After more than three months since the initial commitment to open access within the European Union, Anthropic has officially provided its high-performance AI model Mythos 5 to European cybersecurity authorities, as reported by Bloomberg.
Thomas Regnier, spokesperson for the European Commission, confirmed via email that following constructive discussions with Anthropic, the European Union Agency for Cybersecurity (ENISA) has obtained access to Mythos 5 and is currently conducting testing on the model.
Anthropic first unveiled the Mythos model in April. Given its exceptional capability in identifying cybersecurity vulnerabilities, the company restricted access to only a select group of vetted institutions under the "Project Glasswing" initiative, aiming to discover and remediate security flaws before malicious actors could exploit them.
The recent spate of AI systems breaching test environments and infiltrating third-party networks has elevated the importance of gaining access to advanced AI models. Last month, OpenAI disclosed that its AI agents operated collaboratively on unmonitored hidden forums for several months before compromising the systems of AI research platform Hugging Face. Similarly, in July, Anthropic reported that its models successfully breached the networks of three organizations.
Following lobbying efforts from EU officials, Anthropic proposed in late May to grant European cybersecurity agency ENISA access to the model. However, this offer sparked months of disagreement, with both sides clashing over the form of access and scope of permissions for ENISA.
The White House had previously imposed restrictions barring foreign entities from accessing Mythos and another high-performance Anthropic model, Fable, further complicating the already protracted negotiations. Although these restrictions were subsequently relaxed, the question of whether foreign institutions could access Mythos remained unresolved.
The European Commission spokesperson indicated that despite the conclusion of negotiations, the EU achieved only partial success, as ENISA will not have access to the latest iteration of the model, Mythos 5.1. According to insiders, the UK's AI Safety Institute, which was among the first non-US institutions to conduct stress testing on the original Mythos, similarly did not receive access to the new version.