American companies are deploying AI agents at full speed while European enterprises remain cautious, a divide that leaves Europe exposed to AI-driven cyberattacks. The assessment comes from Holger Mueller, vice president and principal analyst at Constellation Research Inc., who argues that humans cannot match AI-based threats without AI-based defense. For business, the point is direct: the pace of agent adoption now affects both security posture and the ability to compete with US rivals.

US races ahead with AI agents as Europe waits, warns Constellation analyst

Sovereign cloud, tech debt and delayed adoption

Mueller spoke during an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio, as part of Oracle's event AI Cyberattacks Are Escalating: How to Secure Your Data Now, together with Dave Vellante, chief analyst for theCUBE Research, and Krista Case, principal analyst for theCUBE Research. He described Europe as traditionally skeptical toward innovation coming from the US, with conservatism and waiting shaping AI decisions. Sovereign cloud, he said, has become both a major topic and a convenient excuse, even though many European firms operate globally and cannot afford to pause adoption until a domestic cloud option matures.

He acknowledged that humans fundamentally distrust automation, yet argued that gaps in agentic AI frameworks will likely be closed with more AI rather than less. He cited the Hugging Face security incident, in which an autonomous AI agent carried out an intrusion, while defenders later used an open-weight model to analyze the attack after commercial frontier models refused the forensic material. The pattern matters for operations: the choice of model shaped both the attack and the defense, showing why selection and testing cannot be left to chance.

Constellation Research recently examined vendor claims under the label agentic AI washing, applied to companies that overstate how much agent capability their products contain. Tested against the firm's extensive criteria, Oracle's AI database offerings were judged to deliver real agentic capability rather than marketing language. Mueller placed this in a sequence: last year advanced firms built the data source and data plane for agents, this year vendors compete over the better agentic framework, and next year should bring a renaissance of scaling backend systems, which rewards customers with a highly scalable database.

What this means for companies using AI agents

For companies that already run agents, database scalability and cloud elasticity move to the center of planning. Oracle's long standing as a secure transactional database provider, combined with a strategy that keeps a traditional database while sending external workloads to a data lakehouse, lets customers move to the cloud when needed and keep getting value from agents. A small firm without on-premises history can consume AI largely through elastic services, while a large organization first has to clear tech debt accumulated over 20 years, because AI penalizes unmanaged data and infrastructure.

The limits deserve equal attention, starting with verification of vendor claims about agents. Buyers should ask which criteria sit behind the agentic label, how logging and forensic handling work when frontier models block sensitive material, and whether a roadmap toward quantum-safe protection exists where state-level espionage is a concern. Joint attack simulations with other CISOs using black-hat and white-hat techniques belong in preparation, since greater security is needed at every stage and the interview alone does not make every database deployment agent-ready.

A useful marker to watch is whether backend projects shift from framework selection to scaling data platforms for agents during next year. If European enterprises reduce waiting on sovereign cloud and report cloud migrations tied to agent workloads, the gap Mueller described will be closing. If not, exposure to AI-driven attacks will likely grow while US competitors extend their lead.