“The most revolutionary AI in the field of security will be a discreet, specialized system with unfailing reliability”. Hervé Guesdon, Europe Lead at AUBE Security
It is with great pleasure that I welcome Hervé Guesdon, Europe Lead at AUBE Security
Social Media
Part I:
Introduction
Alexandre Martin - Times of AI™
Hi, could you introduce yourself to Times of AI™ listeners and tell us about your professional background and current activity?
Where does your interest in artificial intelligence (AI) come from?
What projects and business ideas are you working on? What are your objectives? Who are they aimed at and in what areas are they being implemented?
Hervé Guesdon - AUBE Security
I’ve spent 25 years at the intersection of networks, cybersecurity and cloud, most of it in technical leadership roles from R&D researchers at Orange (France Télécom), working on MPLS VPN research, to CTO designing automation solutions for the network, cloud and security. Along the way I specialized in cybersecurity, from SASE (Secure Access Service Edge) to security operations.
Since April 2026, I’ve taken on a new chapter as Europe Lead for AUBE Security. AUBE stands for Authorized Users Behavior Evaluation, and brings a genuinely differentiated approach to a problem every CIO or CISO in critical infrastructure knows well: detecting compromised accounts, malicious insiders and early-stage ransomware.
Where my interest in AI comes from?
It grew out of operational necessity rather than abstract fascination. At Orange R&D I was already working with statistical and algorithmic models applied to network routing. Later, as the complexity of hybrid cloud, network and security environments exploded, classic rule-based automation started hitting its limits customers needed systems that could understand intent and act on it. That’s what pushed us toward AI-driven, intent-based automation. I went further, embedding AI agents and MCP (Model Context Protocol) servers directly into integration and operations playbooks.
What really crystallized my interest, though, was seeing how well-scoped, specialized AI can solve very hard, very specific problems that traditional tools can’t touch. That’s exactly the thesis behind AUBE Security, which is why I joined.
What I’m working on today at AUBE Security?
The problem we solve: Critical infrastructure operators are asked to guarantee full auditability of server activity logs across thousands of systems, under strict compliance frameworks like NIS2 and ISO 27001. In practice, that’s impossible to do manually, and traditional SIEM/UEBA tools don’t really help. They require long baseline ‘warm-up’ periods, struggle to keep up with dynamically changing normal behavior, and ultimately flood analysts with false positives (‘alert fatigue’) without ever explaining why something is actually abnormal.
AUBE takes a fundamentally different approach: AI built on dynamic stochastic models that continuously analyze Linux audit logs at the user/command/parameter level, surfacing subtle deviations in the sequence and timing of a legitimate user’s actions, the kind of rare-but-high-impact anomaly that’s too infrequent to ever form a stable baseline, and that conventional UEBA tools simply miss.
Concretely, that means:
No baseline required: value from day one, no warm-up period
No intrusive agents: works directly from existing audit and system logs
Sensitivity to rare events: surfaces low-frequency but severe deviations instead of treating them as noise
Evidence-based, reproducible reports: pinpointing who, when and what deviated, usable directly for audits
Fast time-to-value: results within days rather than weeks or months typical of UEBA, with ROI often realized in the first audit cycle.
Who it’s for?
CIOs, IT managers, CISOs and SecOps teams, primarily in critical infrastructure, telecom, financial services, healthcare and other heavily regulated industries where privileged-access misuse and insider threats carry the highest stakes.
Part II:
Artificial Intelligence (AI)
Alexandre Martin - Times of AI™
Artificial intelligence is a multidisciplinary field. Like its use, there are several definitions of AI. How would you define artificial intelligence?
Hervé Guesdon - AUBE Security
For me, artificial intelligence is a set of techniques that allow a machine to perform tasks that normally require human intelligence like learning from data, recognizing patterns, reasoning, making decisions, generating content and taking action. It’s a broad umbrella, and what falls under it has expanded a lot even in the past couple of years.
LLMs have made AI mainstream as conversational assistants chatting, writing, coding. From there we’ve moved to agentic AI: systems that don’t just answer questions but use tools, access data and take action.
At the very top end, we now talk about frontier AI, the most advanced, general-purpose models pushing the boundary of what’s possible, with capabilities and risks that aren’t always fully understood even by the teams that build them.
Alexandre Martin - Times of AI™
In your professional activity or in your company, do you use Large Language Models (LLMs)? In what contexts do you use LLMs?
Hervé Guesdon - AUBE Security
Yes, daily but I’d split it into two distinct contexts.
LLMs are now an everyday tool: drafting and structuring documents and reviewing or generating code as a coding assistant.
At AUBE, it’s worth being precise: our core detection engine is not an LLM. It’s built on a dynamic stochastic model analyzing sequences of audit-log events.
This is a deliberate choice, because the reproducibility and explainability isn’t something a generative model reliably gives you.
That distinction matters to me: generation and language tasks are a great fit for LLMs; the actual anomaly detection on sensitive customers log data is not for both accuracy and data-sovereignty reasons, we keep that specialized and, wherever customer data is involved, tightly controlled.
Alexandre Martin - Times of AI™
What is your point of view on AI Agents and Agentic AI? In your professional activity or in your company, do you use AI Agents and Agentic AI? Why?
Do you see potential for businesses in the use of AI agents and AI agents? Why?
What do you think about contextual AI?
Hervé Guesdon - AUBE Security
In my point of view Agentic AI is the biggest shift in AI in the past 18 months from ‘AI that talks’ to ‘AI that does’ but autonomy needs to stay scoped, auditable, and stoppable.
