The European Union Agency for Cybersecurity (ENISA) has begun testing Anthropic's advanced artificial intelligence model Mythos 5 after months of negotiations between the company and European officials. The European Commission confirmed the access in September and said ENISA is now evaluating the model in a controlled environment. The arrangement highlights how advanced AI systems with strong cybersecurity capabilities are becoming central to government risk assessments and digital defense planning.
Access Granted After Extended Negotiations
The talks started earlier this year after European bodies expressed interest in testing Mythos 5's cybersecurity capabilities. The discussions covered how the model would be used, the safeguards governing access to systems and data, and mechanisms to ensure the technology is used for defensive purposes. Thomas Regnier, the European Commission spokesperson for tech sovereignty, confirmed that ENISA obtained access and is testing the model now.
Why Access to Mythos 5 Is Restricted
Anthropic launched a preview of Mythos 5 in April, describing it as a model capable of identifying and exploiting cyber vulnerabilities with unprecedented speed. Because of those capabilities, the company limited access to select partners and kept the model away from general availability. Anthropic says it restricts model access to entities that meet security and responsible use requirements.
Project Glasswing and Defensive Use
Project Glasswing was launched to use advanced AI capabilities to protect software and digital infrastructure. The program began with around 50 organisations in April before expanding by roughly 150 more in June, bringing the total to about 200 partners. Early participants identified thousands of high-severity and critical vulnerabilities, including a critical vulnerability found by HackerOne on its own platform.
US Export Controls and European Pressure
The path to European access was also shaped by temporary US export control measures that restricted foreign access to Mythos 5 and Fable 5. Anthropic complied with the directive, while Brussels questioned whether the restrictions were discriminatory toward a trusted partner and raised concerns about Washington's ability to interrupt access to critical technologies. The European Commission, which holds significant regulatory powers under the EU AI Act, continued pressing Anthropic for access until an agreement was reached.
EU Tests Multiple Advanced AI Models
ENISA's evaluation of Mythos 5 follows earlier access to OpenAI's GPT-5.6-Cyber model and the latest GPT-6 Astra model. The broader European push aims to test advanced AI models in practice as their ability to analyze software and interact with digital systems improves. Direct testing lets European authorities assess capabilities in spotting vulnerabilities and analyzing code while studying risks in sensitive environments.
Balancing Security Benefits and Risks
Advanced models now handle tasks that go beyond assisting programmers, extending to analyzing large volumes of code, detecting anomalous patterns, and suggesting remedies. These capabilities give cybersecurity teams better tools, but the same potential can be valuable to malicious actors. Anthropic addresses this by allocating access to specific entities and by supporting the protection of open-source software.
The arrival of Mythos 5 at ENISA marks a significant step in cooperation between artificial intelligence companies and European institutions on cybersecurity. Direct testing gives the agency a chance to assess the model's capabilities in a real-world environment and to understand how it can be used to protect digital systems and infrastructure. As AI models continue to evolve, frameworks for testing and controlled access are likely to become a core part of cybersecurity policy at the government and critical infrastructure level.