EU officials say rogue AI-agent hacks show why high-risk systems need monitoring
Reuters reports that the European Commission is in talks with OpenAI and Anthropic after recent hacking incidents involving their AI models. An EU official said those incidents highlight the need for monitoring by developers under the bloc's AI rules. The report does not say either company violated the AI Act.
The harder question is what a regulator can inspect after an agent run. A policy summary may show which rule applied, but not which tools were called, which credentials were active, or when an approval stopped matching the task.
For future oversight, I think the useful unit is a time-bound action record: tool use, credential scope, approvals, and results that can be checked without rerunning the system.
Which part of that record should the AI Act require providers to preserve first?