Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

MEPs warn EU cyber laws cannot handle AI hacking tools like Mythos

Thirty parliamentarians from six groups demand urgent reform after Anthropic's model outperforms humans in finding vulnerabilities, while the company declines to appear before a parliamentary hearing.

By , Technology Editor

Published

8 min read

Thirty members of the European Parliament have told the Commission that the bloc's cybersecurity framework is fundamentally unprepared for a new class of artificial intelligence tools capable of discovering and exploiting software vulnerabilities without human guidance. The warning, delivered in a letter to Executive Vice President Henna Virkkunen on Monday, centres on Anthropic's Mythos model, which the company announced last month had outperformed human experts in offensive cyber tasks.

A capability shift that changes the threat calculus

Anthropic's announcement marked a threshold moment. Mythos is not merely a coding assistant; according to the company, it can autonomously identify previously unknown vulnerabilities, develop exploits, and execute them, tasks that until now required highly skilled human operators. For defence agencies and critical infrastructure operators, the implication is clear: the barrier to entry for sophisticated cyber attacks has dropped sharply. The MEPs' letter, signed by lawmakers from six political groups including the liberals, greens, socialists, conservatives, left and pirates, argues that existing EU legislation, notably the Cybersecurity Act and the NIS2 directive, was written for a world where vulnerability discovery remained a human bottleneck.

Bart Groothuis, a Dutch liberal MEP who previously served as a senior cybersecurity official in the Dutch government, put the problem bluntly. "Europe is not at the table," he said. "I think that we should shake the tree much, much harder." His frustration reflects a structural asymmetry: the most advanced AI models are developed almost exclusively by US companies, and European regulators have no automatic right to inspect them before deployment.

Parliament demands ENISA access and a European mitigation plan

The letter makes three concrete demands. First, a revision of the EU's rules on the disclosure and remediation of cyber vulnerabilities, which currently assume a coordinated disclosure process between researchers and vendors, a process that breaks down when an AI can find and weaponise flaws at machine speed. Second, a "European mitigation plan" that prioritises protection of what the MEPs call "crown jewels": operators in energy, transport, health, finance and digital infrastructure. Third, and most immediately actionable, they want the EU's cyber agency ENISA to be granted access to Mythos and comparable models so it can conduct independent risk assessments.

ENISA, based in Heraklion and Brussels, currently operates largely through coordination, certification schemes and advisory roles. It has no statutory power to compel access to proprietary AI systems. Granting it that authority would require legislative change, likely through the ongoing reform of the Cybersecurity Act, a file currently steered by Czech Pirate Party MEP Markéta Gregorová, who also signed Monday's letter.

Anthropic declines parliamentary hearing invitation

The Parliament's internal market committee (IMCO) moved quickly after Anthropic's announcement, inviting the company to a public hearing scheduled for later this week. According to a statement shared with journalists on Monday, Anthropic responded that it was "unable to accept" the invitation "at short notice." The refusal underscores a recurring tension: US AI labs treat European parliamentary scrutiny as optional, while European lawmakers have few tools to compel attendance. Groothuis, who sits on IMCO, described the refusal as "disappointing but not surprising."

Anthropic has not publicly explained whether it intends to engage with European legislators at a later date. The company, founded in 2021 by former OpenAI researchers and backed by Amazon and Google, has positioned itself as safety-focused, publishing research on constitutional AI and mechanistic interpretability. But its commercial incentives align with rapid deployment, not regulatory delay. The Mythos announcement was framed as a demonstration of capability, not a warning, though the effect in Brussels has been the latter.

The regulatory timeline: Cybersecurity Act reform and AI Act enforcement

Two legislative tracks now converge on this problem. The Cybersecurity Act reform, already under negotiation between Parliament and Council, offers a vehicle to embed AI-specific risk assessment requirements, mandatory model access for ENISA, and updated vulnerability disclosure obligations. Gregorová has signalled she intends to table amendments reflecting the letter's demands. However, trilogue negotiations with member states are unlikely to conclude before early 2027, given the complexity of the file and the Council's cautious approach to expanding EU agency powers.

The second track is the AI Act, which entered into force in August 2024. Its enforcement architecture centres on the AI Office, a unit inside the Commission's digital policy department (DG CNECT). The Office's full enforcement powers, including the authority to request model access, conduct evaluations, and impose fines, only activate on 2 August 2026. Until then, the Commission relies on voluntary cooperation through the AI code of practice, a non-binding framework for general-purpose AI providers.

Commission says engagement is underway, but enforcement waits

Commission spokesperson Thomas Regnier struck a calmer tone in response to the letter. He confirmed that the Commission has held "numerous" technical meetings with Anthropic since August 2025 to work on implementing the AI code of practice, and "several meetings" specifically on Mythos. "Once the enforcement powers of the AI Office start in August 2026, we will ensure to receive, if needed, model access," Regnier said. The phrasing, "if needed", suggests the Commission still hopes voluntary cooperation will suffice.

That hope may be tested. The AI Act classifies general-purpose models with systemic risk, a category Mythos would almost certainly fall into, as subject to mandatory evaluation, risk mitigation, and incident reporting. But the Act's systemic risk threshold is defined by compute used in training (10^25 floating point operations), not by demonstrated capability. Anthropic has not disclosed Mythos's training compute, and the Commission has not confirmed whether the model crosses the threshold. If it does not, the Act's strongest tools may not apply.

The access gap is structural, not temporary

Behind the diplomatic language lies a harder reality. The EU has no sovereign frontier AI model. Mistral, the French champion, focuses on smaller, efficient models; Aleph Alpha, the German contender, has pivoted to enterprise AI. Neither operates at the scale of Anthropic, OpenAI, Google DeepMind, or xAI. This means European regulators are permanently dependent on foreign companies' willingness to cooperate. The AI Act's extraterritorial reach, it applies to any model placed on the EU market, gives legal leverage, but only once enforcement begins. Until August 2026, the Commission has no power to compel documentation, model weights, or API access.

Member states are aware of the gap. France and Germany have both launched national AI safety institutes in the past year, partly to build independent evaluation capacity. The UK, outside the EU but aligned on AI safety, established its own institute in 2023 and secured voluntary model access agreements from several frontier labs. The EU's AI Office is attempting to replicate that model at bloc level, but starts from a standing start with no pre-existing relationships and a mandate that only becomes binding in fifteen months.

What happens next: a hearing without the subject, a reform without teeth

IMCO will hold its hearing this week without Anthropic. Officials from ENISA, the Commission, and national cyber agencies are expected to attend, along with independent researchers. The session will likely focus on what ENISA needs, legally and technically, to evaluate models like Mythos, and whether the Cybersecurity Act reform can deliver those powers in time. Gregorová has indicated she will propose an amendment requiring systemic-risk AI providers to grant ENISA API access for evaluation purposes, with penalties for non-compliance mirroring the AI Act's fine structure (up to 3% of global turnover).

Sources

  1. POLITICO

    politico.eu · 2026-05-04

People mentioned

Organisations

European Parliament · European Commission · ENISA · Anthropic

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.