Skip to content
Tech News
← Back to articles

Anthropic to Open Mythos AI to EU's ENISA

read original more articles
Why This Matters

The EU's access to Anthropic's Mythos AI model marks a significant step in understanding and managing the risks associated with advanced AI-driven cybersecurity tools. This collaboration highlights the importance of regulatory oversight and responsible AI development to prevent malicious exploitation while harnessing AI for security improvements.

Key Takeaways

The European Union is close to gaining access to Anthropic's frontier AI model, Mythos, after weeks of pressing for inclusion in Project Glasswing, a tightly controlled initiative that provides select organizations with access to the model for cybersecurity research and vulnerability discovery.

In comments to Dark Reading, European Commission spokesperson for Tech Sovereignty Thomas Regnier confirmed media reports this week about Anthropic agreeing to let EU cybersecurity agency ENISA access Mythos for vulnerability research: "I can confirm that the European Commission had several productive meetings with Anthropic. We welcome the latest developments on potential future access."

By way of background, Claude Mythos Preview is an Anthropic AI model that has raised considerable concern for its ability to not just detect software vulnerabilities but to also autonomously develop exploit chains for them at unmatched speed and scale. Anthropic has reported the model discovering thousands of vulnerabilities in widely used software, including a 27-year-old flaw in OpenBSD and a 17-year-old vulnerability in FreeBSD. Many researchers fear that a tool like Mythos could significantly lower the barrier to discovering and exploiting software vulnerabilities at scale, enabling both state and non-state actors to automate sophisticated cyberattacks faster than most organizations can patch or respond.

Related:As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

Mythos a Matter of "Utmost Importance" for the EU

Regnier described the outcome as "the result of the Commission's strong bilateral cooperation and engagement with Anthropic" and stressed that access to Mythos is "of utmost importance to get a clear picture on the potential risks" tied to AI-assisted vulnerability discovery and exploitation.

Regnier emphasized that the concern around the dual-use nature of AI tools extends well beyond a single model. "Mythos is not a one-off — a new wave of powerful models are coming to the market," he said. "This is a shared challenge, and we are intensifying our discussions with like-minded partners, including the United States."

In April, Anthropic announced that it would make Mythos' capabilities available to a tightly vetted group of companies so they could use the technology to look for and secure vulnerabilities in their products before adversaries find them. The so-called Project Glasswing initiative currently includes more than 40 organizations, such as Amazon, Apple, Microsoft, Google, Linux Foundation, JP Morgan Chase, NVIDA, and several others. Among them are organizations that build and maintain critical software infrastructure, and also providers of open source software. Anthropic has said it will commit $100 million in usage credit for these organizations to use Mythos.

Related:Dutch Raid Fails to Dent Russian Bulletproof Host

ENISA: Project Glasswing's First EU Partner

... continue reading