Zscalerのブログ

Zscalerの最新ブログ情報を受信

News & Announcements

No Contradiction Here: Frontier AI Requires More Digital Sovereignty, Not Less

ADAM GELLER, CASPER KLYNGE
August 24, 2026 - 9 min read

The rise of frontier AI and the push for digital sovereignty are often treated as separate agendas. They are not. Let’s be crystal clear: the rapid emergence of powerful AI models makes the case for digital sovereignty more urgent, not less. In Europe and around the world, frontier AI should accelerate the operationalization of digital sovereignty.

How Frontier AI Played into the Tech-Dependency discussion

In April and May 2026, frontier AI models Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5-Cyber raised serious concerns in the cybersecurity community and among those responsible for enterprise security. While demonstrating the potential of embedding AI into defensive workflows, these models also expanded the attack surface and made clear that organizations and governments will soon face unprecedented and sophisticated attacks when these new capabilities are used by malign actors. Other frontier AI models will soon offer similar capabilities, making this a systemic challenge. For policymakers, that is not only a cybersecurity challenge, but a strategic one: it raises urgent questions about resilience, control, and digital sovereignty.

Mythos and GPT-5.5-Cyber represent something fundamentally different from previous models. They can reason across attack paths, weigh exploitability, and generate security-relevant workflows. While malign intent may not have changed, the capabilities, speed, scale, and sophistication of attacks have increased, while the expertise required to deploy them has fallen. In Europe, the arrival of these frontier AI models was felt in two ways: first, as an inflection point in ensuring access to advanced cybersecurity capabilities needed to retain resilience; and second, as yet another reminder of Europe’s dependence on non-European technology providers. Both points were underscored in the European Parliament’s letter to Executive Vice-President Henna Virkkunen [here].

Our colleague, Deepen Desai, wrote in a recent blog [here]: “The question isn't whether these models will impact your security posture; it's whether your team will harness them faster than your attackers.” In Europe, that question is not only about how quickly organizations can embed these tools into their defensive workflows, but also about how to ensure trusted access to them on terms that strengthen resilience, accountability, and strategic control.

Why AI Is Also a Sovereignty Issue

On June 12, 2026, the U.S. administration imposed export controls suspending foreign access to Anthropic’s most advanced models, Claude Mythos 5 and Claude Fable 5, citing national security concerns. The controls were lifted later that month, and access was restored on July 1, 2026. The episode itself was brief. What it revealed was not: frontier AI is now being treated as a strategic asset, subject to the same instincts that have long governed semiconductors, satellites, and encryption. Those with access will be best positioned to shape, secure, and benefit from the next generation of cyber capabilities. 

That message was reinforced by a June 22 Five Eyes intelligence partners’ cyber agencies joint statement that was unusual in its directness: frontier AI models are advancing faster than public expectations, and the resulting shift in offensive and defensive cyber capability is now measured in months, not years. Their advice was strikingly unglamorous: patch faster, reduce unnecessary internet exposure, fix identity and access weaknesses, and put AI to work on defense before adversaries put it to work on offense.

Europe’s Response Is Becoming Operational

At roughly the same moment, after years of increasingly urgent debate, Europe took a significant step toward defining what technological sovereignty means in practice. Driven by geopolitical tensions and growing concern over access to critical digital capabilities on terms Europe does not fully control, the European Commission published its Tech Sovereignty Package on June 3, 2026, with the proposed Cloud and AI Development Act (CADA) at its center.

CADA seeks to turn Europe’s ambition for digital sovereignty into a practical framework against which organizations can assess providers, make procurement decisions, and hold vendors accountable. It would expand EU data-center capacity, encourage public-sector buyers to consider “Union added value” alongside price, and introduce four EU-wide sovereignty assurance levels covering data location, cybersecurity, operational control, supply-chain transparency, ownership, and personnel. Importantly, the framework recognises that sovereignty is not determined solely by where a provider is headquartered: non-EU companies may still support sensitive workloads where they can demonstrate sufficient independence, transparency, and control. For public and private entities, this should bring greater clarity when selecting technologies and matching workloads to the appropriate level of assurance. For technology providers, it raises the bar from making broad sovereignty claims to demonstrating that their products and operations can deliver sovereignty in practice.

AI Changes the Cyber and Sovereignty Equation

As frontier AI models make attacks faster, more adaptive, and harder to catch, the conversations about sovereignty and resilience start to converge. Frontier AI is compressing the timeline across every stage of the cyber lifecycle at once: vulnerability discovery, exploit development, and defensive response are all accelerating together. This points to a structural shift that challenges assumptions security teams have relied on for two decades: that patch cycles measured in weeks are adequate, that legacy systems can be triaged rather than replaced, and that obscurity can still function as a form of defense.

This also helps explain why European policymakers are increasingly framing frontier AI as a question of resilience, competitiveness, and strategic dependency. Members of the European Parliament have openly asked whether Europe’s limited access to frontier AI capability is itself becoming a security vulnerability. The Commission’s AI Cyber Action Plan reflects that shift in emphasis, focusing on strengthening Europe’s cyber resilience, improving trusted access to advanced AI for defenders, and reducing strategic dependencies in ways consistent with European security and sovereignty objectives.

