Law report No. GLW-4616 · filed October 10, 2026

Regulation & EnforcementReported case

Anthropic, OpenAI Face New EU AI Act Scrutiny, CNBC Reports

Anthropic and OpenAI face new scrutiny under the EU AI Act's enforcement powers, per CNBC. Regulators activate tools that carry fines up to €35 million or 7% of global turnover.

By Priya Raman3 min read685 words

Holding

  1. Anthropic and OpenAI named in CNBC report on EU AI Act enforcement scrutiny
  2. EU AI Act penalty ceiling set at €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices
  3. General-purpose AI model obligations took effect August 2, 2025
  4. EU AI Act Regulation (EU) 2024/1689 entered into force August 1, 2024
  5. Systemic-risk threshold set at 10^25 floating-point operations of training compute

Anthropic and OpenAI stand among the artificial-intelligence developers that European Union regulators have begun examining under the bloc's new AI Act, according to a CNBC report.

The CNBC report, headlined "Anthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers," names the two frontier-model developers. The piece describes a feature of the Act's enforcement phase.

What enforcement powers does the EU AI Act provide?

Regulation (EU) 2024/1689, the EU AI Act, entered into force on August 1, 2024 and applies in phases. Member states had to designate national competent authorities by August 2, 2025. The European AI Office, sitting inside the Commission, took up coordination duties in June 2025.

How are the penalties structured?

National authorities can demand documentation, conduct audits, and order the withdrawal or recall of non-compliant systems. Administrative fines reach €15 million or 3% of worldwide annual turnover for most breaches.

For use of prohibited AI practices, fines reach €35 million or 7% of worldwide annual turnover, whichever figure is higher. That ceiling is the steepest financial penalty in any current EU digital rulebook, exceeding the 4% turnover cap of the General Data Protection Regulation.

Which obligations apply to OpenAI and Anthropic?

Both companies develop general-purpose AI models — the foundation systems that underpin consumer products such as ChatGPT and Claude. The Act treats such models under a dedicated chapter.

Providers must keep technical documentation current, supply information to downstream deployers, and maintain a copyright policy covering training data. Non-compliance can trigger penalties across the EU and the wider European Economic Area.

What additional duties attach to large models?

Models trained using more than 10^25 floating-point operations face a "systemic risk" tier with extra duties. Those include model evaluation, adversarial testing, serious-incident reporting, and cybersecurity protection.

OpenAI's GPT-4-class systems and Anthropic's Claude-class systems sit well above the 10^25-FLOP threshold. Both firms have already published some of the elements the new obligations formalise.

What does the new scrutiny mean for in-house counsel?

The shift is operational. Companies should expect:

  • Information requests from national competent authorities, with statutory response deadlines
  • Possible on-site or remote audits of training pipelines and documentation
  • Advance-notice duties when a provider learns of a serious incident
  • A move from "compliance planning" to "compliance demonstration"

Documentation depth will matter as much as documentation existence. Files must show how risk classifications were derived, what human-oversight measures apply, and how post-market monitoring is structured.

What did the CNBC report actually say?

The CNBC report is brief. It names Anthropic and OpenAI as firms in regulators' sights and frames the development as part of the EU AI Act's enforcement phase.

The version available does not name a specific national authority, cite a case reference, or quote a regulator. Practitioners should track European AI Office disclosures for concrete case openings.

When do the remaining AI Act obligations take effect?

The Act's provisions stagger across three years:

  • February 2, 2025 — prohibitions on the most intrusive practices
  • August 2, 2025 — obligations for general-purpose AI models and the penalties regime
  • August 2, 2026 — most duties for high-risk AI systems
  • August 2, 2027 — extended transition for embedded high-risk systems

Each phase widens the surface area available for enforcement.

What should compliance teams prioritise now?

Five items lead the list for AI providers selling into the EU:

  • Technical documentation meeting Annex XI for general-purpose models with systemic risk
  • Copyright-policy disclosures covering training-data sources and rights reservations
  • A serious-incident reporting workflow aligned with the August 2025 obligations
  • Product mapping against Annex III high-risk classifications ahead of August 2026
  • Internal-audit training on conformity-assessment evidence

External counsel with EU regulatory practices will see an uptick in mandates for conformity-assessment reviews and representation before national authorities.

The bottom line

The CNBC report marks a transition point. The EU AI Act has moved from rule adoption to active policing. Anthropic and OpenAI are the named examples in the report. The regulatory posture it describes applies sector-wide.

via GN Enforcement (Source)

Filed under

  • eu-ai-act
  • anthropic
  • openai
  • ai-regulation
  • european-ai-office
Share this article:

More from Priya Raman

Priya Raman

Show full bio

Staff writer covering consumer brands and retail at Global Law Wire.

187 articles

Also before the court

« Previous articleNext article »