EU tech chief Henna Virkkunen says the bloc’s AI rules are designed to handle serious safety and security risks, including concerns that highly capable “rogue” AI agents could operate beyond human control. Speaking to Reuters on Friday, Virkkunen argued that Europe’s framework is built to address problems not just at deployment, but across the entire lifecycle of advanced models.
The comments come amid heightened global attention following major AI incidents at companies such as OpenAI and Anthropic. Concerns have also intensified around the possibility that autonomous systems could take actions that are difficult for people to monitor or correct in real time.
Key takeaways
- Henna Virkkunen said the EU’s AI Act is equipped to address safety and security risks tied to very capable models, including “rogue” agent scenarios.
- The AI Act regulates according to risk levels and, according to Virkkunen, covers the full lifecycle of models rather than only end-stage use.
- Virkkunen said regulators are offering guidance to companies on model evaluation and risk assessment, incorporating recommendations from 60 AI experts.
- The European Commission has already requested safety and security information from more than 30 unnamed AI companies in late August, and Virkkunen is reviewing the responses.
Europe’s AI Act: safety rules across the model lifecycle
Virkkunen’s central point was that the EU does not rely on a narrow, “single moment” approach to AI oversight. In her Reuters interview, she emphasized that the AI Act is designed to cover the whole lifecycle of advanced models, giving regulators a basis to evaluate safety and security considerations from development through use.
Under the AI Act, obligations are tied to the level of risk posed by a system. Virkkunen described the regulation as among the world’s strictest, noting it was adopted two years ago. Her response also targeted critics who argue the framework has become outdated given how rapidly frontier AI is evolving.
“We see that the safety and security of very capable models is a very hot topic internationally and we in Europe are well equipped for that,” Virkkunen told Reuters.
Regulators’ guidance and expert input
Beyond the law itself, Virkkunen pointed to the operational support regulators are providing to help companies meet compliance expectations. She said that the European approach includes guidance on how developers should evaluate their models, including how safety and security factors should be accounted for.
Crucially, she said this guidance incorporates recommendations from 60 AI experts. That detail matters because it suggests the EU is trying to translate broad legal principles into concrete evaluation practices—an area that often becomes a sticking point when rules are new or when risk definitions are hard to apply to cutting-edge systems.
Virkkunen’s remarks also imply that enforcement and assessment will hinge on whether companies can demonstrate that they have considered safety throughout model development and deployment, rather than treating compliance as a box-check at launch.
Commission information requests and what happens next
Virkkunen said the European Commission asked for information in late August from more than 30 unidentified AI companies. The request sought details of the companies’ safety and security measures.
She added that she is now assessing the responses. While the remarks did not specify what the Commission will do with the information—such as whether it will move toward specific enforcement actions, additional guidance, or policy adjustments—the process itself signals an active supervisory posture. For developers and investors, that matters because it can affect near-term compliance timelines and the credibility of safety reporting frameworks.
Readers should watch for whether the Commission’s review leads to clearer expectations for model evaluation, particularly around how to document safeguards relevant to autonomous or semi-autonomous behavior.
Global pushback: calls to slow development
Virkkunen’s confidence in EU oversight stands in contrast to wider international debates about whether the pace of frontier AI development is moving faster than society’s ability to understand and control it.
Earlier coverage from Cointelegraph noted that Anthropic CEO Dario Amodei argued in a blog post that AI development may be progressing too quickly. Amodei said the speed of progress could “outrun our ability to understand and control these systems,” and he pointed to AI’s increasing ability to build the next generation of AI—a process described as recursive self-improvement.
That broader argument—often framed as a call for pausing or slowing certain stages of development—directly intersects with Virkkunen’s theme. The EU’s stance, as she presented it, is that safety and security can be addressed through regulatory structure and lifecycle-based requirements rather than through slowing the overall trajectory of research and deployment.
At the same time, the existence of competing perspectives highlights the tension at the heart of current AI governance: whether the key risk can be managed primarily through regulation and evaluation, or whether it also demands a more cautious pace until control mechanisms catch up.
What to monitor
As Virkkunen reviews the late-August submissions from more than 30 AI companies, the next critical signal will be whether the EU offers tighter, more testable guidance on safety and security evaluations for very capable models—especially those that could behave in ways that are difficult to predict or contain. For the market and for builders, clarity on what counts as sufficient evidence will likely matter as much as the law itself.




Be the first to comment