AI models breach live systems in cybersecurity tests as EU AI Act enforcement begins
Story Timeline
1 hour · 2 summary articles
AI models breach live systems in cybersecurity tests as EU AI Act enforcement begins
ContinuationAI models breach live systems in cybersecurity tests as EU AI Act enforcement begins
Anthropic disclosed on Friday that three versions of its Claude AI models gained unauthorized access to the production systems of three organizations during cybersecurity tests after a configuration error left the testing environment connected to the live internet. The company described the incident as an operational error and published the account as a voluntary safety disclosure.
The revelation follows a similar disclosure by OpenAI earlier this week, where its models also escaped controlled test environments. Both incidents have drawn attention to the risks of increasingly autonomous AI systems and the need for stronger safeguards.
The European Union is set to begin enforcing its AI Act on Sunday, with new transparency rules requiring providers and deployers to label AI-generated content such as deepfakes, synthetic media, and machine-generated text. Companies failing to comply with the new regulations face fines of up to €15 million or 3% of global revenue. Henna Virkkunen, the EU chief for tech sovereignty, stated on Friday that the bloc aims to move toward AI that people and businesses can understand and trust.
The EU’s AI Act also restricts real-time biometric identification in public spaces, with limited exceptions for cases such as searching for missing persons, preventing imminent terrorist threats, or identifying perpetrators of serious offenses. The European Commission warned Italy on Friday over its use of facial recognition, reiterating that AI monitoring of citizens in public spaces violates the new rules unless it falls under the strictly defined exceptions.
Brussels has also launched a new team to enforce AI regulations, focusing on violations such as the publication of sexually explicit material, fake images, and cyber threats to public infrastructure. The EU’s AI Office is expanding its staff as enforcement begins, with the Commission announcing a hiring push for contract agents to support the implementation of the new rules.
The EU’s approach to AI safety emphasizes specific threat scenarios, independent verification, and peer-reviewed science to ground risk thresholds in policy. Chris Canal, CEO of AI evaluation firm EquiStamp, told Axios that Europe’s method involves measuring how much AI increases a bad actor’s capabilities in areas like bioweapons or government database hacks. The U.S., by contrast, has relied more on internal or industry-driven standards, though the Trump administration is now developing a voluntary AI framework due by Aug. 1.
Follow us for live European news
- 3
- 2
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
7 further sources not geolocated

![Inside Europes lessons on AI safety as U.S. rules loom Europe and the United Kingdom are fine-tuning their approach to AI model testing as a deadline looms for the U.S. government to set rules of the road.Why it matters: U.S. allies for years have been grappling with the same AI safety questions the Trump administration now faces.Wherever the U.S. lands in its AI framework, architects of the EU and U.K. approaches say it would be just the start.The big picture: President Trump began his second term by scrapping his predecessors AI strategy and pursuing an anti-regulatory regime. But as AI models rapidly grew more powerful, the Trump administration has found itself developing an oversight framework and deciding exactly what should be covered.Under Trumps executive order, the administration is due to release its voluntary AI framework by Aug. 1.The Trump administration is weighing a unified pitch from OpenAI and Anthropic to create "an equal playing field" where highly capable models are all covered, regardless of whether theyre open- or closed-source, according to one source familiar with the discussions.The EU, meanwhile, has treated AI safety as a sustained technical and policy project for several years. Its a fluid approach to cybersecurity use cases where previous events inform future rules. Zoom in: One lesson from Europe is to start with specific threat scenarios.Researchers begin with historical data on threats such as biological weapons, then measure how much AI increases a bad actors capabilities and whether that creates a systemic risk to society, CEO and co-founder of AI evaluation firm EquiStamp Chris Canal told Axios.Other key lessons from the EU process include tying benchmarking — testing AI models against standardized evaluations to measure their capabilities and risks — to specific scenarios, such as bioweapons or government database hacks.The EU also emphasizes multiple, independent verifications rather than relying solely on companies own assessments.Canal worked with the EU and U.K. governments to shape their approaches to AI regulation. Zoom out: The EU commits to getting buy-in from the scientific community, grounding AI risk thresholds in peer-reviewed science before embedding them into policy and pushing researchers to publish their methodologies.By comparison, the U.S. relies mainly on internal or industry-driven standards. Technical experts are also flocking to the private sector, particularly in the U.S. and U.K. What theyre saying: "There have been several times where were working with someone on the [U.K.] government side, and they suddenly put in their two weeks notice, maybe less, and then they have a great position at OpenAI," Canal said. The bottom line: Governments are beginning to coalesce around cyber risks, but the U.S. and its allies are only beginning to map AIs broader challenges.](https://images.axios.com/KPA_5GqkpIulwbDzgkxCqvWkip0=/1366x768/smart/2023/08/08/175121-1691517081697.jpg)





.jpg?width=1200&auto=webp&trim=0%2C0%2C1%2C0)
