Anthropic 正在限制对 Claude Mythos 的访问权限,该公司称这款 AI 模型在发现安全漏洞方面比大多数人类更出色。欧洲当局对该系统几乎毫无了解,而英国已在进行自己的测试。这一局面暴露了一个更深层次的结构性问题。
Anthropic 上周宣布,将限制其最新 AI 模型 Claude Mythos Preview 的访问权限,仅向选定的技术合作伙伴开放。该公司之所以向少数几家大型科技公司和网络安全公司提供预览版本,是因为它认为这款新模型可能带来前所未有的网络安全风险,并增加大规模 AI 驱动网络攻击的可能性。
在一项名为“Project Glasswing”的计划下,Anthropic 精心挑选了 12 家美国科技公司作为其核心圈,其中包括苹果、微软和亚马逊。另有 40 家机构也获得了访问权限,但 Anthropic 未透露其名称。
欧洲监管机构几乎被排除在外。
大多数欧洲网络安全机构与 Anthropic 几乎没有接触。
POLITICO 表示,他们与来自八个国家欧洲网络安全机构的官员进行了交谈。只有德国联邦信息安全办公室(BSI)确认已与 Anthropic 就 Mythos 展开对话,但迄今无法直接测试该模型。其他欧洲政府机构显然只有有限的了解。
BSI 局长 Claudia Plattner 表示,如此强大的工具最终是否会进入公开市场,这是一个紧迫的问题。她告诉 POLITICO,这个问题对德国、欧洲的安全与主权具有深远影响。尽管 BSI 正与 Anthropic 进行积极对话,但这些对话目前仅提供了对该模型工作原理的有意义见解,并未获得直接测试的权限。
欧盟网络安全局(ENISA)拒绝就其是否与 Anthropic 有联系发表评论。欧盟委员会的人工智能办公室确实与 Anthropic 保持着对话,这是欧盟 AI 模型实践准则的一部分。至于 Mythos 是否属于这些对话的内容,以及该办公室是否获得了访问权限,这些问题均未得到回应。
相比之下,英国则处于完全不同的境地。英国人工智能大臣卡尼什卡·纳拉扬证实,英国人工智能安全研究所(AISI)近期对 Mythos 进行了测试,并已根据测试结果采取了行动。周一,该研究所发布了评估报告。结果显示,在网络能力本就快速发展的背景下,Mythos Preview 相比此前的前沿模型实现了显著飞跃。不过,AISI 也指出,无法确定 Mythos 能否成功攻击防御严密的系统。
无法获取 Mythos,欧洲就无法评估风险
欧洲无法获取 Mythos 不仅是一个治理问题。缺乏可靠的技术细节,监管机构在评估风险和确定防御优先级方面能做的十分有限。
总部位于柏林的人工智能非营利组织 KIRA 的创始人丹尼尔·普里维特拉告诉 POLITICO,Mythos 让人们初步体会到,在未来几年,能否获取前沿人工智能能力将变得何等关键。他表示,欧洲目前没有确保这种获取途径的计划。
人工智能先驱约书亚·本吉奥告诉 POLITICO,他对科技公司而非监管机构来决定如何处理这些风险深感担忧。他表示,这凸显了为政府或第三方建立技术审查渠道的重要性。
曾担任欧盟委员会顾问、协助制定欧盟人工智能开发者行为准则的前欧洲议会议员玛丽耶·沙克也表示,由一家私营公司控制具有深远影响的模型令人担忧。她指出,现在正是就披露规则和监督机制达成共识的好时机。
参与起草《欧盟人工智能法案》的独立人工智能研究员劳拉·卡罗利告诉 POLITICO,欧盟被边缘化了,因为该模型尚未投放市场。如果它投放市场,Anthropic 将面临欧盟法律规定的约束性义务。不过,根据欧盟指南,即使是在内部使用人工智能模型,如果该使用对于在欧盟提供产品或服务至关重要,或者影响到欧盟境内个人的权利,也等同于将其投放市场。
欧盟委员会数字事务发言人托马斯·雷尼耶告诉《政治报》网站,欧盟委员会目前正在审查该事件可能涉及的欧盟法律影响。根据《人工智能法案》,Anthropic 等提供商必须应对其模型带来的网络安全风险;而《网络弹性法案》则对所有在欧盟市场销售的、包含数字组件的产品规定了强制性网络安全要求。
为何欧洲被排除在外——以及这意味着什么
欧洲无法访问 Mythos 是否是过度监管的后果?实际情况更为复杂。Anthropic 与亚马逊、谷歌、IBM、微软和 OpenAI 一同签署了欧盟通用人工智能模型实践准则。缺乏合作意愿并非问题所在。
真正的问题在于,欧洲缺乏一个能在同等技术层面运作的对应机构。英国人工智能安全研究所成立于 2023 年,最初名为前沿人工智能工作组,2025 年更名,拥有 1 亿英镑的公共资金。在极短时间内,该机构通过开展安全测试并从 OpenAI 和 Google DeepMind 招募知名研究人员,获得了进入人工智能行业的渠道。迄今为止,该机构已测试至少 16 个模型,其中包括三个在公开发布前的前沿模型。凭借 100 多名技术人员和良好的人脉关系,该机构拥有获取前沿模型早期访问权限的公信力。
在欧盟层面,人工智能办公室确实存在,拥有 125 名以上员工和自身的安全部门。但据 Transformer News 报道,就在去年秋天,该办公室还面临严重的招聘困难。关键领导职位空缺。据欧盟人事专家安德拉什·巴内特称,僵化的薪酬结构几乎没有空间吸引私营部门人才。由于内部官僚体制,招聘流程拖延数月,导致候选人在此期间接受了其他工作。相比之下,英国同类机构可以提供高于标准的薪酬。
一些欧盟成员国已并行建立了自己的机构。法国于 2025 年初成立了 INESIA,这是一个人工智能评估与安全研究所。西班牙则通过 AESIA 来监控人工智能的安全部署。
