Watch the original meeting: European Parliament webstream — IMCO ordinary meeting, 14 July 2026
The European Parliament's video recording is the original and authoritative record of this meeting. This page is an unofficial, speaker-attributed transcript prepared from an automatic transcription and lightly edited for readability; where the two differ, the video governs. Verify any quotation against the webstream and the official IMCO minutes before relying on it.
On 14 July 2026, the IMCO committee held an exchange of views with Anthropic on the cybersecurity implications of its most capable models (Mythos and Fable) and on Europe’s dependence on non-EU frontier AI. Anthropic was represented — by video from New York — by Donny Greenberg, a technical employee who repeatedly stated he was “not a policy person”; lawmakers had asked for a senior policy figure, and much of the committee’s frustration centred on the many sovereignty, data-protection and governance questions that consequently went unanswered.
Greenberg’s substantive points: the cyber capability of these models is a by-product of general coding ability (dual-use); Project Glasswing now spans roughly 150 organisations in 15+ countries, which found more than 10,000 high- or critical-severity vulnerabilities in the first month (Mozilla alone fixed 271 in a single Firefox release); discovery is no longer the bottleneck — triage, remediation and patching are; the June export-control episode saw access suspended for all users, then restored on 1 July (the added safeguards work applied only to the Fable class, not Mythos); and defenders should rely on a diverse set of models rather than any single one. Members (van Sparrentak, Schaldemose, Chaibi, Arias Echeverría, Guzenina, a Patriots-for-Europe member, Gasiuk-Pihowicz, van Lansschot, Benifei, Cepeda) pressed on the “kill-switch” dependency, data access by US authorities, energy/water use, EU compute, and — most pointedly (Benifei) — that no European entity was among the first partners and that a defensive tool “granted at your discretion and withdrawn at someone else’s” is “a European security problem created by a private access list.”
Commission closing — Lucilla Sioli (Director, EU AI Office). The most consequential official statement came at the end. Sioli confirmed that the AI Office’s enforcement powers under the AI Act apply from 2 August 2026, giving the EU means to check that providers’ safety mitigations are satisfactory when models are deployed in the Union. She highlighted the EU AI and Cybersecurity Action Plan launched on 7 July 2026, which (i) strengthens EU capacity to test and evaluate models in cybersecurity contexts and (ii) provides a “blueprint to organise access to the models” and the choice of “trusted users.” She stressed the aim to ensure cyber hygiene and patching, noted this “doesn’t have to take place through Mythos,” and — framing the whole issue as one of technological sovereignty and security rather than mere tech competition — said the EU will act to “avoid creating new dependencies and always only relying on non-EU frontier models.” She also flagged that model risks extend beyond cyber (e.g. biology). This statement maps directly onto the EU-evaluation-capacity, trusted-access and sovereignty-through-redundancy themes at issue throughout the hearing.
Confidence legend: ✅ high · 🟡 probable · ⚪ role identified, personal name uncertain
| Transcript rendering | Identified speaker | Group / role | Conf. |
|---|---|---|---|
| “Chair” / “Madam Chair” | Anna Cavazzini | Chair, IMCO (Greens/EFA, Germany) | ✅ |
| “Mr. Greenberg” (also “Greenback”, “Gertenbugge”) | Donny Greenberg | Anthropic; technical employee (joined April 2026 via Anthropic’s acquisition of his company, Runhouse); works on Project Glasswing; joined remotely by video from New York. Anthropic sent him rather than head of public policy Sarah Heck, whom lawmakers had requested. | ✅ |
| “Dirk Hoting” | Dirk Gotink | EPP, Netherlands | 🟡 |
| “crystal chaldea” | Christel Schaldemose | S&D, Denmark | 🟡 |
| “kim from sparring” | Kim van Sparrentak | Greens/EFA, Netherlands | ✅ |
| “lila” (spoke French) | Leila Chaibi | The Left, France | 🟡 |
| “Pablo Arias Echeverría” | Pablo Arias Echeverría | EPP, Spain | ✅ |
| “Ms. Gozenina” | Maria Guzenina | S&D, Finland; IMCO rapporteur on CSA2 & NIS2 | 🟡 |
| (unnamed French speaker, “Les Patriotes pour l’Europe”) | Patriots for Europe member, France — possibly Virginie Joron | Patriots for Europe, France | ⚪ |
| “Camilla Gaziuk-Pihubitz” | Kamila Gasiuk-Pihowicz | EPP, Poland (IMCO Vice-Chair) | ✅ |
| “Renier van Lansgoot” | Reinier van Lansschot (POLITICO: “van Lanschot”) | Greens/EFA–Volt, Netherlands | ✅ |
| “Brando Benefe” | Brando Benifei | S&D, Italy | ✅ |
| “José Cepeda” | José Cepeda | S&D, Spain | ✅ |
| “Luchila Scioli” | Lucilla Sioli | Director, EU AI Office (European Commission, DG CONNECT) | ✅ |
Chair (Anna Cavazzini): The reason we are holding this exchange is the implications of these developments for cybersecurity, but also the question of how far the European Union is dependent on other countries’ — other presidents’ — decisions over technology. So I’m very happy we can have this exchange today. Welcome, Mr. Greenberg. You have around seven minutes to present the company and how you see the present situation, and then members can come in with questions and comments. The floor is yours.
