Security

Anthropic grants Enisa access to cyber model Mythos 5

3 min read

TL;DR Too Long; Didn’t read

Since September 10, 2026, the EU agency Enisa has been testing Anthropic's model Mythos 5 for cyber capabilities, five months after its announcement. In parallel, it is testing OpenAI's GPT-6 Astra, which was accessible within a week. The basis is Article 55 of the EU AI Act, which allows regulators independent access to models for the first time. Access remains limited to defensive purposes.

An inspector in a blue vest covered in EU stars holds a magnifying glass over two glowing circuit brains bearing Anthropic and OpenAI logo stickers, labeled “Mythos 5” and “GPT-6 Astra”, with a digital padlock opening between them. Image generated with GPT Image 2

Key takeaways

  • Enisa gains access to Anthropic's Mythos 5 on September 10, 2026 – five months after the announcement in April.
  • OpenAI's GPT-6 Astra was already accessible to Enisa within a week after the launch on September 3.
  • US export controls temporarily blocked Mythos 5 worldwide, even for Anthropic's own employees outside the USA.
  • Article 55 of the EU AI Act allows regulators to conduct their own tests on models with systemic risk for the first time.
  • Thirty EU parliamentarians from six factions called out missing cybersecurity rules against AI hacking tools.
  • Enisa does not receive the latest version Mythos 5.1 – a separate EU testing platform is expected to be ready by the end of 2026.

The EU cybersecurity agency Enisa has been testing Anthropic’s model Mythos 5 since September 10, 2026, for its capabilities in detecting and exploiting software vulnerabilities. This was confirmed by a spokesperson for the EU Commission. At the same time, the agency is already reviewing OpenAI’s GPT-6 Astra – access that was established within a week of its launch, while Anthropic took more than five months.

Anthropic opens access after months of wrangling

Anthropic had already unveiled Mythos in April 2026, stating that the model could surpass humans at detecting and exploiting security vulnerabilities. Initially, access was limited to around fifty selected organizations in the “Project Glasswing” program; in June, Anthropic expanded the circle to about two hundred institutions, including NATO in principle. Enisa itself, however, kept waiting: US export controls on particularly powerful AI models temporarily barred any access by non-American organizations worldwide – reports indicate that even Anthropic’s own employees outside the US were affected. After the worldwide lifting of these restrictions on June 30, 2026, Anthropic’s smaller model Fable 5 became freely accessible again, but Mythos 5 remained restricted to approved US organizations. Only after “constructive cooperation” with Anthropic did the Commission get the green light, explained Commission spokesperson Thomas Regnier, according to Euronews. Enisa’s access remains explicitly limited to defensive testing purposes and does not extend to the latest version, Mythos 5.1 – the British AI Security Institute is also excluded from that newest release.

Article 55 gives regulators their own testing access for the first time

The legal basis is Article 55 of the EU AI Act, which provides for independent safety assessments by authorities for models with systemic risk, rather than relying solely on manufacturers’ own statements. Enisa’s access to Mythos 5 and GPT-6 Astra thus counts as one of the first concrete use cases of this power. Political pressure had already built beforehand: thirty members of the European Parliament from six political groups wrote to Executive Vice-President Henna Virkkunen warning, according to TheNextWeb, that European cybersecurity rules were unprepared for AI-powered hacking tools. To build lasting testing infrastructure, the EU Commission is also working with the Joint Research Centre on a secure testing environment, targeted for completion by the end of 2026.

Mythos is considered particularly capable in the industry at attacking IT systems. Just last month, Anthropic temporarily paused training on several models after an incident during a security test. OpenAI likewise officially classifies its rival model GPT-6 Astra in the highest risk tier of its Preparedness Framework and restricts advanced hacking features to vetted partners in its Daybreak program. Both companies justify the tight access rules by arguing that a tool which reliably finds vulnerabilities could just as easily serve attackers if it fell into the wrong hands.

It remains open whether Enisa will publish its test results or use them only internally for oversight. Just as decisive will be whether the testing platform announced with the Joint Research Centre for the end of 2026 is actually ready on time, and whether future model versions like Mythos 5.1 will then automatically be open to European testers – or will again require months of negotiation.

Frequently asked questions

What exactly is Enisa allowed to test with Mythos 5 and GPT-6 Astra?

Enisa evaluates the capabilities of both models in independently detecting and exploiting software vulnerabilities. Access is reportedly explicitly limited to defensive testing purposes, not offensive use.

Can companies in Germany or the EU also test the models now?

No. The current access is only for Enisa as an authority, within the framework of Project Glasswing or the Daybreak program. A broader European testing infrastructure through the Joint Research Centre is only planned for the end of 2026.

Why did Anthropic take five months longer than OpenAI for the release?

Temporary US export controls on particularly powerful AI models reportedly blocked access for non-American organizations to Mythos 5 entirely, delaying negotiations with the EU Commission.

Does Enisa also gain access to the latest version Mythos 5.1?

As of now, no. Both Enisa and the British AI Security Institute remain excluded from the newest Mythos version.

What does Article 55 of the AI Act mean for other AI model providers?

It fundamentally obliges providers of models with systemic risk to let authorities like Enisa run their own security assessments. The current case counts as the first visible test run of this power in practice.

Sources (4)
  1. Anthropic grants EU cybersecurity agency access to Mythos AI model (Euronews)
  2. EU cybersecurity agency is now testing Mythos 5 and GPT-6 Astra, the Commission says (TheNextWeb)
  3. EU cybersecurity agency gains access to Mythos 5 after a 3-month delay (Techzine)
  4. EU Regulation 2024/1689 (AI Act), Article 55 (EUR-Lex)

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog