EU cybersecurity agency ENISA has been granted access to Claude Mythos 5 and GPT-6 Astra; ENISA still lacks access to Mythos 5.1
Context & Ripple Effects
The access follows June reporting that Anthropic planned to bring ENISA into Project Glasswing and provide Mythos access. It gives the EU agency a route to assess two frontier systems rather than relying solely on vendor-facing safety claims.
The development also lands after the UK AISI reported July evaluation incidents involving Mythos 5 and GPT-5.6 Sol. ENISA’s access to Mythos 5 and GPT-6 Astra, but not Mythos 5.1, makes model-version coverage—not simply access—central to public-sector cyber testing.
First-order effects
- ENISA can directly evaluate Claude Mythos 5 and GPT-6 Astra for cyber risks, while its lack of Mythos 5.1 access leaves the agency unable to assess that version on the same basis.
- Anthropic and OpenAI gain an EU-government testing channel for the models ENISA can access; Anthropic’s newer Mythos 5.1 remains outside that channel.
Second-order effects
- EU cyber-risk assessments will be able to compare the two accessible models, but conclusions about the Mythos line will be bounded by the missing 5.1 version—creating pressure for access arrangements to specify releases rather than model families.
- The arrangement turns the earlier plan for ENISA to join Project Glasswing into an operational benchmark for other frontier-model providers seeking engagement with EU security bodies.
Third-order effects
- If access continues to be negotiated version by version, frontier-model oversight will increasingly depend on release-specific testing rights, with governments’ visibility determined by providers’ access decisions.
- The split between ENISA’s available models and the withheld Mythos 5.1 points toward public cyber evaluations of advanced models becoming part of how states seek practical control over frontier AI risks.
The trend: Frontier-model governance is shifting from broad safety commitments toward state access to specific model versions for independent cyber evaluation.