A minister put a name on the decision

France's Budget Minister David Amiel did something unusual for a digital sovereignty debate: he attached his name and a direct quote to a specific procurement choice. Speaking on Tuesday, 18 August 2026, Amiel said the state would rely on sovereign AI providers, citing Mistral, the French AI lab, as an example. His words, translated: "This excludes OpenAI."

That sentence is the story. Sovereignty pledges from European officials are common; a sitting minister naming a specific US vendor as excluded from a specific government function, in a quotable statement, is not. Telesatellite reported the remarks on 20 August 2026, tying them directly to a separate announcement Amiel made the same day: that the state would use AI tools to hunt for vulnerabilities in its own systems.

The trigger was a breach at the tax authority

The immediate context was a security failure, not an abstract policy exercise. DGFiP, France's tax authority, had been breached, exposing names, contact details, and tax reference numbers for roughly 700,000 taxpayers. The French government's 17 August communique laid out its standing response doctrine: detect and interrupt through ANSSI, the national cybersecurity agency; prosecute, with DGFiP filing a criminal complaint and a judicial investigation now underway; and inform, with notifications to the CNIL and to affected individuals starting Monday, 17 August.

Amiel's AI-vendor comments came the next day, as part of the government's broader push to use artificial intelligence for vulnerability detection across ministries. The breach did not create the sovereignty policy, but it gave the exclusion of OpenAI a concrete, dated trigger rather than a vague strategic backdrop.

Why the vendor choice is a security decision, not just a political one

Testing your own government's systems for weaknesses is among the most sensitive workloads any AI vendor can touch. An AI tool built to find vulnerabilities needs deep, standing access to exactly the infrastructure an adversary would want to compromise. Handing that access to any outside vendor is a risk; handing it to a US-domiciled vendor adds a specific, legally grounded exposure that a French or EU vendor does not carry in the same way, because US providers remain reachable by US legal process in ways a domestic company is not.

That is the honest tension in France's choice. Mistral is a domestic vendor without the scale or track record of the largest US labs, and choosing it for this workload is a real tradeoff, not a costless upgrade. But for this specific use case, jurisdiction is doing real security work, not standing in as political theater. The decision only holds together because it is narrow: a named minister, a named vendor, a named exclusion, tied to a named function.

The decision this raises for every EU organization

France's move gives other governments and regulated enterprises something they lacked before: a concrete, on-record template for excluding a specific foreign AI vendor from a specific sensitive function, rather than a general sovereignty gesture. Any EU or UK body running vulnerability-testing or red-team AI tooling on sensitive infrastructure now has a precedent to point to when making the same call.

The real question this raises is not whether to use AI for security testing at all. It is which jurisdiction the AI vendor answers to, and whether that jurisdiction matters more for this particular workload than it does for an organization's general-purpose AI use elsewhere. France answered that question for one function, in writing, with a name attached. Other institutions handling comparably sensitive infrastructure now have to answer it too.