
Casper Klynge is Zscaler’s Vice President, Head of Government Partnerships and Public Policy across EMEA. He leads political work and strategic relationships with governments, international and regional organisations across Europe, the Middle East and Africa, helping countries, organisations and critical infrastructure operators mitigate cybersecurity issues as well as ensuring data protection and digital sovereignty requirements. Casper previously had a career in foreign affairs spanning several roles in the EU, NATO and in government. With the announcement on June 12 that the US government had suspended access to Fable 5 and Mythos 5 for all foreign nationals, never has the topic of digital sovereignty been more relevant. He discusses how AI has affected digital sovereignty and the conversations surrounding it.
Tell me a bit about your job role.
I have been in this role for a little less than two years, and it’s a relatively new thing, even though the company is not new and been around for a long time. A couple of years ago, Zscaler rightly understood that you need political affairs once you reach a certain level; that’s part of the discipline. You need to be able to have advisory capabilities, and how you handle not only governments, but also the communications better, how you brand the company, how you align with regulations. I have a background in government as a diplomat for many years and then worked for the European Union for many years, for NATO, and then I jumped to the dark side; I was with Microsoft for three years, doing the same job in Europe, and then here I am.
Was it a big decision to make that jump?
I get that question quite often, including from friends. It’s much less dramatic than people make it, because I did a political job before; I was representing interests of a country or an organisation, trying to build bridges between the industry and governments, and I’m doing exactly the same, just from the other side. I think my job is as political as anything I did in government before.
How does Zscaler work with governments?
We work as much with our private customers as we do with governments. If I could make one change, I would not call it government affairs, I would call it political affairs, because I think it gives this impression that it’s only the public sector we work with, and that’s not the case. One of the things with the current political environment is we almost work more with the private companies because they are as concerned or interested in political affairs as the public sector is. We work with policy people, with political leaders, regulators, people within think tanks, academia, journalists. We are also lobbyists for, in our case, Europe and the European Union within the company. We speak to our engineers, our product people, and say we either align and develop and innovate, or we are out of business in a couple of years, so there’s this internal role of representing government interests inside the company as well.
Do the challenges vary between the region with regards to cybersecurity?
You could argue that the differences are not huge, but the way they address the challenges is very different. So, the capabilities and the resources are different. Digital sovereignty is, of course, a huge thing in Europe right now. Sovereignty is a big thing in the Middle East, as well, for slightly different reasons. Africa is a big continent of swing states that are deciding whether to go with Asian technology, US technology, European technology. So, I think there’s a lot at stake, and the cybersecurity space is very much also defining how to handle some of the threats. Some of the challenges for Africa is not only a threat against organisation, but to some extent a threat against overall development, job creation. There are differences and the degree of sophistication, resources and addressing it is different. Fundamentally the sovereign discussion is gaining momentum.
How has digital sovereignty demands changed in the last few years?
It’s on steroids now. I’ve been working in this space for a number of years and have been having conversations with political leaders for a long time, and in my career, I have not experienced such a rapid change in the psychology among political leaders as we’ve seen in the last one and a half years. The traditionally most transatlantic-oriented political leaders or countries are in many ways the most sceptical, critical, concerned when it comes to dependency on non-European technology, so it’s a completely different situation driven by legitimate concerns.
I mentioned the ICC case; Greenland has been a big thing, and what happened on Friday with the US export restriction decision will add momentum to that discussion. Everybody knows more or less what they want, but it’s very difficult to put on a piece of paper, these are the demands that we now have and you better comply, or you’re out of business. That’s why we are trying to lean in a little bit and see if we can help define what sovereignty is in reality, and then have those requirements and demands come back to us.
I think that humble approach to sovereignty is necessary if you want to keep your commercial opportunities moving in.
How will AI affect digital sovereignty?
There is an answer to that prior to Mythos and GPT-5.5 cyber, and there’s an answer afterwards, and you could almost also say that there was an answer after Friday and before [when the US government suspended access to Fable 5 and Mythos 5 for all foreign nationals]. In one of my presentations there is a slide that shows the most valuable companies in the world, and then we have another slide where we show the most valuable AI companies in the world, and when you’re European, it’s not a fantastic slide, because most of them are American, and then you have Chinese companies as well. Therefore, it adds to the feeling of being totally dependent on technology that is developed outside Europe, and then, when something like Mythos happens, it shows that people woke up one day saying, are we now completely vulnerable? Do we have no defence? On Friday everything is just pulled away, so that is not helpful to those who want to have a nuanced discussion on solvency. It polarises the picture a little bit.
Then you combine it with the big discussion in Europe around competitiveness. Digitalisation technology is mentioned more than 900 times in the Draghi report. If you asked Draghi if he had to point to one area where Europe is reading the most chance, he would say that that’s on digitalisation and technology. So feeling a dependency that you have to use US technology, and then at the same time understanding that if you want to be globally competitive, you need to be first to move on AI as well, and I think that’s the schema or the schizophrenic dimension of where Europe is right now.
We will continue to say yes, AI might not be completely mature yet, but we’re seeing in certain industries how it’s pivoting. Europe needs to be on the train, but there’s been too much focus on productivity gains, too little focus on how you defend those systems and create a cybersecurity suite around it, and that’s where we step on board, and say let us help you protect your use of AI That’s the beauty of Zscaler and this zero trust approach is the best way to handle the AI agents. It’s also the best way to handle the feeling of threats from outside.
It seems that the cybersecurity just hasn’t kept up with the growth of AI, and at the same time, everyone wants to grow as quickly as possible to compete, so it’s a difficult situation for everyone, isn’t it?
In some of the customer discussions we are having, people are saying we really need to jump on the AI train now because we feel that everybody is leaving the station, but we also want to do that in a safe, secure way, where our IP or datasets will not be thrown all over the Internet. I do think that Mythos has helped create a more balanced approach to AI, where people say, great tools, although the productivity gains so far are comme ci, comme ça, but we need to make sure that we protect our use of AI and AI agents, and that’s where we come into the picture.


