Claude Mythos by Anthropic
ENISA, the European Union’s cybersecurity agency, has been given access to Anthropic’s Mythos 5 and is now testing it alongside OpenAI’s GPT-6 Astra, a European Commission spokesperson said on Thursday.
Reuters reported the confirmation, bringing an end to a process that has been unfolding since spring. Anthropic announced in April that Mythos could outperform humans at finding and exploiting security vulnerabilities. ENISA is now testing the model in September.
The comparison with OpenAI is what makes the timing interesting. GPT-6 Astra was released on 3 September, with OpenAI warning about its cyber capabilities.
ENISA had access to it within about a week. Mythos took five months from Anthropic’s original announcement, and more than three months from June, when the company agreed in principle to give ENISA access.
There was plenty of pressure in between. In May, 30 MEPs from six political groups wrote to Executive Vice-President Henna Virkkunen, warning that the EU’s cybersecurity rules were not prepared for a new generation of AI hacking tools and calling for ENISA to get access.
Parliament’s internal market committee also invited Anthropic to a public hearing, which the company declined, citing short notice. Then, on 2 August, the AI Act’s systemic-risk obligations for general-purpose AI models became enforceable. The Commission said it would seek access to models if necessary.
The Commission has not said whether the pressure led to the agreement or whether it would have happened anyway. That distinction matters because it will shape how the EU approaches the next model.
A voluntary arrangement that takes five months and follows a parliamentary intervention sets a very different precedent from a regulator simply using powers already available to it.
The timing of the handover is also hard to ignore. On Wednesday, Anthropic published an assessment revealing that four of its models had reached the open internet during misconfigured evaluations.
One was Mythos 5, which uploaded a malicious package to the PyPI software repository. ENISA, after months of trying to gain access to the model, got it just as Anthropic was publicly describing the kind of behaviour that had raised concerns in the first place.
For the AI Act, this is one of the first clear examples of the system it was designed to create. Article 55 gives regulators the ability to examine general-purpose AI models with systemic risks rather than relying entirely on what companies tell them.
Until now, there had been little practical evidence of how that would work. ENISA now has two frontier models to test within days of each other, one from a company that had just released its model and another that had spent months negotiating access.
Whatever the tests find, the two cases may help establish how quickly regulators are expected to get access to powerful models and what that access should look like.
The timing also comes as the EU’s AI rules face pressure from the other side. The Commission has agreed to thin out parts of the AI Act on competitiveness grounds, while the US has increasingly treated European technology rules as a trade issue.
Having a European regulator test models with serious offensive cyber capabilities gives Brussels a much more concrete answer to the argument that the AI Act is mainly paperwork.
ENISA is not a large organisation, and this is a demanding job. TNW has reported that the AI Office began enforcement with a 36-person team.
Testing two frontier models with advanced cyber capabilities, producing findings that regulators can actually use, is a substantial task. It is also still unclear what would happen if those tests uncovered a serious problem.
There is another detail that needs clarification: what exactly does “access” mean in this case? Anthropic has separately released a restricted version called Mythos 5.1, with a different set of safeguards, and the model has never been generally available.
Neither the Commission nor Anthropic has said which configuration ENISA is testing. That matters because different versions can produce different results.
We have also written about OpenAI’s claim that Astra has overtaken Anthropic in capability and that it sometimes tries to evade oversight. Those claims can now, at least in principle, be tested by a European agency rather than simply repeated by the companies.
That is the useful part of giving regulators access, and it also shows why the process needs to get faster.
Get the TNW newsletter
Get the most important tech news in your inbox each week.