READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

EU Gets Power to Inspect and Fine AI Models, Anthropic and OpenAI Now in the Crosshairs

EU Gets Power to Inspect and Fine AI Models, Anthropic and OpenAI Now in the Crosshairs
As of Sunday, the European Commission can demand pre-release access to AI models, block them from the EU market, and fine providers up to 15 million euros or 3% of global revenue, whichever is bigger. Anthropic and OpenAI are already in talks with EU regulators over cyberattacks tied to their models, and Google just ate a $1 billion fine last month. This is Brussels flexing on American tech companies, and Washington isn't going to sit still for it.

Since Google's $1 billion EU antitrust fine in July, the regulatory pressure on American AI companies has only ramped up. As of Sunday, August 2, the European Commission has full enforcement power under the EU AI Act to inspect general-purpose AI models before they launch in Europe, block market access, and fine providers up to 15 million euros or 3% of annual global turnover, whichever number is bigger, according to CNBC.

For a company like Google, 3% of turnover could run into the billions. For smaller labs like Anthropic, it's still enough to change how they do business.

Henna Virkkunen, the European Commission's executive vice-president for tech sovereignty, security and democracy, framed the move as a safety measure. "Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale," she said, according to CNBC.

Who's actually in the crosshairs right now

This isn't hypothetical. CNBC reported that the EU is already in talks with OpenAI and Anthropic following recent cyberattacks linked to their AI models, a development first reported by Reuters last Friday. OpenAI confirmed to CNBC that it's in contact with the EU AI Office. Neither the European Commission nor Anthropic responded to comment requests.

Separately, Anthropic had been fending off EU requests for access to its Mythos model for months before agreeing to share it, per CNBC's reporting. Brussels can now demand that kind of access as a matter of law, not negotiation.

Elisabetta Righini, a partner at law firm Sidley Austin, told CNBC the reach of these rules is broader than most people assume. "A U.S. address does not put a lab outside the EU regulator's reach," she said. Any company offering a general-purpose AI model to EU users has to designate an EU-based representative to deal with regulators, regardless of where the company is headquartered.

Righini also flagged something companies may not be prepared for: you don't have to break a substantive rule to get fined. "What's rarely appreciated is that GPAI liability isn't limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own," she told CNBC.

It means the EU doesn't need to prove your AI model caused harm. Stonewalling an inspector, or answering a regulator's question in a way Brussels considers misleading, is its own violation.

The bigger fight: tech sovereignty versus American tariffs

This enforcement rollout isn't happening in a vacuum. It's part of Europe's broader push for what officials call "tech sovereignty," reducing dependence on American AI and cloud infrastructure. The Google fine in July was the flashpoint. President Trump responded by threatening the EU with a "substantial" tariff, according to CNBC.

The EU says it's protecting consumers and guarding against AI risks "on an entirely new scale," in Virkkunen's words. Critics on this side of the Atlantic see a pattern: European regulators repeatedly targeting the handful of American companies that dominate AI and tech, while European competitors face lighter scrutiny simply because there aren't many European AI giants to regulate in the first place.

AI models genuinely do carry risks, from cybersecurity failures to the kind of misuse regulators worry about, and the cyberattacks tied to OpenAI and Anthropic's models that triggered the current EU talks are a real, concrete example, not a hypothetical one. It's also fair to note that these fines and inspection powers land almost exclusively on U.S. firms, and Brussels' timing right after the Google fine and Trump's tariff threat suggests to many observers leverage in a bigger trade fight, not pure safety regulation.

No formal investigation, fine, or market restriction has been announced against Anthropic or OpenAI as of this writing. The talks CNBC and Reuters described are just that, talks. Anthropic sharing Mythos model access appears to have been voluntary, not court-ordered.

What happens next depends on how those EU-OpenAI and EU-Anthropic conversations resolve. If Brussels decides the cyberattack incidents warrant formal action, that would be the first real test of these new powers against a major U.S. AI lab, and likely the next flashpoint in the argument over whether Trump follows through on tariff threats against the EU.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
CNBCAnthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers