The European Union Agency for Cybersecurity (ENISA) recently used an advanced artificial intelligence model developed by OpenAI to analyze the code of an EU project. This analysis uncovered four security vulnerabilities, one of which was deemed high risk. ENISA confirmed this to the news outlet Politico earlier this month. Access to these American AI models took several months to secure, as ENISA is a partner of OpenAI through the Daybreak program, which provides select partners with access to AI models that have cybersecurity capabilities. Similar agreements exist with France and Germany. The most critical flaw, labeled CVE-2026-73431, was found in Vulnerability-Lookup, an open-source tool used to track software vulnerabilities. The issue affects versions of the software up to 5.5.1 and occurs because the program does not check if an account activation or recovery link has already been used. This could allow an attacker to reuse the link to reset a password and gain unauthorized access to an account. According to the OpenCVE database, this vulnerability is rated 8.8 out of 10 in terms of severity. However, the vulnerability has since been fixed, along with the other three issues identified. ENISA conducts its cybersecurity assessments through the Daybreak program, which grants access to advanced AI models. Tom Duff Gordon, head of public policy at OpenAI for Europe, noted that the time available to detect and address flaws before they can be exploited by attackers is shrinking. Despite this, European institutions that advocate for digital sovereignty are relying on American technology. Vincent Strubel, director general of France's National Cybersecurity Agency (ANSSI), acknowledged this dependency in June, explaining that efforts are underway to develop alternatives, such as the SecNumCloud qualification for cloud computing. These initiatives aim to mitigate risks like the "kill switch," a hypothetical feature that could allow remote control of a system. However, such efforts do not ensure access to the technology if a government restricts its export. The situation highlights a broader debate in Europe about reducing dependency on foreign technology while avoiding overly restrictive policies that could hinder innovation. The EU gained access to OpenAI's tools in July, and since September 10, ENISA has been testing two models—Mythos 5 and GPT-6 Astra—though it has not yet accessed the latest version of Mythos. This is not an isolated case in Europe. For example, Poland's cybersecurity team (CERT) identified six vulnerabilities in MikroTik's RouterOS system on September 5, using OpenAI models before verifying them on actual systems. Meanwhile, the company AISLE announced on September 14 that it had audited the code of a new reporting platform linked to a recent EU regulation on cyber resilience, which became effective on September 11. ENISA and CERT-UE have been using advanced AI models since July to continuously monitor European institutions, with their own testing platform currently under development by the European Union's Joint Research Centre.