France governs AI mainly through EU law applied directly, above all the EU AI Act and the GDPR, implemented in France by the Loi Informatique et Libertes and enforced by the CNIL. There is no France-specific AI statute. What France still has to settle is the domestic plumbing of the AI Act: it has chosen a decentralised model across many authorities, with the CNIL as the reference authority, but the formal designations are still being legislated and France missed the EU August 2025 deadline. This page sets out the instruments, the dates, and which ones are binding versus guidance, with links to the primary sources.
Last reviewed: 22 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
For an organisation in France, the binding rules on AI come from EU law: the EU AI Act, which applies directly without national transposition, and the GDPR, implemented in France by the Loi Informatique et Libertes and enforced by the CNIL. France has not enacted its own comprehensive AI statute, and none is planned; the national effort is about designating which authorities supervise the AI Act.
That designation is still unfinished. France has chosen a decentralised, sectoral model spread across many authorities, with the CNIL as the central reference authority and the DGCCRF as coordinator, but it missed the EU deadline of August 2025 and the enabling legislation was still moving through Parliament in 2026. In the meantime, the CNIL's detailed recommendations on AI and the GDPR are the clearest practical signal of how French supervision works, and France's posture is emphatically pro-innovation, symbolised by the February 2025 Paris AI Action Summit.
France passed one of the world's first data-protection laws, Law No. 78-17, creating the CNIL. It was heavily rewritten in 2018 to sit alongside the EU GDPR, and it remains the French statute through which most AI-relevant data-protection rules are enforced.
Having created a dedicated AI department earlier in 2023, the CNIL published a four-pillar AI action plan covering understanding AI systems, guiding privacy-respecting development, supporting innovation, and auditing and controlling AI. It extended the CNIL's work explicitly to generative AI and chatbots.
The CNIL issued its first set of how-to recommendations on applying the GDPR to the development of AI systems, covering purpose definition, the controller and processor roles, legal basis, data reuse, minimisation, retention and impact assessments. They are guidance interpreting the binding GDPR, focused on the development phase.
The EU AI Act (Regulation 2024/1689) entered into force and applies directly in France as an EU regulation, with no national transposition needed. Its obligations phase in over the following years, layered on top of French and EU data-protection law.
France hosted the AI Action Summit in Paris, co-chaired with India, and announced around 109 billion euros of mostly private AI investment. The summit signalled France's pro-innovation, sovereignty-focused posture; its declaration and pledges are strategy and commitments rather than binding rules.
This was the EU deadline for member states to formally designate the national authorities that supervise and enforce the AI Act. France missed it: the enabling legislation was still in progress, leaving the national supervisory map legally unsettled.
The Direction generale des Entreprises published the proposed allocation of AI Act supervision across roughly fifteen to seventeen authorities, a puzzle model rather than a single AI regulator. The CNIL is positioned as the central reference authority and the DGCCRF as the coordinating point of contact, but the designations still require legislation.
The CNIL published recommendations confirming that AI development, including collecting publicly accessible online data, can rely on the GDPR legitimate-interest basis subject to a three-part test and safeguards, and further guidance on when an AI model is itself subject to the GDPR, on data annotation and on development security.
Most of what binds AI in France is EU-derived law applied directly. The table below sorts the main instruments by whether they carry legal force or are guidance and strategy.
| Instrument | Status | Applies to / owner |
|---|---|---|
| EU AI Act (Regulation 2024/1689) | Binding | Providers and deployers of AI in France (national supervisory authorities being designated) |
| GDPR and the Loi Informatique et Libertes (Law 78-17) | Binding | Any organisation using personal data, including in AI (enforced by the CNIL) |
| French Labour Code, works-council consultation (Art. L2312-8) | Binding | Employers introducing AI or automated tools affecting employees (the CSE) |
| CNIL recommendations on AI and the GDPR (2024 to 2025) | Guidance on the GDPR | Organisations developing AI with personal data |
| ACPR and AMF work on AI in finance | Supervisory guidance | Banks, insurers and financial-market participants |
| National AI strategy and Paris summit commitments | Strategy, not a rule | Whole-of-government direction, not an obligation on firms |
For the wider picture across jurisdictions, see our AI regulation by country comparison and the neighbouring Germany and Netherlands references, which face the same EU AI Act.
The binding obligations come from the EU AI Act and the GDPR as applied in France, not from a national AI law. The CNIL's recommendations are the clearest guide to how French supervision works in practice, especially on training data, legitimate interest and web scraping, and employers should remember the works-council consultation duty when they deploy AI internally.
Because the national AI Act authority map is still being finalised, the practical watch item is the enabling legislation that confirms the supervisory structure. Until then, aligning to the EU AI Act and following the CNIL's guidance is the sound course. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
No. France has no comprehensive France-specific AI statute. AI is governed by the directly applicable EU AI Act plus existing French and EU law, above all the GDPR and the Loi Informatique et Libertes, enforced by the CNIL. What France still has to legislate is only which national authorities supervise and enforce the AI Act.
France has chosen a decentralised, sectoral model with roughly fifteen to seventeen authorities rather than a single AI regulator. The CNIL is positioned as the central reference authority, covering data protection, biometrics, employment and prohibited practices, and the DGCCRF as the coordinating point of contact. As of mid-2026 these designations are still being legislated, and France missed the EU deadline of 2 August 2025.
The CNIL created a dedicated AI department in 2023 and published an AI action plan and a series of recommendations on how the GDPR applies to AI, covering purpose, legal basis including legitimate interest for training data, web scraping, informing individuals, data-subject rights, and when an AI model is itself subject to the GDPR. These are guidance interpreting the binding GDPR.
The CNIL has said AI development, including collecting publicly accessible online data, can rely on the GDPR legitimate-interest basis, subject to a three-part test (a legitimate interest, necessity, and a balancing against individuals' rights) and safeguards such as data minimisation, transparency, and respecting sites that object to scraping.
Under the French Labour Code, an employer that introduces AI or automated tools affecting employees must inform and consult the works council (the Comite social et economique, or CSE) beforehand, as part of its duties on new technologies and changes to working conditions.
France is emphatically pro-innovation and sovereignty-focused. It hosted the AI Action Summit in Paris in February 2025 and announced around 109 billion euros of AI investment. These are strategy and commitments rather than binding regulation, and they sit alongside, not instead of, the binding EU AI Act.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, a practical first step toward EU AI Act and GDPR alignment in France.
This page is general information describing the state of France AI policy as at 22 July 2026, not legal or compliance advice. The national supervisory designations are still being legislated; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.