ENISA can test Anthropic’s Mythos 5 and OpenAI’s GPT 6 Astra, but the UK AI Security Institute reportedly did not receive Anthropic’s newer Mythos 5.1 before its September 1 release. The EU AI Act gives the EU binding duties around evaluation, adversarial testing, risk mitigation, incident reporting and cybersecurit...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What does the EU’s access to Anthropic’s Mythos 5 and OpenAI’s GPT-6-Astra for ENISA testing reveal about the UK’s exclusion from pre-releas. Article summary: The episode exposes a practical weakness in the UK’s frontier-AI regime: an internationally respected evaluator cannot guarantee timely access when testing depends on a developer’s consent. The EU’s ENISA access is signi. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
The UK’s reported exclusion from pre-release testing of Anthropic’s Claude Mythos 5.1 is less a verdict on British technical expertise than a warning about access. A national evaluator cannot independently assess a frontier model on time if participation ultimately rests on the developer’s consent. ENISA’s access to Anthropic’s Mythos 5 and OpenAI’s GPT-6 Astra is important, but it does not mean the EU has a standing right to test every successor model—or that it had access to Mythos 5.1. 9
20
The European Union’s cybersecurity agency, ENISA, has been granted access to Mythos 5 and GPT-6 Astra for testing, according to a European Commission spokesperson. 9 Separately, reporting says Anthropic did not provide the UK AI Security Institute with Mythos 5.1 for testing before release—the first reported instance of Anthropic withholding a major model from that body’s pre-release process.
20
23
Those facts should not be flattened into a simple story of an EU win and a UK loss. ENISA’s access concerns two named models under particular arrangements. Mythos 5.1 is a different release and a more restricted access case. The practical lesson is that safety evaluation is becoming segmented by model version, capability, intended use, jurisdiction and the developer’s own partner criteria.
Anthropic says Claude Fable 5.1 and Claude Mythos 5.1 are the same underlying model with different safeguards. Fable 5.1 is generally available, while Mythos 5.1 is available only through trusted-access programmes designed for work in cybersecurity and the life sciences. 12
That makes the question more than routine product testing. A system intended for sensitive cyber or scientific work raises issues around controlled environments, misuse monitoring, personnel vetting and national-security handling. Reporting says Mythos 5.1 access was initially limited to vetted US organisations. 18
24
The evidence provided does not establish that Anthropic excluded the UK because it distrusted the country or its institute. The restricted-programme design, operational-security concerns and commercial control of access are all plausible explanations. But the outcome still matters: established cooperation and an evaluator’s reputation did not guarantee timely access to a high-consequence model.
The EU has a stronger legal baseline than a purely voluntary regime. Under Article 55 of the EU AI Act, providers of general-purpose AI models with systemic risk must conduct model evaluations using standardised protocols and tools, assess and mitigate systemic risks, track and report serious incidents, and ensure an appropriate level of cybersecurity protection. 43
37
The Act also contemplates evaluation before a model’s first placing on the market, including documented adversarial testing, which may be internal or independent external testing as appropriate. 35
34
However, those provider obligations are not the same as a blanket entitlement for ENISA to receive model weights, unrestricted system access or pre-release access to every frontier release. ENISA’s testing arrangement is consequential precisely because it appears to have been secured through engagement with the companies as well as through the EU’s broader regulatory position. 4
9
In other words, regulation can improve the EU’s ability to demand evidence, risk management and compliance. It cannot eliminate the operational need for secure cooperation when testing models with sensitive cyber, biological or agentic capabilities.
The UK’s reported Mythos 5.1 exclusion puts the limits of voluntary access into sharp relief. Reporting on the episode notes calls for stronger statutory footing and powers for the UK AI Security Institute after Anthropic did not grant it access to the latest model. 23
A voluntary approach can work well when labs see value in collaboration. It may be faster and more technically flexible than rigid rules. Its weakness is predictability: a developer can restrict access, change the eligible partner group or decide that a model belongs in a tighter national-security channel.
That creates a strategic risk for the UK. If its evaluators receive frontier systems only after release—or only after other governments and approved partners have tested them—the UK could move from helping shape safety evidence to consuming evidence generated elsewhere.
The immediate policy objective need not be compulsory handover of model weights. For highly capable models, that could create security and intellectual-property risks of its own. A stronger framework could instead focus on controlled, auditable access.
Possible measures include:
These proposals address the central weakness exposed by the case: access must be designed into the governance system rather than left entirely to relationships with individual labs.
The likely direction is a layered evaluation system. Broad market-facing models will be subject to provider testing, regulatory documentation and incident obligations. More sensitive cyber, biological and autonomous-agent capabilities will increasingly be assessed in restricted settings. The highest-risk systems may be accessible only to a small set of vetted government, laboratory and security partners.
The EU’s ENISA arrangement and the UK’s Mythos 5.1 exclusion illustrate why that distinction matters. The central competition is no longer only over who can build the strongest model. It is also over who can inspect, test and govern the most consequential versions before they reach wider deployment. 9
12
20
For the UK, technical evaluation capability remains valuable, but it is not sufficient on its own. Maintaining influence will require dependable legal powers at home and durable, security-aware access arrangements with partners abroad.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
ENISA can test Anthropic’s Mythos 5 and OpenAI’s GPT 6 Astra, but the UK AI Security Institute reportedly did not receive Anthropic’s newer Mythos 5.1 before its September 1 release.
ENISA can test Anthropic’s Mythos 5 and OpenAI’s GPT 6 Astra, but the UK AI Security Institute reportedly did not receive Anthropic’s newer Mythos 5.1 before its September 1 release. The EU AI Act gives the EU binding duties around evaluation, adversarial testing, risk mitigation, incident reporting and cybersecurity for systemic risk general purpose models—but it does not automatically give ENISA...
For the UK, the episode strengthens the case for statutory information and evaluation powers, secure access arrangements, and closer cooperation with EU and US security partners.