EU Cybersecurity Agency Gains Access to Anthropic’s Mythos 5

ENISA can now test Anthropic's restricted AI model after months of talks, though it still lacks the newest Mythos 5.1 version

The European Commission announced that ENISA, the EU’s cybersecurity agency, has finally been given access to Anthropic’s Mythos 5 model, more than three months after the company first indicated the bloc would receive it. Commission spokesperson Thomas Regnier said in a statement that the constructive dialogue with Anthropic had resulted in ENISA being granted entry to the system, and that the agency has already begun testing it. Anthropic did not offer a comment on the matter.

Anthropic first showed off Mythos back in April. Because the model is unusually effective at finding and exploiting software vulnerabilities, the company kept it under tight control, limiting access to a small group of vetted organizations through an internal effort called Project Glasswing. That caution reflects a broader trend: governments and safety bodies have grown more anxious about advanced AI systems being used to probe or break into computer networks, especially after separate reports that AI agents had been linked to unauthorized intrusions at other companies.

Talks between Anthropic and the EU reportedly started in late May, after European officials lobbied the company to include ENISA among the institutions with access. What followed was months of back-and-forth over exactly what kind of access ENISA would get and how far it would extend. The negotiations grew more complicated when the U.S. government temporarily barred non-U.S. users from Mythos 5 and a related model, Fable 5, under an export-control directive. Even Anthropic’s own staff outside the United States lost access during that period. The restriction was lifted at the end of June, after which Fable 5 became widely available again, but Mythos 5 stayed limited mostly to approved American organizations for some time longer.

Even now, the access ENISA has secured is only partial: the agency has not been given the newer Mythos 5.1 model, according to the Commission. Britain’s AI Safety Institute, an early tester of the original Mythos release, reportedly has not received access to this newer version either.

The timing is notable. Pressure had been building on Anthropic from multiple directions. In May, a group of European lawmakers wrote to a senior Commission official warning that the bloc’s cybersecurity rules were not equipped to handle a new wave of AI-driven hacking tools, and pushed for ENISA to be given access. Separately, obligations under the EU’s AI Act covering systemic-risk general-purpose models became enforceable on August 2, giving regulators a formal basis to seek direct access to powerful models rather than relying only on information from developers. Around the same time, ENISA was also given access to OpenAI’s newest model, meaning the agency is now testing two frontier systems within days of each other.

Observers say the episode could set a precedent for how quickly regulators are able to obtain hands-on access to powerful AI systems in the future, and how that access holds up against the pace at which companies release new versions.

Follow tovima.com on Google News to keep up with the latest stories
Exit mobile version