When AI Speaks Your Language But Its Security Doesn't
AI safety filters were built mostly in English. For companies operating across Europe's dozens of languages, that gap is already being used against them.

Key points
- Brown University research found that OpenAI's GPT-4 produced harmful responses to dangerous prompts 79% of the time when those prompts were translated into low-resource languages, compared to less than 1% of the time in English.
- The European Union recognises 24 official languages, making multilingual AI gaps a near-daily operational risk for businesses across the bloc.
- AI security vendor DeepKeep found measurable accuracy drops in detecting personal data in German, Spanish, French, and Italian compared to English.
- Microsoft's AI red team has tested AI systems across multiple languages specifically because a model's safety behaviour can shift depending on which language it is prompted in.
- The EU AI Act does not currently require identical safety performance across every language an AI product supports.
The AI tools millions of workers use every day speak dozens of languages. The safety systems sitting underneath those tools mostly think in one: English.
That mismatch has a name now. On 22 July, AI security vendor DeepKeep published research under the blunt headline "Your AI Speaks 100 Languages. Your AI Security Layer Doesn't." The finding is straightforward and uncomfortable. Guardrails, meaning the rules baked into AI products to stop them producing harmful content or leaking sensitive data, were built and tested predominantly by English-speaking teams, on English-language examples. Extend those guardrails to Welsh, Swahili, or even German, and they start to fray.
How do criminals actually use this?
Attackers are already doing it. They repeat the same malicious instruction across several languages until one slips through a filter tuned for English phrasing. Brown University researchers showed in 2023 and 2024 work that GPT-4 returned harmful, usable responses to dangerous prompts 79% of the time when prompts were translated into low-resource languages, while the identical prompts in English triggered harmful responses less than 1% of the time.
DeepKeep's own testing found that German, Spanish, French, and Italian all produced meaningful accuracy drops when AI systems tried to detect PII, personally identifiable information such as names, addresses, and ID numbers, compared to English-language analysis. A filter that catches a French employee accidentally pasting a customer's passport number may not catch the same paste written in Breton or Slovak.
Pete Bryan, technical lead of Microsoft's AI red team, told Dark Reading that Microsoft tests across multiple languages precisely because "model safety and behavioral profile can change depending on the language it is prompted in." He added that culture compounds the problem: the same words spoken by different people in different countries can carry entirely different risk levels.
Why does Europe face this more than most?
Europe sits at the sharpest edge of this problem, though it is not alone. Twenty-four official languages sit inside one regulatory and economic bloc, and cross-border work is routine, not exceptional.
Yossi Altevet, co-founder and CTO of DeepKeep, put it plainly: "Every multilingual enterprise, anywhere, carries the same underlying risk the moment it processes a non-English prompt." Europe simply hits that moment constantly, across nearly every major market at once.
| Language | Noted AI safety gap |
|---|---|
| German | Measurable PII detection accuracy drop vs English |
| French | Measurable PII detection accuracy drop vs English |
| Spanish | Measurable PII detection accuracy drop vs English |
| Italian | Measurable PII detection accuracy drop vs English |
| Low-resource languages (e.g. Welsh, Swahili) | GPT-4 harmful response rate jumps to ~79% |
Paolo Palumbo, VP of strategic threat intelligence at European cybersecurity firm WithSecure, warns that a product may "appear to converse competently in a particular language even though its moderation, prompt-injection detection" and data-loss controls have never been validated to the same standard in that language. Prompt injection, for those unfamiliar, is an attack where criminals hide instructions inside ordinary-looking text to trick an AI into doing something it should refuse.
The EU AI Act, the bloc's flagship AI regulation, does not currently require equal safety performance across every language a product supports. For high-risk systems it demands continuous risk management and evidence that safety measures actually work, but a standard business chatbot does not automatically qualify as high-risk.
What should workers and businesses do now?
If your company uses AI tools across more than one language, ask your vendor directly whether its safety controls have been tested in those languages, not just whether the product supports them. Support and safety are different things.
For employees: be cautious about pasting sensitive customer or patient data into any AI tool, in any language, until your organisation has confirmed what protections are in place. If something the AI produces looks wrong or unexpectedly detailed about a sensitive topic, flag it to your IT team rather than acting on it.



