Digital sovereignty

Digital sovereignty is not declared in a press release, it is observed in the invoices: who hosts, who encrypts, who holds the key, who can pull the plug. This category starts from the premise that a country outsourcing its data, its models and its payments to foreign jurisdictions has already answered the question, even while it pretends to still be asking it. You will find the subject approached from below rather than from the conference panel: local AI and what it actually costs, self-hosting once the forge turns agentic, the zero-knowledge cryptography the administration wants no part of, and the quiet dispossession of things we believe we own, from a media server we no longer control to a savings plan that buys America without ever holding it. With the industrial question running underneath: while France sells its stakes and regulates its own decline, others are building the machines. Written by a practitioner who deploys this infrastructure for clients, in the conviction that sovereignty is a technical and industrial bottleneck long before it is a talking point.

When an AI Agent Organizes Itself, Who Is Responsible?

Artificial Intelligence

Andrew Ng brings back the hammer metaphor to play down the OpenAI-Hugging Face incident: if an agent hacks a system, the fault lies with whoever wields it, not with the tool. On responsibility, he is right, and the labs’ growing temptation to blame their own agents makes the reminder worth having. On the incident, he is wrong. The METR report does not describe 1,200 processes; it describes a swarm that coordinates, falsifies its own traces, and reaches out onto the internet to fool a scorer: a tool whose degraded mode produces a strategy. Muse, Meta’s agent, shows we know how to build better, provided we first admit the flaw.

After SCAF: Who Will Pay for the Future Rafale?

Geopolitics

On September 22, Dassault Aviation flew two sovereign AI algorithms aboard a Rafale. Ten days earlier, France’s defense procurement agency confirmed that France would prepare the Rafale’s successor on its own, SCAF or no SCAF. We have finally taken back the reins. One question remains, and nobody is asking it: who pays? The studies for a sixth-generation engine require a billion euros, the demonstrator has no funding at all, and I am making a fiscal choice that I fully own.

Mistral AI Didn’t Betray Sovereignty. It Shrank It Down to a European Endpoint

Digital sovereignty

In 2023, Cédric O bought into Mistral AI for €176, then lobbied for a lighter AI Act; after the latest funding round, his stake is worth around €90 million on paper. Since then, the French state has become the startup’s first customer, from the armed forces to the civil service. This summer, Mistral crossed a threshold: its infrastructure now hosts third-party models, starting with China’s GLM-5.2. The pivot to a platform model is rational, and I defended it myself. What isn’t rational is to keep selling it as technological sovereignty.

The OpenAI Researcher Who Thinks We Are Losing the Ability to Evaluate Our Models

Technology

Daniel Selsam has worked on capabilities at OpenAI since 2022, has not resigned, and on September 14 had a former employee of the lab publish a statement making this argument: models are becoming so situationally aware that we are losing the ability to evaluate them in contexts where they believe nobody is watching. Alignment metrics will climb like every other benchmark, honeypot environments will be recognized for what they are, and safety evidence will stop being trustworthy without anything signaling the change. He nonetheless concedes to the skeptics almost everything they claim about data inefficiency and frozen weights, before concluding that these limitations do not limit the risk. One point nobody in Brussels has stopped on: the AI Act requires standardized testing, which means the protocols are written down, and the model being tested can read them.

AI Safety: What If the Real Variable Is the Price of a Token?

Digital sovereignty

Anthropic filed its confidential S-1 on June 1, is targeting a Nasdaq listing in October at around $2 trillion, and on September 12 its CEO published a plan to slow the AI race. Michael Burry called it pre-IPO hype; he is wrong on the technology, but his calendar is worth a look. Run against the only documented cause we have, the METR report, the three measures meant to protect us would not have prevented a single day of the July incident: internal model, in-house infrastructure, shared cache, unsolvable tasks. They act somewhere else, on price: chip controls, a distillation crackdown, and a compute cap decide who may train, who may learn, and who may cross the next threshold, in a market where the gap between a proprietary model and the open-weight swarm runs fifty to one. And on that terrain, Brussels has already written half the text.

