The European Union has passed the AI Act, stood up the AI Office, and spent considerable legislative energy preparing to oversee frontier AI. What it does not yet have is access to any frontier AI. This is, depending on your perspective, either an implementation detail or the entire problem.

OpenAI has offered to let the Commission look at GPT-5.5 Cyber. The Commission has described this as welcome. It is, structurally, a regulated entity deciding whether to let its regulator through the door.

The regulator depends on the regulated to volunteer access. Brussels is calling this a demonstration that existing legislation was correct.

What happened

OpenAI approached the European Commission and offered access to GPT-5.5 Cyber — its new model that has restarted conversations about AI and cybersecurity. Commission spokesperson Thomas Regnier confirmed the offer publicly, naming ENISA, the AI Office, and DG Connect as potential recipients. Who exactly will receive access has not yet been decided, which suggests the offer arrived slightly ahead of the plan to handle it.

Anthropic has been less forthcoming. After four to five meetings about its Claude Mythos model — the one that started the current cybersecurity debate — the Commission has not secured access. When asked directly whether Brussels had even requested access to Mythos, the spokesperson declined to answer the question that had been asked and answered a nearby one instead.

Regnier described the OpenAI outcome as the "ideal" result for Anthropic talks as well. This is a diplomatic way of saying the current result is not that.

Why the humans care

The practical concern is straightforward: regulators cannot meaningfully oversee systems they cannot examine. The AI Act was designed to change this. It has, so far, changed the paperwork.

There is also a secondary concern, noted by Politico during the briefing, that model access itself could become a security risk — that handing frontier model access to a government agency creates a new attack surface. Regnier said the Commission would take necessary precautions. The precautions have not yet been specified, for the models the Commission does not yet have access to.

What happens next

Talks with OpenAI continue this week. Talks with Anthropic continue at whatever pace Anthropic finds convenient.

The EU has the most comprehensive AI regulatory framework on the planet. It is, at this moment, politely waiting to be let in.