因此,对 Mythos 的处理似乎并非过度监管的例证,而更多是结构性弱点的体现:欧洲在算力、成长资本、本土前沿实验室以及以安全为核心的评估方面仍然落后。所有这些都限制了此类工作所需的人才、算力和影响力储备。自 GPT-3 以来,已经出现过多次类似的警钟。值得肯定的是,欧洲已不再完全处于否认状态。但当下一款同等量级的模型并非来自 Anthropic,而是来自 DeepSeek 这样的公司时,这些努力是否足够——这完全是另一个问题了。
Anthropic is restricting access to Claude Mythos, an AI model it says can find security vulnerabilities better than most humans. European authorities have almost no visibility into the system, while the UK is already running its own tests. The situation exposes a deeper structural problem.
Anthropic announced last week that it would limit access to its latest AI model, Claude Mythos Preview, to a select group of technology partners. The company is giving a preview version to a handful of Big Tech and cybersecurity firms because it believes the new model could pose unprecedented cybersecurity risks and increase the likelihood of large-scale AI-powered cyberattacks.
Under a program called "Project Glasswing," Anthropic handpicked 12 US tech companies as its inner circle, including Apple, Microsoft, and Amazon. Another 40 organizations also received access, though Anthropic didn't name them.
European regulators are barely part of the picture.
Most European cyber agencies had little contact with Anthropic
POLITICO says it spoke with officials from eight national European cybersecurity agencies. Only Germany's BSI confirmed it had opened talks with Anthropic about Mythos without being able to test the model directly so far. Other European government institutions apparently had only limited visibility.
BSI chief Claudia Plattner called it an urgent question whether such powerful tools would eventually be available on the open market. The question has profound implications for national and European security and sovereignty, she told POLITICO. While the BSI is in active dialogue with Anthropic, those conversations have so far only provided meaningful insight into how the model works and not direct access to test it.
The EU's cybersecurity agency ENISA declined to comment on whether it is in contact with Anthropic. The EU Commission's AI Office does maintain a dialogue with Anthropic as part of the EU Code of Practice for AI models. Whether Mythos is part of those conversations, and whether the office has received access, went unanswered.
