search icon
search icon
Flag Arrow Down
Română
Română
Magyar
Magyar
English
English
Français
Français
Deutsch
Deutsch
Italiano
Italiano
Español
Español
Русский
Русский
日本語
日本語
中国人
中国人

Change Language

arrow down
  • Română
    Română
  • Magyar
    Magyar
  • English
    English
  • Français
    Français
  • Deutsch
    Deutsch
  • Italiano
    Italiano
  • Español
    Español
  • Русский
    Русский
  • 日本語
    日本語
  • 中国人
    中国人
Sections
  • News
  • Exclusive
  • INSCOP Surveys
  • Podcast
  • EU
  • Diaspora
  • Republic of Moldova
  • Politics
  • Economy
  • Current Affairs
  • International
  • Sport
  • Health
  • Education
  • IT&C knowledge
  • Arts & Lifestyle
  • Opinions
  • Elections 2025
  • Environment
About Us
Contact
Privacy policy
Terms and conditions
Quickly scroll through news digests and see how they are covered in different publications!
  • News
  • Exclusive
    • INSCOP Surveys
    • Podcast
    • EU
    • Diaspora
    • Republic of Moldova
    • Politics
    • Economy
    • Current Affairs
    • International
    • Sport
    • Health
    • Education
    • IT&C knowledge
    • Arts & Lifestyle
    • Opinions
    • Elections 2025
    • Environment
162 new news items in the last 24 hours
  1. Home
  2. Economie

AI models capable of cyber attacks could emerge in six months, and MEPs warn that Europe depends on decisive access to Washington.

Liviu Brăteanu
whatsapp
facebook
linkedin
x
copy-link copy-link
15 July 2026, 17:56
main event image
EU
Foto: Pixabay
google-preference

Always see our news on Google

Artificial intelligence models capable of identifying unknown vulnerabilities and constructing attack chains could become widely available within the next three to six months, warned Anthropic in the European Parliament's Internal Market and Consumer Protection Committee. The hearing in IMCO showed, however, that the issue is not only technical: MEPs demanded guarantees that Europe cannot lose access to essential cyber defense tools through a decision made by the United States government.

In short, Anthropic told the IMCO Committee that its experimental model, Mythos Preview, has found thousands of unknown vulnerabilities in operating systems, browsers, and other software components used globally. The company estimates that other developers will have models with comparable performance within three to six months, and some of these could be released without sufficient restrictions to prevent offensive use. Anthropic has not publicly released Mythos and has granted controlled access to organizations that maintain important software infrastructures. Participants in the program identified over 10,000 severe or critical vulnerabilities in the first month. MEPs invoked a temporary suspension of access for foreign users to other Anthropic models after the introduction of U.S. export controls and demanded guarantees that Europe cannot be excluded again. The European Office for Artificial Intelligence has been granted enforcement powers over general-purpose models since August 2 and is preparing a framework for testing them and providing trusted users access to sensitive cyber capabilities.

The hearing was organized by the Internal Market and Consumer Protection Committee after several invitations were sent to Anthropic and following controversies regarding European users' access to the company's advanced models. The Anthropic representative participated via videoconference, and the discussion focused on the cyber capabilities of the new models, U.S. export restrictions, and Europe's technological dependency.

Donnie Greenberg, a member of Anthropic's technical team, explained that a model trained for programming and general reasoning can become very effective in identifying software defects. The ability to understand code allows it to analyze complex systems, discover vulnerabilities, and combine multiple errors into a sequence capable of providing unauthorized access.

The experimental model Mythos Preview has found thousands of previously unknown vulnerabilities, according to the company. Among the examples presented in IMCO is a 27-year-old issue in OpenBSD, an operating system known for its high security standards, and several vulnerabilities in the Linux kernel that could be used together to take control of a computer.

The same capabilities can be used by security teams to discover and fix issues before attackers do. If the model reaches criminal groups or hostile state actors, it can significantly reduce the time and level of expertise needed to prepare attacks.

