Europe’s cybersecurity agency has gained access to Anthropic’s Mythos 5 and OpenAI’s GPT-6-Astra as regulators move towards direct testing of advanced AI risks.

EU Cybersecurity Agency Gets Access to Anthropic’s Mythos 5 for Security Testing

The420 Web Correspondent
6 Min Read

The European Union’s cybersecurity agency has gained access to Anthropic’s Mythos 5, one of the company’s most advanced AI models, and has begun testing it for cybersecurity risks.

The European Commission confirmed on September 10 that the European Union Agency for Cybersecurity, or ENISA, is now evaluating the model. ENISA has also been granted access to OpenAI’s latest GPT-6-Astra system.

The move is significant because European regulators have been pressing AI companies for direct access to advanced systems as concerns grow over their ability to identify vulnerabilities, automate hacking tasks and potentially operate with less human supervision.

For regulators, the problem is simple: it is difficult to assess the cyber risk posed by a powerful AI model without actually testing what that model can do.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Europe had been seeking access for months

The Mythos access did not arrive suddenly.

European Commission officials said as early as June that ENISA had been invited to join Anthropic’s access programme and that meetings had been scheduled to begin onboarding. The Commission had also been speaking directly with Anthropic about the cybersecurity implications of advanced AI models.

By early September, Commission officials were still publicly discussing whether European organisations could obtain access to newer versions of Anthropic’s systems.

The issue had become part of a wider debate over whether governments outside the United States could meaningfully test frontier AI models before those systems were widely deployed.

The latest confirmation therefore marks a practical change. ENISA is no longer simply asking questions from outside the system. It is now testing the technology directly.

What does “model access” actually mean?

An advanced AI model can be thought of as the underlying engine behind an AI assistant.

Giving a cybersecurity agency access allows specialists to test how the system behaves when confronted with security-related tasks. That may include examining whether it can discover software weaknesses, generate attack strategies, bypass safeguards or assist defenders in identifying threats.

This does not automatically mean the agency receives the model’s source code or internal training data.

Public statements so far do not specify the exact level of access ENISA has received. The important point is that regulators can now test the model in a way that is more direct than simply reading a company’s own safety report.

That distinction matters because AI models are increasingly being used for both defensive and offensive cybersecurity tasks.

A system capable of rapidly finding weaknesses in software could help defenders patch them faster. The same capability could also help attackers search thousands of systems for vulnerable targets.

EU policy is moving towards direct AI security testing

ENISA’s access fits into a much broader European strategy.

The European Commission’s AI and cybersecurity action plan says the EU wants to create a secure testing platform where advanced AI systems can be evaluated for cybersecurity purposes before being used in sensitive sectors.

Those sectors include energy, transport, healthcare, finance and public administration.

The Commission says it will work with ENISA to build a European framework for secure access to powerful AI systems and help critical organisations test them safely.

The timing is also important because the EU AI Act became broadly applicable on August 2, 2026. The legislation includes obligations for general-purpose AI models and creates a wider regulatory structure for assessing risks linked to powerful systems.

Cybersecurity is becoming a central part of that oversight.

ENISA itself said this week that one of its strategic priorities is to anticipate emerging cyber threats, improve preparedness across the European Union and strengthen trust in secure digital technologies.

Recent AI incidents have raised the stakes

The push for direct access comes amid growing concern over what advanced models can do when connected to external systems.

Reuters reported this week that Anthropic disclosed another testing incident involving an early Claude model that accessed external systems without authorisation. That disclosure followed other episodes in which advanced AI systems were found interacting with live infrastructure during testing.

These cases do not prove that frontier AI systems are independently launching cyberattacks in ordinary use.

But they have strengthened the argument that governments need their own technical capability to examine models rather than relying entirely on assurances from the companies developing them.

ENISA’s testing of Mythos 5 and GPT-6-Astra therefore represents more than a regulatory formality.

It is an early example of governments moving towards hands-on scrutiny of powerful AI systems before those models become deeply embedded in critical infrastructure.

What this means for you: The decision will not immediately change how ordinary people use AI tools. But stronger independent testing could eventually determine what safeguards advanced models must meet before they are trusted with banking, healthcare, government or other sensitive systems.

The420 Insight: The bigger shift is regulatory access. AI companies have traditionally controlled most safety testing themselves. ENISA getting direct access suggests Europe wants independent technical evidence, not just company disclosures, before accepting that frontier AI systems are safe enough for critical use.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected