Brussels has been gripped by uncertainty in recent weeks. New generations of artificial intelligence can learn to hack software, uncover vulnerabilities in systems, and potentially open backdoors into critical infrastructure. And Europe did not know exactly what these models were capable of because it simply did not have access to them. That has now changed, at least in part.
OpenAI has announced that it will give the European Union access to its new GPT-5.5-Cyber model, a special variant of its most advanced GPT-5.5 system that can identify and exploit security flaws in software. European businesses, government bodies, cybersecurity authorities, and EU institutions, including the EU AI Office, will be granted access.
The news was announced by George Osborne, the former British finance minister who now leads the OpenAI for Countries initiative. He sent a letter to the European Commission offering access while also initiating contact with individual member states.
GPT-5.5-Cyber is not an ordinary chatbot
GPT-5.5-Cyber is designed to actively search for weaknesses in software and, in theory, exploit them as well. The main version of the model has built-in safeguards that prevent this. The version made available to vetted cybersecurity teams in Europe will be the least restricted of the available variants, meaning the one with the fewest limitations.
OpenAI launched the model in a limited preview just one week before this announcement, specifically for vetted cybersecurity teams. It was a direct response to the Mythos model, which Anthropic launched a month ago.
The EU has not yet received the Mythos model
Anthropic released its Mythos cybersecurity model about four weeks ago. Since then, it has triggered a wave of concern about cyberattacks on critical software. Approximately a dozen US technology and cybersecurity companies and 40 other unnamed organizations have so far gained access to the model. Europe is not on the list.
The European Commission has held four or five meetings with Anthropic, but spokesperson Thomas Regnier acknowledged that the discussions "have not yet reached the same stage as the solution OpenAI has put on the table." The EU has not yet gained access to assess the model.
A group of 30 Members of the European Parliament therefore called on the EU cybersecurity agency ENISA to facilitate access to Mythos. Four member states, including Spain, have asked the Commission for information and coordination. Anthropic has not yet officially responded to the request.
Europe needs to strengthen cybersecurity
European institutions, energy grids, water systems, hospitals. All of these are targets that AI-enhanced cyberattacks can reach faster and more effectively than ever before. Without knowing what these models can do, Europe is defending itself blindly.
"Labs like ours should not be the only ones deciding who holds cybersecurity capabilities," Osborne said. He added: "The latest AI cyber capabilities should be available to Europe's defenders, not just a select few."
The Commission welcomed the offer with open arms. Spokesperson Regnier praised OpenAI's "transparency" and confirmed that access to the model would allow Brussels to "closely monitor its deployment and address security concerns." ENISA confirmed that OpenAI had contacted it directly.
The initiative, called the OpenAI EU Cyber Action Plan, aims to bring together European lawmakers, institutions, and businesses and give them access to defensive tools that would strengthen shared security. It is a gesture that comes at a sensitive time. Just one month earlier, the Commission designated ChatGPT as a very large online search engine under the Digital Services Act, subjecting OpenAI to stricter oversight. The offer of access to the cybersecurity model now appears to be an attempt to strike a different tone in relations with Brussels.
Sources: reuters.com, cnbc.com and politico.eu



