The State is investing massively in artificial intelligence, and that is excellent news. It remains to transform this investment into lasting success.
The additional 655 million euros recently announced mark a key step in the French digital sovereignty strategy. The ambitions are great: research, computing capabilities, public services, health, internal security. France wants to be one of the leaders in this area.
But to succeed, technical performance alone will not be enough. L’artificial intelligence is a systemic project: if technology is the basis, governance is the condition for success.
The central question: how to manage AI over time?
Artificial intelligence has the potential to simplify administrative procedures, improve relationships with users, automate repetitive tasks and accelerate the processing of files. But for this to work, a clear framework is essential.
Who is responsible for decisions made with the help of AI? How to monitor the results? What audit mechanisms make it possible to identify biases, errors or deviations? How to balance performance, transparency and data protection? These questions directly concern business management, compliance managers, lawyers and public decision-makers.
Without structured governance, AI risks creating new problems in administrations. The challenge is to find the right balance between performance and security.
The challenge of budgetary control and operational efficiency
The government announcement emphasizes the search for efficiency and the reduction of tasks with low added value, a perfectly legitimate objective in a context of budgetary constraints. But experience shows that poorly managed digital transformation often produces the opposite effect.
Acquiring solutions, integrating them into existing systems, monitoring models, security audits and training represent significant and often underestimated costs. Added to this is a new issue: the governance of consumption, measured in tokens, the calculation unit for generative models. Without strict supervision of this consumption, the bill quickly spirals out of control. Several large groups have thus exhausted their entire annual AI budget in three to four months, under the effect of autonomous agents, which are much more demanding than simple conversational assistants. The risk is just as valid for an administration as for a company.
The danger is also operational. Poorly configured or insufficiently controlled AI can generate large-scale errors, slow down processes or require human corrections that negate the desired productivity gains.
The challenge is therefore not simply to invest in AI, but to continuously measure its real value, its return on investment and its concrete impact on the quality of the service provided to citizens.
Sensitive data at the heart of concerns
The stated desire to develop sovereign solutions responds to a major strategic concern: data control.
Administrations handle very sensitive information: health data, tax information, judicial files, internal security data or information relating to critical infrastructure. The growing use of artificial intelligence tools increases the risks of leakage or unintentional exposure of this data.
This is where the major problem with Shadow AI comes into play. A risk which can wreak havoc not only at the top of the State, but especially within local authorities, traditionally less equipped to regulate these new uses. To put it simply: let’s imagine a public agent who, in order to do the right thing and save time, connects an unapproved tool or a general public AI assistant to synthesize thousands of social assistance application files. Without realizing it, he has just exposed personal and confidential data on third-party platforms beyond any control, and created an unprecedented legal, regulatory and sovereign risk.
The question is therefore no longer just to know which artificial intelligences to use, but under what conditions, with what guarantees and under what control.
Humans remain the primary risk factor
The recent history of cybersecurity teaches us a constant lesson: technology alone never fully protects. Cybercriminals exploit human behavior, manipulation errors and social engineering to bypass the most sophisticated devices. Artificial intelligence amplifies this phenomenon. Deepfakes, identity theft, false administrative content, automation of phishing campaigns: generative tools make attacks more credible, faster and more difficult to detect.
The training of public officials is becoming a strategic issue. Each user must understand the risks associated with data sharing, unauthorized tools, information manipulation and new forms of fraud made possible by generative AI. Training agents should no longer be considered as a support measure, but as a fundamental component of security.
Making cyber resilience a pillar of AI strategy
The debate on artificial intelligence cannot be separated from that of cyber resilience. Cyberattacks are no longer simple technical incidents: they can interrupt essential services for several days or weeks. In a context where AI will be gradually integrated into critical functions of the State, the question is no longer only of preventing incidents, but of guaranteeing the continuity of public services when they occur.
Every AI project should integrate security, business continuity, disaster recovery and crisis management requirements into its design. Faced with the complexity of these systems, governance itself must go beyond standard and purely documentary frameworks: it can no longer remain on paper and will have to rely on technology, mobilizing AI itself to audit and secure AI. Digital sovereignty is not just about choosing a French or European supplier: it is also based on the ability to maintain operations, protect data and maintain control of systems in crisis situations.
A historic opportunity to secure
Investment in artificial intelligence is a historic opportunity to modernize public action and strengthen French competitiveness. But the success of this transformation will not be measured solely by the number of models deployed or the amounts invested. It will be measured by the State’s capacity to establish robust governance, protect sensitive data, train its agents, control its costs and build real cybersecurity. It is on this condition that AI will become a sustainable lever for public performance: not by treating cybersecurity as a technical constraint, but as a prerequisite for trust and digital sovereignty.