Mind the (compliance) gap

August 13, 2026

It’s been quite an eventful few weeks for those of us in the world of AI security.

First, it was OpenAI, then Anthropic, then Meta. Over the past few weeks, there have been so many examples of AI systems behaving in unexpected and potentially dangerous ways that it’s been hard to keep up.

Here’s a quick recap.

It began with OpenAI reporting that one of its models had hacked rival company Hugging Face. The model found a way out of its testing environment into the internet, compromised Hugging Face and obtained the answers it was looking for. It later emerged that this was not an isolated incident. Then Meta announced that one of its AI models had inadvertently been given internet access because of a “misconfiguration” during a third-party test. Meanwhile, the UK’s AI Security Institute (AISI) reported that GPT and Mythos agents had carried out a hacking campaign against real people, creating fake online identities in the process. The activity was detected during routine testing and took an hour to contain.

Hugging Face co-founder Thomas Wolf described the incident involving his company as a “wake-up call” for the technology industry.

It certainly is.

There is also some irony in the timing. On 2 August, new EU AI Act transparency obligations came into force, requiring organizations to make clear when people are interacting with AI rather than a human, and to label AI-generated or manipulated content such as deepfakes. Companies that fail to comply can face significant financial penalties.

But what is most interesting about the latest obligations is what isn’t there, because compliance deadlines relating to high-risk AI systems have been pushed back to December 2027 and August 2028 as part of the Digital AI Omnibus.

The misalignment is difficult to ignore; serious incidents are emerging with increasing regularity while some of the most important compliance deadlines are moving further into the future. The gap is widening.

So, what does this mean for those developing AI, and for those deploying it?

For developers, the message should be clear. We are seeing significant security failures involving some of the world’s most sophisticated AI companies. Models and agents are becoming more capable, more autonomous and, in some cases, more adept at circumventing the guardrails placed around them.

Whatever the regulatory timetable, the industry cannot afford to treat safety as a periodic compliance exercise. Pre-deployment testing and occasional spot checks are not sufficient. Continuous monitoring, supported by real-time audit trails, needs to become part of the operating model.

For organizations using AI, consider this: Anthropic’s incidents dated back to April, and were only discovered after OpenAI’s disclosure prompted Anthropic to review its own systems. Months passed before anyone knew. That is the case for continuous monitoring in a single fact, and it’s the lesson for every organization deploying AI, not just the companies building it. 

Outsourcing the technology does not outsource the risk. If an AI system operating within your organization behaves in an unintended or harmful way, it is your customers, systems, data and reputation that may be affected. Safe deployment therefore needs to sit at the heart of every AI procurement decision.

As agents become capable of deception, malicious activity and attempts to conceal what they have done, organizations need to know how those systems are behaving in practice, not simply how they performed during testing. That means monitoring their behaviour, recording their actions and ensuring there is a reliable audit trail when something goes wrong.

Regulation matters. But AI risk is moving faster than the regulatory timetable. Organizations cannot afford to wait for the compliance gap to close.

Try RAIDS AI for free with AWS

Nik Kairinos