FR·EU AI Act series·France implementation·EU timeline checked August 2026
The EU AI Act in France: a decentralised model, still settling.
France has chosen to spread EU AI Act competences across existing regulators rather than create a single new authority. CNIL leads on prohibited practices, ANSSI now holds AI-cybersecurity competences, and PEReN supports technical monitoring. The DDADUE bill that would formally name the national competent authorities passed the Senate on 18 February 2026 and, on the official parliamentary docket updated 24 August 2026, remained before the National Assembly after transmission on 20 February.
ANSSI was formally tasked with EU AI Act cybersecurity competences, anchoring Article 15 robustness and resilience supervision. At EU level, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.
French operators should classify each system and map Article 11, Article 12, and other duties to the applicable pathway. Other provisions retain their own dates; this general overview is not legal advice.
Who supervises what in France
France’s distinctive choice is decentralisation. Existing sector regulators retain their domains; the EU AI Act adds new competences on top. Until the DDADUE bill completes the parliamentary process, the formal statutory designations remain pending; the table below describes the government’s proposed allocation and existing sector roles, not a completed designation.
| Authority | Mandate | Proposed EU AI Act role (August 2026) |
|---|---|---|
| CNIL | Data protection, fundamental rights | Prohibited practices in workplaces and education (emotion recognition, biometric categorization), Article 50 transparency, GDPR and AI Act overlap. Published a strategic plan for 2025 to 2028 with AI as priority axis. |
| ANSSI | National cybersecurity agency | AI Act cybersecurity competences (formally tasked April 2026): Article 15 robustness, accuracy and cybersecurity supervision, including resilience to adversarial input. |
| PEReN | Pôle d’Expertise de la Régulation Numérique | Technical monitoring, model probing, support to other regulators on auditability and post-market surveillance. |
| DGCCRF | Consumer and competition authority | Coordination role; commercial-manipulation prohibitions; single point of contact pending statutory designation. |
| ACPR | Banking and insurance prudential supervisor | Sector-specific high-risk AI in financial services: credit scoring, insurance underwriting, anti-fraud. Conformity-assessment overlap with prudential rules. |
| ARCOM | Audiovisual and digital communications | Information integrity, deepfakes, AI-generated media; Article 50 disclosure interface for media providers. |
| ANSM, HAS | Medicines and Health-Authority bodies | Healthcare AI with MDR/IVDR overlap; ambient documentation, clinical decision support, diagnostic AI under dual conformity routes. |
| Défenseur des droits | Independent rights ombudsman | Article 77 fundamental-rights body; discrimination monitoring on AI-affected decisions. |
INESIA (Institut National d’Évaluation et de Sécurité de l’Intelligence Artificielle), launched February 2025, coordinates ANSSI, Inria, LNE and PEReN on AI safety. It is not a market-surveillance authority under Article 70. Formal national designations remain tied to the pending DDADUE bill. Treat INESIA as a technical convening body, not a designation.
French sector overlays
The Articles 9 to 15 obligations themselves are EU-wide. What differs in France is the supervisory stack you face on top of them. The most common combinations:
| Sector | French regulators on top of the AI Act |
|---|---|
| Healthcare AI | ANSM (medical-device oversight and vigilance), HAS (clinical-evaluation guidance), CNIL (personal-data and applicable Health Data Hub matters), plus any AI Act conformity route that applies. Ambient scribes and clinical decision support require system-specific classification; medical-device AI may fall under Article 6(1) and Annex I when both statutory conditions are met. |
| Financial services | ACPR for prudential conformity on credit scoring and insurance underwriting; AMF on market-conduct AI; Banque de France on payment-fraud models. Anti-money-laundering models continue under existing CRR/MiFID frameworks. |
| Public administration | Heightened CNIL scrutiny on automated decisions affecting citizens; Défenseur des droits as Article 77 fundamental-rights body; Conseil d’État jurisprudence on algorithmic transparency. |
| Workplace and education | CNIL holds the prohibited-practice line on emotion recognition and biometric categorization. Ministry of Labour and Ministry of National Education guidance applies on top of the EU AI Act. |
| Media and content | ARCOM on information integrity, deepfakes, generative-AI labeling; coordination with the EU Code of Practice on Disinformation. |
| Defence and dual-use | Article 2(3) defense carve-out applies; Ministry of Armed Forces ethical principles cover voluntary practice. AI in dual-use industrial systems remains in scope. |
Data-protection overlay: Loi Informatique et Libertés
French AI deployments rarely sit on AI Act obligations alone. The Loi Informatique et Libertés (Law 78-17, as amended) and GDPR remain the operative data-protection regime; CNIL enforces both. The most common overlaps:
- Article 10 (data governance) and GDPR Articles 5 and 6. Lawful basis for training data, purpose limitation, accuracy.
- Article 13 (transparency) and GDPR Articles 13 and 14. Information to data subjects; CNIL’s stricter expectations on automated-decision disclosures.
- Article 14 (human oversight) and GDPR Article 22. Meaningful human review of consequential decisions.
- Article 26 (deployer obligations) and CNIL data-protection impact assessments. Single artefact often covers both with care.
CNIL’s published “AI how-to sheets” (fiches IA) remain the most practical bridge between the two regimes for French operators.
Regulatory sandboxes and innovation routes
France has signalled support for AI Act sandboxes through the France 2030 plan. CNIL’s “bac à sable” (sandbox) program has run thematic cohorts since 2021 and is the closest operational analogue. Healthcare AI deployers can also use Health Data Hub authorizations as a parallel innovation route. The pending DDADUE bill means operators should confirm the current Article 57 national implementation route rather than assume the existing CNIL program is the formal AI Act sandbox.
References
- European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
- CNIL. Plan stratégique 2025-2028. cnil.fr.
- Direction générale des Entreprises. Les autorités compétentes pour la mise en œuvre du règlement européen sur l’intelligence artificielle. entreprises.gouv.fr.
- ANSSI. Tasking on AI Act cybersecurity competences, April 2026.
- French Senate. DDADUE legislative dossier, updated 24 August 2026: Senate adoption on 18 February 2026 and transmission to the National Assembly on 20 February. senat.fr.
- Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
- European Commission. AI Omnibus enters into force, 27 July 2026. digital-strategy.ec.europa.eu.
- European Parliament. AI Act deal on simplification measures; ban on nudifier apps, April 2026. europarl.europa.eu.
Build the evidence trail
French operators: selected control records for the wider evidence trail.
For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by CNIL or a notified body.
Bring us the action that matters. We’ll map the intended controls, operational decision points, and evidence gaps.