France’s government will use sovereign AI providers, explicitly including Mistral and explicitly excluding OpenAI, to test its public services for cybersecurity vulnerabilities, Budget Minister David Amiel announced this week.
The decision follows a breach of France’s tax agency DGFiP that exposed records of roughly 700,000 taxpayers, prompting the government to accelerate its deployment of AI-driven security tools. Amiel made the announcement after the weekly Council of Ministers meeting in Paris.
Sovereignty Over Access
We will call on sovereign AI companies, such as Mistral. This excludes OpenAI.
Amiel’s statement was a pointed reaffirmation of France’s commitment to the “Our AI” program, which aims to ensure French government data and vulnerability assessments remain within domestic infrastructure and European legal frameworks.
The explicit exclusion of OpenAI stems from concerns that vulnerability data processed by US-based AI models could be subject to extraterritorial jurisdiction under American law. By routing security testing through Mistral and other French providers operating on SecNumCloud-certified data centers, Paris aims to prevent sensitive infrastructure mappings from reaching servers governed by foreign legal regimes.
Europe’s AI Sovereignty Push
Mistral AI, France’s largest homegrown large language model builder, has been positioning itself as the preferred European alternative to US frontier labs. The company recently closed a major funding round and operates its own cloud computing facilities in France and Sweden, providing independent infrastructure for European governments and enterprises.
The move comes amid broader European efforts to establish AI sovereignty. The EU AI Act’s transparency requirements have already prompted companies like Anthropic to embed watermarks in AI-generated text, while France’s decision to exclusively use domestic AI for security testing signals a more aggressive posture toward data independence.
France’s approach contrasts with the broader global trend of AI companies serving customers across borders. The decision could set a precedent for other European nations evaluating how deeply to integrate American AI models into sensitive government functions, particularly in cybersecurity and national defense. The effectiveness of automated testing by sovereign AI against real-world intrusion patterns remains an open question, as algorithmic code analysis alone cannot fully replicate human adversarial tactics.
Sources: Reuters; Channel News Asia; Cointribune; TechCrunch
discussion