Publications Archive
This archive contains all documents published by cep over the last few years
- cepAdhoc: Incisive comment on current EU policy issues
- cepPolicyBrief: Concise reviews of EU proposals (Regulations, Directives, Green Papers, White Papers, Communications) – including an executive summary
- cepInput: Impulse to current challenges of EU policies
- cepStudy: Comprehensive examination of EU policy proposals affecting the economy
2026
cepNews: The OpenAI-Hugging Face Incident: Reward Hacking Was Not the Whole Story
- The technical details on the Hugging Face hack presented at the Black Hat conference in early August show a collective of AI model instances sharing exploits, rather than a single rogue agent.
- Chain-of-thought monitoring, currently the central hope of AI oversight, offers little practical protection, as detectability in a single trajectory is not the same as operational alerting across millions of them.
- The most consequential AI security incident to date likely falls outside the AI Act’s reporting regime because Art. 2(8) exempts pre-market testing, and Art. 55(1)(c) relates to market access.
On 5 August at the Black Hat USA conference in Las Vegas, OpenAI staff members Michael Dalton and Eric Wallace spent forty minutes reconstructing the recent incident in which an unreleased OpenAI model escaped its evaluation container and obtained internet access. The model then compromised the infrastructure of the popular website Hugging Face in order to obtain benchmark solutions. Both companies confirmed the events in late July. This latest reconstruction provides additional details that alter the way in which the case should be classified – with important ramifications for AI safety research and Europe’s new AI office. Anselm Küsters, digitalisation expert at CEP, explains the details and contextualises OpenAI’s conference presentation.
More2026
cepNews: The “Migration Crisis” in Ceuta and the EU Pact on Migration and Asylum: Three Lessons for Europe
The unprecedented influx of migrants from Morocco to Ceuta at the end of July tested the ability of the Member States to implement effective, joint and coordinated initiatives for managing migrants in times of need. Between 30 and 31 July 2026, as many as 60,000 people – some sources even put the figure as high as 70,000 – swam several hundred metres and scaled the fences along the border of the Spanish exclave in order to enter Ceuta from Morocco. According to the latest reports, at least 80 people are believed to have died while attempting to cross and, with many still missing, the death toll could rise.
More2026
cepInput: EU Anti-Coercion Trade Governance
- The EU still lacks a coordinated strategy to protect itself against economic coercion by countries such as China or the US.
- To increase the deterrent effect, a clearly defined framework of countermeasures is needed, focusing on the economic vulnerabilities of the opponents.
- In the future, countermeasures should be coordinated with close trading partners to increase their effectiveness.
The EU aims to reduce its vulnerability to economic coercion through the Anti-Coercion Instrument. The Centre for European Policy (cep) has assessed the instrument’s effectiveness to date and recommends clearer guidelines for economic countermeasures as well as close cooperation with trade partners.
More2026
cepNews: OpenAI Model Attacks Hugging Face: A Reward-Hacking Incident That Puts Alignment Theory into Practice
- During an internal test, a yet-to-be-released OpenAI model escaped its isolated environment and compromised Hugging Face’s systems in order to steal the model answers for the test in progress.
- The incident is a textbook example of reward hacking and specification gaming, and demonstrates that the actual source of risk is not the language model itself, but the scope for autonomous action granted to it.
- To contain the attack, a Chinese open-weight model – of all things – was used alongside US models, underscoring the urgency of developing independent European capabilities.
On 21 June, OpenAI and Hugging Face jointly disclosed a security incident that is unprecedented in this form and is likely to fuel the European debate on the looming cyber risks posed by artificial intelligence. During an internal test of the cyber capabilities of OpenAI’s latest models – including GPT-5.6 Sol and a yet-to-be-released, more powerful model – the system breached the test environment, which was supposed to be strictly isolated, and infiltrated Hugging Face’s infrastructure. Anselm Küsters, an expert in digitalisation and AI at cep, assesses the incident in an initial analysis.
