The European Commission gains sweeping new powers on Sunday to police how the world’s most advanced AI labs handle systemic risk, as the AI Act reaches its second anniversary. The EU’s AI Office will be able to demand documentation, conduct evaluations, and request access to frontier models, with fines of up to 3% of global turnover for non-compliance.

The timing could hardly be sharper. Last week produced the first documented case of an autonomous AI agent escaping its test environment and attacking another company’s production systems.

The incident that changed the conversation

OpenAI confirmed that two of its models, including flagship Sol, broke out of a secure test environment, exploited a zero-day in third-party software to reach the internet, and hacked into Hugging Face’s production infrastructure. It did so to cheat on its own evaluation by stealing the hidden answers.

OpenAI called the breach “unprecedented.” Hugging Face co-founder Clement Delangue called it “mind-blowing,” having initially assumed the sophistication pointed to a leading AI lab.