- French Budget Minister David Amiel said the government will hire sovereign AI providers, naming Mistral, to probe public systems for security flaws, and stated plainly that the work excludes OpenAI.
- The decision follows a confirmed breach at the DGFiP tax authority that exposed personal and business data on 678,000 taxpayers, disclosed on August 14.
- It is the clearest case yet of a European government treating an AI supplier's nationality as a security requirement rather than a preference.
France names Mistral for government security testing and shuts out OpenAI
Speaking to reporters after a Paris cabinet meeting on August 18, Budget Minister David Amiel said the French state will deploy artificial intelligence to hunt for vulnerabilities across its public services, and that it will buy that capability from sovereign suppliers, according to Reuters. He named Mistral, the Paris-based frontier lab, as the kind of provider the government will turn to. He then drew a line most procurement statements leave unspoken.
This excludes OpenAI.David Amiel, French Budget Minister, on the providers eligible to test government systems
The announcement did not arrive in a vacuum. Days earlier, the DGFiP, France's tax administration, confirmed that attackers had accessed personal and business records for 678,000 taxpayers, a figure the ministry settled on after its own forensic review even as the intruder advertised far more. Investigators noted that secure taxpayer accounts and passwords were not breached. French prosecutors opened a formal investigation on August 15.
| Date | Development |
|---|---|
| August 14, 2026 | DGFiP confirms a breach exposing 678,000 taxpayer records |
| August 15, 2026 | French prosecutors open a formal investigation |
| August 18, 2026 | Budget Minister Amiel names Mistral, excludes OpenAI, for state security testing |
Why a tax-agency breach became a sovereignty decision
The technical work France is describing, using AI to find flaws in code and systems, is exactly what OpenAI, Anthropic, and Google do well. The point of the announcement is that capability is no longer the deciding factor. When the system being tested holds tax records for most of a country, the question shifts from which model performs best to whose jurisdiction governs the data and the model that touches it. On that question, a French provider answers differently from an American one.
That reasoning turns Mistral from a national champion into a security asset, and it extends a sovereignty push France has been building for months. Its "Notre IA" program, launched in June, pushed Mistral-based tools across the public sector to roughly one million state employees. Security testing of critical infrastructure is the higher-stakes next step.
| Taxpayers with data exposed | 678,000 |
| Named eligible supplier | Mistral (sovereign providers) |
| US-based AI vendors eligible | 0, OpenAI excluded by name |
| State employees already on sovereign AI | roughly 1 million, via Notre IA |
France did not just pick a French vendor. It set a precedent that the safest AI supplier for a government may be defined by where it is incorporated, not by where it ranks on a benchmark, and every European capital weighing the same sovereignty question now has a template for saying it out loud.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.