Berlin is in motion. Civil servants, lobbyists, journalists, and parliamentarians move through the government quarter as tourists gather along the Spree. Just beyond the Reichstag, I meet Jeanne Dillschneider, one of the newest members of Germany’s federal parliament. After passing the security checkpoint, we make our way to the German Parliamentary Society, where conversations about legislation, security, and technology often continue long after committee meetings have ended. The building, sitting on Friedrich-Ebert-Platz directly across from the Reichstag’s east entrance, carries its own history: once the Reichstag president’s palace, it has served since 1999 as the cross-party meeting ground for members of the Bundestag, the state parliaments, and the European Parliament. We find a quiet corner and order our flat whites.
Jeanne was elected to the Bundestag in 2025 for Alliance 90/The Greens. At thirty, she holds a portfolio at the intersection of two defining challenges of our time: she serves as her party’s spokesperson on the Committee for Digitalisation and State Modernisation while also sitting on the Defence Committee. Few parliamentary roles bring questions of artificial intelligence, cybersecurity, and geopolitical competition together quite so directly.
Her interest in technology long predates her career. ‘I’ve always been fascinated by it,’ she says, tracing her curiosity back to her father, who taught computer science and introduced her early to how digital systems work. As a late millennial, she describes a sense of having ‘lived through the whole development curve of digitalisation’. This laid the foundation for a career spent thinking about the relationship between technology, law, and society.
Prior to her election, Jeanne worked as a cybersecurity lawyer. Legal systems, she says, operate slowly, cautiously, and by precedent. Digital systems evolve quickly, iteratively, and often without waiting for institutional clarity. That tension became central to her work: how can law remain meaningful in environments that evolve faster than legal frameworks can adapt?
She emphasises that the human factor remains the weakest link in cybersecurity.
One of the most urgent shifts she points to is the evolution of cyber threats driven by artificial intelligence. Large frontier models can accelerate vulnerability discovery and assist in how those weaknesses might be exploited. This, she argues, adds a new layer of urgency to cybersecurity policy: ‘We are entering a phase where systems can detect weaknesses much faster than before.’ At the same time, she emphasises that the human factor remains the weakest link in cybersecurity. Sophisticated exploits attract attention, but many breaches still begin with a phishing email, a compromised password, or a simple mistake.
Germany’s own parliament has lived through both ends of that spectrum. In May 2015, attackers used targeted phishing emails to penetrate the Bundestag’s internal network, eventually gaining administrator access and extracting an estimated 16 gigabytes of sensitive data, including correspondence from then-Chancellor Angela Merkel’s constituency office. The entire parliamentary IT system had to be taken offline and rebuilt from scratch.
Investigations by German federal police and prosecutors traced the intrusion to a Russian military intelligence service (GRU) hacking unit known as APT28 or Fancy Bear; an international arrest warrant was later issued for the alleged lead hacker, Dmitri Badin, and the EU sanctioned those responsible in 2020.
A decade on, the method has resurfaced in different form: according to Germany’s domestic intelligence service, a phishing wave targeting users of the messaging app Signal, long considered one of the more secure platforms, appears to have reached Bundestag President Julia Klöckner, along with other senior politicians and figures from the military, diplomatic, and journalistic spheres. For Dillschneider, both cases make the same point: even the most ordinary tools and institutions can become entry points for broader disruption.
Cybersecurity policy, she adds, is increasingly shaped by hybrid threats that blur traditional categories. State actors, criminal networks, and proxy groups often overlap in practice, making attribution and response more complex. In many cases, she notes, Russian-linked actors operate alongside opportunistic criminal groups, creating a security landscape that defies neat distinctions between geopolitical and criminal activity.
Alongside external threats, she highlights an internal one: how institutions adopt AI systems without fully understanding what data these tools access or how they process it. ‘People assume these systems are neutral or automatically safe,’ she says, ‘but that is not the case.’ Workplace AI assistants can inadvertently gain access to sensitive information simply because access controls were not clearly designed. The broader risk, she argues, is the tendency to treat automated systems as objective and trustworthy by default. In practice, systems are only as safe as the governance and safeguards that surround them.
“People assume these systems are neutral or automatically safe, but that is not the case.”
Her perspective on security also extends to the political debate around surveillance and policing technologies. She describes ongoing discussions in Germany about expanded cyber capabilities, data retention measures, and tools for large-scale data analysis. She also cautions against the growing use of AI and data-driven profiling in policing: while she supports strengthening investigative capacity, she warns against normalising systems that produce opaque or unverifiable profiles of individuals. Tools that aggregate large datasets to generate behavioural profiles, she argues, risk compressing complex human lives into incomplete or misleading representations. Even low error rates, when applied at scale, can produce significant harm. ‘You cannot treat probabilistic systems as if they were neutral truth machines,’ she says.
Despite the scale of these challenges, she resists purely pessimistic interpretations of technological change. She points to areas where AI is already delivering tangible benefits, from medical diagnostics and neonatal care to Alzheimer’s research. The lesson, in her view, is not that technology is inherently beneficial or harmful, but that its impact depends on the choices societies make about how it is developed, deployed, and governed.
That question of governance follows her onto the Defence Committee too, where debates on Ukraine and the changing nature of warfare raise it in starker form. She describes a shift towards an increasingly digitised battlefield, shaped by drones, satellite systems, logistics networks, and AI-enabled tools. Ukraine, she notes, has been forced to innovate rapidly under extreme conditions, developing significant adaptive capacity as a result. Yet she cautions against romanticising technological advancement. As civilian infrastructure becomes more entangled with digital systems from satellites to logistics networks, vulnerabilities extend far beyond traditional military domains. ‘Without digital infrastructure, nothing else works,’ she says.
“Without digital infrastructure, nothing else works.”
It is a line that could apply just as easily to her domestic digitalisation portfolio as to the battlefield, which is exactly why conversations about the opportunities and security risks of digital technology need to happen across both. Politics still runs in silos – one committee for defence, another for digital affairs, each with its own vocabulary, its own experts, its own sense of urgency – and Jeanne seeks to bridge this, carrying what she works on in one committee into the room where the other one meets.
Our hour is already over. Jeanne checks the time and gets up, gathering her things as we make our way back through the high-ceilinged corridors of the Parliamentary Society; at the door she shakes my hand, already half-turned toward the Reichstag, where another meeting is waiting to start.
The AI over Lunch interview series is a project part of Virtual Routes’ AI-Cyber Research and Policy Hub. If you would like to sponsor this series, please reach out to hu*@************es.org. Have someone in mind we should interview? We’re happy to hear your suggestions!