Frontier AI and Cybersecurity

Lessons for the transatlantic tech community
July 24, 2026

Listen to this article

Audio file

Audio is generated automatically and may contain minor inaccuracies.

The US government’s brief suspension of Anthropic's Fable 5 and Mythos 5 models, which discover and mitigate software vulnerabilities, confirmed Europe's worries about dependency on US frontier AI and gave Brussels a new incentive to push for technological sovereignty. But the broader lesson for all concerned is that a dedicated transatlantic forum is required, one in which governments and regulators can address existing and emerging tensions related to frontier AI capabilities. Similar conflicts will otherwise continue to arise as more-advanced models are rolled out.

The prospect of using powerful AI models to detect software vulnerabilities at scale presentsan opportunity to build more resilient digital ecosystems. But it also creates an urgent new task for public- and private-sector cyber leaders racing to patch preexisting flaws before adversaries can exploit them. Mythos and its smaller sibling Fable can, after all, analyze code at a speed and breadth that far exceeds human capacity. Such AI-assisted tools are also dramatically accelerating vulnerability discovery and mitigation cycles in software at an 87% success rate. Mean remediation times dropped by roughly 47% in 2025 as AI-driven scanning became widespread. For cyber defenders, this is a genuine game-changer, but only if access to these capabilities remains reliable and uninterrupted.

Due to its exceptional code vulnerability discovery capabilities, Mythos 5 was not publicly released but shared under Project Glasswing* with a select group of trusted technology and cybersecurity companies and US government agencies. In early June, the EU negotiated an agreement with Anthropic to also give ENISA, the bloc’s cybersecurity agency, access to Mythos 5. Shortly afterwards, Fable 5, a less powerful but highly capable model with stronger built-in safeguards, was released publicly.

Within days of that release, however, the US Department of Commerce sent Anthropic anexport control directive citing national security authorities. The company claims the directive, which was not publicly released, required it to suspend all access to Fable 5 and Mythos 5 by non-US nationals, including those physically in the United States. Because Anthropic could not reliably enforce the restriction on a nationality basis, it disabled both models for all users.

The directive’s trigger was a jailbreak vulnerability in Fable 5. Researchers had demonstrated that carefully crafted prompts could bypass the model's safety classifiers, potentially enabling it to assist with cyberattacks and other malicious activities. But on June 30, access to Mythos 5 was restored for a strictly limited group of pre-approved US government organizations and Project Glasswing participants. After hardening the model's security architecture and deploying additional classifiers to block bypass attempts, Fable 5 was re-released the following day.

Reactions from European and other allied governments to the chain of events were mixedgiven Washington’s demonstration that it could determine frontier AI access and instantaneously cut it off. Within a week of the export control action, more than 100 senior American and allied cyber experts issued an open letter calling on the US government to lift the restrictions. Leading voices described the decision as an own goal that had pushed allies away and weakened collective cyber defense. Still, despite the geopolitical strains, the trust between European and American cyber communities remained robust thanks to years of joint operations, intelligence sharing, and coordinated responses to state-sponsored attacks on critical infrastructure. The frontier model restrictions nevertheless spurred allies to discuss their technological future in an era in which access to the most capable AI cannot be taken for granted.

Several reports have pointed to the facilitative effect of the restrictions on AI development elsewhere, particularly in Asia. The most capable Chinese models are unlikely to reach the sophistication of Mythos 5 in the near term, but they reportedly perform most of what Fable 5 does, creating an alternative supply the export controls cannot reach.

Perhaps ironically, Anthropic's own testing found that the vulnerability exploitation technique behind the June shutdown was not unique to Fable 5. Every AI model that the companytested could produce the same exploit demonstration. No capability unique to Mythos-class models was discovered.

Advancing Europe’s AI Capabilities and Tech Stack

The whole episode has delivered a hard lesson to the transatlantic tech community. Since the US government can act unilaterally to restrict access to critical technologies, viable alternatives must exist to support cyber defenders, critical network operators, and providers of essential services in finance, transport, energy, and other key sectors. The political case for European AI alternatives is reinforced with companies such as France’s Mistral that have enjoyed steady growth.