The UK, by contrast, is in an entirely different position. UK AI Minister Kanishka Narayan confirmed that the British AI Security Institute (AISI) recently tested Mythos and had already taken action based on its findings. On Monday, the institute published its assessment. The results strongly suggest that Mythos Preview represents a significant leap over previous frontier models in a landscape where cyber capabilities were already advancing rapidly. The AISI did note, however, that it couldn't say with certainty whether Mythos could successfully attack well-defended systems.
Without access, Europe can't assess the risks
Europe's lack of access to Mythos isn't just a governance issue. Without solid technical details, regulators can only do so much to assess risks and prioritize defenses.
Daniel Privitera, founder of the Berlin-based AI nonprofit KIRA, told POLITICO that Mythos offers an early taste of how critical access to frontier AI capabilities will be in the years ahead. Europe currently has no plan for securing that access, he said.
AI pioneer Yoshua Bengio told POLITICO he found it deeply concerning that tech companies, not regulators, are deciding how to handle these risks. It shows how important it is to create pathways for governments or third parties to review the technology, he said.
Former European Parliament member Marietje Schaake, who helped shape the EU's Code of Practice for AI developers as an advisor to the EU Commission, also called it concerning that models with far-reaching impact are controlled by a private company. Now would be a good time to agree on disclosure rules and oversight mechanisms, she said.
Independent AI researcher Laura Caroli, who was involved in drafting the EU AI Act, told POLITICO that the EU has been sidelined because the model hasn't been released on the market. If it were, Anthropic would face binding obligations under EU law. That said, according to the EU guidelines, even internal use of an AI model counts as placing it on the market if that use is essential to providing a product or service in the EU or affects the rights of individuals in the Union.
Thomas Regnier, the EU Commission's digital spokesperson, told POLITICO that the Commission is currently examining possible implications under EU legislation. Under the AI Act, providers like Anthropic must address cyber risks posed by their models, and the Cyber Resilience Act sets mandatory cybersecurity requirements for all products with digital components sold in the EU market.
Why Europe is locked out - and what that means
Is Europe's lack of access to Mythos a symptom of overregulation? The reality is more complicated. Anthropic signed the EU Code of Practice for general-purpose AI models, along with Amazon, Google, IBM, Microsoft, and OpenAI. A lack of willingness to cooperate isn't the issue.
The real problem is that Europe lacks a counterpart that can operate on the same technical level. The UK's AI Security Institute, founded in 2023 as the Frontier AI Taskforce and renamed in 2025, has 100 million pounds in public funding. In a remarkably short time, it has gained access to the AI industry by running safety tests and recruiting high-profile researchers from OpenAI and Google Deepmind. It has tested at least 16 models so far, including three frontier models before their public launch. With more than 100 technical staff and the right relationships, it has the credibility to get early access to cutting-edge models.
At the EU level, the AI Office does exist with more than 125 staff and its own safety unit. But as recently as last fall, the office was struggling with major hiring difficulties, according to Transformer News. Key leadership positions were unfilled. Rigid pay structures left little room to attract private-sector talent, according to EU staffing expert Andras Baneth. The hiring process drags on for months due to internal bureaucracy, causing candidates to take other jobs in the meantime. The UK equivalent, by comparison, can pay above standard rates.
Some EU member states have built their own structures in parallel. France launched INESIA in early 2025, an institute for AI evaluation and safety. Spain monitors safe AI deployment through AESIA.
So it seems the handling of Mythos is less evidence of overregulation and more a reflection of structural weaknesses: Europe still lags behind in compute capacity, growth capital, homegrown frontier labs, and security-focused evaluation. All of that limits the pool of talent, compute, and influence needed for this kind of work. There have been several wake-up calls like this since GPT-3. To its credit, Europe is no longer in full denial mode. Whether that's enough when the next model of this caliber comes not from Anthropic but from, say, DeepSeek—that's a different question entirely.