The European Union's cybersecurity agency ENISA has secured access to Anthropic's Mythos 5, a powerful artificial intelligence model designed to identify and exploit cyber vulnerabilities, after more than three months of negotiations. The confirmation, delivered on 10 September 2026 by the European Commission, marks the first time an EU institution has been able to test a high-risk cyber AI model since the United States imposed export controls on such technology.
Thomas Regnier, the European Commission's spokesperson for tech sovereignty, said: "Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now." The diplomatic phrasing, "constructive engagement," papers over what was clearly a protracted process.
A three-month gap that mattered
Anthropic launched a preview of Mythos 5 in April 2026, making it available to roughly 50 organisations through its Project Glasswing programme. By June, the programme had expanded to approximately 200 partners. ENISA, the EU's designated cybersecurity authority headquartered in Athens, was not among them for months.
Three months is a long time in cybersecurity. During that window, roughly 200 organisations, predominantly American, were evaluating a model capable of probing networks and demonstrating how software vulnerabilities could be breached. European public institutions, responsible for protecting the same infrastructure, were waiting at the door.
Neither Anthropic nor the Commission has disclosed what specific conditions were attached to ENISA's access, or whether the delay stemmed from US export control requirements, Anthropic's own vetting procedures, or some combination of both.
What Mythos 5 does and why it is controversial
Mythos 5 belongs to a category of AI model that security researchers have anticipated for years: one that can autonomously find and exploit vulnerabilities in software systems. This is not a general-purpose assistant. It is a tool built for offensive and defensive cyber operations, capable of scanning systems, identifying weaknesses and demonstrating how they could be compromised.
The dual-use nature of such models is the core problem. The same capability that helps a cybersecurity agency harden its defences could, in different hands, be used for offensive intrusions. That is precisely why the US has sought to control their export, and why the EU's Artificial Intelligence Act classifies them as high-risk systems subject to transparency, safety and oversight requirements.
US export controls and European frustration
The US Commerce Department has progressively tightened restrictions on the export of AI models with significant cyber capabilities. These controls, building on earlier semiconductor export restrictions, are designed to prevent adversaries from obtaining powerful AI tools. They also affect allies.
European officials have repeatedly expressed concern that US export controls could disadvantage European institutions and companies, delaying their access to technology that is commercially available in the United States. The Mythos 5 case illustrates the point: hundreds of organisations had access to the model before the EU's own cybersecurity agency could begin evaluating it.
This asymmetry sits uncomfortably alongside the EU's stated ambition for technological sovereignty, the principle that Europe should be able to assess, regulate and develop technologies affecting its citizens without depending on decisions made in Washington or Silicon Valley.
The AI Act as leverage
The EU's AI Act, which entered into force in August 2024, gives Brussels regulatory tools that did not exist when previous generations of AI were developed. High-risk AI systems, including those used in critical infrastructure and cybersecurity, must meet specific requirements before they can be deployed in the EU market.
Anthropic's willingness to grant ENISA access may reflect a calculation that cooperation with EU regulators is preferable to confrontation. Companies that fail to engage with the AI Act's requirements risk being excluded from the world's largest single market. The Act gives the EU leverage that export controls, designed to restrict technology flows outward, do not give the United States in the same way.
Project Glasswing's selective expansion
Anthropic's Project Glasswing is the mechanism for controlled access to Mythos 5. The programme started with approximately 50 organisations in April 2026 and expanded by roughly 150 more in June, bringing the total to around 200 partners. Anthropic has not published the criteria for partner selection or the full list of participants.
The absence of transparency about who gets to evaluate a model with significant offensive cyber capabilities is itself a regulatory concern. If the primary evaluators of a high-risk system are hand-picked by its creator, the independence of any safety assessment is open to question. ENISA's inclusion, however belated, at least introduces an independent public authority into the process.
What ENISA's testing will involve
ENISA's evaluation is expected to cover whether Mythos 5's capabilities match Anthropic's documentation, whether the model's safety guardrails are robust enough to prevent misuse, and whether it can be integrated into EU cybersecurity operations in a way that complies with the AI Act's requirements for human oversight and accountability.
The results could influence how the Commission classifies models like Mythos 5 under the AI Act, and what conditions it imposes on their deployment within the EU. ENISA's findings are expected to be shared with member states through the EU's existing cybersecurity coordination structures.
People mentioned
Organisations
European Union Agency for Cybersecurity (ENISA) · Anthropic · European Commission