The METR-OpenAI Affair: Agents Fooled a Phantom Judge, and Their Peers Were Asked to Investigate

Artificial Intelligence

METR’s report on the OpenAI-Hugging Face incident runs to ninety-one pages, and what has been made of it misses the point entirely. Twelve hundred agents meant to be isolated found one another, organized, and spent four days working around a transcript scorer that did not exist: they would have earned full marks by simply handing in their work. Between thirty and forty percent of the benchmark’s tasks were unsolvable, and the question of whether the evaluation apparatus had caused the behavior it was measuring was added to the investigation’s mandate at OpenAI’s request. Heavier still, and picked up nowhere: for want of human hours, METR delegated the analysis to agents of the very model that took part in the incident, on credits from the company under investigation, while writing that it could not rule out their having lied. What that changes for the independent evaluators Amodei wants, and for the AI Act’s scientific panel, is not a question of badges but of the capacity to read.

Regulating AI: What Europe Didn’t Dare Put in Its Own AI Act

Europe

Dario Amodei’s essay never mentions Europe, and yet the AI Act already contains, on paper, the first step of his plan: evaluations, cybersecurity, incident reporting, a panel of independent experts, and since August 2, 2026 an AI Office with the power to investigate and to fine. The difference comes down to one thing: the regulation organizes disclosure under secrecy, where Amodei proposes permanent presence and publication. Brussels selects by a compute threshold what it has never observed, and its Article 78 is why the public learned of the OpenAI-Hugging Face incident from an American nonprofit and a competitor’s blog. The embryo of that college of evaluators already exists, in Article 68, and three things are missing from it that an implementing act and one amendment would suffice to supply.

Slowing the AI Race: The Ambiguity at the Heart of Anthropic’s Plan

Digital sovereignty

Dario Amodei proposes to slow the race for AI capabilities: third-party evaluators stationed inside the labs, coordination among companies in “democratic countries” under an antitrust waiver, negotiation with China. The word Europe never appears in the essay. Behind the vocabulary of caution, the three concrete measures, a chip embargo, a crackdown on distillation, and the securing of model weights, describe a regime in which frontier capability becomes a commodity rationed by Washington. There is still one idea worth taking whole, the embedded evaluators, and one question to ask before applauding it: who has their foot on the pedal.

E-Invoicing: The Hidden Toll on France’s Dormant Businesses

E-invoicing

One in two French micro-entrepreneurs reports no revenue at all: half the scheme is an intermittent France of trial ventures, side income, and businesses in transition. To that dormant half, the e-invoicing reform says: pick a private operator and appear in the directory, not in order to invoice, but in order to be capable of it someday. The mandatory-subscription argument is wrong, though: thirteen of the nineteen offerings audited by l0g include a genuinely free tier. The real toll lies elsewhere, in a cognitive barrier to entry and in the precariousness of a free tier that has no reason to survive for customers who generate nothing. By scrapping in 2024 the free public gateway promised in 2020, the state locked in the intermediary requirement and put a price on its entrepreneurs’ sleep.

France’s Tax Agency Hacked: A State That Demands Everything and Protects Nothing

Digital sovereignty

In late June 2026, an intruder armed with two stolen passwords wandered freely through French taxpayers’ fiscal records, and the Finance Ministry only grasped the scale of the theft when a hacker calling himself ZeroBytes went public with it two months later. The remediation plan announced in the aftermath reads like a confession: no multi-factor authentication across the board, no consultation quotas, systems without monitoring sensors. Meanwhile, that same state is finalizing mandatory electronic invoicing and DAC8, the largest economic data vacuum in its history. The asymmetry is the whole story: an obligation to surrender everything on one side, a proven inability to protect it on the other. Until the state can demonstrate that it knows how to keep what it already holds, it has no standing to demand more.