Skip to content

The Legal Framework of AI in France: Issues, Laws, and Perspectives

The DDADUE bill, adopted by the Senate on February 18, 2026, remains in first reading at the National Assembly at the end of July 2026. The French architecture for AI supervision does not yet have legal value. Companies operate in a…

Avocate française analysant des documents juridiques sur la réglementation de l'intelligence artificielle dans un bureau parisien moderne

The DDADUE bill, adopted by the Senate on February 18, 2026, remains in first reading at the National Assembly at the end of July 2026. The French architecture for AI supervision does not yet have legal value.

Companies operate in a regulatory gray area where the European regulation sets obligations without the competent authorities being formally designated.

Distribution of competencies among French authorities: what the DDADUE project provides

The DDADUE text organizes an unprecedented sectoral division. The CNIL would be the main authority for the majority of high-risk systems listed in Annex III of the AI Act. Arcom would inherit the missions related to prohibited practices and content transparency, notably deepfakes.

The ACPR would oversee AI systems deployed in the financial sector, while the DGCCRF would supervise consumer products and vocational training. An intersectoral coordination mechanism is planned to arbitrate overlaps.

We observe that this multi-authority distribution contrasts with the centralized model chosen by other member states. The French approach disperses competence, raising concrete questions: which authority for an AI system used both in banking credit and consumer protection? The text does not clearly address this point. Understanding the legal framework for AI in France therefore requires following the parliamentary evolution of this project, not just the European regulation.

French software engineer examining a code screen and compliance requirements with the European AI law

AI Act obligations as of August 2, 2026: high-risk systems and technical documentation

August 2, 2026 marks the entry into force of obligations related to high-risk AI systems. Specifically, any provider or deployer of a system classified in Annex III must have established a risk management system, documented governance of training data, and a human oversight mechanism.

Technical documentation becomes enforceable. It must cover the system description, its purpose, performance metrics, identified biases, and mitigation measures. Providers must also maintain an activity log accessible to the supervisory authority.

For French companies, the uncertainty regarding the designation of authorities does not suspend these obligations. The regulation has direct effect. A provider marketing an HR scoring system or a candidate sorting tool is required to comply by August 2, 2026, even if the CNIL has not yet formally received its supervisory mandate.

Transparency obligations for general-purpose AI

Since August 2, 2025, providers of general-purpose AI (GPAI) models must publish a sufficiently detailed summary of the training data. This obligation aims to allow copyright holders to exercise their opt-out right as provided by the directive on copyright in the digital single market.

GPAI models presenting systemic risk are subject to enhanced requirements: adversarial assessment (red teaming), notification of serious incidents, and documentation of the model’s energy consumption.

Interaction between AI Act and GDPR: the issue of training data

Training AI models on personal data remains the major friction point between the two regulations. The CNIL has published several series of recommendations on the subject, and its priority controls for 2026 explicitly target AI uses.

Three points of vigilance emerge for companies:

  • The legal basis for processing: legitimate interest, often invoked for training, requires documented proportionality analysis, not just a simple mention in the processing register.
  • The right to object and erase applied to already trained models: the CNIL examines whether a model can technically “unlearn” a data point, and how the data controller manages this practical impossibility.
  • Data transfers to model providers located outside the EU: standard contractual clauses do not always cover the use of data for further training purposes by the subcontractor.

Agentic AI and data protection

In 2026, the CNIL published a note dedicated to agentic AI, systems capable of executing tasks autonomously by chaining multiple actions. Agentic AI poses a problem of persistent memory: an agent that retains the context of successive interactions accumulates personal data without the user necessarily being aware of the extent.

The note reminds that each autonomous action of the agent constitutes a distinct processing operation under the GDPR. The data controller must therefore provide mechanisms for purging, limiting memory, and informing the user at each step of the action chain.

Institutional meeting of French professionals discussing the ethical and legal issues of artificial intelligence

Civil liability and AI: the ongoing gap in French law

The AI Act regulation does not address civil liability. The proposed European directive on liability in AI, which was supposed to complement the framework, did not materialize within the initially planned deadlines. French common law on liability remains the applicable framework by default.

In practice, liability for defective products (Articles 1245 and following of the Civil Code) may apply to an AI system embedded in a product. The difficulty lies in proving the defect: demonstrating that a machine learning model produced a harmful result due to a “defect” requires access to its internal logic, which the opacity of models often makes impossible.

Contractualization then becomes the main lever for risk management. We recommend incorporating specific clauses in contracts for the provision of AI systems regarding the distribution of liability in case of erroneous automated decision-making, the supplier’s documentation obligation, and the audit modalities of the model.

The legal framework for AI in France is being built in layers, between a directly applicable European regulation, an unfinished national transposition, and supervisory authorities preparing their tools without yet having their final mandate. Companies waiting for final clarification to act are taking a risk: the obligations of August 2, 2026, will not wait for the promulgation of the DDADUE law.

The Legal Framework of AI in France: Issues, Laws, and Perspectives