Anthropic is giving the European Union direct access to Claude Mythos, the company’s specialized cybersecurity AI model, months after the system first went live for a small circle of American partners. The European Union Agency for Cybersecurity (ENISA) is now the first EU institution admitted into Project Glasswing, Anthropic’s controlled-access program for the model, according to the announcement and reporting from Bloomberg, the Financial Times, IT Pro, Firstpost, Unite.AI and ThePrint. The move ends a stretch in which European regulators and cyber defenders watched from outside while an AI system capable of finding thousands of critical software flaws stayed locked to a mostly US-based roster.

What Anthropic Announced

The core of the announcement is straightforward: Anthropic PBC has agreed to let ENISA use Claude Mythos, the model the company has positioned as an AI vulnerability scanner built specifically to hunt software vulnerabilities at industrial scale. Reports describe Mythos as having autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities across every major operating system and web browser, a scale of automated bug-hunting that has made the model one of the most closely watched releases in applied AI security this year.

What makes the announcement notable is the gap between Mythos becoming operational and Europe getting a seat at the table. The model has been running inside Project Glasswing for months, used by a roster of mostly American technology and financial firms, while European institutions negotiated for the same access. ENISA’s inclusion changes that, at least for the EU’s own cybersecurity apparatus, even as questions remain about how far access extends to individual member states versus the bloc’s central agency.

Inside Project Glasswing

Project Glasswing is Anthropic’s name for its controlled-access cybersecurity initiative, the mechanism through which outside organizations get to run Mythos against their own infrastructure and codebases. It is not a public API and it is not a product listing on Anthropic’s pricing page. Access is granted case by case, and the company has treated the roster itself as sensitive, given that a tool this good at finding zero-days is also, in the wrong hands, a tool this good at weaponizing them.

That tension, defense value versus offense risk, is the reason Glasswing looks nothing like a typical enterprise AI rollout. Instead of a self-serve signup, Anthropic vets each partner, and the access itself sits alongside what the company calls trusted access programs, the same terminology used for the current Claude Mythos 5.1 listing on Anthropic’s own product page. The structure signals that Anthropic expects this category of model to stay gated indefinitely, not to graduate into a mainstream commercial release the way earlier Claude versions did.

What Claude Mythos Actually Finds

Strip away the branding and Mythos is, in plain terms, an autonomous bug hunter. It reads code, models how a system behaves, and looks for the kind of flaw that would normally take a skilled human researcher days or weeks to isolate. The claimed result, more than 10,000 high- and critical-severity zero-days found across every major operating system and browser, is the figure Anthropic and outside coverage keep coming back to, because it is the number that actually explains why governments want the model rather than just reading about it.

Finding a zero-day is only half the value. What separates Mythos from a fuzzing tool bolted onto a language model is that the discoveries feed directly into patching pipelines at the partner organizations using it, turning what used to be a slow, expensive audit process into something closer to continuous scanning. That is precisely why a body like ENISA, whose job is coordinating vulnerability response across 27 member states, would push hard to get inside the program rather than wait for disclosures to arrive secondhand.

Why the EU Deal Took Months

Mythos did not launch yesterday, and that is the part of this story getting the most attention. The model, referenced in US government and export-control discussions as Mythos 5, has been subject to American export rules that determined who outside the United States could even be considered for access. Anthropic has also had to balance European Commission interest, with Brussels seeking access and being kept informed of developments, against a licensing regime designed by Washington, not Brussels.

Reporting from Bloomberg and the Financial Times has framed the gap as a case study in how export controls built around a single dominant AI developer can slow down cybersecurity cooperation between allies. The United States and the European Union share plenty of threat intelligence through existing channels, but neither Washington nor Brussels controls Anthropic’s model weights, which meant the timeline for EU access ran through Anthropic’s own vetting process and US licensing rules simultaneously rather than through a government-to-government agreement.

