FR·EU AI Act series·France implementation·EU timeline checked August 2026

The EU AI Act in France: a decentralised model, still settling.

France has chosen to spread EU AI Act competences across existing regulators rather than create a single new authority. CNIL leads on prohibited practices, ANSSI now holds AI-cybersecurity competences, and PEReN supports technical monitoring. The DDADUE bill that would formally name the national competent authorities passed the Senate on 18 February 2026 and, on the official parliamentary docket updated 24 August 2026, remained before the National Assembly after transmission on 20 February.

Talk to us All-EU material in the main guide →
Compliance lead DPO General Counsel CISO
Feb 2025
Prohibited practices in force; CNIL begins active oversight
Aug 2025
GPAI obligations live; France missed the formal authority-designation deadline
Apr 2026
ANSSI tasked with EU AI Act cybersecurity competences
Aug 2026
Relevant Annex III high-risk duties apply from 2 Dec 2027 under the AI Omnibus
What changed by August 2026 in France

ANSSI was formally tasked with EU AI Act cybersecurity competences, anchoring Article 15 robustness and resilience supervision. At EU level, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.

French operators should classify each system and map Article 11, Article 12, and other duties to the applicable pathway. Other provisions retain their own dates; this general overview is not legal advice.

Who supervises what in France

France’s distinctive choice is decentralisation. Existing sector regulators retain their domains; the EU AI Act adds new competences on top. Until the DDADUE bill completes the parliamentary process, the formal statutory designations remain pending; the table below describes the government’s proposed allocation and existing sector roles, not a completed designation.

AuthorityMandateProposed EU AI Act role (August 2026)
CNIL Data protection, fundamental rights Prohibited practices in workplaces and education (emotion recognition, biometric categorization), Article 50 transparency, GDPR and AI Act overlap. Published a strategic plan for 2025 to 2028 with AI as priority axis.
ANSSI National cybersecurity agency AI Act cybersecurity competences (formally tasked April 2026): Article 15 robustness, accuracy and cybersecurity supervision, including resilience to adversarial input.
PEReN Pôle d’Expertise de la Régulation Numérique Technical monitoring, model probing, support to other regulators on auditability and post-market surveillance.
DGCCRF Consumer and competition authority Coordination role; commercial-manipulation prohibitions; single point of contact pending statutory designation.
ACPR Banking and insurance prudential supervisor Sector-specific high-risk AI in financial services: credit scoring, insurance underwriting, anti-fraud. Conformity-assessment overlap with prudential rules.
ARCOM Audiovisual and digital communications Information integrity, deepfakes, AI-generated media; Article 50 disclosure interface for media providers.
ANSM, HAS Medicines and Health-Authority bodies Healthcare AI with MDR/IVDR overlap; ambient documentation, clinical decision support, diagnostic AI under dual conformity routes.
Défenseur des droits Independent rights ombudsman Article 77 fundamental-rights body; discrimination monitoring on AI-affected decisions.
INESIA in context

INESIA (Institut National d’Évaluation et de Sécurité de l’Intelligence Artificielle), launched February 2025, coordinates ANSSI, Inria, LNE and PEReN on AI safety. It is not a market-surveillance authority under Article 70. Formal national designations remain tied to the pending DDADUE bill. Treat INESIA as a technical convening body, not a designation.

French sector overlays

The Articles 9 to 15 obligations themselves are EU-wide. What differs in France is the supervisory stack you face on top of them. The most common combinations:

