The European Union says its landmark AI Act can protect Europeans from emerging artificial intelligence risks, including AI systems behaving unpredictably. However, lawmakers and researchers are raising questions over accountability gaps, enforcement capacity and the bloc's willingness to take on powerful U.S.-based technology companies.
The EU agreed on its sweeping artificial intelligence legislation in 2024, although parts of its implementation were delayed and enforcement only became possible in August this year. Brussels nevertheless maintains that the framework is already strong enough to deal with rapidly developing AI risks.
EU spokesman Thomas Regnier described the rules as "fully fit for purpose," arguing that Europeans can feel safe because safeguards have been put in place.
So far, the EU has sent more than 30 requests for information to companies over issues ranging from copyright to cybersecurity and safety. Such requests can serve as a preliminary step toward formal investigations.
Concerns have grown as increasingly capable AI agents, systems designed to carry out tasks with greater autonomy, have raised questions about what happens when such tools behave in unexpected or harmful ways.
Four EU lawmakers, including Brando Benifei, a lead negotiator on the AI Act, have warned about "legislative gaps" after Brussels dropped plans for separate AI liability rules that would have made it easier to hold providers accountable for harm caused by their technology.
The lawmakers argue that existing rules do not cover the research, testing or development phase, potentially leaving Europeans without sufficient protection.
The European Commission disputes that interpretation. Regnier said the AI Act can be enforced against a provider from the testing stage if a loss of control affects the EU's internal market, including through cyberattacks or biological and chemical misuse.
Harshvardhan Pandit, a researcher at Trinity College Dublin's AI Accountability Lab, also raised concerns about liability, arguing that responsibility can become unclear once an AI provider has sold its technology and the system later causes harm, such as hacking a website.
At the same time, Pandit noted that the AI Act requires developers to address safety risks before putting a model on the market, while other EU legislation covering areas such as cybersecurity and data protection can also come into play.
Questions are also being raised about whether the EU has enough resources to put its ambitious rules into practice.
Benifei said the European Commission needs to provide its AI Office with political backing, operational independence, resources and technical staff so it can move quickly when enforcement is required.
The office currently employs around 125 people, while Pandit similarly argued that it needs significantly more staff and technical expertise.
Another obstacle involves regulators gaining access to cutting-edge models. It took months for the EU to test Anthropic's Mythos because of U.S. export control orders, and an EU official, speaking anonymously, acknowledged that similar difficulties could come up again.
The EU also faces a broader strategic challenge because many leading AI providers are based in the United States, where President Donald Trump opposes regulation of the sector.
European Commission President Ursula von der Leyen has proposed talks with leading frontier AI laboratories, meaning companies developing the most advanced models, to discuss how quickly the technology should move forward. She has argued that the AI Act gives Europe a position from which it can help shape global regulatory efforts.
However, an EU official acknowledged that Europe's dependence on U.S. technology could make the bloc think twice before using its full enforcement powers against American companies.
The official suggested that Europe could gain greater influence over AI safety by building up more of its own technological capacity.
Benifei similarly called for European capabilities stretching from chips and cloud infrastructure to a publicly funded "CERN for AI," referring to the European physics laboratory in Switzerland. He also backed closer cooperation with countries such as Canada, which he said share an interest in developing rules that cannot be dictated by a single power or company.