ENISA’s New Role

ENISA is described in coverage as the EU’s cybersecurity agency, and its entry into Project Glasswing makes it the first EU institution to hold that status. In practical terms, that gives the agency a direct line to a model capable of surfacing zero-days at a pace no human red team can match, which matters for an organization whose core mandate is helping member states respond to exactly that kind of threat.

It also puts ENISA in company that, until now, looked almost entirely American and largely corporate. Access for a EU regulatory body changes the character of the program, at least symbolically, from a club of tech giants and banks to something that includes a public-sector cyber-defense coordinator. Whether that access extends further, to national CERTs in individual EU countries or to European private-sector firms outside Glasswing’s existing roster, is the open question analysts are now asking Anthropic and the European Commission to answer.

Export Controls and the Mythos 5 Licensing Shift

Separate from the EU story, but tightly connected to it, the US government has eased part of the export-license requirement tied to Mythos 5. Under the earlier rule, sharing the model outside the United States required an export license regardless of who the end user was. The updated posture removes that requirement specifically for trusted companies and their employees who are not US citizens, while licensing remains mandatory for any company that has not already been approved.

That distinction matters for how the EU access deal actually works in practice. It means Anthropic can extend Mythos to non-US staff at already-vetted partner organizations without running each individual through a separate licensing process, which shortens onboarding for expansion inside existing partners. It does not, on its own, open the door to companies or agencies that have not already cleared Anthropic’s vetting, which is why ENISA’s admission required its own separate negotiation track rather than simply falling out of the licensing change.

Anthropic’s Cybersecurity Model Lineup

Mythos does not exist in isolation inside Anthropic’s product family. The company has been iterating on a specific branch of cybersecurity-focused models alongside its general-purpose Claude line, and the naming has shifted enough over the past year that it is worth laying out plainly what is what.

ModelTypeStatus / Note
Claude MythosProduction modelBuilt to hunt software vulnerabilities at industrial scale
Claude Mythos PreviewPreview releaseOffered to early cybersecurity partners
Mythos 5VersionCentral to the US export-control policy change
Claude Mythos 5.1Current listed versionAvailable through Anthropic’s trusted access programs
Fable 5Related modelReferenced alongside Mythos 5 in export-control discussion

The version numbering is a signal in itself. Anthropic moving from a preview label to a numbered 5.1 release inside a matter of months suggests the company is iterating on Mythos at a pace closer to its consumer Claude releases than to a slow-moving enterprise security product, even though access to it remains far more restricted than anything in the consumer line.

Who Else Is Inside Project Glasswing

ENISA’s addition is easier to understand against the backdrop of who was already in the room. The program’s confirmed roster leans heavily toward large US technology and financial firms, with Britain standing out as the only non-US country to have shared access to Mythos before this announcement.

OrganizationSectorAccess Status
AmazonCloud and technologyProject Glasswing partner
AppleConsumer technologyProject Glasswing partner
MicrosoftCloud and technologyProject Glasswing partner
GoogleCloud and technologyProject Glasswing partner
JPMorgan ChaseFinancial servicesProject Glasswing partner
StrikeCybersecurityProject Glasswing partner
Alto NetworksCybersecurityProject Glasswing partner
United KingdomGovernment (non-US)First non-US government with access
ENISA (EU)EU government agencyFirst EU institution admitted, September 2026

Reading that list, the pattern is clear: cloud infrastructure providers, a major bank, and dedicated cybersecurity firms, plus exactly one non-US government before today. ENISA breaks that pattern in a specific way, since it is neither a private company nor a national government but a supranational regulatory body, which is a different kind of relationship for Anthropic to manage than a corporate NDA.

How Fast Project Glasswing Has Grown

TechCrunch reported in June 2026 that Project Glasswing had already expanded to more than 150 organizations spread across at least 15 countries, up from a much smaller initial group named when the preview version first went out. That expansion, according to the outlet, followed Anthropic’s confidential IPO filing and a funding round that pushed the company’s valuation toward the trillion-dollar mark, a scale of capital that has let Anthropic staff a vetting and support operation big enough to onboard partners at that pace.

