Digital Security and Artificial Intelligence: Evolving Threats and Perspectives - Cigref

Compatibilidad
Ahorrar(0)
Compartir

To mark the publication of its new memo entitled “Digital Security and Artificial Intelligence: Evolving Threats and Perspectives”, Cigref provides an analysis of the changing cyber threat landscape. The industrialisation of attacks at ‘machine speed’ and the geopolitical tensions surrounding cutting-edge artificial intelligence models necessitate a review of the digital security doctrines of major organisations and the rapid establishment of an autonomous European AI capability for cyber defence.

“Cybersecurity has evolved from an augmented human activity to a human-supervised algorithmic process. Without guaranteed and autonomous access to cutting-edge AI models, our entire economy and critical infrastructure are at risk of strategic paralysis.”Henri d’Agrain, General Delegate of Cigref

Cette publication est disponible en français (French version)

A shift towards ‘machine speed’

Based on feedback from its 155 public and private sector members, Cigref’s assessment highlights a major shift. IT security has now moved beyond the purely technical sphere to take centre stage in geopolitical and economic competition.

Recent events confirm that traditional reactive defensive approaches are now obsolete. In this report, Cigref identifies and analyses eight systemic shifts in the cyber threat landscape, notably:

  • The collapse of Time to Exploit (TTE): the time between the discovery of a vulnerability and its exploitation is now negative. Attackers strike before patches are released, rendering reactive responses ineffective in the face of corporate deployment cycles that take 60 to 150 days.
  • Saturation through hyper-volumetry: the automation of attacks and the hijacking of authenticated sessions are overwhelming the human analysis capabilities of security operations centres (SOCs).
  • The weaponisation of AI: the use of algorithmic agents accelerates target identification, the dynamic development of malware and the mass exploitation of previously tolerated vulnerabilities.

Artificial intelligence: critical infrastructure for cybersecurity

Events in the summer of 2026 mark a strategic turning point. The temporary suspension of access to Anthropic’s models, decided by the US authorities in June, demonstrated that an algorithmic shield can be subject to unilateral control measures in the name of national security.

At the same time, the proliferation of high-performance Chinese open-weight models (such as Moonshot AI’s Kimi K3) creates an illusion of autonomy for European organisations. Basing Europe’s resilience on these technologies would expose companies to the risk of subjugation, leaving them defenceless should Beijing decide to block the release of future versions.

Cutting-edge artificial intelligence now constitutes critical cybersecurity infrastructure. Organisations that do not have guaranteed, long-term access to a state-of-the-art model specialising in cybersecurity in the short term will be unable to keep pace with the speed of attacks.

The conditions for a collective European response

Given the scale of investment required to develop state-of-the-art models, no single European state can shoulder this effort alone.

Cigref recommends:

  • The emergence of an industrial coalition: bringing together major economic users and technology players to pool resources, create the essential critical mass and engage in cross-border cooperation, particularly at the Franco-German level.
  • Government support: to support this private-sector initiative through the European Commission’s Action Plan on Cybersecurity and AI, by facilitating access to computing capacity.
  • The requirement for Security by Design: to subject the digital industry to strict standards requiring vulnerabilities to be corrected at source and to put an end to the outsourcing of technical risk to customers.
Detalles de contacto
Cigref