When Jacob Coxon, a researcher at Anthropic, announced his resignation this week with a warning that the people building advanced AI "earnestly believe" their models "could kill us all by the end of the decade," the reaction in Brussels was notably restrained. Not dismissive. Not panicked. Instead, the prevailing response from EU policymakers amounted to: we already have a law for this.
On 30 September, European Parliament lawmakers will raise Coxon's warning in a formal session with the European Commission. The discussion, part of a regular enforcement check-in, will give legislators a platform to press the Commission on how it is applying the AI Act's obligations for "systemic-risk" models, the category covering the most powerful general-purpose AI systems developed by companies such as OpenAI and Anthropic.
A law written for this scenario
The EU's Artificial Intelligence Act, which entered into force in August 2024, classifies certain general-purpose AI models as posing systemic risk if they exceed defined computational thresholds. Companies developing these models must assess and mitigate risks including loss of control over a model and "misalignment," the technical term for when an AI system's objectives diverge from human intentions.
Michael McNamara, an Irish member of the European Parliament and co-lead of its AI monitoring group, was blunt about the connection. "In my view, the EU has already legislated for exactly this scenario: it is called the AI Act," he said.
His counterpart, Italian Social-Democrat Brando Benifei, who served as the Parliament's lead negotiator on the AI Act, pushed for enforcement rather than new legislation. "This is exactly why the AI Act created obligations for systemic-risk models. Europe must now enforce them fully," Benifei said.
The European Commission, which is responsible for enforcing the law, pointed to the existing framework. "The EU already has a legal framework to regulate and mitigate the risk posed by advanced models," Commission spokesperson Thomas Regnier said in a statement.
Independent oversight, contracted in
Enforcement of the systemic-risk provisions falls to the Commission's Artificial Intelligence Office. That office has already begun contracting independent researchers to carry out regulatory oversight. One such contractor is METR, a California-based non-profit research organisation that evaluates AI model capabilities and risks.
METR's involvement in European regulatory work is not purely theoretical. The organisation was called in by OpenAI researchers after a July hack of the AI platform Hugging Face, in which OpenAI-powered agents behaved erratically. That incident, though resolved, illustrated the kind of failure mode the systemic-risk provisions are designed to address.
Vindication and political calculation
For European officials who spent years defending the AI Act against critics who said Europe was regulating technology it did not yet understand, Coxon's resignation and the ensuing alarm have offered a measure of vindication. Since the release of ChatGPT in 2022, the EU was repeatedly mocked by technology enthusiasts for regulating an emerging field. The current panic in Silicon Valley has shifted that conversation.
Uljan Sharka, chief executive of Domyn, an Italy-based company that develops AI models for regulated industries, described Coxon's post as "ridiculous" but said the resulting panic presented a "massive opportunity" for Commission President Ursula von der Leyen to explain the purpose of the AI Act in her State of the European Union speech, scheduled for Wednesday.
"One of the points where Europe is failing is that it does things in the right way, but we're not explaining them enough," Sharka said. "This is not about slowing down innovation; this is about building actually even faster, but with a safe approach."
The gap between law and enforcement
The harder question is whether the AI Act's systemic-risk provisions, as currently written and enforced, are sufficient to address the kind of catastrophe Coxon describes. The law requires companies to identify and mitigate systemic risks before deploying a model. It gives the Commission power to request documentation, conduct evaluations and impose fines. But the provisions apply only to models that exceed a computational threshold for training, a metric that may not capture every dangerous capability.
Coxon's warning was not about a specific model that already exists. It was about the trajectory of AI development and the stated beliefs of people building it. The AI Act can require risk assessments for individual models. It is less clear that it can compel companies to stop pursuing capabilities that their own researchers believe could become existentially dangerous.
What the Commission faces
Von der Leyen's speech next week will be watched for any signal about how the Commission intends to apply the AI Act's systemic-risk rules in practice. The law is on the books. The enforcement mechanisms exist. But designating OpenAI's or Anthropic's frontier models as systemic-risk, and then enforcing compliance, will require technical capacity that the AI Office is still assembling.
There is also a diplomatic dimension. American AI companies are investing tens of billions of dollars in model development and have powerful allies in Washington. Confronting them over risk assessments and misalignment concerns will require political resolve as much as technical expertise.
People mentioned
Organisations
European Parliament · European Commission · Anthropic · OpenAI · Domyn · METR