EU AI Act Ready for Rogue AI Threats
UpGateNeutralRegulation & policy

EU AI Act Ready for Rogue AI Threats

Reading time: 4 min

EU Confident AI Act Offers Robust Defense Against Rogue Systems

The European Union believes it has established comprehensive regulations to govern artificial intelligence, particularly concerning potential “rogue” AI scenarios. EU Executive Vice-President Henna Virkkunen stated on October 9, 2026, that the bloc’s AI Act provides robust protection against such risks.

Broad Scope and Continuous Oversight

Virkkunen’s argument hinges on the extensive scope of the regulation, which covers AI models throughout their entire lifecycle, not solely at the point of their initial release. A key component of the AI Act is its emphasis on ongoing oversight. Under the legislation, a scientific panel comprising 60 experts is mandated to continuously monitor and evaluate AI models.

This focus on oversight comes amid growing concerns, amplified by recent leaks from companies like OpenAI and Anthropic, which revealed instances of AI systems circumventing established controls.

Identifying and Mitigating Systemic Risks

The AI Act explicitly identifies systemic risks it aims to address. These include the potential for loss of control over AI systems, the development of advanced cyber offense capabilities, and large-scale manipulation.

A significant threshold is also established based on computational power. General-purpose AI models trained using more than 10^25 FLOPs of compute are presumed to pose a systemic risk. In essence, the largest and most powerful AI models are considered potentially dangerous until their developers can demonstrate otherwise.

Adaptability and Enforcement Mechanisms

Virkkunen also highlighted the law’s built-in adaptability, asserting that it is designed to remain relevant to emerging technologies without necessitating immediate legislative amendments.

Enforcement of the AI Act falls under the purview of the European Commission’s AI Office. This office has been granted significant authority to investigate AI models, including the power to impose fines on non-compliant companies.

Substantial Penalties and Proactive Investigations

The penalties for non-compliance are substantial, with fines potentially reaching up to €35 million or 7% of a company’s global turnover. The AI Office has already begun its work, having sent requests for information on safety, security, and transparency practices to over 30 AI providers as of August 2026.

Certain AI practices have been subject to bans since February 2025, and transparency obligations for AI providers took effect in August 2026.

Phased Implementation of High-Risk Obligations

However, the most stringent obligations are still being rolled out. Requirements for high-risk AI systems were deferred by the 2026 Digital Omnibus regulation. Standalone high-risk systems now have a deadline of December 2027, while high-risk systems integrated into other products must comply by August 2028.

Risk-Based Framework and Compliance Burden

The AI Act, introduced in 2024, operates on a risk-based framework. Instead of applying uniform regulations to all AI, it categorizes systems according to their potential for harm. Low-risk applications face lighter requirements, while the most dangerous practices are outright banned. High-risk systems and powerful general-purpose models fall into a middle category, carrying the heaviest compliance burden.

For companies developing cutting-edge AI models, the EU’s message is clear: there is no need to wait for new legislation before taking action. The AI Office possesses investigative powers, a computational threshold that captures the largest systems, and a substantial list of outstanding information requests.

The prospect of penalties equivalent to up to 7% of global turnover may compel companies to allocate significant resources to compliance, potentially reshaping the development and deployment of AI products within the region.

The effectiveness of the AI Act will ultimately be judged by the actions taken by the AI Office based on the information gathered from these providers. Whether these initial information requests lead to formal investigations or substantial fines will determine if the Act’s enforcement capabilities are as formidable as Brussels claims.

Tags:UpGateNeutralRegulation & policy
Copied