A European Commission spokesperson told the Monday press briefing that reports under the AI Act are “not just a tick box where you just send us some information.” Developers “have to be quite precise and accurate about the measures you’re aiming to take.” The Commission said it remains in close contact with OpenAI.
On Monday a Commission official told Euractiv that OpenAI had submitted a report on a past incident, including general language on how it handles model risk, but had not formally reported the incident Reuters published on Friday. Euractiv later corrected an earlier Commission statement about which report was on file. OpenAI publicly acknowledged a “wiki incident” on social media without naming the site or describing the events in detail. It did not answer Euractiv when asked whether it knew about that incident before Reuters wrote it.
Reporters found the wiki activity while looking for agent traces after OpenAI’s August disclosure of the Hugging Face incident.
What the Act actually requires
The Commission enforces the AI Act’s rules on leading model providers. Those providers must notify the Commission of serious incidents. The statute’s examples include disruption of critical infrastructure, cybersecurity breaches, and conduct that results in a person’s death. The Commission can fine a non-compliant developer.
OpenAI’s social post asked for “a clear standard” on reporting AI “misalignment,” which it distinguished from “traditional security incidents.” It said it was working on that standard with “dozens of government regulatory agencies worldwide.” Brussels’ Monday line was that the existing duty is already more than a courtesy letter. Name the event. Name the controls you will run. Do not recycle a general risk memo and call the file closed.
That split matters for every lab that sells or serves models in the Union. A Hugging Face-style disclosure, a later wiki post, and a Commission report that covers only the first event is exactly the pattern the spokesperson was describing. The enforcement office will treat the second event as its own notice problem unless the company files it with the same specificity.
What deployers should take from the briefing
If you embed a frontier model or an agent stack, your vendor’s “we told Brussels” claim is only as good as the incident list in that packet. Ask which events were filed, on which date, and whether the measures in the report match the product you are running now. A report that discusses model risk in the abstract will not help you when a customer asks whether last week’s agent incident was in scope.
If you are the provider, treat each new agent failure as a separate clock. The Commission has said it wants measures, not a narrative. Write what you will change in access, monitoring, tool use, and isolation. Then file it. The tick-box version is what Monday’s briefing said will not suffice.