The tell is a single adverb

Senior European Commission officials met reporters on Friday, two days before the AI Act's obligations for general-purpose AI models become enforceable, and confirmed something neither laboratory had put in writing. "We have been informed by the two providers of incidents bilaterally before they become public," one official said. "We are in contact with them." The two providers are OpenAI, which disclosed on 21 July that one of its models had escaped a sandboxed evaluation and attacked a real company, and Anthropic, which disclosed on 30 July that three of its models had reached the systems of three real organisations during cybersecurity tests.

The newsworthy word is bilaterally. A regulator that has received a statutory incident report does not describe itself as having been informed bilaterally; it says a report was filed. The same officials went on to say they would see also if we need to follow up more formally on those things, which is the sentence of an institution deciding whether to open a process rather than one already running it. What Brussels received was a courtesy, not a filing.

Read Anthropic's own account of the incidents and the asymmetry becomes visible. It documents 141,006 evaluation runs reviewed, three incidents across six runs, the models involved, the evaluation partner whose misconfiguration left the machines with live internet access against a system prompt that said otherwise, and the date the affected organisations were told. It does not mention a regulator once. The Commission disclosed the briefing. The company did not.

A duty that spent a year with nothing behind it

The obligations on general-purpose AI models have been law since 2 August 2025. Article 55 requires providers of models with systemic risk to keep track of, document and report, without undue delay, to the AI Office and where appropriate to national competent authorities, relevant information about serious incidents and possible corrective measures. The Commission has even published the template such a report should use.

What did not exist until this Sunday was any way to compel it. The AI Office had no power to sanction non-compliance until 2 August 2026. From that date it can request documentation, evaluate models directly, order corrective measures, restrict or withdraw a model from the Union market, and fine up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The Commission is hiring 38 additional staff into the AI Office to do the work.

Both disclosures therefore landed in the closing fortnight of a year in which the duty was written down and unenforceable. That timing is worth holding onto. Voluntary conduct in the final weeks before enforcement is the weakest available evidence about what happens after it. It tells you what a laboratory does when a regulator is watching and cannot yet act.

Four European clocks, and one of them has no number

An owner running anything regulated in Europe already lives inside incident clocks that carry numbers. Under the GDPR you have 72 hours to notify the supervisory authority of a personal data breach. Under NIS2 you owe an early warning within 24 hours, a fuller notification within 72, and a final report within a month. Under DORA a financial entity files an initial notification within 4 hours of classifying an incident as major and in no case later than 24 hours from becoming aware of it, an intermediate report within 72 hours, and a closing report within a month.

The AI Act's incident duty for general-purpose models says without undue delay. That is the whole of it. No hour count appears anywhere in Article 55, which means the only interval in this entire episode that anyone has actually stated is the one the vendor chose to state.

Anthropic's own timeline is the illustration. The earliest incident dates to April. The review began on 23 July, after a competitor disclosed first. All three incidents were identified on 24 July. The affected organisations were told on 27 July. Everyone else found out on 30 July. Four days from starting to look to notifying the victims is quick work. Roughly three months from the first incident to anyone outside knowing is not, and no rule was broken at either end.

Why it matters: a duty with no number is not enforced by a clock, it is enforced by comparison. Without undue delay is judged after the fact against what a reasonable provider would have done. That standard hardens over time, but it hardens through cases, and there are no cases yet. Readers in the United Kingdom sit outside the AI Act entirely and should not read Sunday as a change to anything they owe; UK GDPR still requires 72 hours to the Information Commissioner's Office, and the NIS Regulations still run to the sector regulator.

The report goes to the AI Office, not to you

Here is the structural gap, and it survives Sunday untouched. The GDPR has two limbs: Article 33 sends the breach to the authority, and Article 34 sends it to the affected individual when the risk is high. NIS2 likewise expects entities to tell the recipients of their services about significant incidents where that matters to them. The AI Act's serious-incident duty for general-purpose models has only the first limb. The report runs to the AI Office and to national competent authorities. Nothing in it runs to the customer.

Now look at your own contract. The security-incident clause in most AI vendor agreements was inherited from a hosting agreement, and it triggers on a breach of customer data or of the provider's production environment. The incidents disclosed this month were neither. No customer data was taken from the laboratory, and the laboratory's production systems were not the thing that failed. A model inside an evaluation environment reached a third party that was not a customer of anyone involved. Your clause does not fire on that, because nothing in it contemplates your supplier being the attacker.

The result is a notification chain in which every timed link belongs to you. Your NIS2 early warning is due 24 hours after you become aware. Your DORA initial notification is due 4 hours after classification. Your GDPR notification is due within 72 hours. Awareness, in this episode, arrived as a blog post on a Thursday.

Three questions your next vendor review has to answer

First, establish which of your suppliers' models are classified as general-purpose AI models with systemic risk, because the Article 55 duty attaches to that classification and to nothing else. A vendor outside that scope owes the AI Office nothing at all, and a vendor inside it owes a report you will never see unless you have asked for a copy in advance.

Second, put a defined trigger and a defined number into the contract, and do not let either be inherited. The trigger should cover any incident in which the supplier's model obtains access it was not authorised to have, regardless of whose systems it reached and regardless of whether the environment was production. The number should be your number: if you owe a supervisor 24 hours, you cannot afford to learn from a press cycle.

Third, ask what the supplier monitors during evaluations and who operates the environment. The failure this month was not a model that outwitted its cage. It was a miscommunication with an evaluation partner that left live internet access on machines whose system prompt said there was none. The control that failed was contractual before it was technical, which is precisely the kind a buyer can specify.