Artificial intelligence models capable of identifying unknown vulnerabilities and constructing attack chains could become widely available within the next three to six months, warned Anthropic in the European Parliament's Internal Market and Consumer Protection Committee. The hearing in IMCO showed, however, that the issue is not only technical: MEPs demanded guarantees that Europe cannot lose access to essential cyber defense tools through a decision made by the United States government.
In short, Anthropic told the IMCO Committee that its experimental model, Mythos Preview, has found thousands of unknown vulnerabilities in operating systems, browsers, and other software components used globally. The company estimates that other developers will have models with comparable performance within three to six months, and some of these could be released without sufficient restrictions to prevent offensive use. Anthropic has not publicly released Mythos and has granted controlled access to organizations that maintain important software infrastructures. Participants in the program identified over 10,000 severe or critical vulnerabilities in the first month. MEPs invoked a temporary suspension of access for foreign users to other Anthropic models after the introduction of U.S. export controls and demanded guarantees that Europe cannot be excluded again. The European Office for Artificial Intelligence has been granted enforcement powers over general-purpose models since August 2 and is preparing a framework for testing them and providing trusted users access to sensitive cyber capabilities.
The hearing was organized by the Internal Market and Consumer Protection Committee after several invitations were sent to Anthropic and following controversies regarding European users' access to the company's advanced models. The Anthropic representative participated via videoconference, and the discussion focused on the cyber capabilities of the new models, U.S. export restrictions, and Europe's technological dependency.
Donnie Greenberg, a member of Anthropic's technical team, explained that a model trained for programming and general reasoning can become very effective in identifying software defects. The ability to understand code allows it to analyze complex systems, discover vulnerabilities, and combine multiple errors into a sequence capable of providing unauthorized access.
The experimental model Mythos Preview has found thousands of previously unknown vulnerabilities, according to the company. Among the examples presented in IMCO is a 27-year-old issue in OpenBSD, an operating system known for its high security standards, and several vulnerabilities in the Linux kernel that could be used together to take control of a computer.
The same capabilities can be used by security teams to discover and fix issues before attackers do. If the model reaches criminal groups or hostile state actors, it can significantly reduce the time and level of expertise needed to prepare attacks.
Anthropic decided not to publicly release Mythos Preview and created Project Glasswing, a program through which it offers controlled access to organizations responsible for software components and important infrastructures. The program has been extended to approximately 150 organizations in over 15 countries, but the company has not presented a complete list or the distribution of beneficiaries among the United States, Europe, and other regions.
Greenberg stated that participants identified over 10,000 high or critical severity vulnerabilities in the first month. Mozilla reportedly found and fixed 271 issues in a single version of Firefox, about ten times more than in the previous version.
The large volume of results, however, changes the point at which delays occur. Finding vulnerabilities can become very quick, while verifying them, prioritizing, developing fixes, and distributing updates remain slow and costly processes.
Hospitals, energy networks, water supply systems, banks, and transport operators often use old equipment and programs that cannot be easily shut down or updated. Even if an error is identified, the organization must determine whether the fix can be applied without interrupting service or causing other issues.
Anthropic estimates that the temporary advantage of defenders will last only a few months. "The window in which defenders hold the advantage is measured in months," said Greenberg, adding that more companies could have models in the same category within three to six months.
This is a company estimate, not a confirmed release schedule. The risk mentioned is that some developers may distribute similar models without controlled access programs, usage monitoring, or other guarantees.
A published model with available parameters can be downloaded, modified, and run independently of the company that created it. This distribution model can support research and competition but makes it very difficult to limit use for attacks.
The debate in IMCO quickly shifted from technical capability to geopolitical dependency. Several MEPs asked whether Europe can build cyber security on tools that can be withdrawn by a decision of the U.S. administration.
Anthropic confirmed that, after the introduction of export controls by the U.S. government, it suspended access for all foreign users to two of its advanced models. The restrictions were lifted on June 30, and access was restored on July 1.
The company specified that the measure targeted models referred to as Fable in the transcript of the hearing and not the Mythos system with sensitive cyber capabilities. During the restriction period, Anthropic worked with U.S. authorities to test and strengthen the safety measures applied to the affected models.
Greenberg stated that there were no comparable changes to the Mythos model before and after the export restrictions, as it was not part of that procedure. Mythos remained in a limited access system, directly managed by the company.
MEPs asked to find out how many European institutions currently have access, whether access to the European Union Agency for Cybersecurity is active, and who can suspend it. The company representative did not provide an exact number in the hearing nor a legal guarantee that a future decision from Washington would not affect European users again.
Brando Benifei emphasized that the first organizations to gain access to the security model were not European and that access to ENISA was temporarily suspended. He stated that European energy operators, hospitals, and water systems use the same software components and may learn about vulnerabilities later than organizations on the company's private list.
