September 7, 2026, 13:38 GMT | Comment
Hacking incidents involving frontier AI models developed by
OpenAI and
Anthropic have raised questions about whether the EU's landmark AI law should be updated to cover the risks posed by technology that's still in the testing phase, lawmakers and legal experts say. While the
European Commission is assessing the incidents, critics say the law and the AI Office’s enforcement powers may be insufficient to tackle this emerging cybersecurity challenge.
Recent hacking incidents involving frontier AI models developed by OpenAI and Anthropic have raised questions about whether the EU's landmark AI law should be updated to cover the risks posed by technology that's still in the testing phase, according to lawmakers and legal experts.
The debate centers on an exemption in the AI Act stating that the law does not apply to “research, testing and development” of AI systems and models that are not placed on the market or put into service. The provision explicitly excludes real-world testing, but it's unclear how it would apply when an AI model escapes a supposedly contained test environment and affects real systems.
That question came into focus after OpenAI disclosed in July that unreleased models left their sandbox without human direction and subsequently attacked online platform Hugging Face’s systems, followed by a similar incident involving Anthropic.
The European Commission should clarify how it interprets the exemption for AI models in testing as soon as possible, said Sergey Lagodinsky, a German lawmaker from the Greens political group, who played a significant role in negotiating and refining the AI Act and subsequent reforms of the law.
An overly broad reading of the exemption could suggest that Europe’s main AI rulebook cannot keep up with a reality in which the technology can autonomously break the constraints of its testing environment and enter the market on its own.
“If that would be the case, the AI Act would need to be updated,” Lagodinsky told MLex in a statement.
The commission told MLex that internal use of an AI model, such as the testing done by OpenAI and Anthropic, might constitute market placement. Regulators plan to assess each incident on a case-by-case basis.
“That is not enough for legal certainty,” Lagodinsky said.
The EU executive also said it's been in communication with the companies involved in the incidents and is working on the issue with the European cybersecurity agency ENISA. It has sent information requests to more than 30 AI companies worldwide, marking its first regulatory move under the EU's AI law (see
here).
Last week, however, a new hacking incident involving OpenAI’s models emerged, this time targeting a German website (see
here).
The pace of regulatory action has raised concerns among some legal experts that European authorities have limited means to punish AI companies that break the law.
“It's quite clear that the AI Act is not enough to regulate frontier AI models in light of recent advancements, particularly in relation to cybersecurity,” said Barry Scannell, a technology law partner at William Fry and member of the Irish AI Advisory Council.
The AI Office, which regulates frontier models, has limited tools at its disposal, Scannell said. While these include structured dialogues, requests for information, evaluations and requests for measures to mitigate risks, it cannot restrict AI models from the European market, and even if it could, it might not matter if the model remains available on the internet.
“Ultimately, the height of the EU AI Office's powers is the ability to impose fines,” Scannell said.
Lagodinsky said the AI Act should be enough to regulate frontier models, but the recent hacking incidents may mean that risks need to be mitigated even before an AI model is formally launched on the market. “The risk does not materialize when a model is made available to the public. It materializes with technological availability.”
Other experts warn that the research and development exemption should not be used to evade the AI Act's requirements when a model escapes control.
“The AI Act cannot be read as creating a regulatory black hole when an experimental AI agent leaves a controlled environment and starts operating in the real world,” said Risto Uuk, Head of European policy and research at the Future of Life Institute*.
*Corrected on Sept 7, 2026, at 15:13 GMT: An earlier version of this article included an incorrect affiliation for the Future of Life Institute.
Please email editors@mlex.com to contact the editorial staff regarding this story, or to submit the names of lawyers and advisers.
Tags
Sections:
Artificial Intelligence
Industries:
Computing & Information Technology
Geographies:
Europe, European Union Member States