Cigref sounds the alarm in turn. In a briefing titled “Digital Security and Artificial Intelligence: Shifts in the Threat Landscape and Outlook,” the association of the major CIOs argues that the early months of the year have marked an unprecedented acceleration of transformations already observed for several years.
First, and not least, the “Time to Exploit” (TTE), the interval between the disclosure of a vulnerability and its active exploitation, has plummeted.
According to Mandiant’s M-Trends 2026 report, cited by Cigref, the gap stood at 63 days in 2018. It became negative as early as 2024, with exploitation occurring on average one day before the patch was published. It then turned negative by 7 days in 2025.
The IBM X-Force Threat Intelligence Index 2026 confirms the trend, noting a 44% rise in attacks exploiting publicly exposed applications in 2025, while 56% of disclosed vulnerabilities would require no authentication to be exploited.
Yet, as Cigref reminds us, the actual patch deployment cycle in a large enterprise typically requires 60 to 150 days, owing to mandatory regression testing.
“From an augmented human activity, cybersecurity has become an algorithmic activity overseen by humans. Without guaranteed and autonomous access to cutting-edge AI models, the entire economy and our critical infrastructures face the risk of strategic paralysis,” warns Henri d’Agrain, the association’s chief executive.
Obsolescence of Traditional Defenses
The association first highlights the broad spread of hybrid warfare. States such as Russia, Iran, or China would increasingly rely on cyber proxies to obscure the political attribution of their operations.
Added to that is the weaponization of AI by attackers themselves, which could tilt the threat to machine speed by industrializing target reconnaissance, the generation of malicious code, and campaigns of social engineering.
The Cigref also documents the mass exploitation of zero-day flaws, driven by a private cyber intrusions industry that, according to analyses by Google cited in the note, for the first time surpassed state capabilities in identifying such vulnerabilities.
This industrialization is accompanied by a saturation of security teams due to hyper-volume. 95% of attacks would now originate from sessions that appear legitimate, making their detection almost impossible without algorithmic assistance.
The Anthropic Episode, a Sign of a New Dependence
The note spends considerable time on an episode that occurred this summer. The U.S. administration subjected Anthropic’s frontier models to export restrictions on national security grounds.
Unable to immediately distinguish users who fall into the “US persons” category, Anthropic suspended access to its Fable 5 and Mythos 5 for non-U.S. users, before Washington lifted these restrictions on June 30 and Anthropic restored access on July 1.
The Cigref sees this as a precedent. Some AI capabilities can now be subject to controls comparable to those applied to other strategic technologies.
The association nonetheless calls for measured action, arguing that the decision reflects a non-proliferation logic rather than discrimination against European allies. It also notes that European industrial players were excluded from Anthropic’s “Glasswing Project,” initially limited to a circle of American actors, a signal of concern for transatlantic trust interoperability.
According to Cigref, this sequence fits into a broader structural dependence.
Citing a study carried out for Cigref in April 2025, the association recalls that roughly 83% of EU companies’ software and cloud services purchases are from the American digital industry. Furthermore, Europe would capture only 5–15% of global cybersecurity venture capital investments, far behind North American and Israeli ecosystems, which together would account for more than three-quarters.
Towards a European “Prometheus Operation”?
The note also examines China’s response to these tensions.
A few days ago, Moonshot AI released Kimi K3, a 2.8-trillion-parameter reasoning model, with the full weights set to be released on July 27. At the same time, China convened twenty-nine countries in Shanghai for the “World AI Cooperation Organization,” presented as an alternative to Western governance frameworks.
Nothing guarantees the durability of this open policy toward AI, warns Cigref, which argues that Europe replacing its dependence on American labs with dependence on Chinese labs would expose itself to the same risk of a sudden loss of access.
The Cigref calls for a renewed collective realism, stressing that Europe’s current dependency largely reflects its own industrial compromises.
The note also references an essay published in Le Grand Continent titled “Operation Prometheus: Can France win the AI race? At what price?”
The authors estimate that about $700 billion over three years would be required to equip France and its partners with a frontier AI lab capable of competing with the top American labs. According to Cigref, this would exceed the capacities of a single European state and calls for an industrial coalition approach.
While waiting for such structural action, Cigref points to a more immediate deadline. On October 31, 2026, the European Central Bank will require the 110 largest banks in the euro area to present an action plan addressing AI-powered cyberattacks.
A full-scale test, according to the association, of the sector’s ability to absorb a threat that now moves at machine speed.