The European Union gained new powers to inspect AI models, restrict EU market access and fine model providers, raising the stakes for U.S. companies like Anthropic and OpenAI and Google.
Under the powers that came into effect on Sunday, the Commission, the EU’s executive arm, can demand to evaluate models before public release in the region, restrict EU market access and fine a provider up to 15 million euros or 3% of its annual turnover, whichever is higher.
The new powers could mean further flashpoints between the U.S. and European Commission, with the two sparring over Europe’s push for tech sovereignty and fines on American tech companies.
Google was hit with a $1 billion fine in July after European regulators said the company gave preferential treatment to its own services. In response, U.S. President Donald Trump threatened the EU with a “substantial” tariff.
How the powers fit into the EU AI Act rollout
The EU AI Office’s supervisory and enforcement powers over general-purpose AI models are part of a staggered rollout of the 2024 EU AI Act, which has imposed a transition period for certain aspects of the law.
Henna Virkkunen, executive vice-president for tech sovereignty, security and democracy at the European Commission, said in a statement: “Harms can occur if AI is not properly designed and used and the most advanced models create risks on an entirely new scale.”
Anthropic, the White House and the Department of Commerce have been approached for comment.
Why U.S. AI labs are exposed
Recent rapid leaps in AI capability have also brought new tensions between AI labs and the EU. The bloc had sought access to Anthropic’s Mythos model for months before the company said it would share access.
Europe’s latest moves come as it scrambles to build up tech sovereignty to stop being so reliant on U.S. systems as tensions with the U.S. administration rise.
The EU is in talks with OpenAI and Anthropic after recent cyber attacks by their models, Reuters reported on Friday. OpenAI confirmed it was in contact with the EU AI Office. The European Commission and Anthropic have been approached for comments on the report.
Elisabetta Righini, partner at Sidley Austin, told CNBC the powers could be used on any company offering a general purpose AI [GPAI] model in the EU, regardless of where they were based.
“A U.S. address does not put a lab outside the EU regulator’s reach,” she said. “Non-EU providers must also appoint an EU-based authorised representative as the regulator’s point of contact.”
Exposure to risks from fines for AI companies is “real”, Righini said.
“What’s rarely appreciated is that GPAI liability isn’t limited to substantive breaches: refusing an information request, giving misleading answers, or blocking a model evaluation is fineable on its own,” she added.
While the new enforcement powers relate to the AI Act, the Commission has taken steps to clamp down on AI in the past.
In January, the bloc said it opened an investigation into Elon Musk’s X over the spreading of sexually explicit material by the AI chatbot Grok.
“We’ve collaborated closely with the European Commission and the wider ecosystem on implementing the AI Act, including its Codes of Practice, and will continue working together to help Europe realise the benefits of the Intelligence Age,” Tom Gordon, VP, EMEA policy at OpenAI, told CNBC when asked to comment on the new powers.
A Google spokesperson said: “As the Act and its codes of practice take effect, we remain dedicated to meeting all applicable rules as part of our primary mission: advancing European AI infrastructure and innovation.”
