For years, cybersecurity has focused on a relatively simple question: how to protect systems. At VivaTech, the discussion between Damien Lucas and Marius Briedis showed that the real challenge of the decade will likely lie elsewhere: how to maintain trust.
Because artificial intelligence does more than just change security tools. It challenges the very foundations on which the Internet was built: identity, authenticity, and sovereignty.
The Age of Digital Distrust
One of the most interesting observations to emerge from the debate is that AI did not actually create the current crisis of trust.
Rather, it has revealed just how fragile that trust is.
For a long time, users assumed that the people they interacted with were real, that the information they accessed was authentic, and that digital infrastructures operated within a relatively stable framework.
Generative AI is shattering these certainties.
Automated creation of phishing sites, video deepfakes capable of imitating a leader, large-scale identity theft, and the generation of malicious code: operations once reserved for experienced cybercriminals are now accessible to much less skilled actors.
As Damien Lucas summarized:
AI doesn’t just reveal vulnerabilities; it makes them exploitable on a massive scale.
This democratization of offensive capabilities is undoubtedly one of the most significant changes observed since the advent of the cloud.
Why Attackers Stay One Step Ahead
The paradox is striking.
AI helps defenders detect vulnerabilities more quickly, analyze suspicious behavior, and automate certain monitoring tasks.
But it also helps attackers.
And for now, attackers seem to have a structural advantage.
The reason is simple: the attacker doesn’t need to be perfect.
The defender, on the other hand, must be.
A malicious actor can generate thousands of phishing attempts, create hundreds of malware variants, or automatically scan millions of lines of code in search of a flaw.
The marginal cost is virtually zero.
Conversely, every vulnerability detected must be verified, patched, tested, and then deployed without breaking existing systems.
AI reduces costs for both sides, but it reduces them even more for attackers.
This asymmetry is likely one of the main reasons for the continued increase in cybersecurity investments despite technological advances.
The New Risk: Speed
Another key takeaway from the panel discussion concerns the widespread acceleration of software development.
Code assistants and AI agents now make it possible to produce applications in a matter of hours rather than several days.
But the speed of creation does not eliminate the need for oversight.
On the contrary.
The panelists highlighted a phenomenon already observed in many companies: developers are producing more code, but security teams must absorb an increasing verification workload.
In other words, AI shifts the bottleneck.
Code generation is now instantaneous.
Validation remains a human task.
This reality explains why the return on investment for AI is sometimes difficult to measure in organizations: productivity gains upstream do not automatically translate into an equivalent increase in production.
Security and Trust: Two Different Concepts
One of the most pertinent points in the debate concerns the distinction between security and trust.
Security is a matter of technology.
Encryption, authentication, data protection, and infrastructure resilience.
Trust is more a matter of governance.
Who owns the data?
Who can access it?
In which jurisdiction is it stored?
Who actually controls the infrastructure?
This distinction becomes particularly important with the rise of large language models.
Millions of users now share personal, medical, or professional information with AI systems without always knowing where that data is stored or how it is used.
The issue is no longer just about protecting information.
The issue is knowing whom we choose to entrust it to.
Digital sovereignty is becoming a strategic issue
It is probably on this point that the debate has taken on its most political dimension.
For years, the multi-cloud strategy was viewed as a resilience solution.
Companies used to spread their infrastructure across multiple providers to avoid excessive dependence.
But according to Damien Lucas, this approach no longer addresses the main emerging risk: geopolitics.
Choosing two U.S. providers is no longer necessarily sufficient diversification.
The risk is no longer merely technical.
It has become regulatory, diplomatic, and strategic.
The central question is no longer:
“How many clouds do we use?”
But rather:
“On which countries do our critical infrastructures depend?”
This development marks a major shift in how the cloud is perceived.
Digital sovereignty is gradually moving beyond the realm of specialists to become a corporate governance issue.
People Remain the Decisive Factor
Despite all the technological sophistication discussed during the session, the two speakers returned to an almost classic conclusion.
The main risk factor remains human.
Security technologies are advancing.
Infrastructures are becoming more robust.
Detection systems are improving.
But users continue to click on fraudulent links, share sensitive information, or trust synthetic content.
The example of deepfakes used to impersonate executives in fraudulent wire transfer requests perfectly illustrates this phenomenon.
As generated content becomes indistinguishable from reality, verification is becoming a fundamental skill.
In the future, the ability to be skeptical could become just as important as the ability to use AI.
The Next Disruption Is Called Quantum
While most current discussions focus on artificial intelligence, Damien Lucas has identified another technological disruption likely to upend the cybersecurity ecosystem: quantum computing.
While AI challenges digital trust, quantum computing could call into question some of the foundations of modern encryption.
Organizations that are preparing today for their transition to post-quantum architectures could reap the same benefits as those that anticipated the adoption of the cloud fifteen years ago.
The Real Issue
The debate ultimately highlighted a simple but essential idea.
AI does not reduce the complexity of the digital world.
It increases it.
It accelerates innovation, but also vulnerabilities.
It strengthens defensive capabilities while simultaneously amplifying those of attackers.
Above all, it transforms trust—long considered a natural consequence of technology—into a strategic asset that must now be continuously built, verified, and protected.
In the coming decade, the question will likely no longer be who has the best artificial intelligence.
But rather, who still deserves our trust when it acts on our behalf.

Cette publication est également disponible en :
