Cybersecurity and AI Evaluations: What French Companies Need to Know About OpenAI's New Requirements

Artificial intelligence has become an essential tool in French companies — from family-run SMEs to large CAC 40 corporations. But with this massive adoption comes growing responsibility: understanding the risks these technologies can introduce, particularly in cybersecurity. OpenAI's recent publication on its third-party cybersecurity evaluations raises fundamental questions that every executive and IT manager should ask themselves today.
In a context where France ranks among Europe's most targeted countries for cyberattacks, and where the European AI Regulation (AI Act) is gradually coming into force, this news is not just a technology story. It's a strong signal about the maturity required to deploy AI responsibly in business.
What OpenAI's Approach to AI Risk Evaluation Reveals

OpenAI recently detailed incidents that occurred during cybersecurity evaluations involving its models by specialized third parties. The company clarified the circumstances of these tests, acknowledged certain limitations in its existing protocols, and announced new measures to strengthen the evaluation framework for its models.
What is notable here is not so much the existence of potential vulnerabilities — any complex system has them — but OpenAI's assumed transparency in its communication. This approach marks an evolution in AI security culture: vendors are beginning to treat their models as critical infrastructure, subject to regular independent audits, much like what has been standard practice for decades in banking and nuclear sectors.
For French companies, this means one concrete thing: if AI vendors themselves are strengthening their internal evaluations, it's time for users of these technologies — that is, you — to adopt the same rigor internally.
Concrete Risks for AI-Using Companies
It would be tempting to assume these AI cybersecurity challenges only concern vendors like OpenAI or large systems integrators. That's a strategic mistake.
Let's take concrete examples from the French business landscape:
In a mid-sized industrial company, integrating an AI assistant connected to ERP data can, if misconfigured, expose sensitive production data or contractual information during interactions with the model.
In a law firm or HR department, using an LLM to synthesize confidential documents creates a data flow whose traceability and security must be regularly audited.
In a local government or public agency, using off-the-shelf AI tools without prior evaluation may violate ANSSI recommendations and GDPR requirements.
The new measures announced by OpenAI — particularly strengthened oversight of third-party evaluations — remind us that an AI model is just one brick in a security chain. The responsibility of the integrator and end user remains complete. In France, the doctrine of security by design, promoted by ANSSI and now enshrined in the AI Act, requires companies to consider cybersecurity from the moment they choose and deploy their AI solutions.
Best Practices: How to Secure Your AI Deployments Now

Faced with these challenges, here are the priority measures French companies should implement without delay:
1. Map AI usage across your organization Many companies don't fully understand the extent of AI usage by their employees. A quick internal audit helps identify tools in use, data being processed, and associated risks.
2. Define an AI usage policy Similar to an IT charter, an AI policy clarifies authorized uses, types of data that can be submitted to an external model, and the responsibilities of each stakeholder.
3. Demand transparency from your AI vendors In any call for proposals or contract renewal involving AI, explicitly ask about security evaluation protocols, certifications obtained, and incident response procedures.
4. Implement regular evaluations Like OpenAI does with independent third parties, consider periodic audits of your AI usage, conducted by external experts capable of identifying drift or vulnerabilities.
5. Align with the European AI Act Companies handling high-risk use cases (HR, credit, health, critical infrastructure) are already within the scope of regulatory obligations. Anticipating rather than reacting is the winning approach.
Train Your Teams: The Human Element as Your First Defense Against AI Risks
Technical tools and protocols are not enough. Experience shows this repeatedly: it's often human behavior that constitutes the primary risk vector. An employee naively submitting a confidential contract to ChatGPT, a manager delegating a sensitive decision to an AI tool without verification, a developer integrating a third-party model without prior security testing — these situations are more common than you might think.
This is why training teams in responsible AI has become a strategic priority. At Ikasia, we work with French companies across all sectors to develop an AI culture that is both ambitious and rigorous. Our training programs cover not only productive AI uses but also best practices in cybersecurity, data management, and regulatory compliance.
Training your teams in AI isn't just about learning to use a tool. It's about developing informed judgment about what you can entrust to a machine, under what conditions, and with what precautions. In an environment where threats evolve as fast as technologies, this critical skill makes the difference between successful AI transformation and unnecessary risk exposure.
Is your company ready to deploy AI with the level of security your customers, partners, and regulations demand?
Ikasia supports you in assessing your AI maturity, training your teams, and building a responsible adoption strategy. Discover our programs at ikasia.ai and speak with our experts for a personalized assessment, with no obligation.
Tags
Related courses
Related articles

AI and National Security: What OpenAI's Strategic Shift Really Means for French Businesses
Read
Patch the Planet: How OpenAI's AI Secures Open Source and Transforms Enterprise Cybersecurity Strategy
Read
GPT-5.5 Cyber: How AI Becomes the Digital Shield for French Enterprises
ReadWant to go further?
Ikasia offers AI training designed for professionals. From strategy to hands-on technical workshops.