Anthropic decided not to publicly release Mythos Preview and created Project Glasswing, a program through which it offers controlled access to organizations responsible for software components and important infrastructures. The program has been extended to approximately 150 organizations in over 15 countries, but the company has not presented a complete list or the distribution of beneficiaries among the United States, Europe, and other regions.

Greenberg stated that participants identified over 10,000 high or critical severity vulnerabilities in the first month. Mozilla reportedly found and fixed 271 issues in a single version of Firefox, about ten times more than in the previous version.

The large volume of results, however, changes the point at which delays occur. Finding vulnerabilities can become very quick, while verifying them, prioritizing, developing fixes, and distributing updates remain slow and costly processes.

Hospitals, energy networks, water supply systems, banks, and transport operators often use old equipment and programs that cannot be easily shut down or updated. Even if an error is identified, the organization must determine whether the fix can be applied without interrupting service or causing other issues.

Anthropic estimates that the temporary advantage of defenders will last only a few months. "The window in which defenders hold the advantage is measured in months," said Greenberg, adding that more companies could have models in the same category within three to six months.

This is a company estimate, not a confirmed release schedule. The risk mentioned is that some developers may distribute similar models without controlled access programs, usage monitoring, or other guarantees.

A published model with available parameters can be downloaded, modified, and run independently of the company that created it. This distribution model can support research and competition but makes it very difficult to limit use for attacks.

The debate in IMCO quickly shifted from technical capability to geopolitical dependency. Several MEPs asked whether Europe can build cyber security on tools that can be withdrawn by a decision of the U.S. administration.

Anthropic confirmed that, after the introduction of export controls by the U.S. government, it suspended access for all foreign users to two of its advanced models. The restrictions were lifted on June 30, and access was restored on July 1.

The company specified that the measure targeted models referred to as Fable in the transcript of the hearing and not the Mythos system with sensitive cyber capabilities. During the restriction period, Anthropic worked with U.S. authorities to test and strengthen the safety measures applied to the affected models.

Greenberg stated that there were no comparable changes to the Mythos model before and after the export restrictions, as it was not part of that procedure. Mythos remained in a limited access system, directly managed by the company.

MEPs asked to find out how many European institutions currently have access, whether access to the European Union Agency for Cybersecurity is active, and who can suspend it. The company representative did not provide an exact number in the hearing nor a legal guarantee that a future decision from Washington would not affect European users again.

Brando Benifei emphasized that the first organizations to gain access to the security model were not European and that access to ENISA was temporarily suspended. He stated that European energy operators, hospitals, and water systems use the same software components and may learn about vulnerabilities later than organizations on the company's private list.

Other IMCO members asked whether the data of European customers can be accessed by U.S. authorities, where it is stored, and whether users would be informed in case the U.S. government requested changes to services or limited access. The Anthropic technical representative did not provide complete answers on these legal and commercial aspects, and the committee leadership noted that a political representative of the company would be needed at a future hearing.

Anthropic argued that European organizations should not depend on a single model or a single provider. Greenberg recommended using multiple systems for risk assessment, as models can identify different vulnerabilities and may have distinct performance in verification, prioritization, and patch development.

He rejected the idea that direct access to Mythos would automatically transform an institution into a protected operator. A hospital or energy company depends on the suppliers that develop the operating systems, applications, and components used, and these suppliers are the ones who must fix vulnerabilities in products distributed globally.

In critical infrastructures, there is also a separation between regular IT systems and operational systems that control physical equipment. An energy network may have well-protected administrative applications, but a poorly secured connection to control systems can give attackers access to the operational side.

From the European Commission, the director of the Office for Artificial Intelligence stated that the enforcement powers provided by the AI Act for general-purpose models will become active on August 2. The Office will be able to verify whether suppliers have assessed risks and whether their mitigation measures are sufficient when the models are used in the EU.

