EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

Europe can finally put Anthropic’s advanced cyber AI through tests of its own.
The EU cybersecurity agency ENISA has gained access to Mythos 5 after months of negotiations with Anthropic, the European Commission said Thursday.

EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

Europe can finally put Anthropic’s advanced cyber AI through tests of its own.

The EU cybersecurity agency ENISA has gained access to Mythos 5 after months of negotiations with Anthropic, the European Commission said Thursday. The access gives European officials a chance to independently examine a model designed to find and exploit software vulnerabilities rather than relying solely on assessments from its developer.

“Following our constructive engagement with Anthropic, we can confirm that the EU’s cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now,” European Commission technology sovereignty spokesperson Thomas Regnier said, according to Euronews.

Anthropic first previewed Mythos 5 in April as a model capable of finding and exploiting software vulnerabilities at speeds that raised significant cybersecurity and national security concerns. Because of those capabilities, the company initially limited access to a small group of vetted organizations through its Project Glasswing program.

The program began with about 50 organizations before expanding by roughly 150 more in June.

There is already one catch: Anthropic has since released Mythos 5.1, meaning ENISA is beginning its evaluation with a model that is no longer the company’s newest cyber system.

Access became a political issue

EU officials had been discussing access with Anthropic since the spring, while members of the European Parliament pushed the Commission to secure access for the bloc’s cybersecurity agency.

The situation became more complicated after the U.S. government imposed restrictions on foreign access to Mythos 5 and another advanced Anthropic model. Those restrictions were later eased, but access for European institutions remained unresolved.

What’s hot at TechRepublic


Advertisement

Europe can now test the claims

The timing gives ENISA an unusual opportunity. The agency has also received access to OpenAI’s GPT-5.6 Cyber and GPT-6 Astra, according to the Commission.

That puts two frontier AI systems with significant cyber capabilities in the hands of a European cybersecurity body, allowing ENISA to examine their behavior rather than relying solely on safety claims made by their developers.

The need for independent testing has become more pressing as AI systems have demonstrated increasingly autonomous behavior during security evaluations. Anthropic recently disclosed incidents in which its models reached the open internet during supposedly contained tests, including one involving Mythos 5.

ENISA now has an opportunity to compare advanced models, probe their offensive cyber capabilities and identify risks that may not emerge from company-run evaluations. But access alone does not guarantee meaningful oversight: ENISA must have sufficient time, technical resources and freedom to test the systems rigorously.

There is also a moving-target problem. ENISA is testing Mythos 5 even though Anthropic released Mythos 5.1 in September, raising a broader question for regulators: Can outside oversight keep pace if frontier models advance faster than governments gain access to them?

Other news: CISA’s reported ChatGPT incident is raising broader questions about AI governance as organizations struggle to determine who is accountable when AI agents access and act on sensitive data.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.