EU cybersecurity agency gains access to Anthropic’s restricted Mythos 5 model
ENISA will test a powerful cyber-capable AI system after a three-month delay that exposed Europe’s dependence on access decisions made by American technology companies.
Restricted access reaches Europe
The European Union Agency for Cybersecurity has obtained access to Anthropic’s Mythos 5 artificial-intelligence model and begun testing it, according to the European Commission. The access arrived more than three months after the advanced cyber-capable system was released to a limited group of partners. The delay had become a test of whether European security institutions could evaluate strategically important American technology on equal terms.
Anthropic restricted Mythos 5 because of its ability to identify and exploit software vulnerabilities rapidly. Initial participation was channelled through a programme involving the United States government, while export controls limited access for non-American users. Brussels pressed the company over the exclusion of a close partner responsible for protecting a large cross-border digital market.
Cyber preparedness meets technological dependence
The immediate benefit is operational. ENISA can assess how the model performs in defensive testing, vulnerability discovery and incident preparation rather than relying solely on descriptions supplied by the developer. Access also lets European specialists examine the risks created when similar capabilities are used offensively, including the possibility that automated systems reduce the expertise and time required to exploit weaknesses.
Official EU planning already assigns ENISA a growing role in artificial-intelligence security. The agency’s July material describes AI as both a defensive tool and a source of manipulation, privacy and infrastructure risks. A 2026 Commission strategy calls for structured European access to advanced AI capabilities, a secure testing platform and faster use of AI in detecting and fixing critical vulnerabilities.
The episode also illustrates a sovereignty problem. Europe possesses regulatory authority through the AI Act and cybersecurity legislation, but much of the most advanced computing capability is controlled by companies headquartered elsewhere. If access can be delayed or withdrawn by a vendor or another government, European regulators and defenders may struggle to assess systems that affect their own networks and markets.
What follows will matter more than the access announcement itself. ENISA must determine how Mythos 5 can be tested securely, how findings can be shared without exposing exploitable details, and whether the arrangement is durable. Policymakers will also watch whether other European institutions obtain timely access to future frontier models. The case may shape rules for cooperation between AI developers, regulators and national cybersecurity authorities.