Donny Greenberg (Anthropic): Chair and honourable members, thank you for the invitation. Let me introduce the company I work for. Anthropic is an AI safety company founded in 2021, headquartered in San Francisco, and we build a family of AI models called Claude. We are a public benefit corporation, which means we are legally bound to weigh the public interest alongside the interests of our shareholders. Our purpose is to ensure the world makes the transition through transformative AI safely. That is why we publish research on where these systems are becoming dangerous, and why we hold ourselves to a Responsible Scaling Policy that ties deployment to demonstrated safety. We were among the first signatories of the General-Purpose AI Code of Practice, and we have championed AI regulation at both state and federal level in the United States.
Before the details: I’d point out that I’m a technical person, not a policy person — my background is AI training and serving systems. Since joining Anthropic I’ve co-led Project Glasswing, to help the cybersecurity world navigate the emergence of AI offensive threats. To be speaking with you today is both an unexpected honour and a clear indication of how important AI and cybersecurity are to the safety and security of our citizens.
Cybersecurity is a clear example of the dual-use nature of AI capabilities. We did not train Mythos Preview for cybersecurity, but rather for coding and general reasoning — but a model that writes and understands code well is inherently good at finding flaws in software systems. In testing, it found thousands of previously unknown vulnerabilities, including in every major operating system and web browser. It found a 27-year-old flaw in OpenBSD, one of the most security-hardened operating systems in the world, and several bugs in the Linux kernel which it was able to chain together to gain control of the machine. We’ve shared more detail in our Frontier Red Team blog.
We concluded that releasing the model broadly would be irresponsible. So instead we began Project Glasswing — a company-level effort, in partnership with cyber defenders, to prepare for the emergence of AI cyber offence. We gave model-access grants and support to the organisations that build and maintain the critical foundations much of the world’s software depends on, so defenders could find vulnerabilities, shore up their defences, and discover new ways to use the models for defence. Last month we extended the programme to roughly 150 further organisations in more than 15 countries. Within the first month, our partners had found more than 10,000 high- or critical-severity vulnerabilities. Mozilla found and fixed 271 in a single Firefox release — ten times what they found in the previous one.
Finding vulnerabilities is no longer the bottleneck. Fixing them — and incorporating AI capabilities across defensive security programmes — is. Triage and remediation have become a major bottleneck; and other areas — incident response, penetration testing, configuration scanning, and patching — all urgently require attention and creativity to give cyber defenders a durable, asymmetric advantage.
[On the recent export-control episode:] … requiring us to restrict access by foreign nationals, we suspended access for every user. The controls were lifted on the 30th of June, and access was restored on the 1st of July. The past month has made us all acutely aware that the technology we’re creating brings additional geopolitical complexity. We welcome cooperation with the United States government to identify a sustainable framework that offers our customers and governments predictability, and we welcome constructive conversations with the AI Office, the European Commission, and ENISA during this first-of-its-kind moment.
Let me end with what I find encouraging: the same capability that makes these models dangerous makes them the most powerful defensive tool that has ever existed for this problem. If wielded properly, we feel strongly this technology favours defenders long-term. If there’s one message I’d want remembered, it’s that now is a moment for organisations to strengthen their cyber resilience — drawing both from well-established best practices and from novel experimentation and industry collaboration. We’ve watched closely as the EU announced its AI cybersecurity action plan, and as other governments hold similar discussions. I expect a difficult period ahead, but on the far side of it we see a world where critical systems are significantly hardened and defenders maintain a durable advantage. No single organisation can reach that alone: frontier AI developers, software companies, security researchers, open-source maintainers, and governments are all essential. I’m grateful for the opportunity, and I look forward to your questions.
