Scope: who is covered?
The EU AI Act (Regulation 2024/1689) defines its scope by the role performed and the connection with the Union, not by the nationality of the people concerned (Article 2(1)). It covers providers, whether established in the Union or in a third country, that place an AI system on the Union market or put one into service in the Union; deployers that have their place of establishment in the Union or are located there; third-country providers and deployers where the outputs produced by the AI system are used in the Union; as well as importers, distributors, authorised representatives and affected persons. A business in Geneva, Montreal or Casablanca therefore falls within scope if it places its system on the Union market or if that system's outputs are used there; a business in Paris or Brussels that deploys an AI system is covered by the regulation simply by virtue of its establishment in the Union.
The regulation distinguishes four risk categories. Prohibited AI practices (subliminal manipulation, social scoring by public authorities, real-time biometric recognition in public spaces in most cases) have been banned since 2 February 2025. High-risk AI systems, which cover sensitive areas such as employment, access to credit, health, education and essential services, are subject to strict obligations.
The key deadlines as updated (Omnibus agreement, May 2026)
The provisional agreement of 7 May 2026 between the Council of the EU and the European Parliament substantially changed the application timeline for high-risk AI:
- 2 February 2025: Prohibitions applicable (already in force)
- 2 August 2025: Obligations for general-purpose AI models (already in force)
- 2 August 2026: Transparency obligations, disclosure of AI chatbots, labelling of AI-generated content (NOT changed by the Omnibus)
- 2 December 2026: Watermarking of AI-generated content (Article 50(2)), a four-month grace period granted by the Omnibus
- 2 December 2027: Core obligations for Annex III high-risk AI (extended by 16 months by the Omnibus, previously August 2026)
- 2 August 2028: Annex I systems embedded in products (extended by one year by the Omnibus)
What French businesses need to do now
The immediate priority for French businesses is to carry out an inventory of the AI systems used across the organisation, whether developed in-house or bought from vendors. For each system, that inventory should identify: its purpose, the personal data processed, the decisions it influences or takes, and the people affected.
Risk classification comes next. The vast majority of AI systems used by businesses fall into the "limited risk" or "minimal risk" category, which means light obligations (essentially transparency requirements). Only a minority of systems, those used in HR, credit, insurance, education or public services, fall into the "high risk" category with its substantial obligations.
The role of the CNIL and the intersection with the GDPR
The Commission Nationale de l'Informatique et des Libertés (CNIL) remains the competent authority for AI-related data protection questions in France. The CNIL has published specific recommendations on AI systems, notably on recommender systems and automated decisions. These recommendations sit alongside Article 22 of the GDPR, which governs fully automated decisions with significant effects on individuals.
The EU AI Act and the GDPR create cumulative obligations for businesses that process personal data through AI systems. Both bodies of rules must be complied with simultaneously; neither derogates from the other.