Artificial intelligence is reshaping almost everything it touches. Yet behind the consumer-facing breakthroughs, a far quieter conflict is unfolding: a covert cyber arms race pitting banks and governments against increasingly capable attackers, with quantum risks looming in the background.
Between lofty talk of digital sovereignty and the operational reality on the ground, the question is stark: how are Europe and its companies adapting to these new cyber threats?
To explore this, we spoke with two specialists from Square Management, a strategy and management consultancy deeply involved with major banking and insurance players: Jules Brochard, researcher and technical co-lead for AI R&D, and Axel Barrault, senior researcher-consultant at the Square Research Center. Here are the 7 key takeaways from our conversation.
European sovereignty is an “TV studio utopia”
In France, the generative AI scene is lively, helped by standout firms such as Mistral AI. But economic constraints and technical dependencies quickly puncture the grand claims of full independence. Jules Brochard argues that insisting on total autonomy is wishful thinking: “Assuming we’ll be able to have a sovereign ecosystem makes for good TV, but it doesn’t stand up to two seconds of real life. It’s a utopia,” he says.
Behind the scenes-whether you look at where Mistral’s funding comes from or its strategic links with the Dutch giant ASML-European AI is tightly interwoven with the rest of the world. With critical reliance on US infrastructure, local champions can sometimes look like a “a kind of genius that’s been stripped of its means”, unable to operate entirely on their own.
The importance of economic interdependence
Europe may be heavily reliant on US tech leaders for cloud services and NVIDIA chips, but that dependency masks a more balanced power dynamic than it first appears. The European Union (EU) remains the world’s second-largest economy, and a market so important that Big Tech cannot realistically walk away from it, even if these firms attempt to apply pressure by aligning themselves with Donald Trump’s political stance.
“Everyone has a hand on everyone else’s chin. The United States doesn’t fully want us to become completely independent, but the big digital powers can’t ignore Europe either,” Axel Barrault explains. Even though some of these companies generate revenues comparable to the GDP of certain countries, they still end up having to comply with European rules.
Claude Mythos: “a movie-style hacker in anyone’s hand”
The public release of Mythos-Anthropic’s highly capable new model designed to detect software vulnerabilities-immediately put security leadership at major banks on high alert.
The reason is straightforward: broad access to tools like this fundamentally changes the threat landscape. As Jules Brochard puts it, “The risk is putting a hacker into the hands of the first person with the right subscription.” Its effectiveness was illustrated rapidly: in under 24 hours after launch, three critical Firefox vulnerabilities were identified, alongside hundreds of other worrying anomalies. That rapid impact also helps explain why the US government chose to slow its rollout.
With such a double-edged tool, defenders are forced to react without much visibility. Lacking sufficient real-world feedback to predict AI-driven automated attacks, organisations are rushing to fortify their environments. According to the expert, the only immediate approach is to “close every door and every window” and hope the reinforcement holds.
The reality of cyberattacks
Popular culture often paints cyberattacks as dramatic and instantly visible. “We all have that movie image where the attack hits, a skull appears on the screen and the accounts are emptied,” Axel Barrault jokes. In practice, incidents are usually far more discreet. The central issue is “dwell time”-the period during which an intruder stays hidden inside a network before taking action.
Attackers frequently break in via a small subcontractor SME with weaker security, then move gradually towards the larger partner bank’s systems. Jules Brochard notes that, on average, it still takes “6 months to detect an intrusion and 2 months to segment the vulnerability.” The defensive priority is to use AI to spot faint signals earlier and cut that delay by a factor of 10, because zero risk is no longer a realistic assumption: once the wolf is in the fold, the affected room must be isolated immediately.
How AI is transforming the cyber threat for individuals
Until now, cybercriminals generally had to choose between scale-sending millions of crude phishing emails-or precision-targeting one person after extensive research. AI has removed that trade-off.
Using tools such as Gemini or Perplexity, an attacker can produce thousands of highly personalised messages in a couple of clicks, with flawless language, referencing your colleagues’ names or your most recent work trips to lower your defences. This mass social engineering is also being reinforced by audio and video deepfakes, enabling criminals to impersonate executives during fake emergency calls.
The quantum “ghost” threat
The combination of artificial intelligence (AI) and quantum computing is expected to blow open traditional security locks-particularly RSA mathematical encryption keys that protect passwords and bank transactions. Even if this ultimate computing power is not yet fully operational, the threat is already tangible. As a result, tomorrow’s cyberwar is being actively prepared today through a formidable strategy pursued by certain foreign powers.
“States like China or Russia are stealing and intercepting our highly confidential but encrypted data right now. They store it on servers while waiting for the 2028–2030 horizon, when quantum computers will be powerful enough to break encryption keys in two seconds and read all our secrets,” warns the cybersecurity expert. The post-quantum cryptography race is therefore already under way in financial circles.
The strength of Europe’s regulatory framework
To round out this overview, there is at least one reason for measured confidence: regulation. While AI is advancing at a pace that can outstrip even the engineers building it, Europe is not simply standing by. “We have an extremely strong regulatory framework. To use a metaphor, the car is completely wild and going at full speed, but the road is very reliable,” Jules Brochard says.
With major legislative instruments such as the AI Act, the NIS 2 Directive, and the DORA regulation for the banking sector, the European Union is compelling tech giants to put safeguards in place. Europe’s legal shield is not flimsy; it ranks among the most robust in the world for constraining algorithmic misuse.
Comments
No comments yet. Be the first to comment!
Leave a Comment