Anthropic opens Mythos access to EU cybersecurity agency ENISA

Anthropic will give the EU cybersecurity agency ENISA access to Claude Mythos through Project Glasswing, ending weeks of stalled talks. The model has found more than 10,000 high- and critical-severity zero-day vulnerabilities, and ENISA becomes the first EU institution to join the controlled-access program.

Anthropic opens Mythos access to EU cybersecurity agency ENISA

Anthropic has agreed to give the European Union’s cybersecurity agency, ENISA, access to Claude Mythos, the company’s AI model for finding software vulnerabilities. The decision, communicated to the European Commission over the weekend, makes ENISA the first EU institution to join Project Glasswing, Anthropic’s controlled-access cybersecurity program.

The move ends weeks of tense negotiations between Anthropic and European officials. According to the source article, euro-area finance ministers, the European Central Bank and several EU member states had pushed for access after learning that Mythos had identified flaws in systems used by European banks, governments and critical infrastructure providers, while no European institution could review the findings.

⚡ New to this?

This story is about access to an AI system that can find serious software bugs before attackers do. ENISA, the EU’s cybersecurity agency, will now be able to use Anthropic’s Mythos model, which matters because the model has found more than 10,000 zero-day vulnerabilities - flaws that are unknown or unpatched. For non-specialists, that means European regulators can finally see security findings that may affect banks, government systems and other critical infrastructure.

🦞 OpenClaw angle

If you run self-hosted security automation, treat this as a reminder to separate vulnerability discovery from vulnerability disclosure. Build workflows that store findings in a controlled system, track who can view them, and support jurisdiction-based sharing rules if you work across regions. If you are testing large codebases with AI agents, add approval gates before any exploit generation or proof-of-concept output is saved, exported, or handed to third parties.

Mythos is not a standard security scanner. Anthropic launched the model in April 2026 as Claude Mythos Preview, and the company says it can autonomously identify security flaws in complex codebases, generate working exploits on the first attempt in more than 83% of cases, and run attack simulations that would normally take human researchers months.

In its first month inside Project Glasswing, Mythos reportedly found more than 10,000 zero-day vulnerabilities across major operating systems and web browsers. A zero-day vulnerability is a flaw that is unknown to the vendor or has not yet been patched, which makes it especially valuable to attackers and urgent for defenders.

Anthropic has worked with more than 50 large technology companies, including Microsoft, Apple, Google and Cloudflare, to deploy Mythos against tightly targeted codebases, according to the source article. The company’s logic is straightforward: an AI system that can understand and modify complex software can also find where that software is weak.

Until this EU decision, access had been limited to about 40 vetted US companies and select government entities, with recent access also granted to UK financial institutions. OpenAI has since launched a competing effort, Daybreak, aimed at finding vulnerabilities and generating patches, but the source article says Mythos remains the benchmark because of its zero-day discovery rate.

The path to EU access was not smooth. Anthropic and the European Commission held four to five meetings soon after Mythos was announced, but the talks stalled. Commission officials then travelled to San Francisco last week to press the case in person, according to the report.

An ENISA spokesperson told reporters, “It’s been offered but the conditions are still being agreed,” confirming that the decision to grant access had been made even though the terms were still under negotiation. The article says the sticking points were not made public, but likely involve data sovereignty, limits on how findings can be shared with EU member states, and the scope of the systems ENISA can test.

The standoff had already prompted BNP Paribas and Mistral to begin work on a European alternative, according to the source article. That effort will continue despite ENISA’s access to Mythos.

The larger issue is that the EU AI Act, which enters full enforcement in August 2026, regulates how AI models can be deployed in Europe, but does not give European regulators a way to force an American company to share its most powerful security model. The article says that gap became more visible as Mythos uncovered vulnerabilities in software used by banks, governments and critical infrastructure.

The European Central Bank convened euro-area banks to discuss the cybersecurity implications after learning about the findings, and the European Commission said it held “several productive meetings” with Anthropic. Whether ENISA’s access will be on commercial terms or through a government arrangement has not yet been disclosed.

Source: The Next Web ↗

More from Security News