I left Forum InCyber Europe 2026 with the impression that two themes had moved beyond trend status and into something closer to market doctrine: artificial intelligence and sovereignty.
That was not only my personal impression from walking the show floor and attending the sessions in Lille. It was also the language of the event itself. This year’s edition was framed around the challenge of securing digital dependencies, and from the opening summit onward, the vocabulary of resilience, autonomy, trust, and sovereignty was everywhere. At the same time, AI was not treated as a niche topic or an innovation sidebar. It appeared as infrastructure, as opportunity, as risk, and, increasingly, as a commercial necessity.
The first takeaway is therefore straightforward: nearly every vendor now needs an AI story.
That story takes several forms. Some vendors present AI as a capability inside their security stack: a way to accelerate detection, automate analysis, reduce alert fatigue, or improve decision support. Others position themselves around securing AI itself: protecting models, data, prompts, and agents and their behavior, including AIdentity and how to manage it. Others still do both at once, which is increasingly the default market posture. At Forum InCyber, this was visible not only in the dedicated “Secure AI” event, where Martin Kuppinger gave a keynote, but also in the surrounding partner agenda. AI is now discussed as part of SOC modernization, data protection, cloud security, red teaming, fraud prevention, and infrastructure strategy.
This matters because AI now influences the lens through which cybersecurity challenges are viewed. A few years ago, vendors could still treat it as an optional differentiator. That window is closed. Today, if a cybersecurity vendor cannot explain where AI fits in its product, in its customer environment, and in the emerging attack surface, it risks sounding absent from the market rather than simply cautious.
At the same time, the quality of these AI narratives varies considerably.
In some cases, the discussion is concrete. It addresses prompt injection, model abuse, shadow AI, data exposure, provenance, or the operational use of AI in detection and response. In other cases, AI functions more as a banner than as a capability. It is invoked because the market expects it, not because the vendor has a clearly articulated position on where value is created and where new risk appears. This is why the current wave of AI messaging should not simply be dismissed as hype. But it should be examined carefully. AI is now too important to remain a generic label.
My second takeaway is that sovereignty is no longer a secondary European talking point. It has become a primary framework for discussing resilience, dependency, and strategic control.
This was especially visible in the official discourse. Sovereignty was presented not as abstract political theater but as a response to dependencies in cloud, infrastructure, data, supply chains, and cybersecurity capabilities. Public authorities spoke about sovereign cyber services, cloud trust, European industrial capacity, post-quantum readiness, and the need to define what a European digital service is. In other words, sovereignty was not framed only as a question of values. It was framed as a question of operating capability.
What also came through in conversations at the event was that sovereignty should not be treated as a value in itself. The more useful question is where, and at what level, sovereignty is required to improve resilience. Not every component demands the same degree of control, localization, or independence. For buyers and policymakers alike, the real task is to analyze dependencies carefully and determine which capabilities, services, data flows, or supply chains require stronger sovereignty measures because their disruption would have a material operational impact.
Vendors have understood this shift and adapted their messaging accordingly. Across the event, sovereignty appeared in references to SecNumCloud, European compliance, European hosting, trusted infrastructure, local control, sensitive data, and autonomous cloud or AI environments. In the French and broader European market, this language is no longer peripheral. It is moving into mainstream positioning.
But this is also where caution is needed.
Because sovereignty is becoming commercially attractive, it is at risk of becoming fuzzy. It can mean hosting locations, legal control, ownership, certification, or operational independence. It can mean all of those things together or only one of them. That ambiguity is useful for marketing but difficult for buyers.
This is why I would distinguish between sovereignty as narrative and sovereignty as implementation.
As a narrative, it is now firmly established. It appears in keynotes, partner messaging, and product positioning. As implementation, the picture is less mature. Public communication is often strong on intent and lighter on detail. The European Champions Alliance (ECA) report lists some 1,300 EU software companies in the cybersecurity space, showing how powerful the ecosystem is. We hear about sovereign clouds, sovereign AI, trusted data environments, and European alternatives. We hear less about how dependencies are reduced in production, what remains tied to non-European software or infrastructure, what compromises customers must accept, and how long these transitions will take.
That does not make the sovereignty discussion false. On the contrary, it makes it more urgent. Europe is no longer debating whether digital dependencies matter. It is debating how far it is willing to go to reduce them, how much it is willing to pay, and which trade-offs it is prepared to accept in exchange.
If I had to summarize Forum InCyber Europe 2026 in one sentence, it would be this: AI has become the market’s common language, while sovereignty has become its political and industrial grammar.
Both themes will remain with us. But both now need a more demanding next phase. For AI, that means moving from broad claims to specific operational value and measurable risk reduction. For sovereignty, it means moving from speeches and positioning to architectures, procurement choices, migration paths, and evidence of real control.
The market is no longer short of language. What it needs now is proof.