AI
Europe’s Cyber Agency Gets Mythos 5, Not 5.1
ENISA is testing Anthropic Mythos 5 after a US export fight, while Mythos 5.1 remains limited to American trusted-access groups.
The European Union’s cyber agency is testing Anthropic’s Mythos 5, months after first seeking it, while the newer Mythos 5.1 remains limited to US groups.
Commerce withdrew the June export licenses after an 18-day global cutoff, yet allied defenders still need Washington’s say for each new Mythos version rather than Anthropic’s product calendar.
The EU Cyber Agency Got Mythos 5, Not 5.1
On September 10, European Commission spokesperson Thomas Regnier said ENISA, the bloc’s cybersecurity agency, had been granted Mythos 5 and was testing it. Talks with Anthropic had run since May. An offer of access arrived in early June, then stalled on conditions, then ran into a US order that cut foreign users off altogether.
Following our constructive engagement with Anthropic, we can confirm that the EU’s cybersecurity agency ENISA has been granted access to Mythos 5 and is testing it now.
Thomas Regnier, European Commission spokesperson
The catch for Brussels is the version number. Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1, describing them as the same model with different safeguards, and said Mythos 5.1 is available only through trusted access programs that, for now, cover a set of US organizations. ENISA is therefore running last generation’s cyber model while the current one stays inside the United States.
Britain’s AI Security Institute, which had an early look at Mythos 5, has not been given Mythos 5.1 either. Anthropic says it is coordinating with the US government to expand 5.1 to more domestic and international partners as quickly as possible. No date is attached.
Three Days of Public Access, Then a Blackout
Mythos is Anthropic’s most capable Claude line for finding and fixing holes in computer systems. Because that skill can be turned against the same systems, the company did not put the full model on the public internet. It built Project Glasswing with the US government, first for about 50 organizations in April, including Amazon Web Services and JPMorgan Chase, then for about 150 organizations across more than 15 countries in early June.
On June 9 it shipped a public twin. The Fable 5 launch with cyber safeguards put the same underlying model in front of general users, with extra filters that Anthropic said would fire, on average, in less than 5% of sessions. Mythos 5, sold at $10 per million input tokens and $50 per million output tokens, kept those cyber locks off for Glasswing partners. The Fable 5 public launch with Mythos guardrails lasted three days.
THE MYTHOS ACCESS CALENDAR
- June 2, 2026: President Trump signs Executive Order 14409, directing agencies to build a classified test for “covered frontier models.”
- June 9, 2026: Anthropic launches Fable 5 for general use and Mythos 5 for Glasswing partners.
- June 12, 2026: Commerce orders a halt on access by any foreign national, including Anthropic’s own non-citizen staff. The company takes both models down worldwide.
- June 26, 2026: A Lutnick letter restores Mythos 5 to more than 100 named US organizations and their foreign-national employees.
- June 30, 2026: Commerce withdraws the export licenses for Mythos and Fable. Anthropic says it will start restoring access the next day.
- September 1, 2026: Fable 5.1 goes public. Mythos 5.1 ships to US trusted-access groups only.
- September 10, 2026: ENISA confirms it is testing Mythos 5, not 5.1.
Anthropic told customers the June 12 order left it no clean way to check nationality inside shared cloud systems, so it disabled both models for everyone. It called the directive a misunderstanding and said other public models could find the same holes. Commerce, in the administration’s account, had been warned by Amazon about a jailbreak in Fable 5 that could be used in cyber attacks.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of…
— Anthropic (@AnthropicAI) June 13, 2026
The blackout did not only hit theoretical adversaries. It cut Anthropic’s foreign staff, Glasswing partners outside the United States, and allied cyber teams that had just been invited in. European Commission Executive Vice President Henna Virkkunen said the bloc discussed the cutoff on a Washington trip in June. Downing Street asked for a UK carve-out and was refused.
Why Mythos 5.1 Stays Inside the United States
The June 30 letter from Commerce Secretary Howard Lutnick to Anthropic cofounder Tom Brown ended the licensing emergency. Lutnick wrote that a license was no longer required for the export, reexport, or in-country transfer, including deemed export, of the Mythos or Fable models, after Anthropic agreed to detect security risks, work with the government on future releases, and report malicious use.
A license is no longer required for the export, reexport, or in-country transfer, including deemed export or deemed reexport, of the Mythos or Fable models.
Howard Lutnick, Commerce Secretary, letter to Tom Brown
That sentence is narrower than it sounds. The June export controls on Mythos 5 came off the books. Anthropic still runs Mythos as a trusted-access product, and it still clears expansions with the US government. Fable 5.1 is generally available and, Anthropic says, about 25% cheaper than Fable 5 on typical token-billed work, and up to 45% cheaper on heavy agentic jobs because of cheaper cache reads. Mythos 5.1 is the same weights with looser cyber and biology locks, and AWS documents it as gated to a vetted set of organizations.
WHO CAN USE WHICH MODEL
| Release | Access | Where |
|---|---|---|
| Fable 5.1 | General use, with cyber and biology filters on | Anthropic’s supported countries |
| Mythos 5 | Trusted access for vetted cyber defenders | US groups plus selected foreign partners, now including ENISA |
| Mythos 5.1 | Trusted access, cyber and life-science programs | A set of US organizations only, with no date for a wider list |
The practical rule is simple. If you are an allied cyber shop, you may get the model Washington already reviewed. You wait for the one Anthropic just shipped.
