AI regulation in France is shaped primarily by the EU AI Act, which entered into force across all member states and is now progressively applying its obligations to businesses operating in the French market. France has also developed its own national enforcement architecture, institutional bodies, and policy priorities that sit alongside the EU framework. For companies deploying or developing artificial intelligence systems in France, understanding both layers - the supranational and the national - is essential to avoid liability, maintain market access, and build compliant products.
This guide covers the current regulatory landscape, the key obligations under the EU AI Act as they apply in France, the role of French national authorities, sector-specific considerations, and the practical steps businesses should take to remain compliant.
The EU AI Act is the world';s first comprehensive horizontal legal framework for artificial intelligence. It applies directly in France as an EU regulation, meaning no transposition into French national law is required. The Act uses a risk-based classification system: AI systems are categorised as unacceptable risk, high risk, limited risk, or minimal risk, and obligations scale accordingly.
Unacceptable-risk systems are prohibited outright. These include AI used for social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), and systems that exploit psychological vulnerabilities to manipulate behaviour. Businesses operating in France must ensure none of their deployed systems fall into this category.
High-risk systems face the most demanding obligations. These include AI used in critical infrastructure, employment decisions, credit scoring, education, law enforcement, and medical devices. Providers and deployers of high-risk systems must implement conformity assessments, maintain technical documentation, register in the EU database, and establish human oversight mechanisms. The Act distinguishes between providers - those who develop and place AI on the market - and deployers - those who use AI in a professional context. Both carry distinct obligations.
Limited-risk systems, such as chatbots and deepfake generators, face transparency requirements. Users must be informed they are interacting with an AI system. Minimal-risk systems, such as spam filters, carry no mandatory obligations under the Act, though voluntary codes of conduct are encouraged.
France has designated the Commission Nationale de l';Informatique et des Libertés (CNIL) as a key national authority for AI oversight, particularly where AI intersects with personal data processing. CNIL has been active in issuing guidance on AI and GDPR compliance, and its role is expected to expand as the EU AI Act';s national competent authority structure is formalised.
The Autorité de Régulation de la Communication Audiovisuelle et Numérique (ARCOM) plays a role in regulating AI-generated content in media and broadcasting contexts. For AI systems used in financial services, the Autorité des Marchés Financiers (AMF) and the Autorité de Contrôle Prudentiel et de Résolution (ACPR) have issued guidance and are monitoring AI adoption in trading, credit assessment, and insurance underwriting.
France has also established the Comité de l';Intelligence Artificielle de la Nation, an advisory body that informs government policy on AI strategy and regulation. While it does not have enforcement powers, its recommendations shape the legislative and regulatory agenda. The French government';s broader AI strategy - including public investment in AI research and the positioning of France as a European AI hub - creates a policy environment that is broadly supportive of AI development while increasingly attentive to compliance.
A non-obvious requirement for many foreign businesses is that deploying an AI system in France, even from outside the EU, can trigger obligations under the EU AI Act if the system';s output is used in France. Territorial scope is broad, and businesses should not assume that operating from a non-EU jurisdiction removes them from the regulatory perimeter.
Compliance with ai regulation france requires businesses to map their AI systems against the EU AI Act';s risk categories and then implement the appropriate measures. The following obligations are the most operationally significant.
For high-risk AI systems, providers must conduct a conformity assessment before placing the system on the market. This involves preparing technical documentation that demonstrates the system meets the Act';s requirements on data governance, transparency, accuracy, robustness, and cybersecurity. The documentation must be kept up to date throughout the system';s lifecycle.
Deployers of high-risk AI systems in France must carry out a fundamental rights impact assessment before deployment. This requirement, which applies to public bodies and certain private deployers, is modelled on the GDPR';s data protection impact assessment and requires a structured analysis of how the AI system may affect individuals'; rights.
All providers and deployers of high-risk systems must register in the EU database for high-risk AI systems. This is a publicly accessible register maintained by the European Commission. Registration is a precondition for lawful deployment in France and across the EU.
