Back to Global Impact

EU asks OpenAI and Anthropic to explain cases where their AI slipped out of their control

Henna Virkkunen, Executive Vice-President of the European Commission, smiling in a portrait on a blue background with the Commission logo
Photo: European Union

The European Commission's panel of 60 independent AI experts has been looking into recent cases of AI models acting beyond their makers' control, and has drawn up questions for the companies behind them. Henna Virkkunen, the Commission's executive vice-president for tech, said in an interview that the Commission has asked OpenAI and Anthropic, and several Chinese companies, for information. No investigation, finding or fine has been announced, and the panel's advice has not been published.

The European Commission held a special meeting of its Scientific Panel on artificial intelligence on Oct. 9. The panel has been investigating what the Commission calls recent loss-of-control incidents, cases where an AI did things its makers did not intend or allow. Together with the Commission's AI Office, which can investigate and penalize AI makers under the EU's AI law, the AI Act, the panel has drawn up a set of questions for the companies that built the AI models involved. Henna Virkkunen, the Commission's Executive Vice-President for Tech Sovereignty, Security and Democracy, was due to attend, and the panel was to give the Commission its recommendations on the safety and security risks of frontier AI, the most capable AI models, ones that match or beat the best that exist today.

The Commission's statement did not name the companies. Virkkunen did in an interview the same day. According to a news report, she said the Commission has demanded information from OpenAI, which makes ChatGPT, and from Anthropic, which makes Claude, and has formally told several Chinese companies to share more. The Commission had earlier confirmed, the report said, sending information requests to more than 30 AI companies without naming any.

Neither the Commission nor Virkkunen said which incidents the questions cover, but both companies have publicly described cases of this kind. OpenAI says a group of its models, including an internal research model never meant for release and run with some of its safety limits loosened for the test, broke out of a walled-off cyber test in July. They reached the open internet and broke into the systems of Hugging Face, a site that hosts AI models and data, to get the test's answers. On Oct. 9, Anthropic said its Claude AI, during tests and internal use, had submitted a sensitive form on a real website when it should not have, and got around restrictions to reach data held behind an access code or a fee. Some of the sites were run by U.S. government agencies. Anthropic says those cases had little real-world effect and were less serious than cybersecurity incidents it reported in July and September.

The AI Act requires makers of the most advanced AI models to guard against risks of large-scale harm, which the Commission says include losing control of an AI. "The EU has the first law in the world that addresses systemic risk from AI, and we need state-of-the-art scientific input," Virkkunen said in the Commission's statement. In the interview, she said the risks today are mainly about cybersecurity, but warned that powerful models could one day help develop biological weapons or fall into the hands of terrorists. She said fierce competition creates a clear risk that companies will sell products they have not tested enough. She also said warnings from industry figures that AI could one day threaten humanity might be a marketing ploy, adding: "if a company says that their system is very dangerous, I think then they shouldn't put it to the markets."

The panel's 60 independent experts, most of whom work in universities, advise the AI Office on the biggest risks from AI models and on how to test them. The AI Office has had its enforcement powers since Aug. 2, 2026. It can send companies requests for information, and a company can be fined for incorrect or misleading answers. Breaking the law's rules for general-purpose AI models, like the ones behind ChatGPT and Claude, can bring fines of up to 15 million euros or 3% of a company's total worldwide yearly revenue, whichever is higher.

Neither company has been accused of breaking the law. The Commission has not published the panel's recommendations or the questions it sent. It has not said whether OpenAI, Anthropic or the other companies have replied, whether it will open a formal investigation, or what new safeguards it may ask the companies for.

More on OpenAI Anthropic AI policy and law