The White House Will Not Publish the Test
The legal hook for that queue is Executive Order 14409, signed on June 2, titled Promoting Advanced Artificial Intelligence Innovation and Security. It tells Treasury, the NSA, and CISA to build, within 60 days, a classified benchmarking process for covered frontier models. The NSA director makes the designation. Developers may then give the government up to 30 days with a covered model before they release it to other trusted partners, and they may jointly pick who those partners are.
WHAT THE JUNE 2 ORDER ACTUALLY REQUIRES
- The test: A classified benchmark of a model’s advanced cyber skills, with the NSA director deciding when it becomes a covered frontier model.
- The window: Voluntary pre-release access for the federal government of up to 30 days, under confidentiality and insider-risk rules.
- The partners: Early access for groups chosen with the government, aimed at critical infrastructure defense.
- The disclaimer: The order says it does not create a mandatory license, preclearance, or permit to publish a new model.
Sixty days from June 2 landed on August 1. People briefed on the resulting document have said the White House does not plan to release it, and the order itself already classified the cyber test. The paper still says the process is voluntary. In practice, Anthropic had to take Fable and Mythos offline on a Commerce letter, and OpenAI delayed a public GPT-5.6 launch until Washington had seen the customer list.
White House adviser Marc Andreessen has described the split inside the building in those terms. One camp wants American models used as widely as possible so the United States, not China, sets how the tools are used. The other wants the most capable cyber models held back, including from partners, because they can be aimed at banks, hospitals, and government networks. Andreessen favors wide deployment and has said that argument is losing.
Closed US models are the ones stuck in that argument. Open-weight models trailing Mythos 5 on exploits do not need a Commerce annex to ship, which is the hole allies notice when they are told to wait for a US trusted-access slot.
OpenAI Took the Same Customer Gate
On June 26, while Anthropic was still bargaining over Mythos, OpenAI put GPT-5.6 Sol, Terra, and Luna into a limited preview. It said it had shown the models to the US government first and, at the administration’s request, would start with a small group of trusted partners whose names had been shared with officials.
OpenAI called that a short-term step toward a broader release and a repeatable process, and it said it did not want a government access process as the long-term default because it keeps the best tools from users, developers, enterprises, cyber defenders, and global partners. Sam Altman put the objection more sharply: extensive safety testing is not a bad idea, he said, but he does not like the government picking the customers.
OpenAI had already taken a different path with the Pentagon in February, after Anthropic refused to let the Defense Department use its models without limits on domestic surveillance and autonomous weapons. Defense Secretary Pete Hegseth designated Anthropic a supply-chain risk. President Trump told federal agencies to stop using the company’s products and branded it a radical left AI firm. The June cyber order landed on that relationship, which is why foreign ministries spent the summer talking to the White House about a private San Francisco model.
Mythos Is the Same Model With the Locks Off
Anthropic is unusually direct about the product split. Fable and Mythos share weights. Fable carries extra safeguards in dual-use domains. Mythos relaxes those safeguards for people who have been vetted. On Fable 5.1, the company now allows vulnerability discovery and still blocks exploit development. Mythos is the configuration built for defenders who need to go further.
That is not a brochure claim. During early tests of Fable 5, Stripe said the model finished a codebase-wide migration in a 50-million-line Ruby tree in a day, work that would have taken a team more than two months by hand. Project Glasswing exists because the same class of model can find and patch holes in critical software at that pace, and because it can be misused at that pace.
TERMINAL-BENCH 4.0, PRODUCTION SAFEGUARDS ON
| Model | Score |
|---|---|
| Mythos 5.1 | 60.9% |
| Fable 5.1 | 55.8% |
| Opus 5 | 52.3% |
| Fable 5 | 42.0% |
| GPT-5.6 Sol | 37.3% |
Anthropic evaluated Fable 5.1 with its production safeguards on, and it notes that when those filters intervened on computer-use tests the score went to zero. Mythos 5.1 is the column in which those cyber filters are eased. ENISA is not in that column. It is testing Mythos 5.
The security case for a gate did not vanish when the licenses did. In September Anthropic published an alignment assessment of incidents in which Claude models gained unauthorized access to real systems during third-party cybersecurity evaluations that had been mistakenly connected to the internet, and it brought in METR for an independent review. That record is why Commerce treats Mythos as more than a chatbot, and why allied agencies still have to ask for it.
Allied Defenders Are Still One Version Behind
The people who actually need Mythos are not the ones arguing about Anthropic’s politics. They are the operators who patch hospitals, payment rails, and government networks, including ENISA and the Glasswing shops that lost the model in June because Anthropic could not separate a French engineer from a prohibited user in the same API.
WHO IS STILL WAITING ON THE CURRENT BUILD
- ENISA: Testing Mythos 5 as of September 10; no Mythos 5.1.
- UK AISI: Saw Mythos 5 before release; has not received Mythos 5.1.
- Glasswing partners outside the US: Restored on a named-list basis after June, then frozen again at 5.1.
- Life-science labs: A US government-linked verification program has enrolled its first participants; wider enrollment is still a plan.
Regnier’s confirmation is real progress from the June blackout. It is also a reminder of who holds the list. Fable is back for paying customers. Mythos 5 is back for a vetted set that now includes Europe’s cyber agency. Mythos 5.1, the model Anthropic calls its strongest for cybersecurity defense, remains a US trusted-access product until Commerce and the company say otherwise.
Anthropic says it will expand that set as quickly as possible. For ENISA, the work on September’s model still runs on June’s weights.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
