Confirmed: EU tests Anthropic's Mythos 5 and GPT-6 Astra at ENISA

The European Union's cybersecurity agency ENISA has been granted access to Anthropic's frontier model Mythos 5 and is now testing it, the European Commission confirmed in September 2026.

Illustration: A matte black sealed container on a laboratory bench surrounded by measuring instruments and a cobalt-blue inspection lamp, a metaphor for the EU cybersecurity agency ENISA testing a closed frontier model.
Illustration
Gift article

Confirmed: EU tests Anthropic's Mythos 5 and GPT-6 Astra at ENISA

The European Union's cybersecurity agency ENISA has been granted access to Anthropic's frontier model Mythos 5 and is now testing it, the European Commission confirmed in September 2026.

The test is one of the first live applications of AI Act Article 55 – and it is happening just as parts of the same law are being rewritten.

Commission spokesman for digital affairs Thomas Regnier confirmed the access in a statement reported by AFP/TechXplore: "Following our constructive engagement with Anthropic, we can confirm that the EU's cybersecurity agency ENISA has been granted access to Mythos 5 and is now testing it." According to TNW's coverage, ENISA is also testing OpenAI's GPT-6 Astra. Together, this constitutes one of the first clear examples of the AI Act's oversight system in actual operation – a milestone for how the EU enforces the rules for general-purpose AI models with systemic risk.

But the story is more complicated than a simple success story. The access came only after months of pressure, a US unavailability, and a letter from 30 European parliamentarians. And while ENISA is finally putting the law into practice, the Council and Parliament are revising other parts of the same law through the Digital Omnibus agreement reached in May 2026. Oversight capability is thus growing at the same time as the law itself is being thinned out – that is the tension this analysis follows.

What Article 55 actually means

The AI Act's systemic-risk obligations for general-purpose AI models became enforceable on 2 August 2026, according to TNW. From that date, models deemed to pose systemic risk could be subjected to EU oversight – not just through voluntary reporting, but through actual examination.

Article 55 is the core of this oversight. As TNW explains, the article gives regulators the ability to examine general-purpose AI models with systemic risk directly, instead of relying entirely on what companies themselves say about them. The difference is practical and significant: Self-reporting depends on developers correctly identifying the risks, testing them thoroughly, and sharing the findings voluntarily. Direct examination allows the authorities to verify the claims themselves.

ENISA's testing of Mythos 5 and GPT-6 Astra is therefore an early operational trial of whether this oversight actually works in practice – not just on paper. That is why the story deserves attention beyond the news value of the access itself: It shows whether the EU's new enforcement apparatus has the capacity and genuine access to do the job the law assigns it.

The campaign for access: April to September

The road to today's testing was long and winding, and it says something about what the balance of power between regulators and frontier companies looks like in practice.

The pressure began in April 2026, according to TNW citing Politico. That month, Anthropic released the Mythos model to a small group of organisations – in the United States only. European institutions were left out. The situation became more complicated, TechRepublic writes: The US government imposed restrictions on foreign access to Mythos 5 and another advanced Anthropic model. Those restrictions were later eased, but access for European institutions remained unresolved.

In May, 30 members of the European Parliament, from six political groups, wrote to Executive Vice-President Henna Virkkunen. The letter, reported by TNW, warned that the EU's cybersecurity rules were not prepared for a new generation of AI-powered hacking tools, and urged that ENISA be given access.

In July 2026, the EU finally gained access to the most capable American models, after months of requests, Politico reported via TNW. And in September, Commission spokesman Regnier confirmed that testing is now under way.

It is worth noting what we do not know about this sequence: The Commission has not said whether the parliamentary pressure was decisive in Anthropic opening up access, or whether it would have happened regardless. The May letter is documented; a causal link is not.

Open questions about the testing itself

Even with access in place, much remains uncertain – and some of the uncertainty materially matters for what the results actually mean.

