Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.
EU agrees to simplify AI rules to boost innovation and ban ‘nudification’ apps to protect citizens: The European Commission welcomes the political agreement reached between the European Parliament and the Council of the EU on the Digital Omnibus on AI. Under the deal, rules for high-risk AI systems will apply from 2 December 2027. Rules for systems embedded in products like lifts or toys will apply from 2 August 2028. In addition, the agreement prohibits AI systems generating non-consensual sexually explicit content or child sexual abuse material, including ‘nudification’ apps. For businesses, certain SME privileges are extended to small mid-caps, the interplay with the Machinery Regulation is clarified, and access to regulatory sandboxes, including an EU-level one, is broadened. The AI Office’s enforcement powers are also strengthened, particularly over general-purpose models and systems embedded in very large online platforms and search engines. The Parliament and Council must now formally adopt the agreement, after which it will enter into force three days following publication in the Official Journal.
Commission opens consultation on draft guidelines for AI transparency obligations: The Commission has published draft guidelines on the AI Act’s transparency obligations and opened them up for stakeholder feedback. From 2 August 2026, people in the EU will have to be informed when they are interacting with an AI system or exposed to certain AI-generated or manipulated content. More specifically, providers will be required to inform users when they are interacting with an AI system and to add machine-readable marks enabling the detection of AI-generated or manipulated content. Deployers will additionally have to inform people when they are exposed to deep fakes, AI-generated publications on matters of public interest, and emotion recognition or biometric categorisation systems. Drawing on input from earlier consultations, the draft guidelines seek to clarify the scope of these obligations and help providers and deployers comply. They will be complemented by a voluntary code of practice drafted by independent experts and expected in June 2026. Stakeholders are invited to share their views by 3 June 2026.
Europe’s laws ‘ill-equipped’ to deal with superhacking AI, lawmakers warn: Sam Clark from POLITICO reports that, in a letter obtained by the outlet, 30 MEPs from six political groups told Commission Executive Vice-President Henna Virkkunen that the EU’s cybersecurity rules are ill-equipped to deal with a new generation of AI hacking tools such as Anthropic’s Mythos, and that the bloc needs to revise its laws and put together a “European mitigation plan”. The warning follows Anthropic’s announcement last month that its model outperformed humans in finding and exploiting security vulnerabilities. Although Parliament’s internal market committee invited Anthropic to a public hearing, the company said it was unable to accept at short notice. In their letter, the lawmakers urged reform of the EU’s rules on the disclosure and remediation of cyber flaws, called on the Commission to prioritise protection of “crown jewels” such as critical sector operators, and pushed for EU cyber agency ENISA to gain access to Mythos and other models to scrutinise the risks. In response, Commission spokesperson Thomas Regnier said the Commission has held numerous technical meetings with Anthropic since August 2025, as well as several meetings specifically about Mythos. He added that “once the enforcement powers of the AI Office start in August 2026, we will ensure to receive, if needed, model access.”
Access is not safety: the real Mythos question Europe isn’t asking: I argue in a LinkedIn op-ed that the Brussels debate over whether the European Commission and the AI Office have access to Anthropic’s Mythos model risks putting the second question first, and that the more fundamental issue is whether Anthropic can mitigate the systemic risks of a superhacking model and why a private company is permitted to develop and deploy such capabilities without binding, independently verified pre-deployment oversight. I stress that the AI Act, and in particular its Article 55 obligations on systemic risks from general-purpose AI models, gives Europe a basis for requiring providers to release a model only when it is adequately safe, and that the General-Purpose AI Code of Practice was designed precisely for capabilities like this. A serious European response, in my view, would make notification and pre-market engagement for systemic-risk models non-negotiable, invest in the AI Office’s technical capacity and independent evaluators, and be willing to refuse market entry when a provider cannot demonstrate that mitigations are adequate and verifiable prior to deployment. I conclude that the “Europe doesn’t have access” narrative recasts a safety question as a competitiveness one, and that access alone will only address the underlying risk if Anthropic are held to account once systemic risk obligations for general-purpose AI become enforceable on 2 August 2026.
The EU AI Act is not ready for agents: Kathrin Gardhouse and Amin Oueslati, both at The Future Society, argue in Tech Policy Press that AI agents, systems which independently pursue complex goals with limited human oversight, have entered the mainstream but introduce unique risks that the EU AI Act was not written to address. They illustrate the point with recent incidents, including Amazon’s coding agent Kiro deleting a live production environment in December 2025 and triggering a 13-hour AWS regional outage. While the Act applies to agents in principle, the authors contend it falls short in practice across several governance challenges in areas relating to performance, misuse, privacy, equity and oversight. For example, while metrics such as robustness remain relevant, others such as accuracy map poorly onto agents, since accuracy presupposes a determinate correct output that agentic tasks often lack. To close these gaps, the authors call for harmonised standards accounting for agentic capabilities before the high-risk obligations come into force, and AI Office guidance for general-purpose models with systemic risks, whose obligations already apply but remain vague.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.