Drooid Logo
Back to story perspectives

Full Breakdown

EU Secures Access to Anthropic’s Mythos AI for Cyber Defense

6/2/2026, 12:34:51 AM

Access Milestone

Early June 2026 the EU’s cybersecurity agency ENISA was granted limited defensive access to Anthropic’s Claude Mythos Preview model via the company’s Project Glasswing program, following a series of meetings with the European Commission.

Background and Model Capabilities

Anthropic unveiled Mythos in April 2026 as a large-language model that autonomously discovers and exploits software flaws, generating full attack chains. Project Glasswing limits use to a vetted cohort of roughly 40-50 U.S. firms and government bodies, offering $100 million in usage credits and $4 million in open-source security donations.

Key Actors

Key participants are Anthropic, ENISA, the European Commission (spokesperson Thomas Regnier), Czech MEP Markéta Gregorová, Eurogroup President Kyriakos Pierrakakis, and the U.S. White House, which has voiced security concerns.

Data Highlights

  • Exploit success rate: 72.4 % (vs. near 0 % for the prior Opus 4.6 model).
  • First-month findings: >10,000 critical flaws, including 23,019 total vulnerabilities, of which 6,202 were high or critical severity.

Official Statements & Responses

The European Commission said meetings with Anthropic were productive and that it seeks to evaluate the model’s risk profile. Anthropic framed the ENISA invitation as a step toward “proper security safeguards.” The White House, per Bloomberg, opposed broader Mythos distribution, citing a need to balance innovation with safety.

Criticism & Opposition

EU officials warn that limited access may widen the competitive gap for European firms. MEP Gregorová cautioned that the Cybersecurity Act could pressure U.S. companies to meet EU standards. U.S. authorities have blocked proposals to extend Mythos to additional entities over misuse concerns.

Conflicting Reports & Gaps

TechZine and CryptoBriefing state ENISA is already in Project Glasswing, whereas CNBC and Politico report that formal access terms remain unsettled and negotiations continue. No public details on safeguards or licensing have been released.

Implications for European Cybersecurity

ENISA’s access could allow EU agencies to identify zero-day flaws before adversaries, narrowing a gap created by earlier U.S. adoption. The model’s dual-use nature, however, sustains concerns about inadvertent exploit proliferation.

What’s Next

The EU aims to finalize safeguard protocols and assess pilot results before any broader rollout. Talks with Anthropic and the U.S. administration are slated to continue through late 2026, aligning with the EU AI Act’s enforcement schedule.

Verbatim Quotes

  • “We welcome the latest developments on potential future access,” — Thomas Regnier, EU tech-sovereignty spokesperson
  • “Let's not forget that Mythos is not one off, a new wave of powerful models are coming to the market,” — Thomas Regnier, EU tech-sovereignty spokesperson
  • “I can see the Cybersecurity Act having an impact on U.S. companies if they don’t oblige by the rules,” — Markéta Gregorová, Czech Pirate MEP
  • “I don’t think we have the luxury of not trying to establish channels of communication with the US.” — Kyriakos Pierrakakis, Eurogroup President