Chair (Anna Cavazzini): Members can now come in for roughly two minutes each. We start with the EPP — Dirk Gotink.
Dirk Gotink (EPP): Thank you, Chair, and thank you, Mr. Greenberg. We’ve talked a lot here about AI in the EU. Speaking to you — I don’t know where you are, maybe San Francisco — the world looks a lot brighter from the AI perspective there than it does looking towards San Francisco from here. Your noble mission of accompanying Europe, and the world, through the AI transition has become a geopolitical and economic tool through the intervention of the White House. That has shocked us and emphasised once again that the transatlantic partnership is not as solid as we expected. On the technological front, it’s now clearly the US leading and the EU trying to catch up.
First, a general question: could Anthropic be developed in the EU? Some argue LLMs cannot be built here because of the regulatory environment and energy constraints. Do you have a reflection? Second: did anything actually change in the product between what was blocked at the first White House intervention and what was freed again at the end of June — did you make changes on the inside? We don’t have the means to verify it here, but it would be important to understand what changed apart from that decision. And how do you foresee rolling out newer models in future without this kind of lock-on? That’s probably the most important question — otherwise we’re in a kind of circus where we first need a president to stop it, and then the rest of the world worries that we’re only giving security advantages to American companies rather than protecting everyone at the same time. Thank you.
Chair (Anna Cavazzini): Thank you. For S&D, Christel Schaldemose.
Christel Schaldemose (S&D): Thank you, and thank you for being here online. Along the same lines as Mr. Gotink — if you were sitting in our chairs here in the European Parliament, wouldn’t you consider whether it makes sense for us to use Anthropic’s business model? On one hand it creates a dependency on you; on the other, we’d generate a lot of growth and data for Anthropic. So wouldn’t you recommend that it’s better for the EU to develop our own systems rather than use yours — for strategic independence, but also to keep the economic value in the EU? If you were here with us, would that be your consideration? Thank you.
Chair (Anna Cavazzini): Next, Kim van Sparrentak for the Greens.
Kim van Sparrentak (Greens/EFA): Thank you. Interesting to hear your perspective. You’ll get a lot of policy questions you perhaps can’t answer as the technical guy — but we’ll ask them anyway, and Anthropic could have anticipated that. We heard that Mythos is essentially able to detect all cybersecurity vulnerabilities. If that’s true, it poses a major risk, especially if it falls into the wrong hands — and even if half of what’s claimed is true, it opens the door to major cyberattacks at scale that can harm our banks, hospitals, and transport systems. Mythos is just the first model. The biggest worry in Europe is that we are in the hands of a high-tech company — and, some would say, in the hands of Anthropic — to decide whether the EU is a trustworthy partner, who gets access, and who is worthy of protection against the dangerous model you’ve built. We’ve also seen the US try to weaponise this model against the rest of the world. So what exactly is Anthropic doing to ensure people and businesses are safe — not only in the US, which I know you care about, but also in Europe — and that the model doesn’t fall into the wrong hands and won’t be weaponised for geopolitical gain? It’s important for European people to know you don’t have to develop this — you could stop — but that if you do, you do it responsibly and safely. Thank you.
Chair (Anna Cavazzini): I’ll take one more and then a short answer round. Leila.
Leila Chaibi (The Left) (speaking French): [opening partly unclear] … we are dependent — whether the technology is American or Chinese — and living under the constant threat of a kill switch, as with the US government here, though it could equally have been China or elsewhere. My question, similar to colleagues’: what was the deal? We now have access again to Fable, as you said — so in exchange, what did you allow access to? Can you tell us the modifications you made to your model that allowed the US government to export it? My second question echoes press articles alleging that your company spied on Claude Code users via tracking tools it considered Chinese, to stop the models being copied — without the consent of the targeted users. Was Anthropic under pressure to do this? [remainder unclear] Thank you.
Chair (Anna Cavazzini): Mr. Greenberg, I give you the floor before we pile up too many questions.
Donny Greenberg (Anthropic): I’ll run through these in order. Yes, I’m at the microphone — I appreciate you having me, and I regret I couldn’t be there in person; I’m joining from New York.
