European Union flags outside the Berlaymont building in Brussels Credit: © Travel_Motion / Getty Images via Canva.com The EU’s cybersecurity agency used an OpenAI model to find four flaws in code for an EU project, Politico reported on 10 September. ENISA spokesperson Laura Heuvinck confirmed the findings to Politico’s Sam Clark. One flaw carries a high-risk rating, and an attacker could use it to hijack accounts. The flaws have since been fixed, Politico reported.
ENISA did the work with CERT-EU, the team that defends the EU institutions’ own systems. According to Heuvinck, the two ran a “security analysis” of the code with an advanced OpenAI model. Politico said nobody had reported this use of the new tools before. TNW has not independently verified the report.
Politico linked the high-risk flaw to CVE-2026-73431. The OpenCVE listing for that record places it in Vulnerability-Lookup, open-source software for tracking vulnerabilities. It affects versions up to 5.5.1. The software did not track whether someone had already used an activation or recovery token.
An attacker with one such link could replay it while it was valid, reset the password, and take over the account again and again. The record scores the flaw 8.8 out of 10 and dates it 12 August. Europe waited months for access The EU gained access to the most capable US models in July, after months of requests, Politico reported. The pressure started in April.
That month, Anthropic released its Mythos model to a small group of US organisations only. ENISA later gained access to Mythos. On 10 September, the European Commission said the agency is now testing Mythos 5 and GPT-6 Astra. EU authorities still lack the newest version of Mythos, according to Politico.
On the OpenAI side, ENISA belongs to the company’s trusted access programme for cyber models. The French outlet IT Social reported in June that OpenAI had set up these partnerships with France, Germany, and ENISA, among others. OpenAI runs the access through Daybreak, its cyber defence programme. Tom Duff Gordon is OpenAI’s head of policy for Europe.
In a statement quoted by Politico, he spoke of a “narrowing window” for AI to find weaknesses before attackers do. “That’s why we work with partners such as ENISA,” he said. Poland’s CERT used OpenAI’s models too ENISA is not the only European team doing this. CERT Polska, Poland’s national response team, published six flaws in MikroTik’s RouterOS on 5 September. Attackers are chaining two of them, which the team calls MikroTrick.
The pair gives full control of routers that expose SSH to the internet. CERT Polska has seen these attacks since at least 2 September. The team found the flaws with OpenAI’s GPT-5.5-cyber and GPT-5.6-sol models, it wrote. It also set a limit on that claim.
The models sped up the analysis, but the team still had to test every hypothesis on real systems. Its own staff judged the impact of each flaw. A second AI review, on the new CRA platform A separate AI code review covered ENISA’s own infrastructure. AISLE builds AI tools for vulnerability management and has offices in Prague and San Francisco.
On 14 September, it said it had reviewed the code of the Single Reporting Platform for the Cyber Resilience Act. Hans de Vries, ENISA’s chief cybersecurity and operations officer, is quoted in AISLE’s announcement. He said ENISA had also carried out user and security testing with stakeholders, including national CSIRTs. “I thank AISLE for their important AI-based secure code review performed,” he added. AISLE said it will keep reviewing the platform for the next 12 months.
The platform went live on 11 September. Manufacturers of products with digital elements sold in the EU must now use it to report exploited flaws and severe incidents. The Register reported that an early warning is due within 24 hours. A fuller notice follows within 72 hours, and a final report within 14 days of a fix.
The 24-hour deadline applies wherever a manufacturer is based. The act counts these reporting duties as core obligations. Breaching them can bring its top fines of €15m or 2.5% of annual turnover, whichever is higher. Most of the act’s other rules apply from 11 December 2027.
What ENISA is building next ENISA and CERT-EU have used advanced models since July to “actively scan” EU institutions, Heuvinck told Politico. The Commission published an action plan on AI and cybersecurity in July. Under it, ENISA and the Joint Research Centre, the EU’s science arm, are building a “secure testing platform” for the most advanced models. ENISA is consulting the centre on the design.
At the end of September, it will hold a workshop on cyber and AI with the Interinstitutional Cybersecurity Board, which governs CERT-EU. The agency set out the stakes in a July paper on frontier AI. Attackers can now weaponise a flaw within 15 minutes of its disclosure, ENISA wrote. The paper also said EU organisations need access to AI models and to develop their own.
Politico wrote that the agency will treat the four flaws as proof that its long push for early access was justified.














Leave a Reply