First: Which configuration of Mythos is being tested? Anthropic has separately released a limited version called Mythos 5.1, with a different set of safeguards, and this model has never been generally available, TNW writes. Neither the Commission nor Anthropic has said whether ENISA is testing Mythos 5, Mythos 5.1, or something else. TNW points out that this matters for what the results actually show – different safety setups can produce different findings.

Second: TechRepublic points to a paradox. Because Mythos 5.1 has already launched, ENISA is beginning its evaluation with a model that is no longer the company's newest cyber system. Oversight, in other words, always lags behind the development curve – a structural problem for any regime intended to examine models that are quickly superseded by newer ones.

Third: It is unclear what actually happens if ENISA's tests uncover a serious problem. TNW notes that this has not been settled – neither the consequences for the company, for the model, nor for further enforcement.

Capacity: How big is the examining machine?

Article 55 oversight presumes that someone actually has the time, expertise and tools to carry out the tests. TNW has previously reported that the AI Office – the Commission's enforcement body for the AI Act – began its work with a team of 36 people.

The number is worth sitting with. Examining frontier models requires technical expertise at the highest level, and ENISA's testing is a cross-agency collaboration. With such a small starting team, it is an open question how many such evaluations the European apparatus can realistically absorb – especially if each test, like this one, takes months of negotiations just to gain access. ENISA's testing of Mythos 5 and GPT-6 Astra is a beginning, not necessarily a template that scales easily.

The parallel track: Digital Omnibus and Article 4

While ENISA tests, the law is being rewritten. In May 2026, the Council and Parliament reached a provisional agreement on the Digital Omnibus package, which – according to an opinion piece by Diogo Soares (BNP Paribas) in IAPP – brings significant changes to the AI Act, changes that have themselves attracted attention.

One of the most notable changes concerns Article 4, the AI literacy provision. In a subtle change, Soares writes, the revised article deletes the words "best extent". That sounds technical, but it changes what providers must actually do to meet the requirement that employees and users have sufficient AI literacy.

Soares argues – and this is his interpretation, not a documented fact – that the change may increase rather than reduce compliance complexity: When a previously more open obligation is reformulated, it becomes unclear what is actually required. At the same time, European data protection authorities have pushed back: The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) warned in their joint opinion that promoting AI literacy should complement, not replace, the existing obligation.

Meanwhile, according to TNW's analysis, the Commission has agreed to thin out parts of the AI Act on competitiveness grounds – while the US increasingly treats European technology regulation as a trade issue. The context, in other words, is not just technical implementation but also geopolitical pressure on the framework itself.

What this means for providers and users

For AI providers, the story points in two directions. First, direct oversight is now a reality: Models with systemic risk can be examined by European authorities, and access to the models is a precondition for that oversight. Anthropic's decision to grant access – under pressure – establishes a precedent other developers will have to reckon with.

Second, the compliance picture is in motion. With Article 4 under revision, and with the EDPB and EDPS opposing a dilution of the obligation, it is uncertain which version of the law providers and users will ultimately have to comply with. A law being enforced while it is revised creates uncertainty for those who must comply with it.

For European institutions and citizens, the long-term question is whether the oversight actually has teeth: ENISA's testing is a first trial, but how quickly and how often such evaluations can be repeated – and what follows from negative findings – remains to be seen.

What remains

Much is still open: which model configuration ENISA is testing, what criteria are being applied, and what happens if the tests uncover something serious. No primary sources from the Commission or Anthropic are publicly available at this point – all confirmations come through secondary coverage from AFP/TechXplore, TechRepublic, TNW and Politico.

What we do know is this: The systemic-risk obligations became enforceable on 2 August. In September, ENISA is testing Mythos 5 and GPT-6 Astra. The oversight machine is running – after months of negotiations, a parliamentary letter and American export restrictions. And while the first trial of Article 55 takes place, Europe's legislators are still debating what the law should actually say. European AI regulation is moving from paper to practice – but on a legal landscape that is still in motion.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.