On whether Anthropic could be built in Europe — honestly, I don’t have a strong answer. Anthropic is a very particular company and culture, but I don’t think today’s topic is specific to Anthropic or to me. The moment of preparing for cyber offence is independent of individual companies or people. The message of Project Glasswing is that AI capabilities are coming to both cyber defence and cyber offence imminently, across the globe — and we expect our competitors to have models of similar capability quite soon, some of them open-weight or without adequate safety. So the real question isn’t whether this specific company could be built in Europe; it’s what we can do globally, as a cybersecurity field, to prepare and collaborate for these capabilities arriving across many providers. [portion unclear]
On what changed before and after the export restrictions — we increased the robustness of the safeguards as an added precaution, but to be clear that was only on our Fable class of models. The Mythos class — the ones of note for dual-use cyber capabilities — were not the subject of that work, as they have limited safeguards. There wasn’t a specific change to the Mythos-class models before and after.
On evolving rollouts to avoid this in future — we are working tirelessly to avoid these complex staged rollouts. When we started on the Mythos class, we faced the dilemma of how to deliver Mythos Preview’s capabilities to cyber defenders without bearing the risk of widespread cyber offence. It was clear it would be a long road to build the access programmes and protections to roll the model out as broadly as we’d have liked. So it was a combination of building those protections and being prudent — analysing the risk as we progressively expanded access, recognising unknown unknowns and the need to monitor closely. [portion unclear] Our message is that this is really not about Anthropic’s models specifically, or any one provider or geography: these models generalise, and over time they will keep growing in capability. It is not our objective for the technology to deliver economic benefits only to whoever holds the model — but to everyone. From a cybersecurity standpoint, defenders should evaluate their security programmes through the lens of a diverse set of models, including ones that may be open-weight or lack adequate safeguards. This isn’t about building one special or magic model with a distinct offensive capability; it’s about up-levelling cyber defence globally, collaboratively. For example, many Glasswing partners use generally available models like Opus 4.8 for triage and patching, rather than Mythos Preview, because they find it highly efficient for those use cases. In general we advocate building these capabilities broadly, not over-indexing on a specific model or provider.
On what we’re doing to keep people and businesses safe globally — this is central to Glasswing. The methodology is about balancing risk: the risk of granting a new organisation access (including compromise or misuse) against the risk of not granting access and denying them the uplift to improve their security. This is not a view with a lens on one country or region — it’s global. The software foundations we prioritise for vulnerability discovery underpin the entire global economy; a compromise wouldn’t discriminate by region. Our safeguards and misuse/compromise-detection systems are designed to protect everyone equally, to ensure access remains only with critical cyber defenders and the model can’t fall into the wrong hands. We have elaborate defence-in-depth systems protecting model access at many levels. [remainder unclear]
Chair (Anna Cavazzini): The next round — Pablo Arias Echeverría for the EPP.
Pablo Arias Echeverría (EPP) (speaking Spanish): Thank you, and thank you, Mr. Greenberg, for being here — but my first question is very simple: are you answering the questions we’re asking, or simply reading what your AI model outputs? I think you’re reading. I’d like you to answer. I haven’t come to attack — I’ve come to debate — but I was surprised by this. I don’t think AI is bad in itself; what’s bad is its use, and there may be dangerous purposes for people who want cash or power through it. So the question is: where can we go so that the technology serves the good of humanity? We heard the same at the start of OpenAI — “for the good of humanity” — and now we see it isn’t exactly that. We made the same mistakes in the digital age, waiting until the internet giants were the ones who benefited, and by then it was indispensable for everyone. We’ve had international agreements before — road-safety rules, for instance, which worked very well: a green light everyone passes, red everyone stops, a stop sign is a full stop. Can’t we try to do something similar with AI before advancing into something that can become extremely dangerous for humanity? I think it’s easy to formulate, if not easy to answer. Thank you.
Chair (Anna Cavazzini): For S&D, Ms. Guzenina.
Maria Guzenina (S&D): Thank you, Chair. I’m also IMCO rapporteur on CSA2 and NIS2, so it’s good to hear these answers. The cybersecurity map in Europe is very fragmented — and one weak link lets attackers infiltrate the whole system. How would you strengthen European cybersecurity as a whole, given different member states, different levels of readiness, and different threats? I come from Finland; we are constantly under hybrid attacks from Russia, so we need strengthening already. Some countries are further ahead; others are still dormant or not taking the threat seriously. We also have threats to the banking system. And there is talk about Q-Day — is it ever going to arrive, and will it become a tool? Thank you.
