In recent months, AI agents under evaluation have crossed the boundaries set for them and reached real systems. The debate over AI's social licence is no longer only about jobs, energy or copyright. It now asks whether we can reliably direct, constrain and, if necessary, stop autonomous systems.
The UN Security Council has discussed artificial intelligence before, in 2023 and again in 2024. But never quite like it did on 23 September. France, which holds the Council presidency this month, convened a meeting on AI and international security. This time, the heads of two of the leading frontier labs were at the table, Sam Altman of OpenAI and Dario Amodei of Anthropic. They sat alongside Clément Delangue, the French co-founder of the open-source platform Hugging Face, and the AI researcher Yoshua Bengio. None of them came to argue against artificial intelligence. The companies they lead, like the countries represented on the Council, are investing in it on an unprecedented scale. What had changed was the level of the warnings, and the context of real incidents behind them. Bengio described the dangers of the most advanced systems as "real and imminent", and said no country could master them alone. Altman warned that "we could lose control of the future to AI". The question in the room was no longer only how fast AI can progress, but how confident we can be of remaining in charge of it.
The same day in New York, Australian Prime Minister Anthony Albanese gave that question a very concrete face. He revealed that on 18 June, an OpenAI agent researching public medical spending during an internal evaluation had gained unauthorised access to a Medicare statistics portal run by Services Australia, reaching both public and non-public files. Canberra says there is no evidence that patient records were compromised, and the impact appears limited. What made the incident significant was the behaviour. Blocked from the data it wanted, the agent looked for another way in. In Albanese's words, it "didn't accept 'no' for an answer". OpenAI has acknowledged that its models took actions the company had not intended. The Australian government was not notified until September, three months after the incident. It has set up a taskforce with its cybersecurity and AI-safety authorities to establish what happened.
Australia was not an isolated warning. In July, OpenAI disclosed that models undergoing cybersecurity evaluations had bypassed isolation controls and gained unauthorised access to systems at Hugging Face, the open-source AI platform co-founded by French entrepreneurs. The two companies have since worked together to investigate the incident and strengthen evaluation security. Anthropic then reviewed more than 140,000 cybersecurity evaluation runs. It found three cases in which Claude models had reached the open internet from evaluation environments and obtained unauthorised access to the systems of three organisations. Anthropic described these incidents as more an operational failure than an alignment failure. The distinction matters. These events do not show that AI has escaped human control. They show something more immediate and more useful for policymakers: as AI agents become more autonomous and capable, the systems designed to test and contain them must evolve just as quickly.
In June, I wrote on this site about the growing scrutiny surrounding data centres in Ireland and France. My argument was not that Europe should stop building them. They are critical infrastructure for the digital economy, and the growth of AI makes computing capacity more strategic still. But their expansion can no longer be justified on economic grounds alone: energy supply, grid constraints, climate commitments and public acceptance all have to enter the equation.
That is the essence of what the mining industry, in the late 1990s, began to call a social licence to operate. A project could hold every formal authorisation and still run into serious difficulty if the communities affected withdrew their acceptance. The licence was never written down; it had to be earned and maintained. Data centres discovered this as their physical footprint became visible. AI may now be entering the same phase, with a broader set of concerns: employment, copyright, misinformation, education, the concentration of technological power, environmental impact and now the reliability of autonomous agents. None of these questions implies rejecting AI. They mean the technology has become important enough that capability alone is no longer a sufficient argument for deployment.
This is what made the French initiative at the UN particularly interesting. By bringing AI and international security to the Security Council, Paris was not arguing for technological retreat. According to a French official, Foreign Minister Jean-Noël Barrot called the meeting because the security implications of AI had received too little attention in the Council. France remains one of Europe's strongest advocates of national and European AI capabilities. The meeting instead recognised that some risks linked to advanced AI cross borders and call for international cooperation. Amodei told the Council that poorly managed AI could represent a risk to humanity as a whole. Both he and Altman urged states to set real safeguards and to prevent the power of AI from being concentrated in one company or country.
The debate behind those statements has a distinctly European edge. On 12 September, Amodei published an essay entitled "We Must Pace the Frontier", urging the industry to slow the rate at which models become more capable. He also called for an antitrust waiver so that leading developers could build safety measures together. Altman and Elon Musk backed the idea of pacing development.
