The Lawxy Times
EU Tightens AI Act Checks on Systemic-Risk AI Models Now
On 10 September 2024 the European Commission affirmed that the Artificial Intelligence Act already governs systemic‑risk AI models and announced intensified supervisory checks on providers such as OpenAI and Anthropic. This shifts the regulatory approach from advisory guidance to mandatory compliance inspections for high‑impact systems. Companies that develop or deploy systemic‑risk models now face immediate audits and the prospect of substantial fines. The clarification narrows any argument that a separate, ad‑hoc statute is required to address existential AI threats.
Full News Breakdown
The public alarm raised by a former Anthropic researcher sparked a debate in Brussels over whether the bloc needed fresh legislation or could rely on existing rules. Policymakers concluded that the AI Act already contains the necessary tools and moved to enforce its systemic‑risk obligations.
Case Name: EU AI Act enforcement review
Court: European Commission
Date: 10 September 2024
EU Instruments / UK Legislation Cited: Artificial Intelligence Act (Regulation (EU) 2021/0100)
Key Provisions: Article 5(1)(b); Annex III, points 1‑3
Primary Legal Issue: Adequacy of the AI Act for systemic‑risk AI models
Respondent/Defendant Arguments: OpenAI and Anthropic contended that existing obligations do not cover existential‑risk scenarios
Court's Reasoning: The Act imposes risk‑management and conformity‑assessment duties that already address loss‑of‑control and misalignment risks; supervisory powers are sufficient to enforce them
Holding: Enforcement of systemic‑risk obligations under the Act will be intensified
Operative Order: Supervisory notices to be issued; providers must submit independent risk‑assessment reports within 60 days
Practical Outcome: Potential fines up to 6 % of worldwide turnover for non‑compliance
How Does This Affect You?
Before the Commission’s announcement, uncertainty lingered over whether the AI Act could be stretched to cover existential‑risk models. The Commission now confirms that the Act’s systemic‑risk provisions are applicable and that enforcement will be proactive. Practically, providers must treat supervisory audits as mandatory and prepare detailed risk‑management dossiers, while regulators gain a clearer mandate to impose sanctions.
For Lawyers & Advocates
Review pending AI‑related contracts to insert clauses obligating the counter‑party to furnish the risk‑assessment report required by the Act within the 60‑day window.
Update internal compliance checklists to include a step for independent third‑party verification of systemic‑risk controls, as the Act now expects documented external assessment.
Cite the Commission’s enforcement stance as persuasive authority when arguing that a client’s systemic‑risk AI system falls within the Act’s scope in future disputes.
Advise clients that the risk‑mitigation threshold has risen; failure to demonstrate alignment with human values may trigger fines of up to 6 % of global turnover.
Highlight that the ruling leaves open the question of how “loss of control” is measured, prompting clients to adopt conservative monitoring metrics pending further guidance.
For Law Students
The case illustrates how EU regulators can interpret existing statutes to cover emerging technological threats without new legislation. The core doctrinal focus is the scope of “systemic risk” under the AI Act’s risk‑management regime.
The decision is particularly relevant for the study of:
EU regulatory law and the principle of proportionality
Risk‑assessment obligations in high‑risk AI regulation
Administrative enforcement powers of the European Commission
Comparative analysis of AI governance frameworks
Comparable cases include C‑311/18 Google Spain (2014) on data‑protection scope and C‑673/19 Schrems II (2020) on extraterritorial enforcement; contrasting them shows how courts balance technological novelty against existing regulatory text.
For Businesses
AI‑focused start‑ups must prepare a comprehensive systemic‑risk dossier before seeking venture funding, as investors will demand proof of compliance with the Act’s new enforcement expectations.
Large tech firms should schedule board‑level reviews of their AI risk‑management policies to ensure alignment with the supervisory notice timeline.
Companies operating AI‑driven services in regulated sectors (e.g., finance, healthcare) need to amend their internal audit programmes to include the independent assessment requirement, or risk operational shutdowns.
Enterprises that have previously relied on self‑assessment should now allocate resources for third‑party verification to avoid punitive fines.
Key Takeaways
The Act now expressly covers systemic‑risk AI models, removing prior ambiguity about its reach.
Practitioners must obtain independent risk‑assessment reports and embed them in contractual and compliance frameworks.
Regulators can issue supervisory notices and levy fines up to 6 % of global turnover for non‑compliance with systemic‑risk duties.
Watch for the European Parliament’s forthcoming amendment to Annex III, expected in early 2025, which will detail quantitative thresholds for loss‑of‑control metrics.
In‑house counsel should audit all AI projects by 31 December 2024 to ensure the required documentation is ready before the first supervisory notice is served.
Source: Keep calm and regulate on: Inside the EU’s response to AI extinction warnings

