France offers one of the most developed national case studies in financial-sector AI governance anywhere in the European Union. Long before the EU AI Act existed as a text, the French prudential supervisor had already opened a public consultation on algorithmic governance in banking and insurance, and the French markets regulator has since built one of the more detailed empirical pictures of AI adoption among any securities regulator in Europe. For banks, insurers and asset managers operating in France, understanding what is expected of them means reading three layers together: the binding EU AI Act, sector-specific EU guidance from the European Supervisory Authorities, and nearly a decade of French supervisory work led by the Autorité de Contrôle Prudentiel et de Résolution (ACPR, the arm of the Banque de France responsible for banking and insurance supervision) and the Autorité des Marchés Financiers (AMF, the securities and asset management regulator).

The EU AI Act as the binding backbone

As an EU member state, France applies Regulation (EU) 2024/1689, the AI Act, directly, as amended by the Digital Omnibus published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Under that amended timeline, the high-risk obligations attaching to standalone, Annex III systems, which include creditworthiness assessment and life and health insurance risk-pricing, are deferred to 2 December 2027, while obligations for AI embedded in regulated products under Annex I move to 2 August 2028. The general transparency duties in Article 50, covering disclosure obligations such as informing people they are interacting with an AI system, were not postponed and still take effect from 2 August 2026. This EU timetable is the single most important date-driven fact for French financial institutions building AI compliance roadmaps, and it applies uniformly regardless of what French supervisors additionally expect.

Banque de France and the ACPR: nearly a decade of supervisory groundwork

The ACPR's engagement with AI predates the AI Act by several years. Its early 2018 report on the digital transformation of banking and insurance identified a proliferation of machine learning projects across supervised institutions, prompting the ACPR to set up a dedicated task force bringing together financial sector professionals and public authorities to examine current and prospective uses of AI, alongside the opportunities and risks involved (ACPR, discussion paper on AI and the financial sector). A first discussion paper, published in December 2018, and public consultation followed, and the ACPR published a synthesis of the feedback it received in June 2019 (ACPR, consultation feedback report). From March 2019 the ACPR also ran exploratory technical workshops with financial institutions focused specifically on the explainability and governance of machine learning, covering three use cases: anti-money-laundering and counter-terrorist-financing controls, internal credit-scoring models, and customer protection (ACPR, document de réflexion).

That groundwork produced the ACPR's most-cited AI publication to date: the 11 June 2020 discussion document on the governance of artificial intelligence algorithms in the financial sector, opened to public consultation until 4 September 2020 (ACPR, Gouvernance des algorithmes d'intelligence artificielle dans le secteur financier), with an English-language version published as Governance of Artificial Intelligence in Finance. The paper set out four principles against which supervised institutions should evaluate AI algorithms and tools: data management, performance, stability, and explainability. The paper is also understood to have addressed varying levels of explanation suited to different purposes, such as informing the customer, ensuring consistency in human decision workflows, or supporting model validation and monitoring, and an approach to auditing AI systems that combines review of source code, data and documentation with methods that generate explanations for individual decisions or overall model behaviour. Because the ACPR's website blocks automated retrieval of the underlying document, the precise terminology used for these explanation levels and audit techniques should be confirmed against the primary source before being treated as a settled reference framework.

2026: from discussion papers to formal AI Act oversight

Six years on, the ACPR's work has moved from exploratory discussion toward formal supervisory positioning under the AI Act. On 1 July 2026 the ACPR convened an industry-wide briefing, a "réunion de place", titled "Encadrement et surveillance de l'IA dans le secteur financier" to set out how it intends to supervise AI under the EU regulation (ACPR, réunion de place, 1 July 2026). The briefing confirmed that the AI Act's high-risk rules relevant to finance, covering systems used to assess the creditworthiness of individuals and systems used for risk assessment and pricing in life and health insurance, apply from 2 December 2027, consistent with the Annex III deferral introduced by the Digital Omnibus. The ACPR also described four ongoing workstreams, fairness, explainability, performance and robustness, and cybersecurity and data protection, with syntheses expected by the end of the fourth quarter of 2026.

Alongside that briefing, the ACPR opened a public consultation on algorithmic fairness in the financial sector, running until 30 September 2026, built around a new reflection document (ACPR, consultation publique sur l'équité algorithmique). The consultation frames algorithmic fairness as the set of principles and methods needed to design and govern systems that avoid unjustified inequalities linked to sensitive personal characteristics, and it explicitly names the underlying tension for the sector: reconciling risk-based price differentiation, which is central to the economic viability of insurance and credit models, with the prevention of unfair or discriminatory treatment. The ACPR states it is working toward an evaluation methodology for AI systems in finance that could eventually serve as a shared reference framework for both institutions and the supervisor itself.

On institutional roles, French authorities have been working through a legislative process (commonly referred to by the DDADUE shorthand used for laws adapting French law to EU legislation) to designate sectoral market-surveillance authorities under the AI Act. The government's published framework describes a general, decentralised principle under which an enterprise already regulated in its sector will, in the vast majority of cases, continue to deal with its usual regulator for AI Act purposes (Direction générale des Entreprises and DGCCRF, draft designation of national authorities), which points toward the ACPR as the likely authority for AI systems used in creditworthiness assessment, credit scoring, and insurance risk assessment and pricing, though that specific attribution is an inference from the general principle rather than a designation named in the cited document itself. As with France's broader national AI Act supervisory architecture, where designations of market-surveillance authorities missed the original 2025 deadline, the precise legal instrument and date finalising the ACPR's financial-sector mandate should be confirmed against the ACPR's and the government's own publications rather than assumed.

