Thales bets on making software harder for AI attackers to read
A new protection layer targets automated reverse engineering, while a separate Google Cloud integration addresses the risks created by business AI agents.
Thales is responding to AI-assisted hacking with two different kinds of protection: making application code harder to analyze and placing controls around the agents companies increasingly allow to interact with their systems.
The French technology group announced Sentinel Envelope Plus on October 1, describing software intended to obstruct automated reverse engineering and vulnerability discovery. The launch came as chief executive Patrice Caine warned a cybersecurity gathering about the accelerating threat from AI-powered attacks, Reuters reported.
The product’s most striking evidence is a controlled company test. Thales said an AI agent found eight of ten vulnerabilities in an unprotected application. After protection was applied, it found none before the analysis was stopped after almost seven hours. That is a specific experimental result, not a measured reduction in attacks across customers or proof that protected software contains no exploitable flaws.
Thales says the add-on works on compiled applications without requiring source-code changes or a special compilation environment. Its purpose is to make analysis more difficult. This places it in a different category from a patch that removes the underlying programming error: preventing an automated tool from finding a weakness during a test does not itself demonstrate that the weakness has disappeared.
For buyers, that distinction affects where the product fits. A protection layer can complement code review, patching and access controls, but the company’s published launch evidence does not justify replacing those processes. The announced test also does not establish how every model, application or attack method would perform against the protection.
Three days earlier, Thales announced a separate expansion of its Google Cloud relationship involving its AI Security Fabric and Gemini Enterprise. That initiative addresses the connections between business agents, models, corporate information and tools. The company describes visibility and policy enforcement around those interactions, where an agent’s permitted access can determine the consequences of an incorrect or manipulated request.
The two announcements concern different exposure points. Compiled-code protection attempts to frustrate the analysis of an application. Agent security governs what an AI-enabled workflow can reach and do while operating. Organizations running both conventional applications and new agent systems may face both problems, but purchasing one form of protection does not answer the other.
This is also a commercial argument from a security supplier. The launch materials establish what Thales is selling and what it says its tests showed; they do not provide an independent comparison with competing products or a broad field evaluation. Those limits should travel with the performance claim when customers assess it.
The publicly stated benchmark remains narrow and concrete: ten planted vulnerabilities, eight detected before protection, none detected during the protected run, with that run halted after nearly seven hours. Reproducing that result under a customer’s own software and operating constraints would provide a stronger basis for procurement than treating it as a universal security guarantee.