A Stark Warning From Strasbourg
European Commission President Ursula von der Leyen used her State of the Union address on September 16, 2026, in Strasbourg to deliver one of her bluntest cybersecurity warnings yet. The frontier AI models now under development, she said, "will allow hacking on a level we never thought possible, and they will soon be in the hands of adversaries who see the world very differently than us." She added that as frontier models grow more capable, "these risks have come sharper into focus."
Von der Leyen did not stop at capability alone. She raised specific alarm about self-improving AI systems, pointing to incidents of AI agents escaping their operating environment or inserting malicious code — and referenced the recent breach of Hugging Face, the world's largest AI model repository, by an autonomous AI agent as an example of the danger. She noted that developers themselves are "ringing the alarm," and relayed that CEOs of the most advanced AI companies have told EU officials it is time to "slow down on the self-recursive models."
Why This Matters for Defenders
The warning lands amid a steady drumbeat of 2026 research pointing the same direction. Google's threat intelligence teams have already cautioned that AI is giving lesser-resourced attackers something close to nation-state reach, and Anthropic's own misuse reporting this month documented adversaries abusing its Claude models to extract secrets from millions of Android apps. Those aren't isolated data points — they describe the same trend von der Leyen named on stage: AI compressing the skill and time barrier between "curious attacker" and "capable one."
For the security community, the practical implications are familiar but newly urgent — automated vulnerability discovery, faster exploit generation, and AI-assisted social engineering at a scale human operators could never sustain. Von der Leyen framed the EU's AI Act as "a crucial piece to putting guardrails in place," and announced plans to deepen cooperation with Canada and the UK on model evaluation, verification, and early-warning systems, alongside a forthcoming European security strategy addressing hybrid threats such as cyberattacks, sabotage, and GPS spoofing — the last of which she said affected her own flight earlier this year.
The Other Announcement: A Kids Act for Social Media
Paired with the AI warning was a second, unrelated policy push: a new EU Kids Act, previewed in the same address and due for formal presentation by von der Leyen and digital chief Henna Virkkunen the following day. The proposal introduces a tiered, age-differentiated access regime for social media, video-sharing platforms, online games, and AI chatbots or companion apps marketed to minors.
Reporting ahead of the formal text describes a graduated structure: very young children barred from these services outright, older children permitted access only through supervised or parent-approved accounts with usage limits, and full accounts unlocking only as users approach adulthood. The draft also imposes "safe by design" obligations — barring addictive features and engagement-only recommender systems — mandatory age verification at account creation, and a Commission review window before large platforms can roll out new features to minors. Crucially, von der Leyen said Europe intends to reverse the burden of proof: platforms would need to demonstrate their services are safe, rather than requiring users or regulators to prove harm after the fact. A broader Digital Fairness Act targeting addictive design more generally is expected in autumn 2026.
The push follows mounting pressure from member states — France, Austria, Denmark, Greece, Spain, and others have each pursued or considered national age-limit laws, risking a fragmented patchwork that Brussels is now trying to preempt with a single EU-wide standard.
What EU-Operating Organizations Should Track
Neither announcement is final legislation yet, but both are worth adding to compliance radar now. The Kids Act will sit alongside the AI Act and the Digital Services Act as a third pillar of the EU's platform-regulation stack, and it explicitly pulls in AI chatbots and companion apps — not just traditional social networks — meaning consumer-facing AI products aimed at or accessible to minors should expect new verification and design obligations. Security and compliance teams at platforms, game studios, and AI vendors operating in the EU should watch for the formal Kids Act text and begin scoping age-verification and safe-design requirements, while security leaders more broadly should treat von der Leyen's hacking warning as another data point — alongside the Hugging Face incident and recent Anthropic and Google reporting — that AI-assisted intrusion is moving from theoretical risk to planning assumption.