RSS Amplifier

The EU AI Act Newsletter · Jul 13, 2026

The EU AI Act Newsletter #106: Calls to Enforce General-Purpose AI Rules

0
Sign in to vote or save

Risto Uuk · The EU AI Act Newsletter

Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.

New EU plan to address the risks and opportunities of advanced AI for cybersecurity: The European Commission sets out a plan to manage the risks and seize the opportunities of advanced AI in cybersecurity. While AI can strengthen security, it can also be misused to find vulnerabilities, automate attacks, and increase the scale and speed of cyber incidents. Accordingly, the plan brings together member states, industry and EU-level organisations. Among its key actions, the Commission will help build an EU evaluation capacity to support the AI Office, work with ENISA to define a blueprint for structured access to advanced models, and create a secure testing platform for cybersecurity with the Joint Research Centre. Furthermore, it calls for stronger cyber hygiene, greater use of AI to fix vulnerabilities, and continued investment through AI Factories, Gigafactories, and a new EU Grand Challenge on AI for cybersecurity. The plan builds on existing rules, including the AI Act, the Cyber Resilience Act, the Network and Information Systems Directive and the Cyber Solidarity Act.

Council gives final green light to simplify and streamline rules: The Council has given final approval to a regulation streamlining certain AI rules as part of the ‘Omnibus VII’ simplification package. Because provisions on high-risk AI systems were due to apply from 2 August 2026, co-legislators prioritised this element and agreed new dates, namely 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in products. Alongside this delay, the law adds a provision banning the generation of non-consensual intimate content and child sexual abuse material from December 2026. Furthermore, it postpones the deadline for national regulatory sandboxes to 2 August 2027 while shortening the transparency grace period for generative AI systems already on the market to 2 December 2026. Finally, it clarifies the AI Office’s supervisory competences, listing exceptions where national authorities remain responsible.

EU enforcement powers to ensure frontier AI models are safe and secure: In an open letter to the European Commission President Ursula von der Leyen and Executive Vice-President Henna Virkkunen, a coalition of AI researchers, civil society organisations and independent experts, including academics Yoshua Bengio and Stuart Russell, express support for the Commission as it prepares to enforce the AI Act’s rules for general-purpose AI models with systemic risk from 2 August 2026. Noting that systemic risks are beginning to materialise and that other jurisdictions, including the US, are following the EU’s approach, the signatories argue that a year on from the finalisation of the Code of Practice, rapid developments make enforcement more urgent than ever. In particular, they point to widely reported cyber-offence capabilities in Anthropic's Mythos model and fast-approaching critical thresholds for biology and loss of control. Accordingly, they first urge the Commission to make full use of its powers under Articles 91, 92, 93 and 101. They also ask it to empower the AI Office's Network of Evaluators to carry out external assessments, and call for the Office to be given adequate resources and political backing.

Nobody gets an A in the latest AI safety rankings: Harry Booth, a reporter at TIME, reports on the latest AI Safety Index published by the Future of Life Institute, which asks an expert panel to grade AI firms on how seriously they manage risk, from pre-deployment testing to plans for controlling ever-more-powerful systems. The grades are unforgiving: Anthropic held the top spot with a modest C+, while OpenAI slipped from C+ to C, narrowly ahead of Google DeepMind in third place. All three, the panel noted, have weakened or dropped earlier pledges to halt development at certain red lines and softened their resistance to military uses. Meanwhile, Meta climbed from D to D+, and Elon Musk’s xAI fell to an F, joining DeepSeek and Mistral. According to Max Tegmark, a genuine “race to the top” will ultimately require regulation, pointing to the EU AI Act, Chinese rules taking effect later this month, and a more risk-conscious US administration.

What is the Scientific Panel and how does it work? The Future of Life Institute’s AI Act website explains that the Scientific Panel of independent experts is a body established under the EU AI Act to support the enforcement of rules on general-purpose AI models and systems. Within the Act’s governance architecture, it sits as one of three advisory bodies, alongside the AI Board and the Advisory Forum. It advises the AI Office and national authorities on systemic risks, model classification, evaluation methodologies and cross-border market surveillance. Established by Article 68, with detailed arrangements set out in Implementing Regulation, the Panel consists of up to 60 independent experts serving two-year renewable terms, selected for gender balance and geographical representation. Appointed on 1 June 2026, its members chiefly advise and support the AI Office, while also being empowered to request information and issue qualified alerts about possible Union-level systemic risks.

The EU AI Act and agentic AI: Vik Khurana, Partner, and Camille Beckmann, Associate, at Bristows examine the challenges of applying the AI Act to agentic AI, arguing that agentic systems are more likely than previous paradigms to engage the Act’s key requirements. Although the Act contains no specific definition of “AI agent”, they note that the functional, technology-neutral definition in Article 3(1), resting on autonomy, adaptiveness and the capacity to generate outputs influencing environments, almost always applies. Consequently, classification questions concern how many systems a deployment contains and which regulatory tier each falls into. Because agents change after deployment, the concept of “substantial modification” is especially likely to be triggered. The authors further explain why compliance becomes harder: the Article 14 human oversight requirement sits in tension with agents’ reduced human involvement, documentation and conformity assessments assume fixed functions, and the Article 50 transparency obligations may not reach people who never chose to interact with AI.

Read the original on artificialintelligenceact.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.