General-purpose AI models - large language models and foundation models - face a separate set of obligations under the Act. Providers of these models must publish technical documentation, comply with EU copyright law, and publish summaries of training data. Models with systemic risk, defined by reference to training compute thresholds, face additional requirements including adversarial testing and incident reporting.
In practice, founders and compliance teams should consider that the Act';s obligations apply not only at the moment of deployment but on an ongoing basis. Post-market monitoring, incident reporting to national authorities, and regular updates to technical documentation are continuing requirements, not one-time tasks.
AI systems in France almost invariably process personal data, which means the General Data Protection Regulation applies in parallel with the EU AI Act. CNIL has published specific guidance on the intersection of AI and GDPR, addressing issues such as lawful basis for training data, data minimisation in AI models, and the rights of individuals whose data is used in automated decision-making.
Article 22 of the GDPR, which restricts solely automated decision-making with significant effects on individuals, is particularly relevant for AI systems used in credit scoring, recruitment, and insurance. In France, CNIL has taken enforcement action in this area, and businesses should ensure that human review mechanisms are in place where required.
A common mistake made by foreign companies entering the French market is to treat GDPR compliance and AI Act compliance as separate workstreams. In practice, they overlap substantially. Data protection impact assessments, records of processing activities, and data governance frameworks built for GDPR compliance provide a strong foundation for AI Act conformity assessments. Integrating the two reduces duplication and strengthens the overall compliance posture.
France';s national data protection law, the Loi Informatique et Libertés, implements and supplements the GDPR at the national level. It contains specific provisions on automated decision-making and profiling that go beyond the GDPR baseline in certain respects. Businesses should review both instruments when designing AI systems that process personal data in France.
If your business is navigating the intersection of AI compliance and data protection in France, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Beyond the horizontal EU AI Act framework, several French sectors have developed specific rules and supervisory expectations for AI use.
In financial services, the AMF and ACPR have jointly published guidance on the use of AI in asset management, credit underwriting, and insurance. The guidance addresses model risk management, explainability requirements, and the need for human oversight of AI-driven decisions. Financial institutions using AI in France are expected to integrate AI governance into their existing risk management frameworks and to document AI model performance on an ongoing basis.
In healthcare, AI medical devices are regulated under the EU Medical Device Regulation and the In Vitro Diagnostic Regulation, both of which apply in France. The Haute Autorité de Santé (HAS) has issued guidance on the evaluation of AI-based medical devices, and the Agence Nationale de Sécurité du Médicament et des Produits de Santé (ANSM) is the competent authority for market authorisation. AI systems used in clinical decision support that meet the definition of a medical device face a dual compliance burden: the EU AI Act';s high-risk requirements and the medical device regulatory pathway.
In employment, the use of AI for recruitment, performance monitoring, and workforce management is subject to both the EU AI Act';s high-risk classification and French labour law. The Code du Travail requires employers to inform and consult employee representative bodies before introducing new technologies that affect working conditions. AI-based monitoring or evaluation tools deployed in France must go through this consultation process, which can take several weeks and may result in modifications to the system.
In the public sector, French administrative law imposes additional transparency and accountability requirements on AI systems used in administrative decisions. The Loi pour une République Numérique and subsequent legislation require that individuals be informed when an administrative decision is made using an algorithm, and that the logic of the algorithm be explained on request.
Consider a US-based software company that has developed an AI-powered recruitment screening tool and wants to deploy it to French corporate clients. The tool analyses CVs and ranks candidates, which places it squarely in the EU AI Act';s high-risk category. Before the tool can be offered to French deployers, the provider must complete a conformity assessment, prepare technical documentation, and register the system in the EU database. French corporate clients who deploy the tool must conduct a fundamental rights impact assessment and ensure human oversight of final hiring decisions. They must also consult their works council before deployment under the Code du Travail. The timeline for completing these steps - conformity assessment, registration, and works council consultation - can realistically take three to five months if started from scratch.