SectorFrench regulators on top of the AI Act
Healthcare AIANSM (medical-device oversight and vigilance), HAS (clinical-evaluation guidance), CNIL (personal-data and applicable Health Data Hub matters), plus any AI Act conformity route that applies. Ambient scribes and clinical decision support require system-specific classification; medical-device AI may fall under Article 6(1) and Annex I when both statutory conditions are met.
Financial servicesACPR for prudential conformity on credit scoring and insurance underwriting; AMF on market-conduct AI; Banque de France on payment-fraud models. Anti-money-laundering models continue under existing CRR/MiFID frameworks.
Public administrationHeightened CNIL scrutiny on automated decisions affecting citizens; Défenseur des droits as Article 77 fundamental-rights body; Conseil d’État jurisprudence on algorithmic transparency.
Workplace and educationCNIL holds the prohibited-practice line on emotion recognition and biometric categorization. Ministry of Labour and Ministry of National Education guidance applies on top of the EU AI Act.
Media and contentARCOM on information integrity, deepfakes, generative-AI labeling; coordination with the EU Code of Practice on Disinformation.
Defence and dual-useArticle 2(3) defense carve-out applies; Ministry of Armed Forces ethical principles cover voluntary practice. AI in dual-use industrial systems remains in scope.

Data-protection overlay: Loi Informatique et Libertés

French AI deployments rarely sit on AI Act obligations alone. The Loi Informatique et Libertés (Law 78-17, as amended) and GDPR remain the operative data-protection regime; CNIL enforces both. The most common overlaps:

  • Article 10 (data governance) and GDPR Articles 5 and 6. Lawful basis for training data, purpose limitation, accuracy.
  • Article 13 (transparency) and GDPR Articles 13 and 14. Information to data subjects; CNIL’s stricter expectations on automated-decision disclosures.
  • Article 14 (human oversight) and GDPR Article 22. Meaningful human review of consequential decisions.
  • Article 26 (deployer obligations) and CNIL data-protection impact assessments. Single artefact often covers both with care.

CNIL’s published “AI how-to sheets” (fiches IA) remain the most practical bridge between the two regimes for French operators.

Regulatory sandboxes and innovation routes

France has signalled support for AI Act sandboxes through the France 2030 plan. CNIL’s “bac à sable” (sandbox) program has run thematic cohorts since 2021 and is the closest operational analogue. Healthcare AI deployers can also use Health Data Hub authorizations as a parallel innovation route. The pending DDADUE bill means operators should confirm the current Article 57 national implementation route rather than assume the existing CNIL program is the formal AI Act sandbox.

Articles 9 to 15, conformity assessment, GPAI, penalties

These obligations apply EU-wide and are not France-specific. To keep this page focused on locality, the in-depth treatment of Articles 9 to 15, the conformity-assessment workflow, GPAI provider duties, and the Article 99 penalty structure is maintained on the main guide.

↑ For all-EU material, see the main guide

TopicAnchor on the main guide
Articles 9 to 15 explainerguide-eu-ai-act#requirements-by-category
Article 12 logging requirementsguide-eu-ai-act#requirements-by-category
Conformity-assessment workflowguide-eu-ai-act#compliance-roadmap
GPAI obligations and Code of Practiceguide-eu-ai-act#gpai-requirements
Article 99 penalty structureguide-eu-ai-act#penalties-enforcement
Member-state implementation tableguide-eu-ai-act#member-states

References

  1. European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
  2. CNIL. Plan stratégique 2025-2028. cnil.fr.
  3. Direction générale des Entreprises. Les autorités compétentes pour la mise en œuvre du règlement européen sur l’intelligence artificielle. entreprises.gouv.fr.
  4. ANSSI. Tasking on AI Act cybersecurity competences, April 2026.
  5. French Senate. DDADUE legislative dossier, updated 24 August 2026: Senate adoption on 18 February 2026 and transmission to the National Assembly on 20 February. senat.fr.
  6. Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
  7. European Commission. AI Omnibus enters into force, 27 July 2026. digital-strategy.ec.europa.eu.
  8. European Parliament. AI Act deal on simplification measures; ban on nudifier apps, April 2026. europarl.europa.eu.

Build the evidence trail

French operators: selected control records for the wider evidence trail.

For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by CNIL or a notified body.

Talk to us See an evidence pack →

Bring us the action that matters. We’ll map the intended controls, operational decision points, and evidence gaps.