EU demands tech sovereignty as Mythos AI model exposes security vulnerabilities

Europe is shooting itself in the foot
A former EU lawmaker on the paradox of weakening AI safeguards while facing American pressure.

In a moment that reveals the deepening fault lines of technological power, the European Union finds itself locked out of an American artificial intelligence system capable of mapping the vulnerabilities of its own critical infrastructure — banks, power grids, defense networks — while the company that built it freely shares access with American corporations. The refusal is not merely commercial; it carries the weight of a geopolitical statement about trust, sovereignty, and who, ultimately, controls the architecture of modern civilization. Europe's institutions are sounding alarms, yet simultaneously softening the very regulations designed to protect against this kind of dependency, caught between the desire for independence and the fear of asserting it.

  • Anthropic's Mythos AI can identify security weaknesses in European banks, defense systems, and power grids — and the company has chosen to share it with American tech giants while refusing access to European institutions.
  • The European Central Bank has already ordered banks to draft contingency plans, and senior officials are warning that increasingly powerful models will reach the market faster than regulators can respond.
  • Rather than hardening its defenses, the EU has quietly agreed to delay enforcement of its own high-risk AI restrictions by eighteen months — a concession that mirrors precisely what the Trump administration demanded in writing.
  • Experts warn that European defense and security infrastructure is dangerously entangled with American cloud systems, leaving it exposed to sanctions or remote shutdown from Washington.
  • Lawmakers who helped write the EU's AI law are now watching it be hollowed out from within, describing the contradiction as Europe 'shooting itself in the foot' at the moment it can least afford to.

Europe is confronting a stark technological reckoning. Mythos, an AI model built by the American company Anthropic, can identify security weaknesses in the continent's most critical systems — its banks, defense infrastructure, and power grids. Anthropic has chosen to share this tool with Apple, Amazon, Google, and Microsoft. It has refused to share it with Brussels.

The refusal has triggered alarm across European capitals. The European Central Bank warned banks to prepare contingency plans. The Commission's executive vice president, Teresa Ribera, told Parliament that Europe cannot allow others to dictate how its economy functions. Anthropic has rebuffed nearly half a dozen meetings with European officials. Dutch MEP Kim Van Sparrentak, who helped negotiate the EU's AI law, drew the conclusion plainly: for Anthropic, Google is a trusted partner. The European Commission, apparently, is not.

Yet even as the warnings multiply, Europe's response is undermining itself. Member states and Parliament have agreed to delay enforcement of restrictions on high-risk AI systems by eighteen months — pushing the deadline to December 2027. The delay mirrors exactly what the Trump administration requested. Former MEP Ibán García del Blanco, who helped draft the AI law, called it self-defeating: 'Europe is shooting itself in the foot.'

Experts warn that appeasement will not hold. Cori Crider of the Future of Technology Institute has documented how European defense systems depend dangerously on American cloud infrastructure, leaving them exposed to sanctions or remote shutdown from Washington. Van Sparrentak raised the stakes further, noting that the United States has declared for a second consecutive year that its strategy includes engineering instability in Europe. 'What better way to create chaos than to hack our transportation systems, our banks?' she asked.

The window for a different choice is narrowing. Advanced AI models are arriving faster than European institutions can respond, and with each delay, each concession, the continent's ability to shape its own technological future recedes a little further.

Europe is facing a moment of reckoning. An artificial intelligence model called Mythos, built by the American company Anthropic, can identify security weaknesses in the continent's most critical systems—its banks, its defense infrastructure, its power grids. And the company that built it has made a choice: it will share the tool with Apple, Amazon, Google, Microsoft, and other American firms. It will not share it with Brussels.

This refusal has set off alarms across European capitals. The European Central Bank warned banks two weeks ago to prepare contingency plans. The European Commission's executive vice president, Teresa Ribera, stood before Parliament and said plainly: we cannot allow others to dictate how our economy functions. Frank Elderson, vice president of the ECB's supervisory council, called the situation urgent. "At a structural level, we must be prepared to face increasingly advanced future models that could reach the market in a relatively short timeframe," he wrote this week.