Now consider a French fintech startup that has built a credit scoring model using machine learning. The model processes personal data and produces credit decisions that significantly affect individuals, triggering both Article 22 of the GDPR and the EU AI Act';s high-risk requirements. The startup must maintain a record of processing activities under the GDPR, conduct a data protection impact assessment, and implement a conformity assessment under the AI Act. CNIL is the primary supervisory authority for the GDPR aspects, while the ACPR oversees the prudential and model risk dimensions. The startup should expect ongoing supervisory engagement from both bodies and should build a compliance function capable of responding to information requests and audits.
The EU AI Act';s obligations are being phased in over a multi-year period. The prohibitions on unacceptable-risk systems applied first. Obligations for general-purpose AI models and their providers followed. High-risk system requirements are applying progressively, with different timelines depending on whether the system is newly placed on the market or already in use. Businesses should track the specific applicability dates for each category of obligation relevant to their systems.
France is expected to designate its national competent authority under the EU AI Act formally, consolidating the current multi-authority landscape. The designation will clarify which body has primary enforcement responsibility for different types of AI systems and will establish the national market surveillance and notification procedures required by the Act.
The European AI Office, established within the European Commission, has a central coordinating role for the regulation of general-purpose AI models. It works alongside national authorities and has the power to conduct investigations and impose penalties at the EU level. French businesses developing foundation models or large language models should monitor the AI Office';s guidance and codes of practice closely.
Many businesses underestimate the pace at which enforcement is developing. CNIL has already taken enforcement action on AI-related GDPR violations, and the broader AI Act enforcement machinery is being built out. Waiting for enforcement to begin before investing in compliance is a high-risk strategy.
To discuss your specific compliance obligations under French and EU AI law, contact info@vlolawfirm.com. We can assist with documents and filings across the full AI Act compliance cycle.
Does the EU AI Act apply to non-EU companies offering AI services in France?
Yes. The EU AI Act applies to providers and deployers of AI systems whose output is used in the EU, regardless of where the provider is established. A company based outside the EU that offers an AI system to French users or businesses is subject to the Act';s obligations if the system falls into a regulated category. Non-EU providers must appoint an authorised representative established in the EU. This representative acts as the point of contact for national authorities and bears certain compliance responsibilities. Failure to appoint a representative is itself a violation of the Act and can result in enforcement action.
How long does it take to complete a conformity assessment for a high-risk AI system in France?
The timeline depends on the complexity of the system, the quality of existing documentation, and whether a notified body is required. For many high-risk systems, conformity assessment can be conducted by the provider itself through an internal process, without involving a third-party notified body. In practice, a well-resourced internal assessment for a moderately complex system takes two to four months. Where a notified body is required - for example, for certain AI systems used as safety components in regulated products - the timeline extends further, as notified body capacity is limited and waiting times can be significant. Businesses should build conformity assessment timelines into their product development and market entry planning.
What are the penalties for non-compliance with the EU AI Act in France?
The EU AI Act sets maximum penalty levels at the EU level, with national authorities responsible for enforcement. Penalties for violations involving prohibited AI systems are set at the highest level, followed by penalties for violations of high-risk system obligations, and lower levels for other violations. For SMEs and startups, the Act provides for proportionality in penalty calculation. In addition to AI Act penalties, non-compliance that also involves GDPR violations can attract separate CNIL enforcement action, including fines calculated as a percentage of global annual turnover. The combination of potential penalties from multiple authorities makes a robust compliance programme a sound commercial investment.
AI regulation in France operates at the intersection of the EU AI Act, the GDPR, French national law, and sector-specific frameworks. The regulatory environment is active and evolving, with enforcement capacity building across multiple authorities. Businesses that invest in structured compliance now - mapping systems to risk categories, completing conformity assessments, and integrating AI governance into existing risk frameworks - are better positioned to operate sustainably in the French market.
VLO Law Firms advises international clients on AI regulation in France. We can assist with risk classification, conformity assessments, GDPR intersection analysis, regulatory filings, and engagement with French and EU supervisory authorities. To request a consultation, contact: info@vlolawfirm.com