Banque de France: the macro-prudential and research lens

Separately from ACPR supervisory guidance, the Banque de France's leadership has repeatedly framed AI as both an opportunity and a systemic-stability question for the financial sector, through a series of public interventions including remarks on the foundations of trustworthy AI in finance, the challenges AI poses from a central bank's perspective, and how to implement effective surveillance of AI in the financial sector (Banque de France, governor's interventions). The Banque de France has also published research examining the legal and regulatory impacts of artificial intelligence, dated July 2025 (Banque de France, Rapport 68), feeding a broader institutional view that AI oversight in finance needs to combine microprudential supervision of individual institutions with a macro-level watch for concentration risk, herding, and third-party dependency across the sector.

The AMF: mapping adoption before writing rules

The AMF has taken a deliberately evidence-first approach, prioritising a detailed empirical study of how French market participants actually use AI before issuing prescriptive guidance. In February 2026 it published The Use of AI by Financial Market Participants in France, a study conducted in coordination with the European Securities and Markets Authority (ESMA) as part of a pan-European initiative, drawing on 100 responses from AMF-supervised financial entities, listed companies, and law and audit firms, supplemented by data from the AMF's Savings and Investment Barometer (AMF, study on the use of AI). The headline finding was that adoption is now near-universal in intent: 90 percent of respondents said they already use AI or plan to within twelve months, with generative AI the most widely deployed technology, and 54 percent, many of them large firms, reporting use cases already in live production rather than pilot stage (AMF, news release). The same news release describes some market infrastructures as already running live use cases and developing further ones, concentrated on internal tasks such as data extraction and synthesis, report drafting, and summary generation via generative tools, and describes a wide majority of respondents expecting their AI investment to keep growing; the more granular use-case counts and investment-growth percentages should be confirmed against the underlying report's own data tables before being cited as precise figures.

The AMF has translated that adoption data into supervisory emphasis rather than a standalone AI rulebook so far, most visibly by calling on financial market participants to strengthen cybersecurity arrangements in light of AI-related threats (AMF, cyber resilience communication), and by contributing to the International Organization of Securities Commissions' (IOSCO) work on AI in financial markets (AMF, on the IOSCO AI report). AI and data quality also featured as a headline theme at the AMF's 2025 international seminar for securities regulators, alongside financial stability and financial education (AMF, 2025 international seminar). For asset managers and investment advisers specifically, existing AMF doctrine on investment services, including its position on the definition of investment advice, continues to apply in full to AI-assisted or AI-driven advice tools; the AMF has not signalled a bespoke AI carve-out from MiFID II-derived conduct-of-business obligations.

EU-level sectoral guidance: ESMA, EIOPA and EBA

French institutions operating in securities, insurance and banking should also track guidance issued directly by the European Supervisory Authorities, which applies across the EU and sits alongside French supervisory expectations. ESMA issued a public statement on 30 May 2024 giving initial guidance to firms using AI in the provision of investment services, confirming that existing MiFID II requirements on organisational arrangements, conduct of business, and acting in clients' best interests apply fully to AI-assisted customer support, investment advice, portfolio management, compliance, and fraud detection, and flagging algorithmic bias, opaque decision-making, and over-reliance on AI outputs as key risks (ESMA, public statement on AI and investment services). EIOPA published its Opinion on Artificial Intelligence Governance and Risk Management (EIOPA-BoS-25-360) on 6 August 2025, addressed to national insurance supervisors and setting high-level expectations for a risk-based, proportionate approach to AI across its lifecycle, meaningful explainability of outcomes, and fairness toward consumers, applying to AI systems in insurance that are not already classified as prohibited or high-risk under the AI Act (EIOPA, Opinion on AI governance and risk management). On the banking side, the European Banking Authority's earlier Report on Big Data and Advanced Analytics (EBA/REP/2020/01), published 13 January 2020, remains a reference point, identifying four pillars for sound adoption, data management, technological infrastructure, organisation and governance, and analytics methodology, that closely parallel the ACPR's own 2020 framework (EBA, Report on Big Data and Advanced Analytics).

What this means in practice

For banks, insurers and asset managers active in France, three obligations run in parallel and none substitutes for the others. First, the AI Act itself: general transparency duties under Article 50 apply from 2 August 2026 regardless of sector, while the high-risk obligations most relevant to finance, on creditworthiness assessment and life and health insurance pricing, apply from 2 December 2027. Second, sectoral EU guidance from ESMA and EIOPA already applies existing conduct, governance and risk-management rules to AI use cases today, well ahead of the AI Act's high-risk deadlines, meaning firms cannot treat 2027 as the starting line for AI governance generally. Third, French supervisory expectations, the ACPR's explainability and governance framework dating to 2020, its ongoing fairness, explainability, performance and robustness, and cybersecurity and data protection workstreams due to conclude by the end of 2026, and the AMF's adoption-driven emphasis on cyber resilience, together indicate that institutions should expect model documentation, explainability evidence, and fairness testing to be examined in supervisory dialogue well before any AI Act deadline forces the issue.

What to watch

  • The close of the ACPR's public consultation on algorithmic fairness in the financial sector, 30 September 2026, and the reflection document it is built on.
  • The ACPR's syntheses of its four AI workstreams, fairness, explainability, performance and robustness, and cybersecurity and data protection, expected by the end of Q4 2026.
  • Final confirmation of the ACPR's designation as market-surveillance authority for high-risk AI systems in credit and insurance, part of France's still-unfinished domestic AI Act authority designations.
  • The AI Act's 2 August 2026 Article 50 transparency deadline, applicable now regardless of sector.
  • The 2 December 2027 date for Annex III high-risk obligations covering creditworthiness assessment and insurance risk-pricing.

Primary sources

Related articles