France Taps Mistral, Not OpenAI, to Test Government Systems for Cyber Vulnerabilities
Key Takeaways
- •Budget Minister David Amiel said France will rely on sovereign AI companies such as Mistral to detect vulnerabilities in government systems, explicitly excluding OpenAI from the effort.
- •A breach at France's Directorate General of Public Finances exposed the data of approximately 700,000 taxpayers after an attacker used a compromised internal VPN and a stolen identity to reach a taxpayer search tool.
- •The compromised records included names, birth details, postal and email addresses, telephone numbers, tax identification numbers, withholding rates, and correspondence with officials, but not usernames or passwords.
- •Tax administration head Amelie Verdier disclosed that a second data breach has been discovered and is still being assessed, while privacy watchdog CNIL was notified and the DGFiP said it would file a criminal complaint.
- •The plan builds on France's 'Notre IA' initiative, whose Mistral-based assistant 'L'Assistant,' developed by DINUM and hosted in SecNumCloud-certified datacenters, is being rolled out to nearly one million state employees.

France will turn to “sovereign” AI providers such as Mistral — and not OpenAI — to test government systems for security vulnerabilities, Budget Minister David Amiel said Tuesday.
The announcement came days after a breach at the national tax agency exposed the data of about 700,000 taxpayers, underscoring why French officials are pairing cybersecurity work with tools they say can be hosted and controlled under domestic rules.
“This excludes OpenAI”
Answering reporters after a cabinet meeting in Paris, Amiel said the state would entrust the work to what he called sovereign AI companies, “such as Mistral.” “This excludes OpenAI,” he said.
Amiel had confirmed the plan earlier the same day: the government will deploy AI tools to identify its own services’ vulnerabilities to cyber attacks. The trigger was the tax agency breach disclosed the previous Thursday, when the French Finance Ministry said the data of some 700,000 taxpayers had been taken.
Mistral, the Paris startup backed by chipmaking-equipment supplier ASML, has become France’s company of choice when the government wants to demonstrate it can operate critical systems without relying on American technology. That positioning also fits a broader push in Paris for public-sector AI that can be used inside trusted infrastructure rather than routed through foreign cloud and model providers.
In June, Amiel unveiled a government plan called “Notre IA,” or “Our AI,” to distribute sovereign tools across public services. Its centerpiece, an assistant called “L’Assistant,” was developed by the state digital agency DINUM, based on Mistral’s model, and hosted in SecNumCloud-certified datacenters. The tool was being rolled out to close to a million state employees.
A breach that keeps growing
Amelie Verdier, who heads France’s tax administration, said Monday that her teams had uncovered a second data breach. The intrusion is still being assessed, she said.
The first breach, at the Directorate General of Public Finances, was reported earlier this month by Cryptopolitan. According to the DGFiP, an attacker used a compromised internal VPN and a stolen identity to reach a taxpayer search tool.
The access was traced back to late June 2026 and closed by the end of the month — by which time the attacker had already seen and pulled records.
The exposed data include names, birth details, postal and email addresses, telephone numbers, tax identification numbers, withholding rates, and correspondence with officials, the DGFiP said. The agency stressed that usernames and passwords were not among the exposed data.
France’s privacy watchdog CNIL was notified, and the DGFiP said it would file a criminal complaint. With tax records among the most sensitive government datasets, the case is likely to keep drawing attention not only to the breach itself but also to how French agencies test, secure, and isolate the systems they run.
The breaches come as France has been hit by a wave of violent attacks on crypto owners in 2026, Cryptopolitan has reported. In April, Telegram founder Pavel Durov said on X that the country had seen 41 kidnappings of crypto holders in the first three and a half months of the year. He blamed leaked personal data, including records held by tax authorities.