AI in the public service: the strategic data of French companies exposed to cloud LLMs?

AI in the public service: the strategic data of French companies exposed to cloud LLMs?

The strategic data of French companies, entrusted to the State, risks passing through foreign LLM clouds. A poorly documented leak danger.

Generative artificial intelligence is rapidly becoming established in French public administrations. Chatbots, writing assistants, file summary or analysis tools: the use cases are multiplying. However, behind these efficiency gains lies a still little-documented risk: that of seeing strategic data from French companies, entrusted to the State within the framework of controls, public procurement or regulatory obligations, passing through language models hosted on foreign clouds.

According to the inter-inspection report published in April 2026 by the General Inspectorate of Finance (IGF), the General Inspectorate of Social Affairs (IGAS) and the General Inspectorate of Administration (IGA), available on the IGAS website, the deployment of AI in public administrations constitutes “a major lever, but not automatic or exclusive, for the transformation of public action”. This report draws up a precise inventory and makes 13 proposals. However, it remains largely silent on a central issue for companies: the protection of their sensitive data when it passes through non-sovereign AI tools.

1. Data shared by companies with the administration: a large and sensitive volume

French companies regularly transmit information of a highly strategic nature to the administration. These data do not only relate to routine administration: they often concern elements of competitiveness, know-how or compliance.

They can be grouped into several main categories. Regulatory compliance and quality data arrives in particular via DGCCRF controls, labor inspections, environmental or health authorizations, or even mandatory certifications. Industrial and process data are frequently communicated in the context of complex public procurement, approvals or technical controls. Financial and tax data are transmitted during declarations, tax administration controls or public procurement. Finally, certain data linked to customers or beneficiaries may be involved in measures to combat social or tax fraud.

This information has a dual interest: it is often protected by business secrecy or contractual confidentiality clauses, and its disclosure can harm the competitiveness of the company concerned. The report also notes that administrations are subject to particularly strong “sovereignty constraints”, without detailing the consequences for the companies which provide this data.

At the same time, civil servants and public agents are subject to strict confidentiality obligations. Professional secrecy (article 226-13 of the Penal Code), ethical rules and, for certain bodies, a specific oath, govern their activity. Disciplinary and criminal sanctions exist in the event of violation. The IGF/IGAS/IGA report, however, underlines that “shadow AI”, spontaneous and unregulated use of general public AI tools, could concern up to 40% of agents in local authorities. This practice directly exposes the processed data to the risk of leakage, especially since the tools concerned generally do not benefit from any guarantee of confidentiality or sovereignty.

2. An official report focuses on AI in the public service… but misses a major risk

The main objective of the April 2026 inter-inspection report is to assess the productivity gains and improvement in the quality of public services made possible by the deployment of artificial intelligence. It is based on a benchmark with the private sector and thirteen foreign administrations, and proposes an operational framework structured around thirteen recommendations: provision of secure general tools, sharing of infrastructures, reinforced data governance, contractual clauses with suppliers, training of agents and technological social dialogue.

The document provides a useful overview of uses (general practitioners, support functions, specialized professions), the exposure of professions according to the ILO methodology and the obstacles to scaling up. It particularly emphasizes the issues of sovereignty, data security and risk management throughout the project life cycle.

However, the report remains very largely focused on the protection of users’ personal data and on the sovereignty of the State. It does not address, or very marginally, the specific risks linked to strategic company data which passes through public information systems and then into AI tools. No analysis is devoted to the consequences for the competitiveness of French companies nor to the risks of leaks to language model publishers or foreign authorities. The focus remains institutional: it is about protecting public action and citizen confidence, more than securing the value chain of data that circulates between the private and public sectors.

3. The concrete risks of leakage of business data via AI practices in administration

Several current or developing practices in administrations create real exposure of business data.

The first risk relates to the use of commercial cloud LLMs. As documented in Appendix However, this label constitutes the prerequisite for the processing of sensitive data, broadly defined by the SREN law as including data whose violation is likely to undermine public order, public security, health or the protection of intellectual property. Annex IX explicitly specifies that, for sensitive data, it is impossible to use operators subject to American extraterritorial laws (Cloud Act, FISA).

The second risk concerns the potential use of the data by the publishers themselves. Appendix X of the report develops at length the phenomenon of technological lock-in and “the illusion of sovereignty through accommodation alone”. Even when data is hosted in Europe, the lack of control of the software chain and exposure to the roadmaps of private publishers create dependency. Data transmitted to cloud models may, depending on the conditions of use, contribute to the improvement of the models or be accessible under certain conditions to the authorities of the provider’s country of origin.

These risks directly expose companies. A leak of industrial data, manufacturing processes, customer data or financial data to an LLM publisher or to a foreign administration may result in a loss of competitive advantage, an infringement of intellectual property or use for economic intelligence purposes. Civil servants and public agents are not immune either: in the event of a leak, they may be held liable, especially when the tool used does not comply with security and sovereignty requirements. The report recalls that shadow AI already constitutes “the main risk linked to AI in administrations” in terms of data leaks.

The April 2026 inter-inspection report constitutes a valuable contribution to the reflection on the deployment of AI in public administrations. It usefully highlights the need for rigorous governance, shared infrastructure and increased attention to sovereignty. However, it falls short of a complete analysis of the systemic risks created by the encounter between strategic company data and non-sovereign AI tools.

At a time when France and Europe are seeking to strengthen their technological autonomy, the protection of data of economic and strategic interest of companies in the public uses of AI deserves to be explicitly integrated into governance policies. This requires strengthening contractual clauses with LLM providers, accelerating the provision of truly sovereign shared infrastructures, and precise mapping of data flows between the private sector and public AI tools. Without this, the transformation lever that AI represents for public action could paradoxically weaken another essential pillar of French sovereignty: the competitiveness of its companies.

Jake Thompson
Jake Thompson
Growing up in Seattle, I've always been intrigued by the ever-evolving digital landscape and its impacts on our world. With a background in computer science and business from MIT, I've spent the last decade working with tech companies and writing about technological advancements. I'm passionate about uncovering how innovation and digitalization are reshaping industries, and I feel privileged to share these insights through MeshedSociety.com.

Leave a Comment