Donny Greenberg (Anthropic): [Brief reply, partly unclear:] We’ll have to keep developing better and better defensive systems — including against those trying to harvest information now that they cannot yet decrypt — and build a stronger defence. [remainder unclear]
Patriots for Europe member (France) (speaking French; personal name not stated on the recording): Madam President — today we are questioning Anthropic, the American flower of artificial intelligence, and in doing so we touch the great European paradox. On one side, models like Mythos — of unprecedented power — are landing on our continent. On the other, what is Europe’s reflex? The stick: the stick of the AI Office, the stick of the amendments that fall from 2 August, the stick of the Commission’s new plan to block access to these technologies. As a member of the Patriots for Europe group, I defend above all the sovereignty of European nations against the Brussels bureaucracy and foreign technological domination. The AI Act imposes heavy, ideological rules that risk stifling innovation, while letting American giants like you prosper on our market. How do you judge this regulatory approach — doesn’t it dangerously handicap our companies and states instead of protecting our citizens? Are you ready to make direct partnerships with member states, without going through Brussels, to develop AI that respects our identity, values and strategic interests? Concretely, would you localise data and processing in Europe, guarantee full transparency on your training, and adapt your models to serve first the security and prosperity of our peoples? What is your position on real digital sovereignty? Thank you.
Chair (Anna Cavazzini): For the EPP, Kamila Gasiuk-Pihowicz.
Kamila Gasiuk-Pihowicz (EPP): Thank you. Following the recent US decisions to restrict access to the most advanced AI models for non-US citizens, Europe faces a fundamental question: can we build our security, competitiveness and digital future on technologies that may become unavailable because of political decisions taken outside Europe? So: how much can Europe count on Anthropic as a long-term partner, not only for innovation but also for cybersecurity and defence — and how can we be sure access to your most advanced technologies will never become a geopolitical bargaining chip? How can you guarantee European institutions, businesses and citizens won’t suddenly lose access because of decisions taken in Washington rather than Brussels? Who ultimately decides where the limits of your models lie — Anthropic, democratically elected governments, or the US national-security apparatus? And on data protection: can European users’ data be accessed by US authorities — yes or no? Where is European customer data stored, and who, technically and legally, can access it? If US authorities requested access to European customers’ data, ordered restrictions, or required changes to how your models operate, would you inform that customer? Thank you.
Chair (Anna Cavazzini): Reinier van Lansschot.
Reinier van Lansschot (Greens/EFA–Volt): Thank you, Chair, and thank you, Mr. Greenberg. You said you’re not specialised in policy but in the technical details, so I’ll frame my questions to the technical side — though I must admit I find it a bit disappointing that we can’t touch the policy side here, because that’s where much of the essence of what we need to address together lies. You said Anthropic’s purpose is to make the world’s transition to AI safe, and that you try to be an AI company with a certain ethics. To what extent is that possible when autocrats and autocratic regimes could hijack your mission and use it for their benefit? Is there anything you’d change in Anthropic’s structure to reduce that risk? I’m also curious about energy and water usage — data centres use a lot of both. As a technical expert, do you expect breakthroughs that diminish the water and electricity used? Both the EU and US grids are already overstretched, and we don’t want this at the expense of new housing and other businesses. And finally: how important is it to Anthropic’s strategy to have more of its compute in Europe, and not only in the US? Thank you.
Chair (Anna Cavazzini): Brando Benifei.
Brando Benifei (S&D): Thank you, Chair. Mr. Greenberg — in April, Anthropic gave 50 organisations early access to a model that finds vulnerabilities at an unprecedented scale. But not one was European. In June, the US administration suspended the access that had just been offered to ENISA; it was restored in July after Brussels lobbied Washington. That sequence tells Europe what it needs to know. We need more digital sovereignty — and we’re working on it, with proposals on the table like the [Cloud and AI Development Act]. But we also need to look deeper. The tool our defenders depend on is granted at your discretion and withdrawn at someone else’s. Mythos has surfaced more than 10,000 critical vulnerabilities. Anthropic says the bottleneck is now patching. European operators of power grids, hospitals and water systems run the same code as your partners — but they’ll learn of the flaws last. That is a European security problem created by a private access list. So, simply: how many European entities hold access today, and on what conditions? Is ENISA’s access working now, and who can take it away? You opened your models to the British institute, which cannot regulate you — but from 2 August the AI Office can, with the competences granted by the AI Act. Will you offer the AI Office and ENISA the same access before your next release? Europe should not trade enforcement for access — we will apply our rules, and we want you to comply. Thank you.
