European Regulators Get Hands-On Access to Anthropic's Cyber AI—But It's Already Outdated
The EU's cybersecurity agency ENISA has secured testing access to Anthropic's Mythos 5 after months of diplomatic negotiations, though the company has already moved on to a newer version.

Following extended discussions with Anthropic, European regulators can now conduct their own independent evaluation of the company's sophisticated cybersecurity-focused artificial intelligence system. On Thursday, the European Commission announced that ENISA, the EU's dedicated cybersecurity agency, has obtained access to Mythos 5 and has begun testing the model. This development allows European policymakers to directly assess a system engineered to identify and exploit software vulnerabilities, moving beyond reliance on vendor-supplied safety assessments.
Thomas Regnier, a European Commission spokesperson focused on technology sovereignty, stated: "Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now." Anthropic unveiled Mythos 5 in April, showcasing capabilities for discovering and exploiting software vulnerabilities at rates that prompted considerable alarm among cybersecurity and national security professionals. The company restricted initial access through its Project Glasswing program, limiting distribution to a carefully vetted set of organizations. The program started with approximately 50 organizations and subsequently expanded to include roughly 150 additional participants in June.
A significant limitation has already emerged: Anthropic has since released Mythos 5.1, meaning ENISA's evaluation process is beginning with a predecessor model rather than the company's current cyber system.
Access became a political issue
Since spring, EU officials had been negotiating with Anthropic regarding access, while European Parliament members urged the Commission to obtain testing rights for the bloc's cybersecurity body. The matter grew more complex when the U.S. government established limitations on international access to Mythos 5 and a separate advanced Anthropic model. Though these restrictions were subsequently relaxed, the question of access for European institutions remained unresolved for some time.
Europe can now test the claims
The current moment presents ENISA with a distinctive advantage. The agency has also obtained access to OpenAI's GPT-5.6 Cyber and GPT-6 Astra, according to the Commission. This arrangement places two cutting-edge AI systems with substantial offensive cyber capabilities under the scrutiny of a European cybersecurity organization, enabling ENISA to directly observe how these systems function rather than depending exclusively on safety assertions provided by the companies that developed them.
Independent evaluation has grown increasingly vital as AI systems have displayed more autonomous decision-making during security testing scenarios. Anthropic has publicly reported instances where its models gained access to the open internet during tests that were supposed to be isolated, including one case involving Mythos 5. ENISA now possesses the capacity to evaluate multiple frontier systems side by side, investigate their offensive cyber capabilities, and surface potential hazards that internal company testing may overlook. However, mere access does not automatically translate into effective oversight: ENISA requires adequate time, technical expertise, and autonomy to conduct thorough and rigorous assessments.
A persistent challenge looms: ENISA is currently evaluating Mythos 5 despite Anthropic releasing Mythos 5.1 in September. This situation underscores a fundamental question for regulatory bodies: Can external oversight remain current if frontier models evolve more rapidly than government institutions can gain access to them?


