← Global AI Policy Radar · Methodology
Jurisdiction Baseline · AI × Policy

AI Regulation in France.

At a glance
AI-Specific Law
No standalone law; EU AI Act applies directly
EU AI Act
Rules apply now; remaining duties phase in
Data Protection
GDPR and French law govern personal data
Sector Enforcement
Consumer, platform, and sector regulators can act

France has no standalone, comprehensive AI-specific law; AI is mainly governed by the directly applicable EU AI Act, an EU regulation that is already partly in force, with prohibited practices and AI literacy rules applying, general-purpose AI obligations applying, and the remaining rules phased in, including recently delayed deadlines for high-risk systems. The GDPR, an EU privacy regulation, and France’s Data Protection Act are the main practical constraints on using personal data, while consumer, employment, health, product-safety, cybersecurity, and platform rules may also apply; enforcement is already active through CNIL, DGCCRF, Arcom, and sector regulators, although France’s AI Act market-surveillance system is still being established.

In force today5 instruments
Artificial Intelligence Act, as amended by Regulation (EU) 2026/1744 partially in forceAI-specific
The EU AI Act applies directly in France. Prohibited practices and AI literacy obligations already apply, general-purpose AI model rules apply, and the main system requirements are phasing in; the 2026 amendment moves many high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products.
AI / automated decisionsDisclosureSafety & security
General Data Protection Regulation in force
The GDPR applies whenever an AI system processes personal data, including for training, fine-tuning, inference, monitoring, profiling, or employee management. Companies must address lawful basis, transparency, data-subject rights, purpose limitation, data minimization, security, automated decision-making, impact assessments, and processor or joint-controller arrangements.
Data processingDisclosureSafety & security
Unlock the full baseline

Get the remaining 3 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.

Already subscribed? Unlock →

Loi Informatique et Libertés in force
This French statute supplements the GDPR, sets national rules and exemptions, and provides the legal basis for CNIL supervision and enforcement in France. CNIL guidance on AI development, scraping, model training, security, and high-risk processing is an important indicator of enforcement expectations.
Data processingSafety & security
Loi visant à sécuriser et à réguler l'espace numérique in force
This French law supplies national implementation and enforcement arrangements for the EU Digital Services Act, including the roles of Arcom, CNIL, and DGCCRF. It matters when AI is used in an online platform, recommender system, chatbot, search service, content-moderation workflow, or service handling illegal or harmful content, especially involving minors.
Content moderationDisclosureMinors
Code de la consommation in force
French consumer law applies to AI products and services marketed to consumers, including AI-generated claims, automated customer interactions, subscription terms, pricing, recommendations, and disclosures about system capabilities. Misleading commercial practices, unfair terms, unsafe products, and inadequate pre-contract information can trigger DGCCRF action even where the AI Act does not apply.
Consumer protectionDisclosureSafety & security
Also worth noting
  • AI Act high-risk obligations now have staggered deadlines of 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in products, following Regulation (EU) 2026/1744.
  • AI Act transparency rules for synthetic content apply from 2 August 2026, with systems already placed on the market receiving until 2 December 2026 for the Article 50(2) marking requirement.
  • Monitor French designation of AI Act market-surveillance authorities and final Commission guidance on high-risk classification, expected by the end of 2026.
Pending and recent legislation3 measures
FR DLR5L17N53359 DLR5L17N53359, Bill establishing a presumption that AI providers use cultural content
Advancing · 2026-06-10
The bill would establish a legal presumption that providers of artificial intelligence systems use cultural content, likely affecting proof, transparency, and related rights or remuneration claims. It targets the relationship between AI providers and creators or holders of cultur
FR DLR5L17N54339 DLR5L17N54339, Bill proposal to generalize algorithmic video surveillance
Advancing · 2026-05-12
The proposal would expand the use of algorithmic video surveillance systems, likely enabling automated analysis of video feeds for public-safety purposes. It is a legislative bill currently under consideration by the relevant committee.
FR DLR5L17N51569 Bill to regulate the siting of data centers in France
Advancing · 2026-03-26
This bill proposes rules governing the establishment and siting of data centers across France. It addresses data-center deployment as a matter of national territorial and infrastructure policy.

Live from the Global AI Policy Radar.

Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?

France has no standalone, comprehensive French AI Act. The EU AI Act applies directly in France and is already partially in force, including rules on prohibited practices, AI literacy, and general-purpose AI models.

Who are the key regulators for AI?

Key regulators include CNIL for data protection, DGCCRF for consumer and product-related issues, and Arcom for online platform and digital-service matters. Sector regulators may also be involved, while France’s market-surveillance structure for the AI Act is still being operationalized.

Which rules apply to AI systems today?

The EU AI Act, GDPR, and France’s Data Protection Act are the main rules. Depending on the use case, the Digital Services framework, consumer law, employment, health, product-safety, and cybersecurity rules may also apply.

What is coming next, and when?

The EU AI Act’s remaining requirements are phasing in. Following the 2026 amendment, many high-risk obligations apply from 2 December 2027 for Annex III systems and from 2 August 2028 for AI embedded in regulated products.

What are the enforcement and penalty risks?

Enforcement is already real through CNIL, DGCCRF, Arcom, and sector regulators, even though the AI Act market-surveillance structure is still being set up. Risks include action over unlawful personal-data processing, misleading consumer practices, unsafe products, platform obligations, and breaches of applicable AI Act requirements.

Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.

Need a company-specific assessment? Explore Nomos →