Chair (Anna Cavazzini): The last MEP speaker — José Cepeda, also S&D.
José Cepeda (S&D) (speaking Spanish): Thank you. First, thank you for being here — we’ve been seeking some explanation of Anthropic’s new Mythos models for a while. The entire field of cybersecurity is, frankly, broken by these models. We’ve seen OpenAI create its own model. Do you have any knowledge of DeepSeek, in the Chinese field, already working on similar models? And on Anthropic specifically — what limits, from the ethical, operational and military point of view, applied in the operation the US military developed in Venezuela, that led Anthropic to separate from the different military AI systems, from Palantir, on that operation and subsequent ones? I work in the Security and Defence Committee, and we are very concerned that offensive-character LLMs of a military nature, using agentic AI without human control, could implement high-risk military systems without any human control. So: what binding legal guarantees can Anthropic give to European capacity that could not be revoked by a unilateral decision of a third government — as happened when the model you put on the cloud for free use was quickly closed off by a decision of the US administration? What guarantees do we have in Europe if our governments start using Anthropic as a defensive force, and a unilateral US decision leaves us out of the system? Thank you.
Chair (Anna Cavazzini): Thank you, and I give the floor back to Mr. Greenberg. You heard our concerns and many critical questions — and one piece of feedback: we’re very happy you’re here, but many MEPs would have liked to speak to the political level too. Perhaps you can take that back for the next exchange of views, which we will definitely hold. The floor is yours.
Donny Greenberg (Anthropic): Thank you — I appreciate all the thoughtful questions. To the first point, about whether it’s me or Claude speaking: I’ll take that as a compliment, since we’re proud of Claude — but it is certainly me speaking. I’m frantically taking notes, because there are so many questions, and reading from my notes.
Let me address a few themes. First, on how infrastructure — especially remote or regional infrastructure — can defend itself in this moment, even without direct access to the model. It’s important to understand the model is not a magic shield, nor a magic spear. Having access doesn’t suddenly make an organisation impenetrable; the model’s cybersecurity capabilities are more subtle than that. If you were a hospital in Finland with access to this model, you don’t necessarily maintain the first-party software you’d analyse with it — you depend on vendors, and those vendors are global, just as a hospital in New York depends on global vendors. The people who steward that software are the ones who need to use the model to shore up those vulnerabilities. These security problems are genuinely hard — they’d be far simpler if we could just give everyone the model and they’d be defended. But the legacy software underneath much of the world’s physical infrastructure is very hard to update and already carries many known vulnerabilities, let alone sophisticated ones an advanced model might find. That is arguably a more fundamental problem than whether a particular power grid uses a model directly.
This is not to say extending access isn’t our objective — it absolutely is. The point is that there’s a huge amount of collaborative work we must take on globally to identify vulnerabilities across this interconnected digital economy, whether using the models or not. A great deal of collaboration needs to happen — and I’m encouraged that a lot of sharing already happens across security organisations, even between staunch competitors, to shore up shared infrastructure. Several policy implications flow from this: it’s more important to be highly qualified, coordinated and collaborative, and to be part of the global security conversation — identifying key vulnerabilities at both the software and operational level, including what can be patched, how quickly, and whether the resources exist to upgrade. In some industries we’ve seen a lot of that collaboration, independent of geography; in others it’s harder — older software, fewer resources, systems more sensitive to downtime.
A country’s security posture in the face of AI offensive threats will depend not on whether a single model scanned a particular piece of infrastructure, but on preparedness across all models and preparedness for the moment of AI cyber offence. Focusing on only a single model — do we have the “right” model in Europe? — leaves a lot on the table; there’s value in analysing the behaviours and differences across models. I don’t think it’s wise to focus on owning or using one model in a particular way. We advocate a diverse, holistic approach, especially against AI threats.
