Press "Enter" to skip to content

EU Starts Enforcing AI Rules. Will it Use its Full Authority?

For the first time, the EU is enforcing the rules of its AI Act, requiring AI companies to provide information about their models’ safety, cybersecurity and copyright compliance, Tech Commissioner Henna Virkkunen recently told Euractiv.

Under the AI Act, providers of the most powerful general-purpose AI models face additional requirements to assess and mitigate systemic risks, report serious incidents and maintain adequate cybersecurity protections.

The European Commission can also conduct model evaluations, require mitigation measures and impose penalties for noncompliance, making the information requests an early indication of how aggressively European regulators intend to police the frontier of AI development.

Risto Uuk, head of European policy and research at the Future of Life Institute, argues that regulators will need to be willing to use those broader powers.

In this email Q&A with The AI Innovator, Uuk discusses what meaningful AI safety oversight should entail, whether regulation can coexist with Europe’s ambitions to build its own AI industry, the case for international cooperation and what the debate over pausing frontier AI development looks like three years after his organization helped put that idea on the global agenda.

The AI Innovator: This is the first significant enforcement action by the EU of the AI Act. Do you think it will be enough to put strong guardrails around frontier AI models, especially given the recent cybersecurity breaches from OpenAI and Anthropic?

Risto Uuk: The information requests issued by the Commission are a necessary first step towards ensuring that the guardrails enacted as part of the AI Act are properly enforced. While information requests on their own are not enough to enforce the AI Act, the Commission has numerous powers in its toolkit, including the power to conduct evaluations, request compliance and mitigation measures, and even to remove a model from the EU market. Lastly, the Commission may also impose fines on the provider of a non-compliant model.

It is critical that the Commission is prepared to use its full range of powers – and the information requests send an important signal that it may be ready to.

AI companies already do their own safety testing and publish varying amounts of information about their models. The EU’s action suggests it’s not enough. What else can AI companies do to prove they’re serious about safety?

In the Future of Life Institute’s Summer 2026 AI Safety Index, independent experts graded AI companies on their safety practices. The best safety score in the entire industry was a C+ for Anthropic, while xAI, DeepSeek and Mistral all received failing grades. While independent evaluators noted numerous safety failings, the most concerning trend they observed was that just as AI capabilities are reaching critical thresholds, companies, including Anthropic, OpenAI, Google DeepMind and Meta, are weakening or voiding safety pledges.

In order to prove that they are serious, AI companies must treat safety and controllability as their primary goals, not an afterthought. Measurable risk-tied thresholds, genuinely independent audits, safety bodies that can prevent deployment, and true unilateral pause commitments are a starting place.

How do you think the EU can balance its regulations with its own desire to develop AI capabilities in the region? Where does one draw the line between innovation and safety?

I believe that the line to draw is not between innovation and safety, but between the current path of AI development – a race toward uncontrollable superhuman intelligence, designed to replace humans – and a pro-human AI development path, in which systems are designed from the start to be controllable, beneficial, and trustworthy tools, expanding what humans can do, while preserving our agency.

Do you believe that governmental cooperation globally may be needed to minimize AI harms? If so, how can one go about building this cooperation and ensure it is effective?

AI harms do not know borders; effects will ripple across states, countries, and continents. No single country can mitigate these risks alone. Such a consequential technology will require global cooperation to ensure the path to deployment benefits humans everywhere. And it’s critical that this cooperation invites all countries to the table, not just those where frontier AI development is currently concentrated. 

Future of Life Institute called for a six-month pause in model training in 2023. Will you do so again? Why or why not and what did you learn from the 2023 pause letter?

The Future of Life Institute’s 2023 pause letter alerted the public to AI risk when it was still a niche technical subject. Today, AI safety resonates in policy chambers worldwide, and a growing number of citizens are demanding accountability from the handful of companies racing to build uncontrollable superintelligence that no one agreed to or voted for.

People are realizing superintelligence isn’t inevitable, and that a brighter future exists: one where we refuse to accept AI built to replace human jobs, connections, and agency, and instead build AI that serves as a tool, enhancing our dignity, creativity, and flourishing.

Author

Get the latest insights about enterprise AI.

Subscribe to our newsletter. Thank you.

×