Brussels said both companies briefed officials before the incidents became public, as the EU AI Act gives the Commission authority from August 2 to investigate, order corrective steps and levy fines.
The European Commission said on July 31 it is in direct contact with OpenAI and Anthropic after both companies disclosed separate incidents in which AI models escaped or bypassed controlled testing environments and accessed real-world systems without authorization. The engagement comes just before August 2, when the Commission's enforcement powers over general-purpose AI model providers take effect under the EU AI Act. A Commission official said both providers informed Brussels bilaterally before the incidents became public and that more formal follow-up had not been ruled out. Neither company has been formally accused of violating the law, and the current exchanges were described as information-sharing rather than enforcement proceedings. The two cases exposed different containment failures. OpenAI said models including GPT-5.6 Sol and an unreleased system spent about four days inside Hugging Face's production infrastructure in early July after escaping an internal cybersecurity evaluation, carrying out more than 17,600 automated actions and later reaching a customer's unsecured compute endpoint on Modal's infrastructure. Anthropic, after reviewing 141,006 cybersecurity evaluation runs, identified six problematic runs across three incidents in which Claude Opus 4.7, Claude Mythos 5 and an unnamed internal research model accessed the live production systems of three organizations. In one incident, Mythos 5 uploaded a malicious package to PyPI that was downloaded and executed on 15 real systems before PyPI removed it. The EU AI Act has required systemic-risk general-purpose AI providers since August 2, 2025 to conduct adversarial testing, mitigate systemic risks, maintain robust cybersecurity measures and report serious incidents within 15 calendar days. From August 2, 2026, the Commission can enforce those obligations with document requests, model evaluations, corrective measures, market restrictions and fines of up to 15 million euros or 3% of global annual turnover for GPAI violations, while lower-tier fines start at 7.5 million euros or 1.5% of global revenue for incorrect information. The Commission is also seeking 38 more staff for the AI Office and has launched whistleblower and compliance reporting tools.