{"slug": "eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says", "title": "EU’s Cybersecurity Agency Granted Access to Mythos 5 AI Model, Commission Says", "summary": "The European Commission confirmed on September 10, 2026 that ENISA, the EU Agency for Cybersecurity, has been granted access to Anthropic's Mythos 5 and OpenAI's GPT-6-Astra frontier AI models for evaluation. The Commission did not specify the scope, duration, or whether the access was voluntary or mandated under the EU AI Act, which entered into force in August 2024 and imposes cybersecurity evaluation requirements on models with systemic risk. The testing could examine model robustness, vulnerability to prompt injection, and potential misuse in cyberattacks, and may inform future regulatory decisions across the bloc.", "body_md": "**September 10, 2026**, (Inside AI) — The European Union's cybersecurity agency has begun testing Anthropic's Mythos 5 artificial intelligence model, the European Commission confirmed on Thursday.\n\nENISA, the EU Agency for Cybersecurity, received access to the model and is now evaluating it. The same agency has also been granted access to OpenAI's latest model, GPT-6-Astra, according to a Commission spokesman.\n\nThe move signals a significant step in the EU's oversight of frontier AI systems. It places two of the most advanced commercial models under direct scrutiny by a government cybersecurity body.\n\nThe Commission did not specify the scope or duration of the testing. It also did not reveal whether the access was voluntary or mandated under the EU AI Act.\n\nThe EU AI Act, which entered into force in August 2024, introduced new obligations for general-purpose AI models. Models with systemic risk face stricter requirements, including cybersecurity evaluations.\n\nMythos 5 and GPT-6-Astra are both considered frontier models. Their scale and capabilities likely trigger the Act's most demanding compliance tier.\n\nENISA's role has expanded beyond traditional cybersecurity. The agency now supports implementation of the AI Act, including technical assessments of high-risk AI systems.\n\nThe Commission's announcement follows a pattern of proactive engagement with leading AI labs. In 2025, ENISA published guidance on securing AI systems against adversarial attacks.\n\nAnthropic and OpenAI have both faced regulatory pressure in Europe. Data protection authorities have previously scrutinized their data handling practices.\n\nThe testing process could examine model robustness, vulnerability to prompt injection, and potential for misuse in cyberattacks. ENISA has developed frameworks for evaluating AI-enabled threats.\n\nIndustry observers note that government access to proprietary models raises intellectual property concerns. However, the EU AI Act allows regulators to request technical documentation and conduct evaluations.\n\nNeither Anthropic nor OpenAI immediately responded to requests for comment. The Commission spokesman did not provide details on testing timelines.\n\nThe announcement comes as the EU prepares to enforce the AI Act's general-purpose AI provisions. The first compliance deadlines for frontier models took effect in August 2025.\n\nENISA's testing could inform future regulatory decisions. Findings may shape guidance on model security requirements across the bloc.\n\nThe EU's approach contrasts with the United States, where voluntary commitments have dominated AI oversight. Europe has favored binding legal obligations for high-risk systems.\n\nThe Commission's disclosure also highlights growing cooperation between regulators and AI developers. Both companies have publicly supported AI safety testing initiatives.\n\nAccess to Mythos 5 and GPT-6-Astra could help ENISA assess systemic risks. These include AI-enabled disinformation campaigns and automated vulnerability discovery.\n\nThe testing may also examine supply chain security. Frontier models rely on vast computing infrastructure, creating potential attack surfaces.\n\nENISA has warned that AI systems could be exploited to enhance social engineering attacks. The agency has called for mandatory security testing of high-risk models.\n\nThe results of the testing may not be made public. Regulators often keep technical evaluations confidential to protect security interests.\n\nThe EU's move could set a precedent for other jurisdictions. Several countries are developing AI safety evaluation frameworks.\n\nThe Commission's announcement is brief but consequential. It confirms that Europe's cybersecurity watchdog now has direct access to two leading AI models.\n\nThe development may accelerate industry standards for AI security testing. It also signals that frontier model developers face growing regulatory scrutiny in Europe.", "url": "https://wpnews.pro/news/eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says", "canonical_source": "https://insideai.news/news/ai-policy-and-regulation/enisa-mythos-5-ai-model-testing/10159/", "published_at": "2026-09-10 11:32:45+00:00", "updated_at": "2026-09-10 11:57:43.172706+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "artificial-intelligence", "large-language-models"], "entities": ["European Commission", "ENISA", "Anthropic", "Mythos 5", "OpenAI", "GPT-6-Astra", "European Union", "EU AI Act"], "alternates": {"html": "https://wpnews.pro/news/eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says", "markdown": "https://wpnews.pro/news/eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says.md", "text": "https://wpnews.pro/news/eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says.txt", "jsonld": "https://wpnews.pro/news/eus-cybersecurity-agency-granted-access-to-mythos-5-ai-model-commission-says.jsonld"}}