On whether AI will serve humanity — that is our expressed objective, and specifically Glasswing’s mission: to help these models serve humanity by navigating toward a world where defenders have a durable, asymmetric advantage. That can only be done collaboratively — no single entity, and no single country’s industry, can solve it; it’s a global problem with global interdependencies. On the point that one weak link lets attackers in — that’s right, and it must be analysed at all levels. You can’t reason “we depend on a few flagship vendors; if they’re protected, we’re protected.” It’s simply not true. A simple example: in physical infrastructure like power grids and water systems, there’s a distinction between OT systems (which control the physical infrastructure) and IT systems, and the connection between them is at the communications layer. Even if your business software is secured because your vendors assure you it is, if the communications layer is the weak link, offensive threats can traverse into the OT infrastructure. You have to be extremely precise at all levels, understand the global picture and interdependencies. Our objective is for us as a model provider, governments and private organisations to collaborate closely to identify these weak links and prepare for when models of this capability are more broadly available.
I’ll close on a positive note. The spirit of collaboration in cybersecurity is extremely strong. I meet many CISOs across the globe, and they remark that this is a moment of intense focus and collaboration to identify vulnerabilities and prepare for AI coding and cyber capabilities broadly — not just for their one company or region. It’s been a global effort, which is encouraging. Thank you.
Chair (Anna Cavazzini): Thank you. We still want to give the Commission the floor. I welcome Lucilla Sioli, Director of the AI Office, in the room.
Lucilla Sioli (Director, EU AI Office): Thank you very much, and dear honourable members, thank you for this exchange — it was very interesting for us at the Commission to follow your questions and the replies. I’m the Director of the AI Office. Let me start by reminding you that very soon — on the 2nd of August — the enforcement powers of the AI Office under the AI Act will apply. That will help ensure these models, at least when deployed in the European Union, are safe: we have important safeguards and ways of checking that companies’ mitigation measures are satisfactory from a safety point of view.
I’d also remind you that now, in the United States too, there is regulation on these models — an executive order inviting providers of the most advanced models to designate them and have them checked before they are placed on the market. This first piece of US AI regulation is important to keep in mind.
In Europe, we also just launched an AI and Cybersecurity Action Plan on the 7th of July. On the one hand it strengthens our capacity to test and evaluate these models, in particular when applied to cybersecurity contexts; on the other, it provides a blueprint to organise access to the models — which I think will be very important for the future and for the relationship with providers, in terms of the choice of trusted users. With the action plan we also try to ensure cyber hygiene and ongoing patching. We heard it doesn’t have to take place through Mythos — it can take place through other tools — and what is important is that we act to avoid creating new dependencies and always only relying on non-EU frontier models. Today we focused very much on cyber capabilities, but I want to remind you these models increase their capabilities and may bring other risks — for example in biology — and we must prepare to live safely with these capabilities. All in all, this is not just a question of competition in tech; it’s very much a question of technological sovereignty and security. I very much welcome the Parliament’s attention to these matters. Thank you.
Chair (Anna Cavazzini): Thank you for being here and giving the AI Office’s perspective. And thanks again to our external guest from New York, Mr. Greenberg, and to all members who raised questions and concerns — it was a very important debate. This concludes Agenda Item 9.
[Per POLITICO’s report, Greenberg was no longer visible on the video link by the time the Chair delivered this closing thanks.]
Original video. Official record / authoritative source: European Parliament webstream (IMCO, 14 July 2026). This transcript is a derived, unofficial rendering.
About this document. This is a speaker-attributed, lightly cleaned rendering of the Anthropic exchange of views only. All other agenda business from the same meeting (the voting session, the MFF and 2027-budget files, Omnibus IV, the common-charger report, and the Circular Economy Act) has been removed. Speakers are identified from the Chair’s spoken introductions, cross-checked against the IMCO roster and the public record. Obvious ASR (automatic-transcription) duplication has been removed; passages garbled beyond reliable reconstruction are marked [unclear]. Nothing has been added to any speaker’s meaning.
Cross-check. Speaker identifications and several quotations have been verified against POLITICO’s report on this hearing (Pieter Haeck, “‘Anthropic doesn’t care about Europe’ — EU officials peeved after AI giant sends junior staffer to testify about safety,” 14 July 2026). That report confirms the Anthropic speaker as Donny Greenberg and confirms the exchanges attributed above to van Sparrentak, Arias Echeverría, van Lansschot and the Chair.
Verification. Speaker attributions carry the confidence levels shown in the speaker key (✅ high · 🟡 probable · ⚪ role identified, personal name uncertain). Passages marked [unclear] could not be reliably reconstructed and should be verified against the official IMCO minutes and the Parliament’s web-stream recording before quotation.
End of the Anthropic exchange. Prepared 14 July 2026 from an automatic transcription; all non-Anthropic agenda business from the same meeting has been removed.