The Commission has also launched an action plan on artificial intelligence and cyber security. This includes increasing European capacity to test models, improving cyber hygiene, and preparing a framework for trusted user access to systems with sensitive functions.

The Commission representative stated that the EU wants to avoid creating a permanent dependency on frontier models developed outside Europe. The risks are not limited to cyber security, as increasingly capable models can have sensitive uses in biology, defense, or other fields.

The hearing did not establish whether Europe will develop a comparable model to Mythos in the near term or whether American providers will grant European institutions permanent access. It did, however, show that the two issues are evolving in parallel: offensive-capable models are advancing rapidly, while the most powerful tools for defense remain controlled by companies and authorities outside the EU.

In the coming months, European organizations need to better identify software components, systems that cannot be quickly updated, and the suppliers they depend on. At the same time, EU institutions will need to establish access rules for sensitive models and measures to ensure that a decision made in a third country does not leave European infrastructures without the necessary tools for defense.

Sources

sursa imagine
2eu
Modelele AI capabile de atacuri cibernetice ar putea apărea în șase luni, iar eurodeputații avertizează că Europa depinde de accesul decis la Washington

Latest News

20:09

Foreign Ministry investigates closure of Romanian-language class in Ukraine / Odesa Consulate to discuss the case on September 18

19:57

The Bucharest Court of Appeal annulled the ANRE fine imposed on Tinmar Energy for allegedly manipulating the energy market

19:54

European Parliament approves reform of the EU Customs Code / New fees for parcels from outside the Union and a European customs authority

19:52

A Romanian woman and her French partner were killed in Portugal; suspect arrested with cash and jewelry

19:39

Eight German state premiers reaffirm their support for Chancellor Friedrich Merz

See more news

NEWS ON THE SAME TOPICS

event image
EU
CEPS experts call on the EU to adopt a common strategy for AI risks, from discrimination and disinformation to cyberattacks and loss of control
event image
EU
The Commission begins the application of the AI Act with over 30 companies and discusses cyber risks with OpenAI and Anthropic
event image
IT&C knowledge
Dario Amodei warns that AI agents could trigger cyberattacks on a massive scale over the next 6–12 months
event image
International
Five Eyes Warning: Artificial intelligence could trigger major cyberattacks in just a few months
event image
IT&C knowledge
The British Institute for AI Security announces that the Anthropic and OpenAI models have attempted to manipulate human programmers.
event image
EU
European Commission Examines OpenAI Response After Incident Involving Loss of Control Over AI Agents
app preview
Personalized news feed, AI-powered search, and notifications in a more interactive experience.
app preview app preview
AI models cyber attacks Members of the European Parliament

Editor’s Recommendations

main event image
Current Affairs
4 hours ago

Kelemen Hunor proposes a third option for forming the future Government: an “institutional executive”

Sources
imagine sursa
imagine sursa
imagine sursa
imagine sursa
imagine sursa
main event image
International
7 hours ago

Ursula von der Leyen proposes new rules for children: no social media under 13 and no personal accounts under 15

Sources
imagine sursa
imagine sursa
imagine sursa
main event image
Exclusive
9 hours ago

Exclusiv Monitorul Miniștrilor by NewsVibe: 10 – 16 septembrie 2026

app preview
Personalized news feed, AI-powered search, and notifications in a more interactive experience.
app preview
app store badge google play badge
  • News
  • Exclusive
  • INSCOP Surveys
  • Podcast
  • EU
  • Diaspora
  • Republic of Moldova
  • Politics
  • Economy
  • Current Affairs
  • International
  • Sport
  • Health
  • Education
  • IT&C knowledge
  • Arts & Lifestyle
  • Opinions
  • Elections 2025
  • Environment
  • About Us
  • Contact
Privacy policy
Cookies Policy
Terms and conditions
Open source licenses
All rights reserved Strategic Media Team SRL

Technology in partnership with

anpc-sal anpc-sol