Thirty Members of the European Parliament from six political groups have written to Henna Virkkunen, European Commission Executive Vice‑President, urging the EU to revise its cybersecurity framework to address AI‑driven hacking technologies such as Anthropic's Mythos. The letter was reported by Politico.
What happened and why it's concerning
Anthropic announced in spring that Mythos can identify and exploit software vulnerabilities more effectively than most humans. The company has not released the model commercially; instead it first granted access to twelve U.S. tech giants — including Apple, Microsoft and Amazon — and then to a further forty unnamed organisations. Anthropic has also been in ongoing discussions with the U.S. government.
European authorities, however, have received very limited information. Politico contacted eight national agencies in mid‑April; only the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) reported that it had entered talks with Anthropic, and even the BSI has not been able to test the model.
By contrast, the United Kingdom's AI Safety Institute has already examined Mythos and taken measures based on its findings.
The MEPs' demands
In their letter the MEPs request that the EU Agency for Cybersecurity, ENISA, be granted access to Mythos and similar models to enable a thorough assessment of risks. They also call for reforms to rules on the disclosure and remediation of cyber vulnerabilities, and for strengthened protection of critical infrastructure.
Signatories include Markéta Gregorová, the rapporteur for the ongoing review of the EU Cybersecurity Act, and Dutch liberal MEP Bart Groothuis, who said: “Europe is not at the table.”
Anthropic and the EP hearing
The European Parliament's internal market committee invited Anthropic to a public hearing, but the company declined, citing the short notice for the invitation.
The MEPs say they intend to use the current review of the EU Cybersecurity Act as the vehicle for the response they seek.
Expert and national security concerns
Claudia Plattner, head of the BSI, warned in mid‑April that an open availability of such "extraordinarily powerful" tools would raise profound national security and sovereignty implications. Yoshua Bengio, a researcher at the Université de Montréal and one of the early leaders in AI, told Politico it is "extremely worrying" that decisions on how to handle these risks are effectively being made by tech companies rather than regulators.
Laura Caroli, a former key figure in drafting the EU AI Act, pointed out that the EU's limited involvement is partly because the model has not been commercialised; had it been a commercial product, Anthropic would be subject to binding obligations under the AI Act and the Cyber Resilience Act. Caroli also suggested considering how the situation might differ if a non‑U.S. company — for example a Chinese firm — were in Anthropic's position.
Why this matters
The case highlights a gap: there is no global mechanism to oversee the risks of the most advanced AI models, leaving access and control decisions largely in the hands of private companies. MEPs and officials involved say the situation requires urgent European action and regulatory adjustment so that the EU can assess and mitigate similar technological risks promptly and effectively in future.