Yet even as the alarm bells ring, Europe's response appears inadequate to the scale of the threat. Anthropic has rebuffed nearly half a dozen meetings with European officials. OpenAI, by contrast, has announced it will grant access to its latest models—including a version specifically designed for cybersecurity work—to European companies like Deutsche Telekom, BBVA, and Telefónica. The asymmetry is stark and deliberate. Kim Van Sparrentak, a Dutch member of the European Parliament who helped negotiate the EU's artificial intelligence law, put it bluntly: "It is very concerning that Anthropic says it only works with trusted partners. For them, Google is a trusted partner. Apparently, the European Commission is not. Anthropic has always made clear that its ethics apply only to the United States."

The timing compounds the crisis. Just as European leaders are demanding stronger technological sovereignty, the same European Commission is quietly weakening the very safeguards designed to protect it. Member states and Parliament have agreed to delay enforcement of restrictions on high-risk AI systems by eighteen months—pushing the deadline from June 2026 to December 2027. The delay is not accidental. It is exactly what the Trump administration requested in a letter to Brussels. "On one hand we congratulate ourselves, and on the other we are afraid to enforce our own rules," said Ibán García del Blanco, a former Socialist member of Parliament and now international affairs director at the Lasker consulting firm, who helped draft the AI law. "Europe is shooting itself in the foot."

Experts across the continent are warning that appeasement will not work. Cori Crider, executive director of the Future of Technology Institute, has documented how European defense and security systems depend dangerously on American cloud infrastructure—leaving critical capabilities exposed to sanctions or, worse, to a remote shutdown ordered from Washington. "We have seen repeatedly with this administration that Trump interprets appeasement as an invitation to intensify intimidation and increase demands," Crider said. "The only thing that truly protects you from these attacks is resilience."

The stakes are not abstract. Van Sparrentak pointed out that the United States has stated for a second consecutive year that its strategy is to engineer regime change in Europe. "What better way to create chaos than to hack our transportation systems, our banks?" she asked. "The US is the only one with these tools in its hands. If the European Commission does not start moving quickly and ensure that companies like Anthropic work with us, we will have a real problem."

Vera Franz, executive director of the Economic Democracy Project at the London School of Economics, framed the choice starkly: "Europe can decide to be braver and leverage the influence and resources we have, or we can keep writing checks to tech oligarchs and watch our democracy fade away slowly." The window for that choice is narrowing. Advanced AI models like Mythos are arriving faster than Europe's institutions can respond. And with each delay in enforcement, each concession to American pressure, the continent's ability to shape its own technological future slips further away.

It is very concerning that Anthropic says it only works with trusted partners. For them, Google is a trusted partner. Apparently, the European Commission is not.
— Kim Van Sparrentak, Dutch MEP
The only thing that truly protects you from these attacks is resilience. We have seen repeatedly with this administration that Trump interprets appeasement as an invitation to intensify intimidation.
— Cori Crider, Future of Technology Institute
A Conversa do Hearth Outra perspectiva sobre a história
Inventor

Why does it matter that Anthropic won't give the EU access to Mythos when OpenAI is sharing its models with European companies?

Model

Because it signals a hierarchy of trust. Anthropic is saying: we trust American corporations and American interests, but not European institutions or European regulators. That's not a technical decision—it's a political one.

Inventor

But couldn't the EU just build its own AI model?

Model

In theory, yes. In practice, Europe has spent decades letting American companies dominate cloud infrastructure and AI development. You can't build sovereignty overnight when your critical systems already depend on American servers and American tools.

Inventor

The EU has strong AI regulations. Doesn't that give it leverage?

Model

It should. But the Commission is simultaneously weakening those regulations—delaying enforcement by eighteen months—at the exact moment it should be enforcing them. It's like drawing a line in the sand and then erasing it yourself.

Inventor

Is this about money, or ideology?

Model

Both. American companies want fewer rules. The Trump administration wants Europe destabilized and compliant. And some European governments are hoping that if they relax their standards, they'll avoid American pressure. It's a miscalculation. Appeasement hasn't worked before.

Inventor

What would real technological sovereignty look like?

Model

Public investment in European infrastructure and European companies. Enforcing the rules you write. Negotiating from a position of strength, not weakness. And understanding that resilience isn't isolation—it's the ability to make your own choices about your own future.

Quer a matéria completa? Leia o original em EL PAÍS ↗
Fale Conosco FAQ