In Europe, the reaction was far more sceptical. Mistral, which Reuters describes as the region’s best hope for a frontier model of its own, accused American rivals of using safety concerns to entrench their dominance, arguing that “some incumbents are using this moment to consolidate their market position”. Raphael Auphan, chief operating officer of the Swiss company Proton, called the initiative “totally self-serving”, while Germany’s Black Forest Labs warned against “arbitrary thresholds” that could stifle innovation. Clément Delangue took a more nuanced position: Europe should keep advancing, but he supports Amodei’s call for independent assessment. The debate is not, however, about stopping model development altogether. Ten days after Amodei’s essay, Anthropic unveiled a new model and OpenAI expanded its own model family. As advocates of “pacing the frontier” define it, the aim is to slow the rate at which capabilities advance and ensure that safeguards keep pace, rather than to halt model development or product releases.
Brussels has added a sharper argument of its own. According to reports of her remarks, Henna Virkkunen, the Commission's Executive Vice-President for tech sovereignty, reminded the industry that European law already requires companies, Anthropic included, to assess the risk of loss of control, and that no other jurisdiction does so. Since August 2025, Article 55 of the AI Act has required providers of general-purpose models with systemic risk to conduct adversarial testing, report serious incidents and evaluate risks, including loss of control. The Commission's enforcement powers have applied since 2 August 2026. Part of what is presented in the United States as a new proposal is therefore already binding law in Europe. What the EU does not have is a mechanism for coordinating the pace of development between labs. Its direct reach over developers in China that do not serve the European market is also limited, even if its regulatory and commercial weight gives it indirect influence.
The framework is also evolving. Following the AI Omnibus, rules for high-risk uses in areas such as employment, education, biometrics and critical infrastructure will apply from December 2027, and those for some AI embedded in regulated products from August 2028. The aim is to give companies, regulators and standardisation bodies time to build workable implementation mechanisms without weakening the Act's protections.
The recent incidents raise a different question. Much of AI safety work takes place before systems reach the market, in laboratories and evaluation environments, and testing must grow more sophisticated because the systems being tested are more capable. The UN's scientific panel on AI notes that failures cross company and national borders, and that no single organisation or country sees enough incidents to identify every emerging pattern. It points to aviation, nuclear power and cybersecurity, which all built mechanisms for sharing incident information for precisely that reason. AI will need a comparable culture.
The emerging debate is therefore not a simple contest between those who take AI risks seriously and those who do not. It is about how to manage those risks without freezing the current balance of technological power. It is also about who gets to write the rules: the handful of companies at the frontier, or the public authorities that already have the legal tools to hold them to account.
France has certainly not taken its foot off the accelerator. When the Osez l'IA programme marked its first anniversary at Bercy on 3 September, the government reported that more than 35,000 companies had been reached through 615 AI Ambassadors, and that 88 providers of AI solutions for SMEs and mid-sized companies had been referenced. The next phase is explicitly about moving from awareness to deployment.
At the same time, the vocabulary of risk, resilience and sovereignty has become central. In February, Minister for Artificial Intelligence and Digital Affairs Anne Le Hénanff set up an expert commission on the risks and vulnerabilities of consumer uses of generative AI. Its purpose is not to prevent those uses but to understand where safeguards need to evolve. On 10 September, the government signed a Pacte Numérique et IA, linking AI, cloud and cybersecurity to greater control over strategic digital deployments and the development of sovereign, resilient solutions. The environmental question remains on the table too. France benefits from a comparatively low-carbon electricity system, a real advantage for future computing infrastructure, but the rapid growth of digital demand means energy efficiency and environmental impact cannot be set aside.
Le Hénanff has given this approach a name. Before the Senate's delegation for business on 28 April, she called for "a third way for AI between an American vision and a Chinese vision", and argued that it could become a competitive advantage for France and Europe. In an interview with the JDD after the G7 digital ministerial in May, she presented the line France had defended there as a French and European third way. It means accelerating the spread of AI without giving up protection, sovereignty or freedom, with humans at the heart of AI and regulation designed to protect rather than to hold back innovation. The JDD headlined the interview with a line that captures its spirit: "Don't be afraid of AI, but don't let yourselves be dominated." She was speaking mainly about technological dependence, sovereignty and individual use.
After this summer, the third way takes on a further resonance. Rather than asking Europe to align with either of the two dominant visions, American or Chinese, it proposes a distinct path: the broad diffusion of AI, combined with safeguards and a real capacity to decide. That matters in a debate where the choice is too often presented as racing ahead or slowing down. The goal is not independence in every component of the value chain, which France itself acknowledges would be unrealistic. It is to keep enough capabilities, alternatives and safeguards to retain real freedom of action. AI sovereignty is not only about producing European models. It is about keeping the capacity to decide where, how and under what conditions they are deployed.
