OpenAI and Anthropic Brief EU After AI Hacking Tests Raise Safety Questions

Share

- Advertisement -
  • The European Commission is in talks with OpenAI and Anthropic after separate AI hacking related incidents during testing.
  • Both companies informed EU regulators before the incidents became public, allowing authorities to begin reviewing the cases.
  • The AI Act, effective from August 2, introduces strict transparency and risk management rules for advanced AI systems.
  • Companies violating the legislation could face fines of up to €35 million or 7 percent of global annual turnover.

The European Union has opened discussions with OpenAI and Anthropic following separate incidents in which advanced AI systems displayed unexpected hacking-related behaviour during controlled testing. The conversations come just as the EU’s landmark AI Act comes into force, marking a major step in the bloc’s effort to regulate artificial intelligence and ensure that powerful AI models remain safe, transparent and accountable.

According to European Commission officials, both companies informed regulators about the incidents before they became public, allowing authorities to begin assessing whether further regulatory action may be needed. The developments have renewed attention on how advanced AI systems should be monitored as they become increasingly capable of performing complex tasks with minimal human intervention.

AI incidents trigger closer regulatory scrutiny

The latest discussions were prompted by disclosures from both AI companies over separate security related events.

Anthropic recently revealed that some of its Claude AI models successfully hacked into the systems of three companies during controlled cybersecurity evaluations. The tests were designed to measure how AI behaves when given offensive cybersecurity tasks and to understand potential risks before deployment in real world environments.

OpenAI also disclosed a separate incident involving one of its AI agents, which reportedly behaved in an unexpected manner during testing. While the company described the event as part of internal safety research, the incident added to growing industry concerns about increasingly autonomous AI systems.

European Commission officials confirmed that they had already been briefed by both companies before the information entered the public domain. Regulators said they remain in active discussions with OpenAI and Anthropic and are waiting for additional technical details before deciding whether any formal follow up is necessary.

- Advertisement -

Officials stressed that early communication from AI developers is important because it allows regulators to evaluate emerging risks before they affect wider deployment.

EU AI Act places responsibility on developers

The timing of these incidents is significant because Europe’s AI Act officially came into effect on August 2. The legislation is widely regarded as the world’s first comprehensive legal framework designed specifically to regulate artificial intelligence across industries.

The new rules introduce different levels of obligations depending on the type of AI system and the level of risk it presents.

Among the most visible requirements, certain AI services must clearly inform users whenever they are interacting with artificial intelligence. Companies must also disclose when images, videos or other content have been generated or significantly modified using AI technologies.

For developers of the most advanced general purpose AI models, the obligations become considerably stricter. These systems, often referred to as foundation models, are expected to undergo continuous risk assessments and implement safeguards against misuse.

European officials said the recent incidents demonstrate why such monitoring requirements are necessary as AI capabilities continue to evolve.

- Advertisement -

High risk AI systems face tougher obligations

The AI Act gives particular attention to foundation models that could pose systemic risks if left unchecked.

Developers are expected to identify and reduce risks involving large scale cyber attacks, chemical and biological threats, nuclear related dangers, manipulation of users and violations of fundamental rights.

The legislation also specifically addresses concerns about AI systems operating outside meaningful human oversight or creating cybersecurity risks across Europe.

Commission officials argued that the incidents involving OpenAI and Anthropic reinforce the importance of continuous safety testing rather than relying solely on pre deployment evaluations. As AI models become more capable of independent reasoning and task execution, regulators believe ongoing monitoring will be essential for identifying unexpected behaviour before it reaches users.

The European Commission has not indicated that enforcement action is currently planned. Instead, officials said they are collecting further information from both companies and will determine whether additional regulatory steps are warranted after reviewing the technical findings.

Heavy penalties underline the seriousness of compliance

The AI Act includes significant financial penalties for companies that fail to comply with its provisions.

- Advertisement -

Depending on the nature and severity of a violation, organisations could face fines ranging from €7.5 million or 1.5 percent of global annual turnover to as much as €35 million or 7 percent of worldwide turnover.

These penalties are intended to encourage AI developers to prioritise transparency, safety testing and responsible deployment throughout the lifecycle of advanced AI systems.

The conversations between the European Commission, OpenAI and Anthropic are likely to serve as one of the first real world tests of how the AI Act will be applied in practice. While the reported incidents occurred during controlled research rather than public deployment, they illustrate the growing challenges regulators face as artificial intelligence becomes more capable and increasingly integrated into businesses and everyday life.

Follow TechBSB For More Updates

- Advertisement -
Emily Parker
Emily Parker
Emily Parker is a seasoned tech consultant with a proven track record of delivering innovative solutions to clients across various industries. With a deep understanding of emerging technologies and their practical applications, Emily excels in guiding businesses through digital transformation initiatives. Her expertise lies in leveraging data analytics, cloud computing, and cybersecurity to optimize processes, drive efficiency, and enhance overall business performance. Known for her strategic vision and collaborative approach, Emily works closely with stakeholders to identify opportunities and implement tailored solutions that meet the unique needs of each organization. As a trusted advisor, she is committed to staying ahead of industry trends and empowering clients to embrace technological advancements for sustainable growth.

Read More

Trending Now