Anthropic PBC has handed its most capable security model to European regulators, ending a standoff that ran through the summer. ENISA, the bloc's cybersecurity agency, is now running tests on Mythos 5 — the first EU institution admitted to the access program that governs the system, and the first live rehearsal of how Brussels intends to vet frontier AI before the AI Act's evaluation rules take effect.
"Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now," Thomas Regnier, a spokesperson for the European Commission, said in an email.
The handover lands more than three months after Anthropic first told the bloc it would get access. Negotiations opened in early June 2026 and ran through the summer, slowed by US export controls on advanced AI technology and by disagreement over the scope and terms of the arrangement, according to Bloomberg. ENISA and the UK's AI Safety Institute remain limited to Mythos 5; neither has been given the newer Mythos 5.1 version, a person familiar with the matter said.
What ENISA is testing is not a general-purpose chatbot. Anthropic built Mythos for defensive cybersecurity work, and in preliminary testing the model autonomously identified more than 10,000 zero-day vulnerabilities — software flaws vendors did not know existed, the class of weakness nation-state hackers and criminal groups pay millions to exploit. The model also posted success rates above 83 percent at generating working exploits on a first attempt, a step up from the earlier Opus 4.6 generation, according to Anthropic's disclosures.
The access route is Project Glasswing, Anthropic's structured rollout program for Mythos. It opened in April 2026 with roughly 50 organizations, almost all US-based. By June the partner list had grown by another 150 organizations across more than 15 countries, including France, Germany, Italy and NATO. ENISA's addition gives that network an institutional anchor inside the EU's own machinery rather than a set of national participants.
Why the delay matters more than the deal
The three-month gap between promise and delivery is the part other frontier labs should read closely. Anthropic proposed ENISA access in late May, and the Commission confirmed testing only on Sept. 10. US export controls on sophisticated AI technology created friction throughout, which means the binding constraint on European AI oversight may sit in Washington rather than Brussels.
That has a direct read-through for Anthropic's listing plans. The company has filed for an IPO after a funding round that valued it near the $1 trillion mark, with a revenue run rate reported above $65 billion. Demonstrating that a flagship model can clear EU regulatory review removes a market-access risk that would otherwise sit in the prospectus — and the same review is coming for OpenAI, Google DeepMind and Meta Platforms, none of which has an equivalent institutional testing arrangement in place with the bloc.
The precedent cuts both ways. A testing regime that produces documented findings gives European supervisors a factual basis for AI Act enforcement, but it also creates a queue: every frontier lab seeking EU deployment will need to negotiate access terms, and the Mythos timeline suggests that process runs in months, not weeks. For Anthropic, the near-term value is defensive — a regulator that has tested the model is harder to shut out than one that has not.
The next checkpoint is whether ENISA's findings are published and whether Mythos 5.1 access follows. Neither has a date. Anthropic did not immediately respond to a request for comment.
This article is for informational purposes only and does not constitute investment advice.