Back Thenextweb The EU built the world's most comprehensive AI regulation. It does not give Europe access ...
TL;DR Euro-area finance ministers met in Brussels to demand access to Anthropic’s Mythos, an AI model that can autonomously find and exploit zero-day vulnerabilities in every major operating system and browser. No European government or bank has access; the model is restricted to American tech companies and the NSA under Project Glasswing, while the White House blocks expansion. A Discord group breached access in April. Europe’s AI Act, the world’s most comprehensive AI regulation, has no mechanism to compel an American company to its most powerful model, exposing the limits of regulation as a response to a capability gap.
Euro-area finance ministers met in Brussels to demand access to Anthropic’s Mythos, an AI model that can autonomously find and exploit zero-day vulnerabilities in every major operating system and browser. No European government or bank has access; the model is restricted to American tech companies and the NSA under Project Glasswing, while the White House blocks expansion. A Discord group breached access in April. Europe’s AI Act, the world’s most comprehensive AI regulation, has no mechanism to compel an American company to its most powerful model, exposing the limits of regulation as a response to a capability gap.
Euro-area finance ministers met in Brussels on Monday to a problem none of their regulations were designed to solve: a single American company has built an AI model that can find and exploit zero-day vulnerabilities in every major operating system and every major web browser, and no European government has access to it. Anthropic announced Claude Mythos Preview on 7 April under a restricted programme called Project Glasswing, limiting access to a vetted consortium of launch partners including Amazon, Apple, Google, Microsoft, Nvidia, JPMorgan Chase, and roughly 40 other organisations. All are American or operate under American jurisdiction. Europe’s banks, payment systems, and critical infrastructure are on the outside.
Mythos is not an incremental improvement over AI systems. Anthropic describes it as a general-purpose frontier model with exceptional strength in computer security tasks, a framing that understates what independent evaluators have found. The UK’s AI Safety Institute assessed Mythos and concluded it can autonomously discover zero-day vulnerabilities in real open-source codebases, reverse-engineer exploits on closed-source software, and chain multiple vulnerabilities together into working attack sequences without human guidance.
In testing, Mythos wrote browser exploits linking four separate vulnerabilities, obtained local privilege escalation on Linux by exploiting subtle race conditions, and produced a remote code execution exploit on FreeBSD’s NFS server that granted full root access to unauthenticated users. One vulnerability it discovered, triaged as CVE-2026-4747, allows an attacker anywhere on the internet to obtain complete control over a target server.
The oldest vulnerability Mythos found had been present in OpenBSD for 27 years. The model does not merely detect known weaknesses. It discovers unknown ones at a speed and scale that no human security team can match. The cybersecurity industry in 2025 produced 308 petabytes of telemetry across four million identities and endpoints, generating 30 million investigative leads of which only 93,000 were genuine threats . Mythos does not through noise. It reads code, identifies structural weaknesses, and writes working exploits. The capability gap between organisations that have access to this tool and those that do not is not a competitive advantage. It is a security asymmetry.
Project Glasswing’s partner list reads like a roster of American technology dominance: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks. JPMorgan Chase is the only financial institution with confirmed access. No European bank, no European government, and no European cybersecurity agency has been granted access to Mythos.
The model is simultaneously available to the US National Security Agency, which is using it for offensive and defensive cyber operations. The White House has opposed Anthropic’s plan to expand access to 70 additional organisations , citing national security concerns and limited compute capacity, creating a situation in which Washington uses the tool through its intelligence services while blocking its international distribution.
The breach complicates the picture further. In late April, a Discord group gained unauthorised access to Mythos by guessing the model’s endpoint URL. One member held active contractor credentials for an Anthropic vendor environment. The group used naming convention knowledge leaked in a separate data breach at the AI training startup Mercor to locate the model.
No exploit code, no social engineering, and no sophisticated reconnaissance were required. Anthropic confirmed it was investigating. The group reportedly retained access and continued using the model. The implication for European finance ministers is stark: a Discord group has access to Mythos. European banks do not.
Spain’s economy minister Carlos Cuerpo told reporters before the Eurogroup meeting that Mythos and other new models may be able “to find vulnerabilities or backdoors in virtually all our institutions, not only in the financial sector and companies, but across all sectors.” He pushed for Europe to consider “regulatory and legislative instruments such as the AI Act” in response.
Eurogroup President Kyriakos Pierrakakis acknowledged the issue is serious enough that ministers will need to revisit it at future gatherings. ECB Vice President Luis de Guindos told the European Parliament’s economic committee that these technologies “should be focused on identifying the flaws of your operating systems” but warned that if bad actors gain access, it “can give rise to a lot of problems.”
The Bundesbank has been more direct. Germany’s chief banking supervisor Michael Theurer urged the European Commission to request access from Anthropic or from Washington directly. Bundesbank President Joachim Nagel said “all relevant institutions should have access to such technology to avoid competitive distortions.” The framing is notable: the German central bank is characterising Mythos access as a competitive issue, not merely a security one.
American banks with access can scan their own systems for vulnerabilities that Mythos can find. European banks cannot. Mythos is moving between governments faster than regulators can track it , and the access disparity is hardening into a structural disadvantage.
Mythos dominated conversations at the IMF spring meetings in Washington in April. IMF Managing Director Kristalina Georgieva said the world does not have the ability “to protect the international monetary system against massive cyber risks” and warned that “time is not our friend on this one.” ECB President Christine Lagarde framed the core tension: a responsible company built something that could be very good, but in the wrong hands, could be very bad. The problem is that “wrong hands” and “right hands” are being determined by a single company’s partner list and the American government’s national security priorities, not by any international framework or European regulatory authority.
Europe’s AI Act was designed to give the continent a regulatory framework for managing AI risk , with the most substantive obligations for high-risk systems taking effect on 2 August 2026. The regulation imposes transparency requirements, audit trails, incident reporting, and penalties of up to 3 per cent of global revenue for non-compliance. What it does not do is compel an American company to give European institutions access to its most powerful model. The AI Act regulates the deployment of AI systems within Europe. It has no mechanism to address the strategic disadvantage of not having access to an AI system that exists outside Europe and can be used against European infrastructure from anywhere.
Cuerpo’s instinct to invoke the AI Act is understandable but reveals the limits of regulation as a response to a capability gap. Europe has spent five years building the world’s most comprehensive AI governance framework. That framework does not help when the problem is not a model being deployed in Europe, but a model being withheld from Europe while adversaries who breach access restrictions or operate outside the law can use it against European targets. Anthropic raised $25 billion from Sequoia and other investors in its latest round , and is now weighing a further raise at a valuation approaching $900 billion.
The company is the most valuable AI startup in the world. Its most powerful model is controlled by an American access list, monitored by American intelligence agencies, and governed by no international treaty. Europe’s finance ministers left Brussels on Monday having agreed that the issue is serious. They did not leave with access.
Get the most important tech news in your inbox each week.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