Other IMCO members asked whether the data of European customers can be accessed by U.S. authorities, where it is stored, and whether users would be informed in case the U.S. government requested changes to services or limited access. The Anthropic technical representative did not provide complete answers on these legal and commercial aspects, and the committee leadership noted that a political representative of the company would be needed at a future hearing.
Anthropic argued that European organizations should not depend on a single model or a single provider. Greenberg recommended using multiple systems for risk assessment, as models can identify different vulnerabilities and may have distinct performance in verification, prioritization, and patch development.
He rejected the idea that direct access to Mythos would automatically transform an institution into a protected operator. A hospital or energy company depends on the suppliers that develop the operating systems, applications, and components used, and these suppliers are the ones who must fix vulnerabilities in products distributed globally.
In critical infrastructures, there is also a separation between regular IT systems and operational systems that control physical equipment. An energy network may have well-protected administrative applications, but a poorly secured connection to control systems can give attackers access to the operational side.
From the European Commission, the director of the Office for Artificial Intelligence stated that the enforcement powers provided by the AI Act for general-purpose models will become active on August 2. The Office will be able to verify whether suppliers have assessed risks and whether their mitigation measures are sufficient when the models are used in the EU.
The Commission has also launched an action plan on artificial intelligence and cyber security. This includes increasing European capacity to test models, improving cyber hygiene, and preparing a framework for trusted user access to systems with sensitive functions.
The Commission representative stated that the EU wants to avoid creating a permanent dependency on frontier models developed outside Europe. The risks are not limited to cyber security, as increasingly capable models can have sensitive uses in biology, defense, or other fields.
The hearing did not establish whether Europe will develop a comparable model to Mythos in the near term or whether American providers will grant European institutions permanent access. It did, however, show that the two issues are evolving in parallel: offensive-capable models are advancing rapidly, while the most powerful tools for defense remain controlled by companies and authorities outside the EU.
In the coming months, European organizations need to better identify software components, systems that cannot be quickly updated, and the suppliers they depend on. At the same time, EU institutions will need to establish access rules for sensitive models and measures to ensure that a decision made in a third country does not leave European infrastructures without the necessary tools for defense.
In short, Anthropic told the IMCO Committee that its experimental model, Mythos Preview, has found thousands of unknown vulnerabilities in operating systems, browsers, and other software components used globally. The company estimates that other developers will have models with comparable performance within three to six months, and some of these could be released without sufficient restrictions to prevent offensive use. Anthropic has not publicly released Mythos and has granted controlled access to organizations that maintain important software infrastructures. Participants in the program identified over 10,000 severe or critical vulnerabilities in the first month. MEPs invoked a temporary suspension of access for foreign users to other Anthropic models after the introduction of U.S. export controls and demanded guarantees that Europe cannot be excluded again. The European Office for Artificial Intelligence has been granted enforcement powers over general-purpose models since August 2 and is preparing a framework for testing them and providing trusted users access to sensitive cyber capabilities.
The hearing was organized by the Internal Market and Consumer Protection Committee after several invitations were sent to Anthropic and following controversies regarding European users' access to the company's advanced models. The Anthropic representative participated via videoconference, and the discussion focused on the cyber capabilities of the new models, U.S. export restrictions, and Europe's technological dependency.
Donnie Greenberg, a member of Anthropic's technical team, explained that a model trained for programming and general reasoning can become very effective in identifying software defects. The ability to understand code allows it to analyze complex systems, discover vulnerabilities, and combine multiple errors into a sequence capable of providing unauthorized access.
The experimental model Mythos Preview has found thousands of previously unknown vulnerabilities, according to the company. Among the examples presented in IMCO is a 27-year-old issue in OpenBSD, an operating system known for its high security standards, and several vulnerabilities in the Linux kernel that could be used together to take control of a computer.
The same capabilities can be used by security teams to discover and fix issues before attackers do. If the model reaches criminal groups or hostile state actors, it can significantly reduce the time and level of expertise needed to prepare attacks.
Anthropic decided not to publicly release Mythos Preview and created Project Glasswing, a program through which it offers controlled access to organizations responsible for software components and important infrastructures. The program has been extended to approximately 150 organizations in over 15 countries, but the company has not presented a complete list or the distribution of beneficiaries among the United States, Europe, and other regions.
Greenberg stated that participants identified over 10,000 high or critical severity vulnerabilities in the first month. Mozilla reportedly found and fixed 271 issues in a single version of Firefox, about ten times more than in the previous version.
The large volume of results, however, changes the point at which delays occur. Finding vulnerabilities can become very quick, while verifying them, prioritizing, developing fixes, and distributing updates remain slow and costly processes.
