In July, OpenAI’s models broke into Hugging Face’s systems. OpenAI’s recently released technical report on the incident revealed that an “internal-only research model had the broadest confirmed role in the incident.” This raises the question of whether the European Union’s AI Act applies to models not released publicly but merely deployed internally.
This question is not new. It is especially important in the context of recursive self-improvement or, in other words, artificial intelligence (AI) systems being able to create new versions of themselves entirely autonomously, which often constitutes the internal deployment of AI. Indeed, AI companies have already made several statements about AI systems being heavily involved in AI research and development, with both Anthropic and OpenAI claiming that AI writes up to 80 percent of the company’s code, and Google and Meta not trailing far behind.
While the companies claim humans still review the code and while agentic coding based on human commands falls short of AI systems’ true independence in self-improvement, the companies also warn that it may not be long before AI takes the reins. AI achieving such capabilities would have numerous implications, including losing control over the AI system after it surpasses our own capabilities.
This is why it is of utmost importance to examine whether the EU AI Act, the world’s first comprehensive AI legislation, regulates internal deployment. With the European Commission having been able to exercise its enforcement powers under the EU AI Act since Aug. 2, an affirmative answer to this question would enable the European Commission to take action (including by imposing fines) against AI companies that conduct autonomous AI research and development or otherwise internally deploy their models without complying with the EU AI Act.
by Lawfare – You Don’t Have to Sell It to Be Bound by It: GPAI and the EU AI Act



