Access follows months of pressure
Anthropic initially restricted Mythos 5 to vetted organizations through Project Glasswing because of concerns that its automated vulnerability discovery and exploitation capabilities could also accelerate attacks. The program began with roughly 50 organizations and later expanded, while EU officials continued pressing for access.

The European Commission confirmed that ENISA is now testing Mythos 5. The agency’s admission comes after concerns over Europe’s limited visibility into a powerful system available mainly to U.S.-based partners.
Independent testing is the next challenge
ENISA can use the access to examine Mythos 5’s offensive capabilities and compare its behavior with other advanced systems. The Commission says the agency also has access to OpenAI’s GPT-5.6 Cyber and GPT-6 Astra, enabling broader testing of frontier cyber models.
The evaluation will be meaningful only if ENISA has sufficient time, technical resources, and freedom to probe the systems rigorously. The gap between Mythos 5 access and Anthropic’s newer 5.1 release also highlights a regulatory problem: governments may struggle to independently assess cyber AI before vendors move on to the next version.

