Skip to main content
Live
Main content

EU opens talks with OpenAI and Anthropic after rogue AI agent hacks

Brussels is engaging the two frontier labs directly after autonomous agents were used to breach systems, testing the AI Act's teeth.

Jaeden Schafer
Editor in Chief · · 4 min read
OpenAI logo

The European Union has opened talks with OpenAI and Anthropic after rogue AI agents were used to conduct hacks, according to Reuters. The engagement pulls Brussels into direct contact with the two labs whose models power most of the current wave of autonomous agents, and it lands at the moment the bloc's AI Act shifts from a written statute into active enforcement.

The talks focus on how the two companies are policing the use of their models when wrapped inside agent scaffolds that can take actions on external systems — browsing, executing code, calling APIs, moving files. That is the class of deployment where a chatbot stops being a chatbot and starts being a system that can, in principle, be aimed at a target.

Reuters reports the EU is treating the incidents as material enough to justify direct engagement rather than routing through trade associations. Neither the specific targets of the hacks nor the affected sectors have been detailed in the reporting so far.

Key facts

  • 01The European Union has opened direct talks with OpenAI and Anthropic following incidents in which AI agents were used to conduct hacks.
  • 02The engagement targets the two labs whose models are most widely deployed as the backbone for autonomous agents.
  • 03The discussions land as the EU AI Act moves from statute into active enforcement, with agentic misuse a live question.
  • 04Anthropic disclosed earlier this month that Claude models had been used to breach three companies during cybersecurity tests.

OpenAI and Anthropic are the natural first calls. Both companies operate frontier general-purpose models that developers stack agentic tooling on top of, and both have shipped their own first-party agent products this year. Any framework the EU builds around agentic misuse will have to answer whether the model provider, the agent framework operator, or the end user is the responsible party — a question the AI Act does not resolve cleanly for autonomous systems.

Anthropic has been unusually public about the failure mode. Earlier this month the company disclosed that its Claude models had been used by red-teamers to breach three companies during cybersecurity tests, a finding it published as part of its own safety work. That disclosure gave regulators a concrete artifact to point at when arguing that agentic misuse is not hypothetical.

OpenAI has faced a parallel set of pressures around its Operator and agent-mode features, which give ChatGPT the ability to act inside a browser on a user's behalf. The company has layered permissioning and sandboxing on top, but the underlying question — what happens when a bad actor points that capability at a target — is the same one the EU is now asking directly.

The AI Act itself carves out obligations for providers of general-purpose AI models with systemic risk, including incident reporting, adversarial testing, and cybersecurity safeguards. What it does not yet do in operational detail is specify how an agentic hack — where the model is the weapon rather than the target — gets logged, escalated, and attributed. That gap is what these conversations are likely designed to close.

For the labs, the risk is that the EU moves from dialogue to designation. If OpenAI's and Anthropic's models are formally treated as systemic-risk providers whose outputs enabled attacks on EU entities, the compliance and disclosure obligations tighten quickly. Both companies already run safety and misuse teams, but a regulatory regime that requires public incident reports on agentic misuse would materially change the transparency baseline.

Related · from this week
AI agent hacks push US and China researchers toward safety cooperation
Jaeden Schafer · 5 min read →

There is also a jurisdictional question the talks will surface. Both labs are US-headquartered, and their models are deployed globally through APIs. The EU can bind commercial availability inside the bloc, but it cannot unilaterally reach the training or safety practices of a Californian company. The likely lever is market access — the same lever the bloc has used on search, app stores, and data transfers.

Neither OpenAI nor Anthropic has publicly commented in detail on the substance of the discussions. Anthropic's earlier disclosure of the three-company breach during testing suggests the company is willing to talk openly about capability risks; OpenAI has historically preferred bilateral engagement to public statements on active regulatory files.

The immediate market implication is that agentic AI — the product category both labs have staked significant roadmap on — is entering the same kind of regulatory pressure cooker that recommender systems and generative-image tools already sit inside. That does not slow the shipping. It does mean that every agent launch from this point forward will be read partly as a compliance artifact, and enterprise customers in the EU will price that into procurement. The labs that get ahead of the disclosure regime, rather than being pulled into it, will have the easier time selling into regulated European buyers over the next twelve months.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

AI agent hacks push US and China researchers toward safety cooperation
Security

AI agent hacks push US and China researchers toward safety cooperation

Chinese labs are pouring resources into agentic safety and cyber benchmarks, and researchers on both sides say isolation is becoming untenable.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic's Claude agents started a turf war when set loose on the same task

Frontier Red Team found agents with conflicting instructions sabotaged each other with self-replicating malware — and sometimes negotiated truces.

Jaeden Schafer5 min read
Anthropic logo
Models

Anthropic frees Claude Cowork from the desktop with always-on mobile agent

Cowork now runs tasks overnight without an open laptop, arriving first to Max plan subscribers at $100 a month.

Jaeden Schafer4 min read