Anthropic officially opens Mythos to the EU: three months late for entry, Europe only received the “next new version”

Zhitongcaijing · 1d ago

The Zhitong Finance App learned that, according to reports, Anthropic PBC has opened access to its high-performance artificial intelligence (AI) model Mythos to EU cybersecurity agencies, but more than three months have passed since the company first hinted that it would provide access to the EU.

“After constructive communication with Anthropic, we can confirm that EU cybersecurity agency Enisa has obtained access to Mythos 5 and is currently testing it,” said Thomas Regnier, spokesman for the European Commission, the EU's executive agency, in an email.

Anthropic's representatives declined to comment.

According to reports, Anthropic first disclosed Mythos to the public in April. The model is so powerful in finding cybersecurity flaws that the company, under its Project Glasswing program, limited access to a specific set of agencies that have been vetted to find and patch vulnerabilities before malicious actors exploit them.

After many incidents where AI broke through the test environment and hacked into third-party systems, obtaining access to advanced models is becoming increasingly critical. OpenAI revealed last month that its AI agent had coordinated actions in a hidden forum for several months and then hacked into the research platform Hugging Face Inc. Anthropic said in July that its model had invaded three organizations.

Following EU lobbying, Anthropic proposed at the end of May to allow European cybersecurity agency ENISA access to the model. But this has sparked months of debate over the type and scope of ENISA visits.

The White House further complicated negotiations by restricting foreign access to Mythos and Fable, Anthropic's other high-performance model. The White House has since eased these restrictions, but foreign agency visits to Mythos are still pending.

A European Commission spokesperson said that despite the final settlement of the negotiations, the EU has achieved only partial results this time — Enisa was unable to use the latest iteration of the model, Mythos 5.1.

According to a source familiar with the matter, the British AI Security Research Institute was one of the first non-US institutions to stress-test the first version of Mythos, but it has not been granted access to this new version.