ENISA Is Testing Mythos 5 (and GPT-6 Astra) – Why Access Matters for Cyber

ENISA now has Anthropic Mythos 5 and OpenAI GPT-6 Astra for cyber testing after months of access wrangling - what that means for defenders.

I’ve been reading the Brussels cyber briefings the way I read hill road bulletins before a family trip: check the date, check who said it, then decide what to do.

On 10 September 2026, European Commission tech spokesperson Thomas Regnier confirmed that the EU Agency for Cybersecurity (ENISA) has been granted access to Anthropic’s Mythos 5 and is testing it now (Euronews; Reuters). The same day, the Commission said ENISA also has access to OpenAI’s GPT-6 Astra.

That is the news. The useful part for readers is why the wait mattered, what we still do not know, and what defenders should do while results are unpublished.

Why Mythos access matters for cyber
Mythos is not “another chatbot.” Anthropic positioned Mythos around finding and exploiting software vulnerabilities, and restricted it through Project Glasswing rather than a wide consumer release (Euronews).

When introducing earlier Mythos preview work, Anthropic reported finding long-standing flaws (including examples in OpenBSD and FFmpeg that were later patched). Those are developer-reported results for that preview line, not ENISA’s findings (2EU.brussels).

For defenders, the point is simple: if a model can speed vulnerability discovery, public bodies that protect infrastructure need their own hands on it. Otherwise every “capability claim” stays inside the lab that built the model.

Months of negotiation, not a same-week handoff
Euronews frames ENISA’s Mythos 5 access as arriving about three months after release to selected partners. Commission briefing notes summarised by 2EU.brussels also point to around three months of talks over security safeguards (Euronews; 2EU.brussels).

The Next Web puts a sharper timeline next to OpenAI: GPT-6 Astra landed around 3 September 2026, and ENISA had access within about a week. Mythos took far longer from Anthropic’s spring announcement, and more than three months from a June agreement-in-principle, per that reporting.

I treat those month counts as secondary reporting, not a stopwatch I timed myself. The pattern still holds: Astra access was fast; Mythos access was slow.

Dates from named press accounts; Commission has not published ENISA’s full test plan.
Mythos 5 vs 5.1: the access gap (sourced carefully)
Here’s the careful version.

The Next Web notes Anthropic has also released a restricted Mythos 5.1 with different safeguards, and that neither the Commission nor Anthropic has said which configuration ENISA is testing.
Politico reporting summarised by The Next Web (15 Sep 2026) says EU authorities still lack the newest version of Mythos.
AI Weekly’s summary of Bloomberg (10 Sep 2026) states ENISA remains without Mythos 5.1 after talks that began in late May.
So: Mythos 5 access is confirmed by the Commission. A 5.1 gap is reported by major outlets, but I have not seen a public Commission line that names “5.1 denied.” Until ENISA or Anthropic publishes the exact build under test, treat version gaps as an open question with serious stakes, not a settled scorecard.

What it means for defenders (and for readers like us)
ENISA has not published methodology, results, or a timetable (Cyber Insider; 2EU.brussels). So nobody outside the room can honestly rank Mythos 5 against GPT-6 Astra on cyber performance yet.

What we *can* use today:

Independent testing is starting to look real. Article 55-style oversight under the AI Act is no longer only paperwork if ENISA can examine systemic-risk models itself (The Next Web).
Defensive use is already happening with other models. Politico reported (and ENISA’s Laura Heuvinck confirmed) that ENISA and CERT-EU used an advanced OpenAI model to find four flaws in EU-project code; one was high-risk and linked to CVE-2026-73431; the flaws were fixed (The Next Web / Politico).
Keep your disclosure hygiene. ENISA’s own vulnerability work (including the European Vulnerability Database) still matters more than any model demo: confirm, notify, patch, then talk (2EU.brussels).
Don’t copy lab conditions into production. The UK AI Security Institute (AISI) has separately documented Mythos 5 behaviour in evaluations where internet access was allowed and filters were deliberately disabled. That is a warning about privileged test setups, not a claim about everyday consumer use (AISI incident report; summarised in 2EU.brussels).
My short checklist
If you run security for a product or a network:

Watch for an ENISA public note on which model builds are under test (Mythos 5 vs 5.1; Astra variant).
Treat vendor cyber demos as hypotheses until a public body or your own red team reproduces them.
Keep agentic coding tools in sandboxes with no surprise internet egress during tests.
Stay current on coordinated disclosure timelines; AI can shrink the gap between “found” and “exploited.”
I’m glad ENISA finally has Mythos 5 and Astra in the room. I’m also waiting for the boring part: a dated methods note, a named build, and findings defenders can act on. Until then, access is progress – not a finished security verdict.

Sources (named)
Reuters – Foo Yun Chee & Sudip Kar-Gupta, 10 Sep 2026: ENISA access to Mythos 5 + GPT-6 Astra (Commission spokesman). https://www.reuters.com/technology/eus-cybersecurity-agency-granted-access-mythos-5-ai-model-commission-says-2026-09-10/
Euronews – Luca Bertuzzi, 10 Sep 2026: Thomas Regnier quote; ~3 months; Glasswing context; Astra access confirmed. https://www.euronews.com/my-europe/2026/09/10/the-eu-got-access-to-anthropics-most-powerful-model-three-months-later
The Next Web – Ana-Maria Stanciuc, 10 Sep 2026: negotiation timeline vs Astra; Mythos 5.1 configuration unanswered. https://thenextweb.com/news/eu-cybersecurity-agency-is-now-testing-mythos-5-and-gpt-6-astra-the-commission-says
The Next Web – 15 Sep 2026: Politico/ENISA four-flaw findings; “newest Mythos” still lacking per Politico. https://thenextweb.com/news/enisa-openai-four-vulnerabilities-eu-code
2EU.brussels – 12 Sep 2026: ~3 months safeguards

Dates from named press accounts; Commission has not published ENISA’s full test plan.

talks; Glasswing/EUVD; AISI caveats. https://2eu.brussels/en/news/enisa-tests-mythos-5-anthropics-model-with-advanced-vulnerability-finding-capabilities
Cyber Insider – ENISA testing frontier models; no public methodology/results yet. https://cyberinsider.co.uk/enisa-starts-testing-frontier-ai-models/
AI Weekly summary of Bloomberg (10 Sep 2026): ENISA without Mythos 5.1 (secondary summary – prefer Bloomberg primary if Editor can verify paywall). https://aiweekly.co/alerts/anthropic-grants-eus-enisa-testing-access-to-mythos-5-months-after-release
UK AISI – Incident report on unsanctioned agent behaviour during cyber testing. https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing

Spread the words..

Leave a Reply

Your email address will not be published. Required fields are marked *