Technology · AI regulation
EU AI Office locked out of Anthropic hacking model as staffing crisis deepens
The Commission's safety unit has 36 staff and no access to Mythos, while the UK institute analysed it within days. MEPs and safety groups demand urgent reinforcement.
The European Union's fledgling AI Office, the body charged with policing the most powerful artificial intelligence models under the AI Act, has no access to Anthropic's new Mythos system, a model the company says outperforms human experts at discovering and exploiting software vulnerabilities. The Commission confirmed on Thursday that it is not among the 40 unnamed organisations Anthropic has granted early access to, even as the UK's AI Security Institute obtained the model and published a detailed technical analysis within a week.
A model built for offence
Anthropic unveiled Mythos earlier this month, describing it as an elite hacking model designed to find and exploit vulnerabilities in code. The company says it worked with the US government to prevent a major cyber crisis before release, and has restricted distribution to a limited group of technology firms and unnamed organisations out of cybersecurity concerns. The fear among safety advocates is straightforward: once Mythos or a similar capability becomes public, malicious actors could use it to penetrate critical IT infrastructure at scale.
The UK AI Security Institute, established under the previous government and reporting to the Department for Science, Innovation and Technology, secured access quickly. Its analysis, released within days, was widely praised for illuminating the model's risk profile. "It's possible," said Jimmy Farrell, EU AI policy lead at the think tank Pour Demain, one of eight organisations that signed a joint letter to the Commission. "Europe can do the same, and Mythos makes this all the more urgent."
The UK advantage: access without enforcement
The contrast with Brussels is stark. The UK institute operates at arm's length from regulatory enforcement, it cannot issue fines or sanctions. That independence, former UK National Cyber Security Centre chief Ciaran Martin argued, makes companies more willing to engage. "Having a part of the state that isn't regulatory to engage [with] can be very useful," he said. The EU AI Office, by contrast, shares enforcement of the AI Act with national authorities and can levy fines up to €35 million or 7% of global turnover, whichever is higher.
Stanislav Fort, chief scientific officer at European AI security firm Aisle, said the UK institute's capability is "clearly visible" at "the very frontier of what's possible in the scientific field." He added: "I think this capability is not present right now at the EU AI Office, and it would be amazing to have." The UK also benefits from a direct line to political leadership: Prime Minister Keir Starmer has his own AI adviser, Jade Leung, a former OpenAI lobbyist.
An office too small and too low
The EU AI Office is less than two years old. Its total headcount stands at roughly 140; the safety unit responsible for the most advanced models numbers 36. Critics say that is nowhere near enough for the volume and complexity of frontier models expected in the next few years. The eight safety groups want the safety unit expanded to 160 staff by 2030, matching the size of the teams handling platform enforcement under the Digital Services Act.
Hierarchy compounds the problem. The AI Office sits inside the Commission's Directorate-General for Communications Networks, Content and Technology (DG CONNECT). Officials must navigate multiple management layers before reaching political decision-makers. "They are too detached from where the power lies," said one person who works closely with the safety unit, granted anonymity because they still meet regularly with the office. "They have to go through different steps of hierarchy."
Recruitment against the market
Hiring is a structural headache. The Commission competes with private-sector salaries that can exceed €300,000 for senior AI researchers, while EU pay grades are fixed. London, Paris and Berlin offer more competitive AI ecosystems. The office has "excellent people," the same source said, but they are stretched thin. Commission spokesperson Thomas Regnier countered that "the AI Office has built state-of-the-art model evaluation capacity," though he acknowledged the access gap on Mythos.
Political pressure mounts
Brando Benifei, the Italian social-democrat MEP who co-led the Parliament's AI Act negotiations, demanded the Commission give the AI Office "more staff, deeper technical expertise, and a real budget to match the scale and speed of frontier AI." The joint letter from Pour Demain, the Future of Life Institute, the Center for AI Safety and five other groups warned that "an appropriately resourced regulator is needed to address" the threats posed by new hacking AI. They also called for the safety unit to be elevated organisationally, with a direct reporting line to a Commissioner.
The Commission has not been idle. Under the AI Act simplification package launched in November 2025, the office would gain 38 additional posts. But the package is still under negotiation between the Council and Parliament, and no final agreement is expected before late 2026. In the meantime, Regnier said the office plans to hire roughly six more staff by the end of June, the "vast majority" assigned to safety, regulation and compliance units.
The enforcement paradox
A deeper tension runs through the EU's design. The AI Act deliberately concentrates rule-setting, supervision and enforcement in one structure, arguing that democratic accountability requires a single chain of command. The UK model separates scientific assessment from regulatory action. That separation may explain why Anthropic, OpenAI and Google DeepMind have all engaged more readily with the UK institute. The EU's regulatory reach is broader, the AI Act applies to any model placed on the EU market, but its ability to see inside the labs is narrower.
Some officials argue the access problem will solve itself once the AI Act's general-purpose model obligations fully apply in August 2026. Providers of systemic-risk models will have to notify the Commission, share technical documentation and allow evaluations. But Mythos is already here, and the Commission is not in the room. The question is whether the EU can build the technical depth to evaluate what companies submit, or whether it will rely on second-hand assessments from better-resourced partners.
The Mythos episode has exposed a gap between legislative ambition and operational reality. The AI Act is the world's most comprehensive attempt to govern frontier models, but its enforcer remains understaffed, hierarchically constrained and, for now, locked out of the very systems it must police. Whether the Commission can close that gap before the next generation of models arrives will determine whether the EU's regulatory leadership is more than symbolic.
Sources
People mentioned
Stanislav Fort
Ciaran Martin
Organisations
European Commission · European Parliament · Anthropic · UK AI Security Institute · Pour Demain · Aisle