A Government Picks Its Vendor by the Job, Not the Brand
On August 18, 2026, French Budget Minister David Amiel stood at the Finance Ministry in Bercy and apologized for a breach that had exposed tax and land-registry data on 678,000 individuals and businesses. The intruder had used stolen credentials from a DGFiP employee and an authorized third party to sit inside the tax agency's systems since late June before the theft became public. Alongside the apology, Amiel announced the ministry's next move: deploying AI tools to hunt for vulnerabilities across state systems, run by Mistral AI rather than OpenAI, which he named as explicitly excluded from this specific task.
The measures package attached a real budget and a real deadline to the announcement, not just a preference. Two hundred million euros comes from the France 2030 plan to fund the hardening effort. Every DGFiP agent gets dual authentication by the end of 2026. The digital directorate has been told to have sovereign AI detection tools operational by September 2026, a target set roughly three weeks after the announcement itself.
Why It Matters: The Scan Result Is the Dangerous Document, Not the Input Data
Most sovereign-AI stories are industrial policy dressed as security policy: a government prefers the domestic vendor because it wants to build a domestic AI industry, and frames that preference as protecting sensitive data. Amiel's stated reason is narrower and more specific than that, and it is the part worth reading past the headline for. The exclusion applies to a vulnerability-hunting AI specifically because, in his own framing, doing that job well produces a map of exactly where the state's systems are weak, and that map cannot be allowed onto infrastructure reachable by a foreign legal process.
That argument does not generalize to every AI use case the same way. A chatbot answering citizen questions leaks little if a foreign court can compel disclosure of its logs. A vulnerability scanner's output is different in kind: it is a prioritized list of every place an attacker should look next, generated by the very tool meant to close those gaps first. Putting that specific document within reach of a subpoena, a national-security letter, or any extraterritorial legal mechanism turns a defensive tool into a potential attack roadmap the moment its output leaves the country's own control.
What This Means for a Business Choosing a Pentesting or Scanning Vendor
| Measure announced August 18, 2026 | Deadline or scale |
|---|---|
| Dual authentication for all DGFiP agents | By end of 2026 |
| France 2030 hardening budget | 200 million euros |
| Sovereign AI vulnerability-detection tools operational | By September 2026 |
Any EU or UK business running an AI-assisted vulnerability scanner, attack-surface mapper, or automated pentesting copilot faces a version of the same question France just answered for itself, whether or not the business has thought to ask it. The relevant fact is not simply where the vendor is headquartered. It is where the scan results, the actual output describing what is broken and where, get stored and processed, and whether that location sits inside a legal jurisdiction that can compel disclosure without the business's own knowledge or consent.
That question does not apply with the same force to an AI writing marketing copy or summarizing meeting notes, because the output of those tools rarely doubles as a target list. It applies specifically to any AI whose job is to find weaknesses, because the one document worth protecting more than the underlying system itself is the accurate, prioritized record of exactly how to break in.
Read next: A Fake Think Tank Targeted France And Germany With AI | France Bars OpenAI From Its Own Cyber Defenses



