Philippe Roche
President of Team2i – Ancien X-Mines-Ponts-Telecom
The first half of 2026 marks a quiet but profound turning point for French companies.
For several years, digital transformation was primarily driven by goals such as performance, innovation, and cost optimization. Today, another force is becoming increasingly influential: European regulation.
Generative AI, cybersecurity, data governance, digital sovereignty, system traceability… European regulations are multiplying and gradually reshaping the very nature of IT needs within organizations.
The issue is no longer purely technological.
It is becoming organizational, legal, operational, and strategic.
And in this context, a question is beginning to emerge in many executive committees:
Do companies truly have the skills needed to absorb this new regulatory complexity?
Regulatory Pressure Is Changing the Nature of IT Projects
For a long time, IT projects were primarily designed around three dimensions: cost, timelines, and technical performance.
That model is no longer sufficient.
With the gradual implementation of European regulations such as the AI Act, the strengthening of NIS2 cybersecurity requirements, and growing expectations around data governance, companies must now integrate a new variable: continuous compliance.
This fundamentally changes how information systems are designed.
An AI application is no longer assessed solely on its functional capabilities.
It must now meet requirements related to transparency, human oversight, model documentation, data quality, and, in some cases, auditability.
Cybersecurity projects follow the same logic.
Organizations must now demonstrate resilience, document incident management procedures, strengthen monitoring capabilities, and prove their control over risks.
Regulation no longer comes after technology—it now redefines how technology isdesigned.
For many executives, the shock is less legal than human: they discover that their existing teams do not always possess the expertise required to meet these new frameworks.
The Emergence of Still-Rare Roles in the Market
Perhaps the most striking phenomenon of early 2026 is the rapid emergence of hybrid profiles.
Jobs that barely existed three or four years ago have suddenly become critical.
Growing demand is appearing for:
• AI governance specialists
• AI compliance experts
• Regulatory cybersecurity architects
• Data compliance managers
• NIS2 consultants
• Model auditability experts
• Algorithmic risk management specialists
• Sovereign cloud security engineers
• Advanced IAM experts
• Digital resilience consultants
• Professionals capable of bridging IT, legal, and business teams
The challenge is that these skills remain scarce.
The French market has already suffered from a shortage of cybersecurity experts for several years. The simultaneous rise of AI and compliance requirements is adding further pressure.
Companies are seeking not only technical experts but also professionals who understand the regulatory and organizational implications of deployed technologies.
These profiles typically require years of cross-functional experience spanning infrastructure, security, architecture, data, and governance.
They cannot be developed in a matter of months.
The real challenge of 2026 is not access to technology—it is access to the skills capable of making technology sustainable and compliant.
Cybersecurity Is Becoming a Governance Issue
For a long time, cybersecurity was viewed primarily as a technical issue handled by IT teams.
That paradigm is changing rapidly.
With NIS2 in particular, accountability is moving much higher within organizations.
Executive management and boards of directors are increasingly becoming responsible for their companies’ digital resilience.
This shift is changing hiring needs.
Organizations are no longer looking solely for technicians capable of configuring security systems.
They are seeking professionals capable of establishing governance frameworks, managing risk programs, organizing business continuity procedures, and coordinating company-wide incident responses.
This evolution is creating significant pressure on highly experienced professionals.
Experts capable of communicating with CISOs, business leaders, legal teams, and executive management are becoming especially valuable.
The Strategic Return of Legacy Skills
Paradoxically, this new regulatory wave is also bringing older technical skills back into focus.
Many large French organizations continue to rely on critical legacy environments: mainframes, IBM systems, hybrid architectures, complex network infrastructures, UNIX environments, and older databases.
These systems must now also comply with new security, traceability, and governance requirements.
As a result, expertise that was sometimes considered outdated is regaining strategic value.
COBOL, MVS, CICS, Oracle, complex networking, industrial systems, and hybrid architectures are once again becoming critical subjects when they must be integrated into modern cybersecurity and compliance frameworks.
Some organizations are even discovering that they no longer have the internal resources necessary to maintain or secure these critical environments.
Scarcity does not affect only new professions—it also affects historical skills that companies long assumed were abundant.
Anticipating Critical Skills Becomes a Competitive Advantage
Many companies still approach regulation from a defensive perspective.
How can we avoid penalties?
How can we remain compliant?
How can we minimize risk?
But some organizations are beginning to adopt a different approach.
They now view the anticipation of critical skills as a genuine competitive advantage.
Because when regulation becomes fully enforceable, the market tightens rapidly.
Rare profiles become harder to recruit, costs increase, projects slow down, and trade-offs become more difficult.
Organizations that anticipate these needs will enjoy a significant advantage: they will be able to continue transforming their systems while others struggle simply to catch up.
In this environment, the ability to quickly identify rare skills becomes a strategic challenge.
Not only for large enterprises but also for SMEs and mid-sized companies facing the same regulatory obligations with often more limited resources.
Finding the Unfindable Skills
This market evolution is precisely what some specialized firms have been observing for several years.
One such example is Team2i, a company founded and led by Philippe Roche, which has spent more than ten years addressing the challenge of rare IT skills.
His observation is straightforward:
The difficulty companies face is no longer simply recruiting talent.
It is now identifying professionals capable of operating in technological environments that have become extremely specialized and increasingly constrained by regulatory requirements.
This reality applies equally to:
• Cybersecurity experts
• Complex project managers
• Systems architects
• Network engineers
• Legacy infrastructure specialists
• Highly specialized technical experts
• Hybrid professionals capable of connecting technology, governance, and business operations
The challenge now extends far beyond a simple talent shortage.
It directly affects companies’ ability to continue their digital transformation in an increasingly complex regulatory environment.
And in this new phase, leaders capable of anticipating critical skills will likely enjoy a decisive advantage in the years ahead.