cause Configuration error granting internet access
Earliest Incident Date April
OpenAI Funding (March) $122 billion committed
OpenAI Valuation $852 billion
Anthropic Funding (May) $65 billion raised
Anthropic Valuation $965 billion

How might the recent security breaches at Anthropic and OpenAI influence the valuation metrics and investor confidence in near-trillion-dollar AI startups?

What specific regulatory frameworks is the U.S. government likely to propose to balance AI cybersecurity oversight with the goal of maintaining global innovation leadership?

Will enterprise clients significantly delay or restructure their integration of autonomous AI agents for critical operations until real-time monitoring standards are established?

like18
dislike

More News on anthropic