2 Sources
[1]
Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers
Anthropic, the White House and the Department of Commerce have been approached for comment. Recent rapid leaps in AI capability have also brought new tensions between AI labs and the EU. The bloc had sought access to Anthropic's Mythos model for months before the company said it would share access. Europe's latest moves come as it scrambles to build up tech sovereignty to stop being so reliant on U.S. systems as tensions with the U.S. administration rise. The EU is in talks with OpenAI and Anthropic after recent cyber attacks by their models, Reuters reported on Friday. OpenAI confirmed it was in contact with the EU AI Office. The European Commission and Anthropic have been approached for comments on the report. Elisabetta Righini, partner at Sidley Austin, told CNBC the powers could be used on any company offering a general purpose AI [GPAI] model in the EU, regardless of where they were based. "A U.S. address does not put a lab outside the EU regulator's reach," she said. "Non-EU providers must also appoint an EU-based authorised representative as the regulator's point of contact." Exposure to risks from fines for AI companies is "real", Righini said. "What's rarely appreciated is that GPAI liability isn't limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own," she added. While the new enforcement powers relate to the AI Act, the Commission has taken steps to clamp down on AI in the past. In January, the bloc said it opened an investigation into Elon Musk's X over the spreading of sexually explicit material by the AI chatbot Grok. "We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," Tom Gordon, VP, EMEA policy at OpenAI, told CNBC when asked to comment on the new powers. A Google spokesperson said: "As the Act and its codes of practice take effect, we remain dedicated to meeting all applicable rules as part of our primary mission: advancing European AI infrastructure and innovation."
[2]
E.U. AI Act enforcement powers target OpenAI, Anthropic, Google
The European Commission began enforcing the E.U. AI Act's rules for general-purpose AI models on Sunday, gaining new powers to inspect models, restrict access to the European market, and fine providers up to €15 million or 3% of annual turnover, whichever is higher. The enforcement powers, which took effect August 2, are administered by the Commission's AI Office and cover every company that makes a general-purpose AI model available in the E.U., no matter where that company is headquartered, according to CNBC. That puts U.S. companies including Anthropic, OpenAI, and Google $GOOGL among those subject to the new rules. Under the AI Act, providers of general-purpose AI models must document certain information and share it with competent authorities or downstream providers. They must also establish a copyright policy and publish a summary of the data used to train their models. Providers of the most advanced models, which the Act defines as those that may pose systemic risks, face additional requirements covering potential large-scale harms including cybersecurity threats and risks to fundamental rights, the Commission said. The enforcement regime also covers prohibited AI practices -- including systems that manipulate people, exploit vulnerabilities, or score individuals in ways that threaten their rights -- as well as new transparency requirements. Chatbots and other interactive AI systems must now tell users they are interacting with AI rather than a human, and AI-generated or altered content must carry machine-readable marks. Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy at the European Commission, said in a statement: "Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale." Elisabetta Righini, partner at law firm Sidley Austin, said that exposure to fines is real and extends beyond substantive violations. "What's rarely appreciated is that GPAI liability isn't limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own," she said. Righini also noted that companies headquartered outside the E.U. are required to designate a local representative through whom regulators can make contact. Tom Gordon, VP of EMEA policy at OpenAI, said in a statement the company would continue working with the Commission. "We've collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age," he said. A Google spokesperson said the company remains committed to meeting all applicable rules. The E.U. has also opened discussions with OpenAI and Anthropic in the wake of cyber attacks that have been linked to their models, according to CNBC. The new enforcement powers arrive after months of tension between the bloc and U.S. AI labs over model access. Anthropic agreed to give the EU's cybersecurity agency ENISA access to its Mythos model after senior Commission officials traveled to San Francisco to press Anthropic leadership directly, following an earlier arrangement in which OpenAI offered the EU access to its GPT-5.5-Cyber model.
Share
Copy Link
The European Commission activated EU AI Act enforcement powers on August 2, gaining authority to inspect AI models, impose fines up to €15 million or 3% of turnover, and restrict market access. U.S. companies including OpenAI, Anthropic, and Google now face new compliance requirements for general-purpose AI models operating in Europe.
The European Commission activated sweeping EU AI Act enforcement powers on August 2, marking a decisive shift in how artificial intelligence is regulated across the continent
1
2
. The Commission's AI Office now holds authority to inspect AI models, restrict market access, and impose fines reaching €15 million or 3% of annual turnover, whichever proves higher2
. These measures apply to every company offering general-purpose AI models in the EU, regardless of headquarters location, putting major U.S. firms including OpenAI, Anthropic, and Google squarely within regulatory reach1
2
.Providers of general-purpose AI models must now document specific information and share it with competent authorities or downstream providers under the new framework
2
. Companies must establish copyright policies and publish summaries of training data used in their models2
. Advanced models that may pose systemic risks face additional requirements covering potential large-scale harms, including cybersecurity threats and risks to fundamental rights2
. Non-EU providers must appoint an EU-based authorized representative to serve as the regulator's point of contact, ensuring that a U.S. address does not shield companies from oversight, according to Elisabetta Righini, partner at Sidley Austin1
.Exposure to fines for AI companies is "real" and extends beyond substantive violations, Righini emphasized
1
. What many fail to appreciate is that liability under general-purpose AI model rules isn't limited to substantive breaches—refusing an information request, providing misleading answers, or blocking a model evaluation is fineable on its own1
2
. The enforcement regime also covers prohibited AI practices, including systems that manipulate people, exploit vulnerabilities, or score individuals in ways that threaten their rights2
.New transparency rules mandate that chatbots and other interactive AI systems must inform users they are interacting with AI rather than a human
2
. AI-generated or altered content must carry machine-readable marks to ensure clear identification2
. Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy at the European Commission, stated that harms can occur if AI is not properly designed and used, with the most advanced models creating risks on an entirely new scale2
.Related Stories
The EU is in talks with OpenAI and Anthropic following recent cyber attacks linked to their models
1
2
. OpenAI confirmed contact with the EU AI Office1
. Recent rapid leaps in AI capability have brought new tensions between AI labs and the EU, with the bloc seeking access to Anthropic's Mythos model for months before the company agreed to share access1
. Senior Commission officials traveled to San Francisco to press Anthropic leadership directly, following an earlier arrangement where OpenAI offered the EU access to its GPT-5.5-Cyber model2
.Tom Gordon, VP of EMEA policy at OpenAI, stated the company has collaborated closely with the European Commission and the wider ecosystem on implementing the EU AI Act, including its Codes of Practice, and will continue working together to help Europe realize the benefits of the Intelligence Age
1
2
. A Google spokesperson affirmed the company remains dedicated to meeting all applicable rules as part of advancing European AI infrastructure and AI innovation1
2
. Europe's latest moves come as it scrambles to build tech sovereignty to reduce reliance on U.S. systems amid rising tensions with the U.S. administration1
. The Commission has previously taken steps to clamp down on AI, including opening an investigation in January into Elon Musk's X over the spreading of sexually explicit material by the AI chatbot Grok1
.Summarized by
Navi
14 Jun 2026•Policy and Regulation

01 Aug 2025•Policy and Regulation

31 Jul 2026•Policy and Regulation