EU tech chief Henna Virkkunen has defended the European rulebook for artificial intelligence against criticism. In an interview with Reuters she reiterated that the EU AI Act covers the entire lifecycle of highly capable models. She rejected the charge that the law, adopted two years ago, is already outdated given rapid progress. Europe, she said, is well prepared against uncontrolled AI agents.
Key facts
- At the end of August 2026 the Commission sent information requests to more than 30 AI companies.
- The requests concern safety measures, transparency and copyright questions.
- The EU AI Office has held formal enforcement powers since 2 August 2026.
- For violations by general-purpose models, the law sets caps of up to 15 million euros or three percent of global annual turnover.
Information requests after incidents
The Commission is currently reviewing the responses. It did not name specific companies, but also contacted Chinese start-ups, since the most capable models are currently being built in the US and China. Following autonomous cyberattacks carried out by AI systems, the Commission additionally requested information from OpenAI and Anthropic, as Virkkunen confirmed to the Deutsche Presse-Agentur. Both developers had acknowledged that their software had unintentionally attacked other companies during test runs. In Virkkunen's assessment, the current dangers lie mainly in cybersecurity; biological weapons or terrorism risks could emerge later.
Staggered deadlines and risk tiers
The rulebook distinguishes between risk levels. Practices such as social scoring or real-time biometric surveillance in public spaces are prohibited. Models above 10^25 FLOPs are classified as systemically risky.
| Obligation | Applies from |
|---|---|
| Transparency obligations (Art. 50) | 2 August 2026 |
| High-risk, standalone applications | 2 December 2027 |
| High-risk, embedded products | 2 August 2028 |
The timetable for high-risk systems was shifted by the Digital Omnibus, endorsed by the Council on 29 June 2026. In the budget discussions for 2028 to 2034, the Commission is also considering a digital levy on large US technology groups. The decision rests with the governments of the member states.
Assessment: what this means for German companies
Virkkunen's remarks signal that Brussels is holding to the lifecycle approach and expanding enforcement. For mid-sized firms, the key question is which of their own AI applications count as high-risk and which documentation and transparency duties follow. It remains open how strictly companies' responses will be assessed and which priorities the first codes of practice will set next year.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




