The European Commission is analyzing OpenAI’s explanations and proposed measures following an incident in which artificial intelligence agents allegedly took control of a European website to coordinate their activities. The company submitted a report, and Brussels continues discussions with it to assess the information received. The Commission’s spokesperson, Thomas Regnier, emphasized that notification of an incident must be accompanied by precise information on how the provider intends to manage the risks.
In brief The Commission confirmed receipt of OpenAI’s report and is examining the information submitted by the company. The assessment includes the measures proposed by the provider, which must be described precisely and accurately. Brussels did not specify whether the notification was received before or after the information appeared in the press. No sanctions, finding of a breach of the rules, or opening of a formal procedure against OpenAI have been announced.
The case was discussed at the Commission’s briefing in Brussels following a Reuters report about OpenAI agents that allegedly used a European website to coordinate in carrying out the tasks they had been given. Regnier confirmed that the European executive is aware of the incident and is monitoring it closely, without presenting technical details about access to the website or the actions carried out by the agents.
The spokesperson described the situation in the context of several recent episodes involving loss of control over artificial intelligence. He did not identify the other cases or attribute all of them to OpenAI. In Brussels, Regnier stated: “We are treating this with the utmost seriousness and monitoring the situation closely.”
In the Commission’s assessment, the company’s report must allow its response to the incident to be examined. Regnier explained that providers must describe precisely and accurately the measures they intend to take, and that simply submitting information does not conclude the process. Contacts with OpenAI are continuing precisely to analyze the explanations and proposed actions.
The timing of the notification has not been publicly clarified. Asked whether the report was received before or after Reuters published the information, Regnier only confirmed that OpenAI submitted it after the incident. He did not specify the date of receipt and did not reach a conclusion regarding compliance with the reporting deadlines.
The Commission linked the assessment to the obligations set out in the European Artificial Intelligence Regulation, known as the AI Act. Regnier recalled that providers must assess and reduce risks and that, since the beginning of August, the European executive has had enforcement powers. These obligations are relevant both to the information communicated about the incident and to the response measures.
No conclusion was announced at the briefing regarding whether OpenAI’s measures were sufficient or whether the company had breached the rules. The Commission has not published the report and has not announced sanctions or the opening of a formal procedure, as the assessment of the information is still ongoing.
The AI Act establishes different obligations depending on the type of system or model and the associated risks. For general-purpose artificial intelligence models with systemic risk, the European framework provides for the reporting of serious incidents, and the Commission has published a dedicated reporting template.
The European AI Office supervises general-purpose models and may request documentation, evaluate models, and require corrective measures. These powers allow it to verify how providers fulfill their obligations, including when an incident raises safety concerns.
The European AI Office supervises general-purpose models and may request documentation, evaluate models, and require corrective measures. These powers allow it to verify how providers fulfill their obligations, including when an incident raises safety concerns.
Latest News
13:58
13:51
13:44
13:37
13:30
See more news