cd /news/ai-policy/eus-cybersecurity-agency-granted-acc… · home topics ai-policy article
[ARTICLE · art-125705] src=insideai.news ↗ pub= topic=ai-policy verified=true sentiment=· neutral

EU’s Cybersecurity Agency Granted Access to Mythos 5 AI Model, Commission Says

The European Commission confirmed on September 10, 2026 that ENISA, the EU Agency for Cybersecurity, has been granted access to Anthropic's Mythos 5 and OpenAI's GPT-6-Astra frontier AI models for evaluation. The Commission did not specify the scope, duration, or whether the access was voluntary or mandated under the EU AI Act, which entered into force in August 2024 and imposes cybersecurity evaluation requirements on models with systemic risk. The testing could examine model robustness, vulnerability to prompt injection, and potential misuse in cyberattacks, and may inform future regulatory decisions across the bloc.

by read3 min views3 publishedSep 10, 2026
EU’s Cybersecurity Agency Granted Access to Mythos 5 AI Model, Commission Says
Image: Insideai (auto-discovered)

September 10, 2026, (Inside AI) — The European Union's cybersecurity agency has begun testing Anthropic's Mythos 5 artificial intelligence model, the European Commission confirmed on Thursday.

ENISA, the EU Agency for Cybersecurity, received access to the model and is now evaluating it. The same agency has also been granted access to OpenAI's latest model, GPT-6-Astra, according to a Commission spokesman.

The move signals a significant step in the EU's oversight of frontier AI systems. It places two of the most advanced commercial models under direct scrutiny by a government cybersecurity body.

The Commission did not specify the scope or duration of the testing. It also did not reveal whether the access was voluntary or mandated under the EU AI Act.

The EU AI Act, which entered into force in August 2024, introduced new obligations for general-purpose AI models. Models with systemic risk face stricter requirements, including cybersecurity evaluations.

Mythos 5 and GPT-6-Astra are both considered frontier models. Their scale and capabilities likely trigger the Act's most demanding compliance tier.

ENISA's role has expanded beyond traditional cybersecurity. The agency now supports implementation of the AI Act, including technical assessments of high-risk AI systems.

The Commission's announcement follows a pattern of proactive engagement with leading AI labs. In 2025, ENISA published guidance on securing AI systems against adversarial attacks.

Anthropic and OpenAI have both faced regulatory pressure in Europe. Data protection authorities have previously scrutinized their data handling practices.

The testing process could examine model robustness, vulnerability to prompt injection, and potential for misuse in cyberattacks. ENISA has developed frameworks for evaluating AI-enabled threats.

Industry observers note that government access to proprietary models raises intellectual property concerns. However, the EU AI Act allows regulators to request technical documentation and conduct evaluations.

Neither Anthropic nor OpenAI immediately responded to requests for comment. The Commission spokesman did not provide details on testing timelines.

The announcement comes as the EU prepares to enforce the AI Act's general-purpose AI provisions. The first compliance deadlines for frontier models took effect in August 2025.

ENISA's testing could inform future regulatory decisions. Findings may shape guidance on model security requirements across the bloc.

The EU's approach contrasts with the United States, where voluntary commitments have dominated AI oversight. Europe has favored binding legal obligations for high-risk systems.

The Commission's disclosure also highlights growing cooperation between regulators and AI developers. Both companies have publicly supported AI safety testing initiatives.

Access to Mythos 5 and GPT-6-Astra could help ENISA assess systemic risks. These include AI-enabled disinformation campaigns and automated vulnerability discovery.

The testing may also examine supply chain security. Frontier models rely on vast computing infrastructure, creating potential attack surfaces.

ENISA has warned that AI systems could be exploited to enhance social engineering attacks. The agency has called for mandatory security testing of high-risk models.

The results of the testing may not be made public. Regulators often keep technical evaluations confidential to protect security interests.

The EU's move could set a precedent for other jurisdictions. Several countries are developing AI safety evaluation frameworks.

The Commission's announcement is brief but consequential. It confirms that Europe's cybersecurity watchdog now has direct access to two leading AI models.

The development may accelerate industry standards for AI security testing. It also signals that frontier model developers face growing regulatory scrutiny in Europe.

── more in #ai-policy 4 stories · sorted by recency
── more on @european commission 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/eus-cybersecurity-ag…] indexed:0 read:3min 2026-09-10 ·