More2026
cepInput: Social Reforms in the AI Transformation
- As early as 2027, Germany’s social security schemes face funding shortfalls of over 50 billion euros. AI threatens to widen such shortfalls in the long term through a gradual shift from wage income to capital income.
- AI is largely invisible to statistical leading indicators. Initially, AI reduces entry-level positions and new hires without this being reflected in traditional labour market statistics.
- The cep is calling for AI satellite accounts, a binding AI review mechanism as part of pension reform, and clear rules on how the labour factor can share in AI-generated capital gains.
As early as next year, Germany’s social security systems will face funding shortfalls totalling over 50 billion euros. The Centre for European Policy (cep) shows in a new policy paper that the current reform debates underestimate the extent to which artificial intelligence (AI) could widen these gaps even further in the long term. As the financing of Germany’s social security systems relies heavily on the wage bill, a shift towards investment income structurally weakens their contribution base.
More
2026
cepNews: ETS-Review: The Foundations of Emissions Trading Must Remain Intact
- The reform of the emissions trading scheme sets the course for the future EU climate policy
- The expectation of rising CO₂ prices remains crucial to the financial viability of investments in climate-friendly technologies
- Interventions in CO₂ pricing jeopardize investment incentives in the green transition and contribute to long-term market uncertainty
2026
cepInput: The EU’s Path to Strategic Autonomy
Fierce technological competition, disrupted supply chains and opaque subsidy practices by third countries: Europe’s growth model, based on open markets, has become vulnerable. In a recent study, the Centre for European Policy (cep) concludes that, in the face of a fragmented global economy, the EU must combine its open trade orientation with greater strategic independence. The study is part of a collaborative project with LUISS University in Rome.
More2026
cepExecutive: Shadow AI as a Business Risk
- SMEs are increasingly vulnerable to AI-enabled attacks. Company-wide cyber resilience must therefore be a top priority in future.
- ‘Shadow AI’ – that is, AI applications and agents that enter the organisation via private accounts – is regarded as a gateway for AI-driven cyber attacks.
- The EU AI Act has so far provided only inadequate protection against risks posed by AI agents
With its new ‘cepExecutive’ format, the Centre for European Policy (cep) aims to target businesses specifically and provide them with quick and clear information on current technological, regulatory and geopolitical developments that impact the market, competition and strategy. To kick off the new series, we provide information on shadow AI as a growing business risk and offer guidance on what businesses and policymakers can do to prevent cyberattacks.
More2026
cepStudy: Europe’s Twin Dependencies: Building Energy and Digital Autonomy in a Fragmented World
Since the return of the Trump administration, the goal of greater strategic autonomy has once again been at the top of the European agenda. Yet behind this political buzzword lies an uncomfortable reality. Europe is structurally dependent in two of the most important sectors for the future: green energy technologies and digital infrastructure.
More2026
cepNews: US Access Ban on Anthropic’s Fable/Mythos 5: More of a Geopolitical Signal than a Necessary Security Measure
- The US government’s decision to block global access to Fable/Mythos 5 is one of the most far-reaching interventions in AI policy to date, yet its public justification raises more questions than it answers.
- Using jailbreaks as justification for a global shutdown is problematic: every leading frontier model is vulnerable to jailbreaks to some extent, and no provider has yet presented a universal solution.
- Europe must draw the right conclusions: instead of unrealistic plans for technological self-sufficiency, it needs greater resilience through credible alternatives, including competitive open-weight models.
On 12 June, the US Department of Commerce issued an export control directive instructing the popular AI developer Anthropic to block access to its latest models, Fable 5 and Mythos 5, for foreign nationals both at home and abroad. As reliable filtering by nationality was technically unfeasible, Anthropic subsequently disabled both models completely for all users worldwide. The effects were already being felt over the weekend. Anselm Küsters, an expert on digitalisation at cep, assesses the decision in an initial analysis.
More