Drooid Logo
Back to story perspectives

Full Breakdown

EU Pressures Anthropic Over Access to Super-Hacking AI Model Mythos

5/6/2026, 8:40:56 PM

Anthropic’s Mythos Model and EU Scrutiny

Anthropic released Mythos Preview in early April 2026. The model can locate and exploit software flaws, uncovering nearly 300 Firefox bugs and tens of thousands of vulnerabilities across major operating systems. Access is limited to a small partner group, notably JPMorgan Chase, while European regulators are excluded.

Regulatory Background and Timeline

The European Parliament set a Wednesday hearing on Mythos risks. Thirty MEPs urged Commission tech chief Henna Virkkunen to devise a mitigation plan. Commission spokesperson Thomas Regnier said the AI Office’s enforcement powers, effective August 2026, will let the EU demand model access. Spain’s AESIA director Alberto Gago asked for coordination, and ENISA seeks direct access.

Scale of Vulnerabilities

Mythos found about 300 Firefox bugs—over ten times more than its predecessor—and “tens of thousands” of unpatched flaws across software.

Impact on Cybersecurity and Finance

EU banking regulators warn AI-driven exploits could spark ransomware attacks on schools, hospitals and banks, threatening critical infrastructure. Anthropic’s CEO says firms have a six-to-twelve-month window before Chinese AI models match Mythos, urging rapid patching amid a global cybersecurity talent shortage.

Official Statements

Commission spokesperson Thomas Regnier said the AI Office, active from August 2026, will compel model access if needed. U.S. Senator Gary Peters said he wants to explore why Mythos is not shared with European regulators.

Criticism & Opposition

MEP Kim van Sparrentak called Anthropic’s refusal to attend the hearing “extremely worrying.” Bart Groothuis said Europe “is not at the table.” Markéta Gregorová warned the EU cannot rely solely on corporate goodwill.

Conflicting Reports & Gaps

Anthropic cites safety concerns for limiting Mythos, while EU officials say restricted sharing endangers critical infrastructure. The U.S. has voluntary vetting deals with AI firms; the EU lacks such a framework. No European banks have access, and a rollout timeline is absent.

Verbatim Quotes

  • “We cannot rely solely on the goodwill of companies for this.” — Kim van Sparrentak, Dutch MEP
  • “I can see the Cybersecurity Act having an impact on U.S. companies if they don’t oblige by the rules,” — Markéta Gregorová, Czech Pirate MEP
  • “The danger is just some enormous increase in the amount of vulnerabilities, in the amount of breaches, in the financial damage that's done from ransomware on schools, hospitals, not to mention banks,” — Dario Amodei, CEO, Anthropic
  • “They can help us by not overburdening us when we have eight regulators asking us the same damn questions every day.” — Jamie Dimon, CEO, JPMorgan Chase

What’s Next

The EU may use its AI Office’s enforcement powers to compel model access, while Anthropic faces pressure to expand its partner program. A U.S.–EU technology forum could shape cross-Atlantic governance. Financial firms are urged to patch within the six-to-twelve-month window before comparable Chinese AI systems emerge.