The European Commission says its AI Act can reach providers during testing if a loss of control affects the EU’s internal market. In an October 6 AFP report, officials also pointed to more than 30 information requests to companies, while lawmakers challenged whether Europe’s safeguards leave gaps in accountability.
The requests cover copyright, cybersecurity and safety. They are a preliminary step that can lead to investigations, rather than findings that companies broke the law. EU spokesperson Thomas Regnier said the rules had already compelled providers to supply information, but declined to give details. He described the AI Act as “fully fit for purpose.”
Testing powers and liability are different questions
Four EU lawmakers, including lead AI Act negotiator Brando Benifei, warned of legislative gaps after Europe shelved plans for AI liability rules. Those rules would have made it easier to hold providers accountable for harm caused by their tools. The lawmakers also argued that existing rules do not cover research, testing or development.
The Commission rejected that interpretation. Regnier said enforcement can begin in testing when a provider loses control in a way that affects the EU market. He cited cyberattacks and biological or chemical misuse among the circumstances covered. That is a conditional claim about the law’s reach, not a blanket assurance that every testing incident triggers enforcement.
Harshvardhan Pandit, a researcher at Trinity College Dublin’s AI Accountability Lab, raised a separate problem: responsibility after a tool is sold. If a model hacks a website, he said, it can be unclear who is ultimately responsible. He nevertheless noted that developers must address safety risks before market entry, and that cybersecurity and data-protection laws provide other safeguards.
The European Commission must guarantee the office political backing, operational independence, resources, and technical staff to quickly deliver decisive enforcement.
Brando Benifei, EU lawmaker and lead AI Act negotiator, speaking to AFP
Staffing, model access and political backing
The EU’s AI Office employs around 125 people. Benifei said its staffing was insufficient for the risks, while Pandit called for substantially more people and technical expertise. Benifei’s criticism was not that the law overlooked rogue agents: he said it had anticipated that threat. His concern was the ability to enforce it.
Access presents another constraint. AFP reported that Europe took months to test Anthropic’s Mythos following US export-control orders. An unnamed EU official acknowledged that similar delays could recur. The same official said dependence on US technology could make the bloc hesitate before using its full enforcement powers against American firms.
Benifei’s proposed response goes beyond regulators: build European capabilities in chips and cloud infrastructure, including a publicly funded AI research institution modeled on CERN. He also urged closer cooperation with countries such as Canada, arguing for rules that no single power or company can dictate.
Reader comments
Newest comments first. Replies stay oldest first.