EU AI regulations questioned after new AI threats
Thirty MEPs have warned that current cybersecurity regulations are insufficient to handle AI-based hacking tools, as demonstrated by Anthropic.

What happened?
On 4 May, 30 Members of the European Parliament expressed concerns to the Commission's Executive Vice President Henna Virkkunen. They claim that the EU's existing cybersecurity rules are not equipped to meet the new generation of AI-driven hacking tools. This warning follows demonstrations of how AI, such as Anthropic's Claude Mythos, outperforms humans in identifying and exploiting security vulnerabilities.
Key facts
| Varningsdatum | 4 maj 2026 |
|---|---|
| Antal parlamentariker | 30 |
| Nämd AI-modell | Claude Mythos (Anthropic) |
| Berörd myndighet | ENISA (EU:s cybermyndighet) |
”Artificial intelligence is advancing faster than regulation can keep up. For policymakers, the critical question is how to narrow this gap and regulate technology that evolves in months across institutions that move in years.”
”On 4 May, 30 Members of European Parliament warned Commission Executive Vice President Henna Virkkunen (pictured) that the EU’s cybersecurity rules are ‘ill-equipped’ to deal with a new generation of artificial intelligence (AI) hacking tools.”
Why it matters
Development in AI technology, particularly in the field of cybersecurity and potential threats, is occurring at a faster pace than regulatory frameworks. The EU AI Act is the most comprehensive framework to date, but new tools like Claude Mythos highlight the challenge of regulating a technology that evolves significantly faster than traditional legislation. This creates a gap between technical capability and regulatory control.
Who is affected?
MEPs, the European Commission, and AI developers such as Anthropic are directly affected. Indirectly, companies and organisations at risk of AI-enhanced cyberattacks are affected, as well as EU citizens whose data may be compromised.
Impact on the EU
The EU AI Act is the flagship regulation for AI in Europe. However, the current issue highlights gaps in existing cybersecurity directives in relation to rapid AI development. Demands have been made for the EU cybersecurity agency ENISA to be granted access to tools like Claude Mythos for risk assessment and auditing.
What else you should know
Commission spokesperson Thomas Regnier has confirmed that meetings have been held with Anthropic since the warnings were issued, indicating that the matter is being taken seriously.
Quick answers about this story
Vad har hänt?
När hände det?
Varför spelar det roll?
The link opens in a new window and leads to the publisher's own site.
Källan har spårats automatiskt från utgivaren via Aheadlines signalkedja.
AI-verktyg i artikeln
Topics
Get similar news straight to your inbox
The reader's room
Send in a question or an addition. The newsroom reads everything before it's published and replies when relevant. No AI-generated text – just people.
Sign in to submit a comment or question.
Read the article through your role
- Decide whether this affects strategy over 6–12 months or is just noise.
- Discuss with leadership: do we own the right question or does ownership need to move?
- Ask: what risk are we taking by NOT acting on this this quarter?
Generated angle — not editorial analysis of "EU AI regulations questioned after new AI threats"