The same TechCrunch reporting cited an Anthropic risk assessment warning that a serious attack on one of its Glasswing partners could affect well over 100 million people, a framing the company has used to justify why access stays this tightly controlled even as the roster grows. Named partners cited in that coverage include Okta, Samsung, and South Korean firms SK Hynix and SK Telecom, alongside NATO, which points toward a program that has moved well beyond its original core group of American tech and finance names.

The Competitive Field: OpenAI, Google and the Race for AI Security Tools

Anthropic is not running this race alone. The Next Web’s coverage of the ENISA deal notes that OpenAI has pursued a parallel effort branded Daybreak alongside a cybersecurity-tuned model it calls GPT-5.5-Cyber, positioning OpenAI as Anthropic’s most direct rival in the same niche. The same reporting points to at least one bank, BNP Paribas, exploring an alternative approach built on Mistral’s models rather than waiting on either US lab.

That matters for how the EU access story should be read. This is not simply Anthropic doing Europe a favor. It is a company defending a first-mover position in a category, autonomous vulnerability discovery, where the customer base includes the exact governments and regulators that will eventually decide how AI-driven security tools get licensed and audited. Losing the EU’s cybersecurity establishment to a rival product, or to a homegrown European alternative, would cost Anthropic more than the ENISA contract itself. It would cost the company influence over how the category gets regulated on a continent that has already shown it is willing to move first on AI rules.

Market Impact: What This Means for Cybersecurity Vendors

For established vulnerability-management vendors, the news is uncomfortable reading. A model that autonomously finds thousands of zero-days and plugs the results into a partner’s patching workflow is a direct substitute for a chunk of what commercial penetration-testing and bug-bounty operations sell today. That threat is not evenly distributed. Firms already partnered with Anthropic through Glasswing, including the cybersecurity companies Strike and Alto Networks named in the program’s roster, are positioned to fold Mythos into their own offerings rather than compete against it directly.

For everyone outside the program, the calculus is different. A European security vendor that cannot get access to Mythos, or to a comparable model from OpenAI or Google, is competing against tools it cannot even evaluate directly. That asymmetry is part of why ENISA’s access matters beyond the symbolism: a regulator that can see inside the leading tool in a category is better positioned to write rules for that category than one working from vendor marketing material and press coverage alone.

Historical Context: From Bug Bounties to Autonomous Hunting

Automated vulnerability discovery is not new. Static analyzers, fuzzers, and bug-bounty platforms have been part of the security stack for well over a decade, and government-run programs have long paid researchers to find flaws before attackers do. What is new with Mythos is the claim of autonomy at scale, a system that does not just flag suspicious patterns for a human to check but independently chases a lead from suspicion to confirmed, high-severity zero-day, repeated across more than 10,000 findings.

The controlled-access model Anthropic has built around that capability also has precedent, even if the specifics are new. Export-controlled cryptography and dual-use research have followed similar patterns for decades, restricted to vetted partners because the same capability that defends can also attack. Project Glasswing extends that logic to a large language model for the first time at this scale, which is exactly why an export-control debate, rather than a simple product launch, has shaped so much of the coverage around Mythos since its preview release.

Risks and Open Questions

The obvious risk sits in the name of the program itself. A model this effective at finding zero-days is, by definition, effective at generating a roadmap for attacking the same systems, and every organization added to Glasswing widens the pool of people who could misuse that capability, whether through a compromised account, an insider, or a partner whose own security does not match Anthropic’s vetting standards.

There is also a governance question specific to the EU deal. ENISA coordinates cybersecurity policy across the bloc, but it is not the only body with a claim to this kind of access. National CERTs, the European Commission’s own cybersecurity units, and individual member-state intelligence services could reasonably argue they need direct access too, and Anthropic has not said how far it intends to extend Mythos within the EU beyond ENISA’s initial admission. How that plays out will likely shape whether other export-restricted AI capabilities follow a similar country-by-country, agency-by-agency negotiation path in the future.