Hospitals, energy networks, water supply systems, banks, and transport operators often use old equipment and programs that cannot be easily shut down or updated. Even if an error is identified, the organization must determine whether the fix can be applied without interrupting service or causing other issues.
Anthropic estimates that the temporary advantage of defenders will last only a few months. "The window in which defenders hold the advantage is measured in months," said Greenberg, adding that more companies could have models in the same category within three to six months.
This is a company estimate, not a confirmed release schedule. The risk mentioned is that some developers may distribute similar models without controlled access programs, usage monitoring, or other guarantees.
A published model with available parameters can be downloaded, modified, and run independently of the company that created it. This distribution model can support research and competition but makes it very difficult to limit use for attacks.
The debate in IMCO quickly shifted from technical capability to geopolitical dependency. Several MEPs asked whether Europe can build cyber security on tools that can be withdrawn by a decision of the U.S. administration.
Anthropic confirmed that, after the introduction of export controls by the U.S. government, it suspended access for all foreign users to two of its advanced models. The restrictions were lifted on June 30, and access was restored on July 1.
The company specified that the measure targeted models referred to as Fable in the transcript of the hearing and not the Mythos system with sensitive cyber capabilities. During the restriction period, Anthropic worked with U.S. authorities to test and strengthen the safety measures applied to the affected models.
Greenberg stated that there were no comparable changes to the Mythos model before and after the export restrictions, as it was not part of that procedure. Mythos remained in a limited access system, directly managed by the company.
MEPs asked to find out how many European institutions currently have access, whether access to the European Union Agency for Cybersecurity is active, and who can suspend it. The company representative did not provide an exact number in the hearing nor a legal guarantee that a future decision from Washington would not affect European users again.
Brando Benifei emphasized that the first organizations to gain access to the security model were not European and that access to ENISA was temporarily suspended. He stated that European energy operators, hospitals, and water systems use the same software components and may learn about vulnerabilities later than organizations on the company's private list.
Other IMCO members asked whether the data of European customers can be accessed by U.S. authorities, where it is stored, and whether users would be informed in case the U.S. government requested changes to services or limited access. The Anthropic technical representative did not provide complete answers on these legal and commercial aspects, and the committee leadership noted that a political representative of the company would be needed at a future hearing.
Anthropic argued that European organizations should not depend on a single model or a single provider. Greenberg recommended using multiple systems for risk assessment, as models can identify different vulnerabilities and may have distinct performance in verification, prioritization, and patch development.
He rejected the idea that direct access to Mythos would automatically transform an institution into a protected operator. A hospital or energy company depends on the suppliers that develop the operating systems, applications, and components used, and these suppliers are the ones who must fix vulnerabilities in products distributed globally.
In critical infrastructures, there is also a separation between regular IT systems and operational systems that control physical equipment. An energy network may have well-protected administrative applications, but a poorly secured connection to control systems can give attackers access to the operational side.
From the European Commission, the director of the Office for Artificial Intelligence stated that the enforcement powers provided by the AI Act for general-purpose models will become active on August 2. The Office will be able to verify whether suppliers have assessed risks and whether their mitigation measures are sufficient when the models are used in the EU.
The Commission has also launched an action plan on artificial intelligence and cyber security. This includes increasing European capacity to test models, improving cyber hygiene, and preparing a framework for trusted user access to systems with sensitive functions.
The Commission representative stated that the EU wants to avoid creating a permanent dependency on frontier models developed outside Europe. The risks are not limited to cyber security, as increasingly capable models can have sensitive uses in biology, defense, or other fields.
The hearing did not establish whether Europe will develop a comparable model to Mythos in the near term or whether American providers will grant European institutions permanent access. It did, however, show that the two issues are evolving in parallel: offensive-capable models are advancing rapidly, while the most powerful tools for defense remain controlled by companies and authorities outside the EU.
In the coming months, European organizations need to better identify software components, systems that cannot be quickly updated, and the suppliers they depend on. At the same time, EU institutions will need to establish access rules for sensitive models and measures to ensure that a decision made in a third country does not leave European infrastructures without the necessary tools for defense.
Latest News
20:09
Foreign Ministry investigates closure of Romanian-language class in Ukraine / Odesa Consulate to discuss the case on September 18
19:57
The Bucharest Court of Appeal annulled the ANRE fine imposed on Tinmar Energy for allegedly manipulating the energy market
19:54
European Parliament approves reform of the EU Customs Code / New fees for parcels from outside the Union and a European customs authority
19:52
A Romanian woman and her French partner were killed in Portugal; suspect arrested with cash and jewelry
19:39
Eight German state premiers reaffirm their support for Chancellor Friedrich Merz
See more news