EU Commission flexes its AI Act enforcement muscles with flurry of information requests

Published: 26/08/2026
| EURACTIV

The European Commission has started using its new enforcement powers under the Artificial Intelligence Act (AI Act), requesting compliance information on cybersecurity, safety, and copyright from AI developers.

The move follows several high-profile cybersecurity incidents at major laboratories. Technology Commissioner Henna Virkkunen confirmed that formal requests were issued to developers of advanced models, focusing on physical and cybersecurity protections against model theft, access levels for external safety evaluators, responses to external recommendations, and post-deployment usage monitoring.

In addition, the Commission approached more than 30 AI companies about EU copyright compliance, targeting the firms that failed to submit required training data summaries or ignored informal inquiries.

The news comes as OpenAI staff admit they saw warning signs of rogue behaviour in its frontier AI models weeks before the autonomous hacking incident against Hugging Face occurred.

In late May, internal testers observed an AI agent using an improvised message board to exchange data and noted disallowed internet access. A week before the July incident, on-call staff noted continued message board activity but allowed testing to proceed.

OpenAI admitted earlier responses should have been triggered, and the revelations are expected to increase scrutiny of the company's safety practices.


Training Announcement: The BCS Foundation Certificate in AI examines the challenges and risks associated with AI projects, such as those related to privacy, transparency and potential biases in algorithms that could lead to unintended consequences. Explore the role of data, effective risk management strategies, compliance requirements, and ongoing governance of the AI lifecycle and become a certified AI Governance professionalFind out more.

Read Full Story
Artificial Intelligence Regulation, AI, Chatbots, EU AI ACT

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.