What Comes Next: Five Predictions

  • Other EU bodies, particularly national CERTs in larger member states, will push for their own direct Glasswing access rather than routing everything through ENISA.
  • OpenAI and Google will each publicize expanded access programs for their own cybersecurity-focused models within the next two quarters, using the ENISA deal as a competitive benchmark to match or beat.
  • US export-control policy toward Mythos and comparable models will keep evolving in stages, easing restrictions for vetted partners while keeping a hard line against unvetted companies and adversarial states.
  • Anthropic will use its expanding government and regulator relationships, including ENISA, as leverage in upcoming AI-safety and AI Act compliance discussions with Brussels.
  • Commercial vulnerability-management vendors without a Glasswing-equivalent partnership will accelerate their own AI-assisted scanning products to avoid losing ground to Mythos-equipped competitors.

None of these are certainties, and Anthropic has not confirmed a roadmap for further EU expansion beyond ENISA’s admission. But the direction of travel, from a US-only roster toward a broader international one, plus rival labs racing to match Anthropic’s positioning, makes each of these a reasonable bet based on how the program has grown since its preview release.

The Bigger Picture

Strip away the diplomacy and this is a story about who gets to see the most powerful bug-hunting tool built so far, and on what terms. Anthropic built Mythos to be too dangerous to hand out freely and too useful to keep entirely to itself, and Project Glasswing is the compromise it landed on. ENISA’s admission shows that compromise can flex to include a European regulator, months after it first flexed to include American banks and cloud providers. Whether it flexes further, to more governments, more sectors, more countries, is the question that will define how much this single AI model ends up shaping global cybersecurity policy rather than just national defense inside the United States.

Frequently Asked Questions

What is Claude Mythos?

Claude Mythos is Anthropic’s specialized AI model built to hunt software vulnerabilities at industrial scale. It has been credited with autonomously discovering more than 10,000 high- and critical-severity zero-day vulnerabilities across every major operating system and web browser.

What is Project Glasswing?

Project Glasswing is Anthropic’s controlled-access cybersecurity initiative through which vetted organizations get to use Claude Mythos against their own systems. It is not a public product and access is granted case by case rather than through a self-serve signup.

Why did it take months for the EU to get access to Mythos?

The delay reflected a combination of US export-control rules tied to the model, referenced as Mythos 5 in government contexts, and a separate negotiation track between Anthropic and the European Commission. Bloomberg and the Financial Times have both covered the standoff as a flashpoint in transatlantic AI policy.

What is ENISA and what will it do with Mythos?

ENISA, the European Union Agency for Cybersecurity, is the EU’s cybersecurity agency and is now the first EU institution to join Project Glasswing. Its role is coordinating cybersecurity response across EU member states, which is the function its Mythos access is meant to support.

Does this mean Mythos is now publicly available in Europe?

No. Access remains restricted to vetted Project Glasswing partners. ENISA’s admission gives the EU’s cybersecurity agency direct access, but Mythos has not been released as a public or commercial product in Europe or anywhere else.

What changed with US export controls on Mythos 5?

The US eased its export-license requirement so that Mythos 5 no longer needs an individual export license to reach non-US employees at already-trusted companies. Companies that have not been vetted still require a license before gaining any access.

Who else has access to Mythos through Project Glasswing?

Confirmed partners include Amazon, Apple, Microsoft, Google, JPMorgan Chase, and the cybersecurity firms Strike and Alto Networks. Britain was the only non-US country with access before ENISA’s admission, and TechCrunch has reported additional partners including Okta, Samsung, SK Hynix, SK Telecom, and NATO as the program expanded through mid-2026.

Is Anthropic’s Mythos the only AI model built for this kind of cybersecurity work?

No. OpenAI has pursued a comparable effort under the name Daybreak alongside a model branded GPT-5.5-Cyber, and at least one financial institution has explored building its own alternative on Mistral’s models rather than relying on either US lab, according to The Next Web.