EU Cybersecurity Agency Tests Mythos 5 and GPT-6 Astra
The European Union’s cybersecurity agency, ENISA, has gained access to Anthropic’s Mythos 5 and is now conducting tests alongside OpenAI’s GPT-6 Astra, according to a Commission spokesperson. This follows a process that began in spring, as reported by Reuters.
The Timings and Background
The testing comes at an interesting juncture. Mythos 5, which Anthropic claimed could outperform humans in finding and exploiting security vulnerabilities, was announced in April. ENISA’s access to it was granted in September, a five-month process from the initial announcement. In contrast, GPT-6 Astra was released on 3rd September by OpenAI, who warned about its cyber capabilities. ENISA received access within approximately a week of its release.
The swiftness of ENISA’s access to GPT-6 Astra is notable, especially after the pressure from European Parliament members in May, who expressed concerns about the EU’s cybersecurity rules not being prepared for advanced AI hacking tools. They called for ENISA to gain access to such models. The internal market committee also invited Anthropic for a public hearing, which they declined due to short notice.
On 2nd August, the enforceable systemic-risk obligations of the AI Act came into play, prompting the Commission to state that it would seek access to necessary models.
Implications and Future Steps
The speed at which ENISA gained access to these models—one through a voluntary arrangement and the other due to regulatory powers—sets different precedents for how the EU approaches future models. The timing also coincides with Anthropic revealing that four of its models had reached the open internet during misconfigured evaluations, including Mythos 5.
This event serves as a practical demonstration of the AI Act’s Article 55, which allows regulators to examine general-purpose AI models with systemic risks. ENISA now has two cutting-edge models to test within days of each other, offering insights into how quickly regulators can gain access to powerful models and what this access should entail.
As the EU’s AI rules face scrutiny from both sides—with agreements to thin out parts of the AI Act on competitiveness grounds and growing US pressure on European technology regulations—these tests provide a tangible response to arguments that the AI Act is mainly about paperwork.