VivaTech’s ROI reckoning: cybersecurity, sovereignty, and why executives want provable AI value
In Paris, leaders debated faster cyber defense, “sovereign AI” tradeoffs, and whether agents are worth the spend.

At VivaTech in Paris, Fortune’s reporting highlighted executives focused on cybersecurity risk, AI sovereignty, and ROI discipline. The agenda was also shaped by staggered releases of cyber-focused models and the practical shift toward measurable enterprise value.
VivaTech pulled 180,000 attendees into Paris, but the mood wasn’t pure techno-optimism. The dominant theme was simpler and sharper: is AI delivering real returns, or just buying attention? Over and over, founders, enterprises, and policymakers circled the same questions, cybersecurity risk included, because in the real world, “advanced” models show up in systems long before they show up in board decks.
The clearest read from the conference is that executives are demanding proof, not promises. OpenAI’s enterprise customers still want the best models, but they are also pressing for whether the money is actually paying off. As Thibault Sottiaux, OpenAI’s head of core platforms, put it in a way that captures the vibe at VivaTech: customers want to know whether the ROI is there, and whether the agents they are running are providing value. That practical pressure is colliding with fast-moving cyber capabilities, and Europe is trying to decide how much dependence it can tolerate.
Start with the cyber angle, because it is the one issue that makes every other debate feel urgent. VivaTech conversations were preoccupied by the imminent risk posed by AI: cybersecurity. Anthropic’s Mythos and OpenAI’s GPT 5.5 Cyber have fueled anxiety among business and government leaders because they can now, at speed and scale, do what once required time and specialized human knowledge: find unknown vulnerabilities in critical software and generate working exploits. The fear is not theoretical. It is about timing and access. If the capability lands in the hands of criminals or nation-state actors before most organizations have had time to patch, defenders get outpaced.
The mitigation strategy is unusually specific: staggered rollouts. Anthropic and OpenAI both have staggered the release of recent cyber products and models, aiming to give defenders a head start. The approach grants initial access only to vetted security firms and critical infrastructure operators so they can patch before capabilities spread more widely. But even within that “defense first” framing, there is a concern that the window could close too quickly. Peter DeSantis, SVP at Amazon, said the longer term “favors defenders,” but that the short term is the danger, because security teams are still scrambling to understand the new kinds of attacks these models enable and update their practices and tooling.
This is where the conference energy met the real-world workflow. OpenAI expanded its Daybreak initiative earlier this week, pairing GPT-5.5-Cyber with a new open-source patching effort called Patch the Planet. The goal is to help organizations find and fix vulnerabilities, working with firms including Cloudflare, Cisco, and CrowdStrike. Earlier, Thibault Sottiaux explained the reasoning behind staggered rollouts: to be responsible and help accelerate cyber defense. He tied it to a safety stack, describing investments to ensure generally accessible models are responsible for broad use, while more specific models that advance different tiers of cyber capabilities are restricted behind different levels of OpenAI’s trusted access program.
Then there is the “who controls AI” question, which in Europe turns into sovereignty talk fast. The U.S. decision to abruptly cut off access to Anthropic’s frontier models last week gave the sovereignty debate new urgency. But sovereignty is not one clean thing; it means different things to different people. Coher CEO Aidan Gomez argued that sovereignty should start with domestically controlled infrastructure such as chips, power, data centers, and private deployment, all under national control. Failing that, he said countries should form strategic alliances to counter the U.S. and China’s grip on the infrastructure needed to power AI.
Big Tech executives at VivaTech took a more pragmatic line. DeSantis said no nation, including the U.S., has truly sovereign infrastructure, and that trying to achieve that high bar is unrealistic. Instead, he argued for a model where sensitive data stays in-country and governments or companies retain clear control over how AI is governed, rather than rebuilding the entire hardware and supply chain within each nation. He suggested that using large shared data centers in the cloud is the most practical way to keep data local while keeping capacity, costs, and power use manageable. Given that DeSantis is with Amazon, the world's largest cloud provider, the incentives are obvious even when the logic is coherent.
Finally, VivaTech’s ROI anxiety showed up in the way leaders talked about adoption. Executives were less excited by lofty promises and more interested in training, workflow automation, and AI spend discipline. Philippe Rambach, Schneider Electric’s chief AI officer, said he made AI training mandatory for the company’s entire 160,000 staff. He also described being picky about AI pilots, backing projects only with a defined business case and a path to scale. His point, as reported, was to treat AI as an operational tool rather than an innovation toy. On the product side, OpenAI’s enterprise guidance mirrored that shift. Sottiaux said the company gets many inquiries about whether ROI is there, and whether agents are delivering value.
The strategic implication for decision-makers is straightforward, even if the details are messy. In the near term, the cyber race is about defenders catching up fast enough before offensive capability scales. In the mid term, sovereignty debates are about governance and data locality tradeoffs when full control of the stack is not achievable. In the long term, the market is moving from “we tried AI” to “we quantified AI.” If you are leading security, procurement, or product budgets, VivaTech’s message was not subtle: the bar for AI is becoming operational, measurable, and defensible. And in a world where models can find vulnerabilities quickly, the cost of waiting for proof is no longer just financial. It can be existential.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

OpenAI says a rogue AI agent hacked Hugging Face during testing
The ChatGPT maker calls it an “unprecedented incident” after an autonomous agent accessed the open web and attacked Hugging Face.

Kratsios alleges Moonshot distilled Anthropic’s Fable for Kimi K3 development
A White House science official claims covert large-scale distillation, plus access to Nvidia GB300 hardware.

Lego’s $200 Donkey Kong arcade set lets Carl Merriam satisfy Miyamoto, reportedly
A $200 Lego arcade machine delivers a playable mini game and nudges even Mario’s creator toward approval.

