European Commission says it is in close contact with Anthropic and OpenAI regarding hacking incidents
Commission outreach of this kind sits in the category of early-stage engagement rather than enforcement: historically, public confirmation that a regulator is in contact with firms over a security incident has preceded information-gathering and, only later, any formal process, and the gap between the two has usually been measured in months rather than weeks. The firms named are private, so the direct equity read-through runs through listed partners and investors, a channel that in past episodes has moved prices only where the incident touches shared infrastructure, integration dependencies, or contract-level liability rather than the headline alone. The distinction worth drawing is between a breach confined to a model provider's internal systems and one affecting enterprise deployments or customer data, since only the latter has tended to trigger disclosure obligations and the sustained regulatory follow-through. The operative framework here is the EU's incident-reporting regime, which sets the clock and the threshold for what must be disclosed and to whom. The follow-ons are any formal notification from the companies, confirmation of scope from the Commission, and whether other national authorities signal parallel contact.