At its Paris Cyber Summit, Thales launched five new offerings and a global framework, arguing that AI-driven attacks, state-sponsored actors and the quantum threat leave no room for half measures.
Cyber defence must work at machine speed, but human judgement must stay in charge. That was the core message of the Thales Cyber Summit, held in Paris on 1 October 2026 under the motto “Halfway is no way”.
Opening the event, Thales CEO Patrice Caine called cybersecurity a matter for the board and a permanent fixture at the centre of his company. “We sell trust,” he said. Caine pointed to three trends. First, AI has changed the scale, speed and autonomy of attacks: cyber weapons circulate on the darknet, operations take hours instead of days, and some decisions are made without human control. Second, the attackers have changed. Besides cybercriminals, state actors now target critical systems, often aiming at sabotage rather than profit, and they probe the supply chain for its weakest link. Third, the time horizon is growing: adversaries harvest encrypted data today to decrypt it with quantum computers later, so information that must stay confidential for more than ten years needs post-quantum protection now.
Complexity compounds the problem. Customers typically run at least seven security tools, Caine noted, comparing it to one medicine per disease, and perfect protection remains impossible. His answer is a platform approach with one policy everywhere, identity as the central control point, and crypto agility so that algorithms can be swapped without rebuilding systems. Perimeter security still matters, he said, but it is no longer enough.
Other speakers sharpened the picture. Isabelle Möller, CEO of the Biometrics Institute, recalled the field’s successes, from border control to victim identification in Thailand in 2004, but warned that agentic AI and deepfakes now threaten confidence in digital identity. She called for human oversight, education and a simple hierarchy: policy comes first, process follows policy, and technology is guided by both. Identity expert Martin Kuppinger, founder and Distinguished Analyst responsible for KuppingerCole research, of argued that zero trust has been secured in the middle, while its edges, identity and data, remain poorly guarded. With AI agents growing fast and caring mainly about data, uncontrolled AI use leaves the “front doors wide open”, he said, and he called for data-centric access.
Practitioners echoed the urgency. Chris Betz, CISO of Google Cloud, said the era of manual defence is over: attacks and defence are both becoming agentic, while geopolitics fuels hybrid warfare. His advice was to double down on strong foundations. Antoine Leblais, CISO of Foyer Group in Luxembourg, likened broad access to AI to putting a nuclear weapon in a child’s hands and urged companies to quantify their risks and return to basics.
Philippe Vallée, EVP Cyber & Digital Identity at Thales, described identity as the cornerstone of cybersecurity as AI reshapes authentication. Thales builds successive lines of defence to protect both against and with AI, he said, citing an AI-assisted SOC for analysts, an AI Security Fabric that gives real-time visibility into agents and records their track, and a new hardware-based PKI. He also pointed to the regulatory pressure from DORA, NIS2, the AI Act and GDPR, as well as the Cyber Resilience Act, which puts software bills of materials and open-source risk in focus. Sovereignty matters to European customers: Thales offers a sovereign cloud in France, with Germany to follow.
At the press conference, Vallée stressed that AI agents need guardrails and that humans must remain in control. Thales relies on open-source LLMs and sees AI as the “new kid in town” in defence as well. One example is Sentinel Envelope+, a security wrapper for software that can delay attacks, because LLMs tend to give up after hours and consume huge numbers of tokens.
Quantum was a recurring theme. Caine warned that state actors are already stealing data for later decryption and said solutions exist today. Eva Rudin, SVP cybersecurity products at Thales, said organisations should be ready for post-quantum cryptography by 2035, some as early as 2029, and that Thales could deploy in 2027.
Beyond the talks, Thales used the summit to launch five offerings: the Luna 8 hardware security module, the AI-boosted CipherTrust Data Security Posture Management, Sentinel Envelope+, a partnership with Google Cloud to secure agentic AI workflows, and a global framework against frontier-AI attacks. The framework rests on five blocks: application security, AI-augmented detection and response, a converged cyberdefence platform, continuous testing and critical-asset resilience. As a member of Google’s Fairwind programme, Thales will also give critical industries access to tools such as Gemini 3.8 Flash Cyber and CodeMender. Customers can bring their own keys with Azure and AWS, and a sovereign cloud with Google is planned for France, later Germany.
The summit’s verdict was consistent: AI accelerates both sides, and only strong foundations, interoperable tools and human oversight will keep defenders in the race.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de