EU's Virkkunen says AI Act offers robust protection against rogue AI risks

Editorial illustration: Three metallic network spheres connected by a glowing curved line sit inside a transparent capsule, with gold stars on a dark blue backdrop.

In brief

  • Henna Virkkunen, EU Executive Vice-President, said October 9 the AI Act offers robust protection against rogue AI risks.
  • AI models fall under the law across their whole life cycle, not just at launch, Virkkunen argued.
  • The AI Office can fine firms up to €35 million or 7% of global turnover.
  • Digital Omnibus pushed high-risk system deadlines to December 2027 and August 2028.

What the Act targets

The AI Act was introduced in 2024 and built around a risk-based framework (low-risk uses face lighter requirements, while the most dangerous practices are banned outright). For the biggest models, compute draws the line. General-purpose AI models trained with more than 10^25 FLOPs are presumed to pose systemic risk, and the Act names those risks as loss of control, cyber offense capabilities and manipulation at large scale.

Crypto Briefing reported that a scientific panel of 60 experts is tasked with continuously monitoring and evaluating AI models under the Act. "Robust protection" is Virkkunen's description, and it's her view, not an independent finding.

Who enforces it

Enforcement sits with the European Commission's AI Office, which can investigate AI models and fine companies that don't comply. Penalties can reach up to €35 million or 7% of global turnover.

The office has already started asking questions. As of August 2026, it had sent information requests to more than 30 AI providers about their safety and security practices (transparency protocols included), according to Crypto Briefing.

A staggered timeline

Bans on certain AI practices have been in force since February 2025. Transparency obligations for AI providers took effect in August 2026. The high-risk rules are on a different schedule: the outlet reported that the 2026 Digital Omnibus regulation pushed those requirements back, so standalone high-risk systems now face a December 2027 deadline and high-risk systems embedded in other products have until August 2028.

That leaves a gap. Virkkunen's case rests on life-cycle coverage, the AI Office and the expert panel, and the high-risk requirements won't apply until late 2027 at the earliest.

Frequently asked questions

Which AI models does the EU AI Act treat as posing systemic risk?

General-purpose AI models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk under the Act. The systemic risks it names include loss of control, cyber offense capabilities and large-scale manipulation.

Who enforces the EU AI Act, and what are the penalties?

The European Commission's AI Office enforces the Act. It can investigate AI models and fine companies that don't comply, with penalties of up to €35 million or 7% of global turnover. As of August 2026, it had sent information requests to more than 30 AI providers, according to Crypto Briefing.

When do the AI Act's high-risk requirements apply?

Crypto Briefing reported that the 2026 Digital Omnibus regulation pushed back the requirements for high-risk AI systems. Under that schedule, standalone high-risk systems face a December 2027 deadline, and high-risk systems embedded in other products have until August 2028, according to the outlet.