A humanoid robot seated at a conference table
AI

EU tech chief says AI Act can handle “rogue” AI agents as safety review runs

Henna Virkkunen said the Commission is assessing safety and security responses from more than 30 AI companies contacted in late August.

By Emma Carter4 min read

EU tech chief Henna Virkkunen said Europe is “well equipped” to address safety and security risks from highly capable AI models, arguing the bloc’s rules can deal with fears of “rogue” AI agents acting beyond human control. Her comments land as the European Commission reviews safety and security information it requested in late August from more than 30 AI companies.

Henna Virkkunen, the European Union’s tech chief, is leaning hard on the European Union’s Artificial Intelligence Act as a ready-made framework for frontier-model safety, positioning it as capable of handling the “rogue agent” scenarios now driving international debate.

“We see that the safety and security of very capable models is a very hot ​topic internationally and we in Europe are well equipped for that,” Virkkunen said in an interview with Reuters on Friday.

Her argument is procedural, not philosophical. Virkkunen pointed to the EU AI Act’s risk-based design, where obligations scale with the level of risk, and stressed that the law is meant to cover the full life cycle of AI models rather than only their initial release. “We have our AI Act in place and the AI Act covers the whole life cycle ​of these models,” she said.

Virkkunen also pushed back on a familiar critique from industry and policy circles that Europe’s rules are already behind the curve. She dismissed claims that the bloc’s AI rules are outdated, noting the AI Act was adopted two years ago.

The Commission’s posture here matters for crypto-adjacent automation because “rogue agents” is not just a lab-safety phrase anymore. It is increasingly used as shorthand for autonomous systems that can take actions, chain tools, and persist in ways that exceed or evade human control, which is exactly the kind of capability that starts to intersect with payments, custody operations, and AI-driven trading workflows once agents are allowed to touch real-world rails.

Brussels Is Reviewing Safety Responses From 30+ AI Companies

Virkkunen’s comments are landing in the middle of an active information-gathering cycle. The European Commission requested information in late August from more than 30 unidentified AI companies, asking for details of their safety and security measures. Virkkunen said she is now assessing the responses.

The Commission has not identified which companies received the request, and it has not disclosed what the responses contained or whether any follow-up steps are planned. That leaves the market with an enforcement-relevant signal, but not yet the details that would let traders handicap which firms or model families are likely to face the most friction under the AI Act’s higher-risk requirements.

Virkkunen framed the Commission’s approach as technical and iterative, with regulators providing guidance to companies on how to evaluate their models. She said that guidance is factoring in recommendations from 60 AI experts, a detail that reads like an attempt to pre-empt the criticism that a legislative framework cannot keep pace with fast-moving model capabilities.

The policy backdrop is a rising global focus on “rogue AI agents,” with the debate sharpened by references to incidents at OpenAI and Anthropic. The specific incidents were not detailed, which makes it hard to map the Commission’s current review to a defined set of failure modes or threat models.

One concrete marker of how the safety conversation is being framed came from Anthropic CEO Dario Amodei, who previously warned that the speed of AI development may “outrun our ability to understand and control these systems.” The same discussion has pointed to recursive self-improvement, where AI helps build more capable AI systems, as a driver of acceleration that can outstrip oversight.

The next signals are procedural. Traders should watch for whether the Commission discloses which “more than 30” companies were contacted, or publishes any aggregate findings that effectively benchmark safety practices across the sector. A second tell will be any follow-up guidance on model evaluation that tightens expectations under the AI Act’s life-cycle coverage and risk-based requirements. The third is definitional: public clarification of what “rogue AI agents” risk scenarios regulators are prioritizing, given the current lack of detail on the OpenAI and Anthropic references.

My read: Europe is signaling enforcement posture before naming names

The comments are being read as reassurance, but the more market-relevant detail is that the Commission is already collecting safety and security disclosures from more than 30 AI firms, which is the kind of input you gather when you want to compare practices across a sector and decide where guidance ends and supervision begins.

The threshold that matters is whether this review produces publishable outputs, either in the form of named recipients, aggregate findings, or model-evaluation guidance that becomes a de facto compliance baseline under the AI Act. If that happens, “rogue agents” stops being a rhetorical risk category and starts functioning as an operational standard that AI firms, and any downstream users integrating agents into financial workflows, will have to build around.

Sources