If you are building AI agents and eyeing the European market, stop assuming your current compliance docs are enough. Henna Virkkunen, the EU’s tech chief, told Reuters on Friday that the bloc’s AI Act is fully equipped to handle rogue AI agents. While that sounds like bureaucratic reassurance, the practical reality for builders is a heightened focus on the 'whole life cycle' of your models, not just the final deployable artifact.
The Lifecycle Isn't Just a Buzzword
Virkkunen’s argument hinges on the idea that the AI Act regulates risk from development through deployment. For developers, this means regulators are now providing specific guidance on how to evaluate your models and how much time you need to allocate for these assessments. It is not a one-time checkbox at launch. The EU is integrating recommendations from a scientific panel of 60 AI experts to inform this oversight. If your internal testing pipeline doesn't account for ongoing monitoring and external expert review, you are already behind the curve.
Audit Season Is Here
This isn't theoretical. In late August, the European Commission sent requests for information to more than 30 AI companies. The inquiries weren't vague; they demanded details on safety and security measures, followed up with questions about transparency and copyright obligations. Virkkunen confirmed that Chinese startups were included in this sweep, noting that the most capable models currently in the market come from both the United States and China. If you haven't received a letter yet, consider it a matter of time. The Commission is actively assessing responses, and the next phase of enforcement depends on how transparent your data is.
The Financial Stakes for Non-Compliance
Let’s talk about the cost of getting this wrong. These information requests can lead to investigations, and those investigations can result in fines of as much as 7 percent of a company’s global annual turnover. That is a massive liability for any startup or enterprise shipping AI products. Critics have argued the AI Act is outdated given the pace of generative AI, but Virkkunen dismissed this, stating that legislators anticipated these developments by mandating ongoing risk assessments. The rules are static, but the enforcement is dynamic.
Key Takeaways
- Fines for non-compliance can reach 7% of your global annual turnover, making compliance a core business cost, not just a legal fee.
- The EU is actively auditing over 30 companies, including Chinese startups, on safety, transparency, and copyright obligations.
- Regulation covers the 'whole life cycle' of models, meaning you need ongoing monitoring mechanisms, not just pre-launch testing.
- A panel of 60 AI experts is influencing regulatory guidance, so align your internal evaluation criteria with scientific best practices.
- The 'digital levy' discussion is still in the hands of EU governments for the 2028-2034 budget, so keep an eye on future financial burdens.
The Bottom Line
The 'move fast and break things' era is over for AI agents in Europe. If you are shipping code to the EU, you need to treat safety and transparency as core product features, not post-hoc legal patches. The Commission is watching, and the bill for ignoring them is 7% of your revenue.