Cybersecurity is no longer just a niche policy area among many. It is becoming one of the defining enablers, or constraints, of Europe’s technological ambitions and, as the Draghi report made clear, a key condition for growth, job creation, competitiveness, and Europe’s ability to shape global developments. For organizations, that means preparing now for the cyber effects of frontier AI before these capabilities fall into adversaries’ hands. And recognizing that without cybersecurity, digital sovereignty is impossible.

The Five Cs of Digital Sovereignty

As a US headquartered technology company it's not our place to decide how Europe should handle that challenge. It's Europe's call to make, and it's a legitimate one - also in the current geopolitical environment. What we can do is build for it. At Zscaler, we think about digital sovereignty through five practical principles that define what sovereignty should mean in operational terms. For us, sovereignty is fundamentally about choice, control, continuity, collaboration, and compliance. Together, these principles provide a way to understand sovereignty as an operational capability rather than a marketing slogan or political rhetoric. As a technology provider, we are prepared to be judged by how effectively our products deliver against them:

  1. Choice: provides organizations the flexibility to select and switch providers without prohibitive cost, vendor lock-in, or interoperability barriers.
  2. Control: ensures organizations remain in charge of their data, policies, and encryption keys, including when AI systems are making decisions on their behalf.
  3. Continuity: supports resilience through disruption, whether from a cyberattack, a regulatory shift, or an export-control decision.
  4. Collaboration: enables localized offerings through partnerships with trusted local providers.
  5. Compliance: reflects the legitimate and evolving regulatory expectations of the jurisdictions in which organizations operate.

Architecture Matters

Building on this 5C approach, architecture becomes critical. Many of the technical properties CADA asks organizations to demonstrate — continuous control, strong identity, operational resilience, supply-chain transparency, and reduced structural dependency — are precisely the properties modern Zero Trust architectures were designed to deliver.

We are already seeing this shift emerge in how enterprises are architecting for the agentic AI era. AI agents challenge most of the assumptions on which legacy security models were built: known human identities, predictable access patterns, and static directories. An agent can hold valid credentials and operate entirely within its authorized scope, yet still pose serious risk if it is over-permissioned, loosely governed, or invisible to the security stack. Zscaler starts from a different premise: if you’re reachable, you’re breachable. In an AI-driven threat environment the true strategic advantage lies in reducing exposure by hiding applications from the internet, eliminating lateral movement, and replacing implicit trust with direct, policy-based connections. In our view, resilience and sovereignty depend not just on where systems are hosted, but on making them materially harder to reach and exploit.

This is the logic behind extending the Zscaler Zero Trust Exchange - a platform that already brokers more than 750 billion transactions daily - into a dedicated architecture for frontier AI models and agentic AI. Defenders now have the chance to improve speed, precision, and scalability in ways that were difficult to achieve through human effort alone, but adversaries will pursue the same advantages creating unprecedented threats. In this next phase, leadership will depend on combining frontier AI with strong architecture, trusted context, and disciplined enforcement. In our view, this is the point at which frontier cyber capabilities, Zero Trust, and digital sovereignty begin to converge.

Zscaler’s European Commitment

Europe now has a genuine opportunity to shape a model of technology sovereignty that strengthens resilience while remaining open to innovation and trusted international partnerships. The Commission has been explicit that sovereignty should not mean isolation or decoupling, and getting that balance right will matter for more than competitiveness. It may also determine how well Europe navigates the next era of AI-driven cyber risk, at a moment when European governments and the Five Eyes alliance are warning, in unusually blunt terms, that AI is increasing both the likelihood and the potential impact of damaging cyberattacks.

In line with our 5C framework, we also recognize the need to adapt and align with Europe’s sovereignty priorities and that collaboration will be essential. That is why we recently announced a strategic partnership with Schwarz Digits, the IT and digital division of Schwarz Group [here] combining Zscaler’s Zero Trust Exchange platform with STACKIT, Schwarz Digits’ European sovereign cloud, the partnership creates a sovereign Zero Trust secure access service edge (SASE) service designed to counter AI-driven threats and strengthen cyber resilience. The service will be hosted in STACKIT-operated data centers. More importantly, the partnership reflects a practical commitment to Europe at a time when the tech sovereignty package is beginning to take shape. Together, we will help customers reduce their attack surface and limit lateral movement while supporting compliance with European legislation through EU data residency. The goal is straightforward: to deliver strong security in a way that is fully aligned with Europe’s sovereignty expectations.

The world has become more challenging and less predictable, and cybersecurity has become an increasingly critical and complex domain to navigate. Meeting that challenge requires policymakers, regulators, and technology providers to work closely together to defend organisations, institutions and in many ways the societies and values they were built upon. Europe is, rightly, demanding greater control over its own digital destiny. For the technology industry, that means adapting, aligning, and delivering through the design of our technologies and products. For every organisation, it means making deliberate choices about the architecture it relies on to strengthen both resilience and digital sovereignty. At Zscaler, we will continue to innovate on a foundation that was architected from day one to be digitally sovereign by default.

Adam Geller is Chief Product Officer & Casper Klynge is VP & Head of Government Partnerships & Public Policy EMEA.

form submtited
お読みいただきありがとうございました

このブログは役に立ちましたか?

免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。

Zscalerの最新ブログ情報を受信

このフォームを送信することで、Zscalerのプライバシー ポリシーに同意したものとみなされます。