cd /news/ai-policy/eu-says-its-ai-act-can-handle-rogue-… · home › topics › ai-policy › article
[ARTICLE · art-148541] src=cryptobriefing.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

EU says its AI Act can handle rogue AI risks

EU Executive Vice-President Henna Virkkunen said on October 9, 2026 that the bloc's AI Act already provides robust protection against rogue AI risks, citing a 60-expert scientific panel and a compute threshold of 10^25 FLOPs above which general-purpose models are presumed to pose systemic risk. Enforcement sits with the European Commission's AI Office, which can fine non-compliant companies up to €35 million or 7% of global turnover and had sent information requests to more than 30 AI providers as of August 2026. High-risk AI system obligations were delayed by the 2026 Digital Omnibus regulation to December 2027 for standalone systems and August 2028 for systems embedded in other products.

by read3 min views1 publishedOct 9, 2026
EU says its AI Act can handle rogue AI risks
Image: Cryptobriefing (auto-discovered)

Flag of Europe (Wikimedia Commons, public domain)

Tech chief Henna Virkkunen argues the bloc's rulebook already covers autonomous AI threats, even as key obligations slip to 2027 and 2028

The European Union thinks it has already written the rulebook for AI that goes off script. On October 9, 2026, EU Executive Vice-President Henna Virkkunen said the bloc’s AI Act offers robust protection against rogue AI risks.

Her argument rests on scope. The regulation covers AI models across their entire life cycle, not just at launch.

What the EU is actually claiming #

Virkkunen’s case leans heavily on ongoing oversight. Under the AI Act, a scientific panel of 60 experts is tasked with continuously monitoring and evaluating AI models.

Concern has grown following recent leaks from firms like OpenAI and Anthropic, which showcased instances of AI systems bypassing controls.

The Act explicitly names the systemic risks it is watching. These include loss of control, cyber offense capabilities, and manipulation at large scale.

It also draws a line based on raw computing power. General-purpose AI models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk. Put plainly, the biggest models are treated as dangerous until their makers show otherwise.

Virkkunen also stressed that the law was built to adapt. According to her, it can stay relevant to emerging technologies without requiring immediate legislative changes.

Teeth, timelines, and a few delays #

Enforcement sits with the European Commission’s AI Office. The office has been empowered to investigate AI models more decisively, including the authority to fine companies that fail to comply.

AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

Those fines are not rounding errors. Penalties can reach up to €35 million or 7% of global turnover.

The office has already started knocking on doors. As of August 2026, it had sent requests to more than 30 AI providers seeking information on their safety and security practices, including transparency protocols.

Bans on certain AI practices have been in force since February 2025, and transparency obligations for AI providers kicked in during August 2026.

The heaviest obligations, though, are still on the horizon. Requirements for high-risk AI systems were pushed back by the 2026 Digital Omnibus regulation.

Standalone high-risk systems now face a December 2027 deadline. High-risk systems embedded in other products have until August 2028.

How we got here #

The AI Act was introduced in 2024 and built around a risk-based framework. Rather than regulating all AI the same way, it sorts systems by how much harm they could plausibly cause.

Low-risk uses face lighter requirements, while the most dangerous practices are banned outright. High-risk systems and powerful general-purpose models sit in the middle, carrying the heaviest compliance load.

What this means for AI developers and investors #

For companies building frontier models, the message is that the EU sees no need to wait for new laws before acting. The AI Office already has investigative powers, a compute threshold that captures the largest systems, and a long list of information requests outstanding. Firms facing potential penalties of up to 7% of global turnover may be pushed to devote significant resources to compliance, which could reshape how AI products are developed and deployed in the region.

The other thing to watch is what the AI Office does with the answers from those 30-plus providers. Information requests are a starting point. Whether they lead to formal investigations or fines will show whether the Act’s teeth are as sharp as Brussels says.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-policy 4 stories · sorted by recency
── more on @european union 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/eu-says-its-ai-act-c…] indexed:0 read:3min 2026-10-09 · —