The European Union says its artificial intelligence rules are strong enough to protect people in Europe. But some lawmakers and experts are not so sure.
The debate comes as concerns grow about AI agents going rogue and as warnings about the technology get louder.
The EU agreed its AI Act in 2024. It delayed part of the rollout, and enforcement has only been possible since August this year.
The law forces companies to assess and reduce risks. Firms that break the rules face large fines or even bans.
EU spokesman Thomas Regnier said the rules are "fully fit for purpose." He added, "You can feel safe at home in Europe, precisely because we have put all these safeguards in place."
So far, the EU has sent more than 30 requests for information to companies. These cover issues from copyright to cybersecurity and safety, and they can lead to investigations.
Regnier said the rules have already forced AI providers to share information with regulators. He declined to give details.
There are also questions about access to new models. It took months for the EU to test Anthropic's Mythos model following US export control orders. An EU official, speaking anonymously, said this could happen again.
Lawmakers Point to Gaps in the Rules
Four EU lawmakers, including lead AI Act negotiator Brando Benifei, have warned of "legislative gaps." This follows the EU's decision to shelve plans for AI liability rules.
Those rules would have made it easier to hold AI providers responsible for harm caused by their tools.
The lawmakers say current rules do "not apply to the research, testing or development phase," leaving Europeans "unprotected."
The European Commission rejects this. Regnier said the law can be enforced against any provider "starting from the testing phase" if a loss of control affects the EU market, including cyberattacks and biological or chemical misuse.
Researcher Harshvardhan Pandit of the AI Accountability Lab at Trinity College Dublin shared the liability concerns. "We are missing these pieces of accountability," he said.
Pandit said that if a model hacks a website after it is sold, "we don't know" who is responsible. He also noted that recent incidents, including with OpenAI agents, happened during testing, before models reached the market.
Staffing and US Pressure
Benifei said the AI Office does not have enough staff to match the risks. The office employs around 125 people, and Pandit said it needs "far more people and technical expertise."
Most major AI providers are based in the US, where President Donald Trump opposes regulating the sector. The EU official said the bloc may think twice before using its full powers against American firms, given Europe's reliance on US tech.
EU chief Ursula von der Leyen has proposed talks with leading AI labs to "pace" the technology's growth.
Benifei said Europe must build its own capabilities, "from chips and cloud to a publicly funded CERN for AI." He also said the EU should work more closely with middle powers like Canada, as von der Leyen pledged last month.