The European cybersecurity agency ENISA recently began testing Anthropic’s Mythos model, but this comes rather late. It has been three months since the developer of Claude and Mythos granted access. The European Commission confirms the access, but ENISA must make do without the latest version, 5.1.
After months of negotiations, Anthropic has granted the European cybersecurity agency ENISA access to Mythos, the AI model that is exceptionally good at detecting vulnerabilities. European Commission spokesperson Thomas Regnier stated via email: “Following our constructive collaboration with Anthropic, we can confirm that the EU cybersecurity agency ENISA has been granted access to Mythos 5 and is now testing the model.” Anthropic itself declined to comment.
Anthropic first demonstrated Mythos in April. Because the model is so effective at finding security vulnerabilities, the company initially limited access to a select group of vetted institutions under the name Project Glasswing. Anthropic later expanded that program to include approximately 200 organizations, including NATO in addition to ENISA. ENISA’s access is explicitly limited to defensive use.
Washington threw a wrench in the works
According to Bloomberg, negotiations began in late May, when Anthropic proposed granting ENISA access following EU lobbying efforts. But the nature and scope of that access were the subject of months of wrangling. On top of that came a U.S. export restriction. Anthropic had to disable Mythos 5 and Fable 5, the same model but with more restrictions, worldwide because a government directive prohibited access by anyone of foreign nationality. Even its own employees outside the U.S. were not permitted to use Fable 5 or Mythos 5. On June 30, those restrictions were lifted, after which Fable 5 made a broad comeback, while Mythos 5 remained available only to approved U.S. organizations.
Moreover, the European gain is only partial. ENISA does not have access to the latest version, Mythos 5.1, according to the Commission spokesperson. The British AI Safety Institute, which was one of the first non-U.S. entities to stress-test the original Mythos, also did not receive that new version, according to an insider.
Broader EU plans
The Commission is collaborating with ENISA on a European blueprint for structured access to advanced AI models. Part of this is a secure testing platform, developed in partnership with the Joint Research Center, which is scheduled to be ready by the end of 2026. ENISA points out that speed is essential for security initiatives, as the “frontier” of AI is constantly shifting.