Ireland starts from a different position but faces the same balance. Its strategy is strongly pro-adoption: the government wants the country to become a global hub for applied AI innovation, building on its multinational technology sector, its research base and its wider digital economy. At the same time, the institutional framework has been considerably strengthened. The AI Office of Ireland, established this summer as an independent statutory body, now coordinates implementation of the EU AI Act. The government describes its ambition as combining innovation with human-centric, trustworthy AI and robust, proportionate regulation.
Minister of State for AI and Digital Transformation Niamh Smyth gave this philosophy its sharpest expression in January. Responding to the non-consensual intimate images generated by Grok on X, she said that "the sophistication of safeguards must match the sophistication of the technology". She was talking about harmful generated content, but the principle now reaches well beyond that controversy. It applies just as much to autonomous agents, to cybersecurity evaluations and to the systems meant to constrain them. Greater capability requires more sophisticated safeguards, built into the way the capability is developed and deployed rather than added after incidents occur.
Ireland is also revealing because the physical infrastructure behind AI is unusually visible there. According to the Central Statistics Office, data centres accounted for 23% of the country's metered electricity consumption in 2025, against 5% in 2015, with a 10% rise in a single year. Data centres are not synonymous with AI; they support cloud services, enterprise software, streaming, financial services, public administration and much of the digital economy. But AI's appetite for computing makes the links between digital infrastructure, energy policy and AI strategy ever harder to separate.
Ireland has not responded by rejecting further development; it has moved towards managed development. Under the Commission for Regulation of Utilities' connection framework, new data centres must provide generation or storage capacity. Over a six-year ramp-up period, they must also meet at least 80% of their annual demand through additional renewable generation in Ireland, and take account of grid constraints and location. The answer to the infrastructure problem has been neither unrestricted expansion nor prohibition, but conditions under which development can continue. AI may need exactly the same philosophy.
That makes the International AI Summit at the RDS on 14 October particularly timely. One of the flagship events of Ireland's Presidency of the Council of the EU, it will launch European AI Innovation Month under the theme "Harnessing AI to Revolutionise Europe's Competitiveness". Ireland is a fitting host. Few countries combine such a large multinational technology presence with a European regulatory environment, a growing domestic AI ecosystem and such visible infrastructure constraints. Announcing the summit, Niamh Smyth described Ireland as a bridge between Europe and the global tech sector. She added that "our success depends on merging rapid progress with trust and accountability".
Dublin's calendar that day captures the European dilemma rather neatly. While political and business leaders gather in Ballsbridge to discuss AI, competitiveness and investment, another Presidency conference at the Irish Film Institute in Temple Bar will examine copyright and human creativity in the age of AI. Competitiveness in Ballsbridge, creators' rights in Temple Bar: less a contradiction than a picture of what a mature AI policy should look like.
What connects the two is a shift in the burden of proof. Showing that AI can do something is no longer enough; companies and governments will have to explain why it should be done, under what conditions, with what safeguards and for whose benefit. The questions come from every direction. Workers want to know what automation will mean for their jobs, and creators how their work is being used. Teachers and universities are rethinking learning and assessment. Governments are contending with deepfakes, harmful content and cyber threats. None of this signals hostility towards progress. It is what happens when a technology becomes powerful and embedded enough to demand economic, ethical and political choices.
This summer added one more requirement, and it is harder to ignore than the others. Developers must now be able to show that autonomous systems can be monitored, constrained and, where necessary, stopped, including when an agent meets an obstacle in the middle of a complex task and looks for another way through. Europe should resist two equally simplistic responses: assuming that every new capability is desirable because it is possible, and treating every incident as a reason to step away from AI altogether.
France and Ireland have chosen neither. France is accelerating adoption and building European capabilities under the banner of a third way, while taking AI safety and international security to the Security Council. Ireland is expanding the use of AI while strengthening its regulatory capacity and insisting on trust, accountability and proportionate safeguards. Their approaches differ because their circumstances differ. Both rest on the same principle: innovation and control are not competing objectives, and they have to advance together.
The debate over data centres already taught this lesson. Technological progress lasts only as long as societies remain confident that its consequences can be managed. For artificial intelligence, that means mastery rather than rejection. Europe's next AI test will not be measured only by the power of its models, but by its ability to remain in charge of the technologies it chooses to deploy.