EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model

ENISA is testing Anthropic’s Mythos 5 after gaining access to the advanced cyber AI following months of negotiations. Image: Christian Lue/Unsplash

ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.

Sep 11, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

Europe can finally put Anthropic’s advanced cyber AI through tests of its own.

The EU cybersecurity agency ENISA has gained access to Mythos 5 after months of negotiations with Anthropic, the European Commission said Thursday. The access gives European officials a chance to independently examine a model designed to find and exploit software vulnerabilities rather than relying solely on assessments from its developer.

“Following our constructive engagement with Anthropic, we can confirm that the EU’s cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now,” European Commission technology sovereignty spokesperson Thomas Regnier said, according to Euronews.

Anthropic first previewed Mythos 5 in April as a model capable of finding and exploiting software vulnerabilities at speeds that raised significant cybersecurity and national security concerns. Because of those capabilities, the company initially limited access to a small group of vetted organizations through its Project Glasswing program.

The program began with about 50 organizations before expanding by roughly 150 more in June.

There is already one catch: Anthropic has since released Mythos 5.1, meaning ENISA is beginning its evaluation with a model that is no longer the company’s newest cyber system.

Access became a political issue

EU officials had been discussing access with Anthropic since the spring, while members of the European Parliament pushed the Commission to secure access for the bloc’s cybersecurity agency.

The situation became more complicated after the U.S. government imposed restrictions on foreign access to Mythos 5 and another advanced Anthropic model. Those restrictions were later eased, but access for European institutions remained unresolved.

What's hot at TechRepublic

Advertisement

Europe can now test the claims

The timing gives ENISA an unusual opportunity. The agency has also received access to OpenAI’s GPT-5.6 Cyber and GPT-6 Astra, according to the Commission.

That puts two frontier AI systems with significant cyber capabilities in the hands of a European cybersecurity body, allowing ENISA to examine their behavior rather than relying solely on safety claims made by their developers.

The need for independent testing has become more pressing as AI systems have demonstrated increasingly autonomous behavior during security evaluations. Anthropic recently disclosed incidents in which its models reached the open internet during supposedly contained tests, including one involving Mythos 5.

ENISA now has an opportunity to compare advanced models, probe their offensive cyber capabilities and identify risks that may not emerge from company-run evaluations. But access alone does not guarantee meaningful oversight: ENISA must have sufficient time, technical resources and freedom to test the systems rigorously.

There is also a moving-target problem. ENISA is testing Mythos 5 even though Anthropic released Mythos 5.1 in September, raising a broader question for regulators: Can outside oversight keep pace if frontier models advance faster than governments gain access to them?

Other news: CISA’s reported ChatGPT incident is raising broader questions about AI governance as organizations struggle to determine who is accountable when AI agents access and act on sensitive data.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.