Podcast Episode
On 7 May, OpenAI began rolling out GPT-5.5-Cyber in a limited preview to vetted cybersecurity teams. The model is a variant of its flagship system with fewer restrictions for tasks such as vulnerability research, malware analysis, and reverse engineering. Safeguards against malicious uses, including credential theft and malware deployment, remain firmly in place.
With the EU's AI Act obligations for general-purpose models set to take effect on 2 August, the regulatory backdrop adds further pressure on both companies to formalise their European engagements. The UK's AI Security Institute also published an evaluation finding that GPT-5.5 performs comparably to Mythos on cybersecurity tasks, suggesting the capabilities are part of a broader trend in frontier AI development.
OpenAI Offers EU Access to GPT-5.5-Cyber as Anthropic Holds Back on Mythos
May 11, 2026
Audio archived. Episodes older than 60 days are removed to save server storage. Story details remain below.
The European Commission has confirmed that OpenAI is proactively offering EU access to its new cybersecurity AI model, while talks with Anthropic over its Mythos model remain in early stages. The split highlights a widening gap in how the two leading AI labs are approaching Europe's demand for frontier cyber defence tools.
OpenAI Takes the Initiative
The European Commission confirmed on Monday that OpenAI has offered to grant the EU access to its latest AI model for cybersecurity purposes. Commission spokesperson Thomas Regnier told reporters that OpenAI is 'proactively offering to give access' to the model, a move the EU executive welcomed. The offer follows OpenAI's broader push into cybersecurity, which began in late April with the publication of a five-part action plan titled 'Cybersecurity in the Intelligence Age'. The plan outlines a strategy to democratise AI-powered cyber defence for governments, critical infrastructure operators, and vetted businesses.On 7 May, OpenAI began rolling out GPT-5.5-Cyber in a limited preview to vetted cybersecurity teams. The model is a variant of its flagship system with fewer restrictions for tasks such as vulnerability research, malware analysis, and reverse engineering. Safeguards against malicious uses, including credential theft and malware deployment, remain firmly in place.
Anthropic's Cautious Approach
Anthropic's position offers a striking contrast. Regnier said the Commission has held four or five meetings with the company, but 'no discussions on a possible access to its AI models have taken place yet'. Anthropic unveiled Claude Mythos Preview on 7 April, a frontier model capable of autonomously identifying zero-day vulnerabilities and generating working exploits with minimal human guidance. The company has restricted access to more than 40 American firms, including Apple, Amazon, and JPMorgan Chase, as well as cybersecurity firm Palo Alto Networks.Europe's Urgency
The stakes for Europe are rising. In late April, Germany's Bundesbank publicly called on the EU to demand access to Mythos, arguing that European banks could not adequately test their infrastructure without it. Euro-area finance ministers convened in early May to discuss the gap, though no formal agreement emerged. Palo Alto Networks warned that the window before attackers gain comparable AI capabilities 'has accelerated significantly'.With the EU's AI Act obligations for general-purpose models set to take effect on 2 August, the regulatory backdrop adds further pressure on both companies to formalise their European engagements. The UK's AI Security Institute also published an evaluation finding that GPT-5.5 performs comparably to Mythos on cybersecurity tasks, suggesting the capabilities are part of a broader trend in frontier AI development.
Published May 11, 2026 at 8:22pm