A Breach, Then A Procurement Decision
France's Finance Ministry disclosed that its tax agency, the DGFiP, was hit by a cyberattack that stole data belonging to roughly 700,000 taxpayers, including names, dates of birth, postal and email addresses, phone numbers, tax identification numbers, withholding rates, and correspondence with officials. Days later, Budget Minister David Amiel told reporters after a cabinet meeting in Paris that the government would turn to what he called sovereign AI companies, such as Mistral, to test state systems for the kind of vulnerabilities that made the breach possible. 'This excludes OpenAI,' he said.
The sequence matters: this is not an abstract sovereignty policy announced in a strategy paper, it is a specific procurement decision made in direct response to a named security failure, with a named winner and a named exclusion.
Sovereignty Was Already The Plan
Amiel's announcement extends a policy line France had already set in motion. In June 2026 he unveiled 'Notre IA' ('Our AI'), a government plan to distribute sovereign AI tools across French public services. Its centerpiece, an assistant called L'Assistant built on Mistral's model and hosted in SecNumCloud-certified datacenters, was already being rolled out to close to a million state employees before this latest announcement.
Mistral, the Paris-based startup founded in 2023 and valued at more than 11 billion euros, has become France's default answer whenever it wants to demonstrate it can run sensitive systems without depending on US technology. Backing from chipmaking-equipment supplier ASML has reinforced that positioning. The cybersecurity-testing mandate is a new use case layered on an existing relationship, not a standalone decision.
Why This Matters For Every EU Vendor Selling Into Government
For any company selling AI-adjacent services into European public-sector or regulated-sector contracts, this is the moment 'sovereign AI' stopped being a slogan in a policy document and became a concrete line item in a real procurement decision, triggered by a real breach with a real number attached. A US-headquartered vendor was named and excluded from a specific, security-sensitive task, not on performance grounds, but on sovereignty grounds.
| Date | Development |
|---|---|
| June 2026 | Amiel unveils 'Notre IA', a plan to deploy sovereign AI tools, built on Mistral, across French public services |
| Mid-August 2026 | Finance Ministry discloses the DGFiP cyberattack; data of about 700,000 taxpayers stolen |
| Days later | Amiel announces the state will use only sovereign AI providers such as Mistral, explicitly excluding OpenAI, to test system vulnerabilities |
Any vendor, EU-based or not, competing for government or critical-infrastructure contracts anywhere in the bloc should now expect a genuine sovereign-hosting or sovereign-model requirement to appear in tender language, not just a data-residency checkbox, and should have a credible EU-controlled answer ready before it is asked for one.
What This Does Not Settle
One ministry excluding one vendor from one testing mandate is not a blanket ban on US AI tools across the French state, and it says nothing about whether Mistral's tools will actually be better than OpenAI's at finding the class of vulnerability that let 700,000 taxpayer records leak in the first place. Sovereignty and security capability are separate questions, and France has only answered the first one publicly so far.
The wider EU push toward sovereign cloud and AI infrastructure, from Gaia-X to the bloc's planned AI gigafactories, is still early and largely national in practice rather than unified. France's decision is a data point for that broader trend, not proof it has already arrived EU-wide.
Read next: A Fake Think Tank Targeted France And Germany With AI | Mistral Just Split Sovereign AI Into Two Bets


