The European Union’s cybersecurity agency has gained access to Anthropic’s advanced Mythos 5 artificial intelligence model after more than three months of discussions with the US-based technology company.
The European Commission said the European Union Agency for Cybersecurity (ENISA) is now testing the model, whose access had initially been limited because of its powerful cybersecurity capabilities.
“Following our constructive engagement with Anthropic, we can confirm that the EU’s cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now,” said Thomas Regnier, the European Commission’s spokesperson for tech sovereignty.
Anthropic introduced a preview of Mythos 5 in April. The model was designed with capabilities that allow it to identify and exploit software vulnerabilities at high speed, raising concerns about its potential use in cyberattacks.
Because of those capabilities, Anthropic initially limited access through Project Glasswing, a programme operated in cooperation with the US government. The initiative began with about 50 organisations in April before being expanded by roughly 150 additional partners in June, taking participation to around 200 organisations.
The situation became more complicated after the US government introduced export restrictions that prevented non-American users from accessing the technology worldwide. The restrictions also affected Anthropic employees based outside the United States.
The measures prompted concerns in Brussels about whether European organisations were being treated differently from US partners. European officials also raised broader questions about the ability of Washington to restrict access to advanced American technology.
The European Commission continued discussions with Anthropic and eventually secured access for ENISA on Thursday.
The development comes as the EU seeks greater technological and cybersecurity capabilities while maintaining oversight of rapidly developing artificial intelligence systems. The European Commission has significant regulatory authority under the EU AI Act, which sets rules for high-risk and advanced AI technologies.
Access to highly capable models can also provide regulators and cybersecurity specialists with an opportunity to assess their potential risks and security implications directly.
Regnier said ENISA had previously received access to OpenAI’s GPT-5.6-Cyber model. He added that the agency had also been granted access to OpenAI’s latest model, GPT-6 Astra.
The EU’s access to Mythos 5 gives its cybersecurity specialists an opportunity to test one of the most capable AI systems in the cyber field and assess both its defensive applications and the risks associated with its ability to identify software vulnerabilities.
