Artificial intelligence is disrupting every sector it touches. Yet beyond consumer-facing innovation, an unseen conflict is under way. Between fantasies of sovereignty and conditions on the ground, how are Europe and its businesses responding to emerging cyber threats?
We spoke with two specialists from Square Management, a strategy and management consultancy with a strong presence among major banking and insurance players: Jules Brochard, researcher and joint technical R&D lead for AI, and Axel Barrault, senior researcher-consultant at the Square Research Center. Here are the seven main takeaways from our discussion.
European sovereignty is a “TV studio utopia”
In France, the generative AI ecosystem is thriving, driven by standout companies such as Mistral AI. However, economic and technical realities quickly undermine sweeping claims of independence. For Jules Brochard, the pursuit of complete autonomy at any cost is unrealistic: “Assuming that we will be able to build a sovereign ecosystem may work well in TV studios, but it does not survive two seconds of real life. It is a utopia,” he states bluntly.
Behind the scenes, whether through the origins of Mistral’s funding or its strategic ties with Dutch giant ASML, European AI is deeply interconnected with the rest of the world. Given the essential nature of US infrastructure, local European champions can sometimes resemble “a genius somewhat stripped of the means to act” and unable to go it alone.
Why economic interdependence matters
Although Europe is heavily reliant on US giants for cloud services and NVIDIA chips, this dependence masks a more balanced relationship of power than it might first appear. The European Union (EU) remains the world’s second-largest economy and a vital market that the GAFAM cannot afford to boycott, even where they seek to exert pressure by aligning themselves with Donald Trump’s policies.
“Everyone has a hold over everyone else. The United States does not entirely want us to become fully independent, but major digital powers cannot ignore Europe either,” says Axel Barrault. While these companies have economies larger than those of some countries, they are nevertheless compelled to comply with European rules.
Claude Mythos: “a movie hacker in anyone’s hands”
The public release of Mythos, Anthropic’s new high-performance model for identifying IT vulnerabilities, immediately put the security teams of major banks on alert.
For Jules Brochard, widespread access to tools of this kind fundamentally changes the situation: “The risk is that you put a hacker in the hands of the first person with the right subscription.” Its capabilities were such that, within 24 hours of launch, three critical Firefox vulnerabilities were found, alongside hundreds of other concerning flaws. This also explains the US government’s decision to slow its rollout.
Faced with this double-edged weapon, defenders are operating without clear visibility. Since there is not yet sufficient empirical evidence to predict AI-automated attacks, businesses are urgently locking themselves down. According to the expert, the only immediate approach is to “close every door and every window” and hope the protection holds.
The reality of cyberattacks
In the public imagination, a cyberattack is a dramatic event. “We all picture the film scene where an attack happens, a skull appears on the computer screen and the accounts are emptied,” Axel Barrault jokes. In reality, attacks are far more subtle, and the key issue is the “dwell time”: the period for which an intruder remains concealed within a computer network before taking action.
Attackers often gain entry by targeting a smaller, less protected subcontracting SME, then gradually work their way towards the systems of its major banking partner. Jules Brochard notes that, on average, it still takes “6 months to detect an intrusion and 2 months to contain the breach”. The entire purpose of defence is to use AI to identify weak signals and cut this delay by a factor of 10, because zero risk no longer exists: once the wolf is in the sheepfold, the affected area must be isolated at once.
How AI is transforming the cyber threat for individuals
Until now, cybercriminals had to choose between scale-sending millions of clumsy phishing emails-and precision, which meant spending considerable time researching a single target. AI has removed that trade-off.
Using tools such as Gemini or Perplexity, an attacker can create thousands of highly tailored messages in just a few clicks, without a single French-language mistake, referring to colleagues by name or to recent work travel in order to lower a target’s guard. This mass social engineering is also being equipped with audio and video deepfakes to impersonate executives during fake emergency calls.
The looming quantum threat
The combination of artificial intelligence (AI) and quantum computing is set to break through conventional security safeguards, especially the mathematical RSA encryption keys that protect passwords and banking transactions. While this ultimate computing power is not yet fully operational, the threat is already very real. Tomorrow’s cyberwar is therefore being actively prepared today through a formidable strategy used by certain foreign powers.
“Countries such as China and Russia are already stealing and intercepting our highly confidential but encrypted data. They are storing it on servers while waiting for the 2028–2030 timeframe, when quantum computers will be powerful enough to break encryption keys in two seconds and read all our secrets,” warns the cybersecurity expert. The race towards post-quantum cryptography is already under way in financial circles.
The strength of the European regulatory framework
To end this overview, there is reason for a degree of confidence in the regulatory framework. Although AI is advancing at a pace that can sometimes outstrip even engineers, Europe is not simply standing by. “We have an extremely strong regulatory framework. To use a metaphor, the car is completely out of control and travelling at high speed, but the road is very reliable,” Jules Brochard explains.
Through major legislation including the AI Act, the NIS 2 Directive and the DORA Regulation for the banking sector, the European Union requires technology giants to introduce safeguards. Europe’s legal shield is far from porous; it stands as one of the world’s strongest frameworks for governing algorithmic excesses.
Comments
No comments yet. Be the first to comment!
Leave a Comment