At AUBE, agentic AI is central to where we’re heading next. Today, our dynamic stochastic model detects the rare, high-impact deviations in privileged-user behavior, compromised accounts, malicious insiders, early-stage ransomware. The natural next step, which was actively considering, is an AI agent for remediation, able to act on a high-confidence detection by automatically blocking or containing the suspicious activity.
The potential of AI agents is enormous, but it has to be earned through good governance. The productivity case is the obvious one automating repetitive, well-defined tasks and freeing people from the judgment calls that actually need a human.
The less obvious case, and the one that matters most to me in security, is speed: an agent doesn’t sleep, doesn’t hesitate, and can act on a detection in seconds instead of the hours it might take a human analyst to triage an alert queue. In insider-threat and ransomware scenarios, that gap between detection and containment is exactly where the damage gets done.
Realizing that potential comes down to trust: the agent needs to act on evidence-based, explainable detections rather than guesses, and within a scope that’s been explicitly authorized.
In cyber Security Contextual AI is key. It’s what turns a generic model into something actually useful in production. An AI that understands the specific environment, its normal operating patterns, its privileged accounts, its compliance obligations, its history, produces answers and actions you can actually trust.
Part III:
The Future of AI
Alexandre Martin - Times of AI™
Questions about Artificial General Intelligence (AGI)
Do you think AI systems will be able to achieve a level of autonomy? Why?
Hervé Guesdon - AUBE Security
Within specific, well-defined tasks, yes, and we’re already there in some domains like autonomous driving. What I’m far less convinced of is that the path runs through a single system autonomous across every domain of human intelligence.
That’s a much harder, much less predictable problem, and I’m not sure it’s the most useful and frugal one to chase for real-world impact.
What I find more realistic, and frankly more useful, is a future built on specialized systems, each highly autonomous within a narrow, well-governed scope, coordinated by agents to tackle broader problems together.
Security reinforces that view for me: an agent with unlimited, ungoverned autonomy is a liability, not an asset. Remove human control and the ability to stop it, and you’ve also removed accountability for the decisions it makes. So my honest answer is more autonomy, yes, but bounded autonomy, task by tasks, with a human able to see what the system is doing and switch it off.
Autonomy without those guardrails isn’t progress, it’s just risked see what happened with the recent Hugging Face incident involving an Open AI agent.
Alexandre Martin - Times of AI™
Would you and your company be interested in using AGI within your department?
What would be the benefits for your company?
Hervé Guesdon - AUBE Security
Not for now. AUBE is built on the opposite philosophy: a specialized, explainable model trusted by CIOs and CISOs. A general-purpose AGI would trade away exactly the predictability and control that value depends on.
It is not a permanent no. A genuinely governed AGI proving real value under strict oversight would get a serious look.
Longer term, the more likely fit is AGI as a coordination layer orchestrating specialized agents (detection, remediation, reporting, compliance) but only if that layer stays transparent and bounded, since any benefit has to come with governance attached.
Alexandre Martin - Times of AI™
What emerging trend(s) do you believe in?
Hervé Guesdon - AUBE Security
AI trends are numerous, and honestly, nobody today truly knows what the future holds. The subject is so vast that I’ll limit myself to my own domain: security.
In security, I believe value will keep shifting toward specialized AI grounded in evidence, producing fewer false positives and answers an auditor can actually verify, rather than toward raw model size.
I also believe in frugal AI with models right sized to the task, using only the compute they actually need. This isn’t just an environmental argument but what makes local, on-prem deployment viable and economically sustainable.
Alexandre Martin - Times of AI™
From your point of view, what would be the ideal evolution of AI for you and your company?
Hervé Guesdon - AUBE Security
I think detection will increasingly give way to remediation, with agentic AI closing the gap between spotting a threat and stopping it, under human-defined guardrails. And I believe sovereignty and interoperability will become the real battleground where data lives, and whether tools open up to agents via protocols like MCP, will matter more than which model is biggest.
Underneath all of it, the most transformative AI in security won’t be the flashiest demo; it’ll be the quiet, specialized system doing one job reliably enough that a human stops having to double-check it.
Part IV:
Regulation of AI
Alexandre Martin - Times of AI™
In your opinion, is the implementation of regulations on artificial intelligence a solution for better regulating artificial intelligence? Why?
Hervé Guesdon - AUBE Security
History has taught us, over and over, that without guardrails, bad things happen. So yes I believe a regulatory framework is necessary, not optional.
The stakes (sovereignty, data protection, security, employment, power concentration) go well beyond the technology itself. But regulation only works if it’s specific enough to bite: frameworks like NIS2 already push critical infrastructure toward auditable, explainable practices, and AI regulation should reinforce that same logic: proof, not promises.
Regulation alone won’t be enough, though. Companies and citizens also need to be trained and educated on what these systems can and can’t do. Rules set the boundaries; understanding is what lets people actually use the space inside them.
Alexandre Martin - Times of AI™
Among the various existing regulations on artificial intelligence, which do you think is the most effective regulation for regulating artificial intelligence? Why?
Hervé Guesdon - AUBE Security
For me, it’s the European AI Act, the most advanced attempt at balancing innovation, citizen protection and accountability, using a risk-based approach rather than one blanket rule for every use case.
What’s especially useful from where I sit is how naturally it lines up with what critical infrastructure already lives day to day under NIS2: transparency, human oversight and accountability for high-risk systems.
Alexandre Martin - Times of AI™
Thanks so much Hervé Guesdon.

