EU faces calls to enforce systemic-risk AI rules
The European Commission set out a plan to manage the risks and opportunities of advanced AI in cybersecurity, warning that AI can strengthen defenses but also help attackers find vulnerabilities, automate attacks, and increase the scale and speed of incidents. The plan brings together member states, industry, and EU-level bodies, with work planned on evaluation capacity for the AI Office, structured access to advanced models with ENISA, and a secure testing platform with the Joint Research Centre.
The Council gave final approval to an Omnibus VII regulation streamlining AI rules. High-risk AI provisions were due to apply from 2 August 2026, but the new dates are 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in products. The law also bans the generation of non-consensual intimate content and child sexual abuse material from December 2026, moves the sandbox deadline to 2 August 2027, shortens the transparency grace period for generative AI systems already on the market to 2 December 2026, and clarifies AI Office supervisory powers.
A coalition of researchers, civil society groups, and independent experts urged the Commission to robustly enforce rules for general-purpose AI models with systemic risk from 2 August 2026 and use its powers under Articles 91, 92, 93 and 101. Additional analysis highlighted the Scientific Panel’s role in supporting oversight, with up to 60 independent experts appointed on 1 June 2026, and warned that agentic AI may strain human oversight, documentation, conformity assessment, and transparency duties.