Anthropic has granted the European Union's cybersecurity agency ENISA access to its Mythos 5 artificial intelligence model following months of negotiations that began in late May.
ENISA is testing Mythos 5 to evaluate its dual-use cyber capabilities and inform EU-level risk and policy discussions. The arrangement includes access to Project Glasswing, Anthropic's testing environment.
But the agreement excludes Mythos 5.1, the latest iteration. That limitation significantly constrains the scope of ENISA's evaluation—the agency cannot assess the model's most current security properties.
Thomas Regnier, a spokesperson for the European Commission, said: "Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now."
The negotiations required U.S. coordination, underscoring the international complexity of regulating advanced AI tools with potential security implications. Anthropic first publicly disclosed Mythos 5's hacking abilities five months ago, prompting EU officials to flag concerns that such tools could exploit critical infrastructure vulnerabilities.
ENISA is also testing OpenAI's GPT-6 Astra, reflecting the EU's broader effort to assess leading AI models for cybersecurity risk.

