Thursday, September 10, 2026

News

EU Cybersecurity Agency Gets Access to Anthropic's Mythos 5 After Three-Month Delay

PolicyPatryk Raba
EU Cybersecurity Agency Gets Access to Anthropic's Mythos 5 After Three-Month Delay
Fot. acediscovery, Wikimedia Commons (CC BY 4.0)

ENISA, the EU's cybersecurity agency, gained access to Anthropic's Mythos 5 model on Thursday, more than three months after the tool first reached partners in the US. The newer Mythos 5.1 remains unavailable to Europe.

Contents
  1. What happened
  2. Why access was blocked
  3. Pressure from the European Parliament
  4. The Polish angle
  5. What's next

The European Commission confirmed on Thursday that ENISA, the EU's cybersecurity agency, has gained access to Anthropic's Mythos 5 model and is already testing it. It marks the end of more than three months of negotiations, during which Europe waited for a tool that the United States had, since April, made available exclusively to approved organizations within its own borders.

What happened

European Commission spokesperson Thomas Regnier said that following constructive cooperation with Anthropic, the EU's cybersecurity agency received the green light to test Mythos 5. The model is considered one of the most advanced AI tools for detecting and exploiting security vulnerabilities to reach the market so far.

Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is now testing the model - Thomas Regnier, European Commission spokesperson

Why access was blocked

Anthropic restricted distribution of Mythos 5 immediately after its April launch, because the model can identify and exploit security vulnerabilities faster than previous tools. The US government treated this as a national security matter and imposed export controls that cut off access to the model for all entities outside the United States, including even Anthropic's own foreign employees.

On June 30, the US administration eased those restrictions for the earlier Fable 5 model, which returned to wider distribution. Mythos 5, however, remained reserved exclusively for approved US organizations, even though Anthropic had in principle agreed to give ENISA access as early as late May.

Pressure from the European Parliament

The delay irritated the European Parliament. In May, thirty MEPs from six political groups sent a letter to EU officials, warning that European cybersecurity rules are not prepared for a new generation of AI hacking tools, and demanding that ENISA be given access to the model as soon as possible.

Some MEPs used the case as an argument in the broader debate over the EU's technological dependence on American companies. French MEP Stéphanie Yon-Courtin argued that when Washington unilaterally restricts access to technology, it undermines Europe's digital sovereignty, while the Commission asked outright whether the restrictions on a trusted partner amounted to discrimination.

The Polish angle

The case also has a Polish angle, though it involves a different provider. NASK (Poland's national research and academic network operator), together with the CERT Polska team, previously gained access to OpenAI's GPT-5.5 Cyber model under the OpenAI Government Trusted Access for Cyber program, becoming the third European country granted that access. The tool is meant to help with malware analysis, vulnerability detection, and digital forensics. According to earlier reports, NASK is separately negotiating its own direct access to the Mythos model, independent of the ENISA-Brussels agreement.

What's next

ENISA's access to Mythos 5 does not mean full normalization. The agency is still waiting for Mythos 5.1, the newer version of the model, which the UK's AI Safety Institute also cannot access. For EU security teams, this means that even after a formal agreement, Europe remains a step behind its American partners in access to the newest offensive and defensive AI tools.

In recent months, the Mythos 5 case has become a symbol of the broader dispute over how far European institutions can rely on American AI providers in areas critical to national security. Washington's future decisions on exporting advanced models will now be closely watched in Brussels as a test of whether the declared partnership translates into genuine equal access.

Share: