This report examines how AI is becoming embedded across French organizations and the security challenges that come with that shift. It looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.
AI is becoming deeply embedded in French organizations: Active AI users rose from 43% to 69% over the past year, and organization-managed adoption climbed from 28% to 66% as personal AI use fell from 80% to 51%. But AI now reaches far beyond standalone tools: 96% of employees use applications with embedded AI features, and 89% interact with systems that use customer or user data for training.
Sensitive data is following AI into the enterprise: Regulated data accounts for 58% of AI-related data policy violations in France, followed by source code at 26%, intellectual property at 9%, and passwords and API keys at 6%. Remote MCP activity has surged since May, with users up roughly 5000% and events up around 2800%. Organizations need to understand not just which AI applications employees use, but what those applications and agents can access.
Attackers are following the AI trend: AI lure activity has held steady at around 80 users per 100,000 since August 2025, making impersonation of trusted AI brands a persistent tactic rather than an occasional campaign. Encounters with malicious AI links have fallen from more than 100 per week per 100,000 users to around 35, though the residual volume still warrants attention. Familiar AI services are increasingly part of the attack chain.
