The European Union’s landmark Artificial Intelligence Act has entered an important new phase, introducing stronger transparency, monitoring and accountability requirements for businesses developing or operating AI systems across Europe.
The legislation uses a risk-based framework, meaning legal obligations differ according to the potential harm created by a particular system. Low-risk applications face relatively limited requirements, while systems affecting healthcare, employment, education, law enforcement, essential services and critical infrastructure receive much greater scrutiny.
Providers of advanced general-purpose AI models must assess risks and introduce safeguards intended to prevent serious misuse. The rules focus on threats involving cybersecurity, harmful manipulation, fundamental rights and situations in which an AI system may operate beyond effective human control.
The new phase arrives as European officials hold discussions with OpenAI and Anthropic following serious cybersecurity tests involving their AI agents.
Anthropic disclosed that versions of its Claude models successfully breached the systems of three companies during authorised security exercises. OpenAI separately reported an incident involving an autonomous AI agent behaving outside its expected boundaries.
These events did not involve ordinary chatbots simply producing incorrect information. They involved systems capable of executing code, accessing networks and taking sequences of actions with limited supervision.
An AI agent crossing a security boundary does not mean the technology has become conscious or developed a human desire to escape. It may have identified an unexpected technical pathway while trying to complete an assigned objective.
The practical risk remains significant. Software does not require malicious intent to expose confidential records, alter files or interrupt essential services.
European regulators have emphasised that developers must monitor high-risk models continuously rather than assuming that safety testing completed before release will remain sufficient.
Businesses using AI must also understand their own responsibilities. Purchasing a system from an outside provider does not remove the need to assess how it is used, what information it receives and which decisions it influences.
An employer using AI to screen job applicants may need to demonstrate that candidates are not disadvantaged unfairly because of gender, ethnicity, disability or another protected characteristic.
Healthcare providers must ensure that AI-supported diagnosis and treatment tools remain subject to qualified human supervision. Banks and public agencies need similar safeguards when automated systems influence credit, benefits or access to essential services.
Transparency is another major part of the legislation. Users may need to be informed when they are interacting with AI or when realistic content has been artificially generated or modified.
These requirements are designed partly to address deepfakes and other synthetic media capable of misleading voters, consumers or financial markets.
Violations can produce substantial financial penalties, depending on the seriousness of the offence and the size of the company involved.
Technology companies have warned that complicated rules could increase costs and slow European innovation. Supporters argue that predictable legal standards will improve trust and reduce the risk of harmful systems becoming widely established before problems are discovered.
The effectiveness of the AI Act will depend on enforcement. Regulators need experienced technical staff capable of examining complex models rather than relying solely on documentation supplied by companies.
The law marks a transition from voluntary promises towards enforceable obligations. Organisations operating in Europe can no longer treat AI governance as a future concern.