Full technological sovereignty is neither achievable nor a practical policy goal, but Europe is likely to pursue a phased approach in which national security data is increasingly governed by autonomous, home-grown systems, while the US technology stack continues to serve commercial and industrial users. Recent decisions by France and Germany to replace US-based Palantir with a European alternative point clearly in this direction. France's domestic intelligence agency, the DGSI, announced in June that it is dropping Palantir in favor of ChapsVision, a domestic firm, for large-scale data processing. Germany's Federal Office for the Protection of the Constitution has similarly changed vendors.

Europeans are learning, again, ways to navigate technological dependencies and build their own AI and critical tech capabilities. The European Commission's recent Tech Sovereignty Package and the new EU Multiannual Financial Framework allocate more resources to technology innovation, creating in Europe the conditions for its own technological advancement that will, it is hoped, result in a more balanced transatlantic technology partnership.

Let’s Work Together

Anthropic's response to the Fable 5 incident underscored a broader reality: Industry and governments now recognize that frontier AI presents cybersecurity and national security challenges that require more structured governance. With the model’s redeployment, the company publicly detailed its vulnerability, the likelihood that the vulnerability could be exploited, and the safeguards implemented, while also participating with Google, Microsoft, Amazon, and others in developing voluntary standards for frontier AI security. The recent cyber incident in which autonomous OpenAI agents broke out of a sealed-off testing environment and hacked another company clearly shows that stricter AI guardrails and standards are urgently needed.

Washington and Brussels have also begun moving in this direction. The Trump administration’s recent executive order promoting advanced AI innovation and securityestablished a voluntary framework for the secure deployment of frontier AI models, while the European Commission's July Action Plan on Cybersecurity and Artificial Intelligence aims to strengthen evaluation capabilities and create structured mechanisms for secure access to advanced AI systems. These parallel efforts, combined with commitments under the US-EU Framework on Fair and Reciprocal Trade to pursue a cybersecurity mutual recognition agreement, and growing industry calls for closer cooperation, provide a foundation for a more durable transatlantic dialogue on frontier AI governance.

Such discussions would help build the foundation for a global coalition. Around the same time as the US export controls were applied, a G7 summit in France hosted a working lunch that brought together G7 leaders with the CEOs of Anthropic, Google DeepMind, and OpenAI. The industry leaders jointly called on world leaders to establish a US-led international AI coalition to set binding rules and safety standards for frontier AI that coversstructured access to advanced models, semiconductor trade controls that exclude adversaries, and cooperation on AI risks in cybersecurity, bioterrorism, and intelligence. The meeting marked a significant shift for industry, which is now pushing for firmer international governance rather than waiting for regulators to do so.

The case for bringing allies into this framework is straightforward. The most powerful AI models are currently developed by US companies, but key partners control critical components of the AI ecosystem. Germany, Japan, the Netherlands, South Korea, and others play crucial roles in the semiconductor and AI value chain, from chip design to advanced lithography equipment. No credible export control regime for frontier AI will work without their active participation.

Existing multilateral export control regimes are not well suited to the task. Their consensus-based decision-making, broad membership, and slow list-update cycles make them structurally incapable of keeping up with the pace of AI development.

The United States has built a sophisticated unilateral framework for critical technology controls in recent years, but there is no equivalent shared framework among allies. Adedicated coalition of like-minded partners that together control the essential nodes of the AI value chain and can agree on common access standards, safety requirements, and coordinated controls is needed. Calls for AI dialogue by the EU AI Action Plan's European Blueprint, Project Glasswing, the G7, and the Trusted Tech Alliance all point in this direction.

The building blocks for transatlantic AI governance are being assembled, but the political architecture to hold them together remains missing. To construct it, one option is to establish a transatlantic working group on frontier AI, anchored by the Turnberry cybersecurity mutualrecognition agreement and drawing on the coordination in the Trusted Tech Alliance and Pax Silica. This would give the transatlantic relationship what it lacks: a forum in which AI export-control disputes get resolved before they become another source of friction.

* Project Glasswing is an Anthropic initiative to secure the world's most critical software for the AI era. The company is partnering with organizations responsible for core IT infrastructure on which billions of people depend and giving these organizations a head startwith Claude Mythos Preview. The platform finds and fixes software vulnerabilities before attackers exploit them. For more information, go to www.anthropic.com/glasswing.

The views expressed herein are those solely of the author(s). GMF as an institution does not take positions.