CNIL's expanding footprint in French AI governance

The Commission Nationale de l'Informatique et des Libertes, France's data protection authority since 1978, has become the country's most active AI regulator in practice, even though its statutory mandate is the GDPR and the domestic Loi Informatique et Libertes rather than AI as such. Because almost every AI system of consequence, from a customer-service chatbot to a generative model trained on scraped web text, processes personal data at some point in its lifecycle, the CNIL's data protection powers reach deep into AI development and deployment. The CNIL states that it remains "fully competent to apply the GDPR" to AI providers established in France, including providers of general-purpose AI models, and intends to guide compliance with the GDPR and the EU AI Act together rather than as separate exercises, as set out in its own questions and answers on the entry into force of the AI Act.

This positioning matters because France is home to prominent AI developers, including Mistral AI, whose main establishment in Paris puts it under the CNIL's lead GDPR supervision, a point noted in commentary following the CNIL's 2025 guidance wave, including analysis from Skadden, Arps, Slate, Meagher and Flom. That gives the CNIL's interpretive choices on legal basis, data subject rights and what counts as personal data inside a trained model outsized influence on how AI companies operating from France build their systems, independent of whatever national AI Act authority is eventually confirmed.

From the 2023 action plan to a body of AI-specific recommendations

The CNIL's AI work began with a dedicated internal AI unit created in January 2023, ahead of a four-pillar action plan the CNIL published in May 2023 covering understanding how AI systems work, enabling privacy-respecting development, supporting the French and European AI ecosystem, and auditing and controlling AI systems, described on the CNIL's action-plan page. That plan set a staged, consultative agenda rather than a single omnibus document.

A first series of practical how-to sheets on constituting AI training databases went to public consultation in October 2023, and the CNIL finalised its first set of recommendations on applying the GDPR to AI system development on 8 April 2024, the date given on the CNIL's original French-language announcement. The English-language version of that announcement, cited here as the source for this section, carries a later 7 June 2024 publication date, which appears to mark when the translation was posted rather than a separate finalisation of the recommendations. That tranche addressed determining the applicable legal framework, defining a clear purpose for an AI system, qualifying the roles of the actors involved as controllers, joint controllers or processors, selecting a lawful basis, when a data protection impact assessment is required, and building in data protection by design. The CNIL noted that these recommendations account for the EU AI Act adopted the same year, and that where personal data is used to develop an AI system, the GDPR and the AI Act both apply, one does not substitute for the other.

Guidance continued to accumulate through individual "fiches pratiques," short, topic-specific sheets rather than one monolithic document, indexed on the CNIL's AI practical sheets page. By mid-2025 that index ran to roughly thirteen sheets, covering web scraping, data annotation, development security, and whether a given AI model falls within GDPR scope.

Legitimate interest as a legal basis for training data

One of the CNIL's most closely watched positions concerns the legal basis for using personal data, including data scraped from the open web, to train AI models. Rather than requiring consent from every individual whose data might appear in a training set, an approach the CNIL itself regards as often impractical at AI-training scale, it confirmed in a recommendation published on 19 June 2025 that legitimate interest under the GDPR can serve as a lawful basis for AI development, provided organisations run and document the GDPR's three-part legitimate interest test and put concrete safeguards in place. The recommendation is set out on the CNIL's page on development of AI systems and legitimate interest.

The safeguards described include excluding certain categories of data from collection, giving individuals a genuine opt-out, favouring pseudonymisation or anonymisation where feasible, and respecting technical signals that a website objects to scraping. The CNIL has also indicated that reusing chatbot conversations to further train a model can rely on legitimate interest where similar protections, including notice and an opt-out, are in place. This is guidance interpreting an existing GDPR legal basis, not a new AI-specific exemption, and the burden of showing the balancing test comes out favourably still sits with the organisation.

Informing individuals and enabling their rights inside AI systems

A harder operational problem is satisfying GDPR transparency and individual-rights obligations once personal data has been absorbed into a trained model, where it may no longer exist as an identifiable, extractable record. The CNIL addressed this in two recommendations published on 7 February 2025, described on its page on AI and GDPR: new recommendations to support responsible innovation: one on informing people that their data trains a model, the other on ensuring and facilitating the exercise of data subjects' rights.

On transparency, the CNIL accepts that individual, one-to-one notice is not always feasible for data gathered at web scale, and allows general information, for example a clear website notice or model documentation, where directly contacting each person would be disproportionate. On rights, it confirms that people retain rights of access, rectification, objection and erasure over personal data used in AI development, while acknowledging that architecture can make individual-level deletion technically difficult once a model is trained. Where that is genuinely the case, the CNIL allows alternatives such as output filtering, documented exclusion logic applied at the earliest practical stage, and audit trails showing what was done and why. Its own language is candid that cost, impossibility or practical difficulties may sometimes justify refusing a rights request, but that determination must be made and documented case by case, not treated as a blanket exemption for AI systems.

Annotation, development security and whether the GDPR applies at all

The CNIL finalised its remaining first-wave recommendations on 22 July 2025 alongside its future work programme, described on its page on the finalisation of its AI system development recommendations. These covered protecting personal data during the annotation phase of building a training set, managing security risks specific to AI development environments, and, more fundamentally, determining whether a given AI model is itself subject to the GDPR at all, a threshold question addressed on the CNIL's page on analysing the status of an AI model with regard to the GDPR.

Alongside finalising these sheets, the CNIL set out further work under its 2025 to 2028 strategic plan: sectoral recommendations for education, health and employment, a framework for allocating responsibility among actors in an AI value chain, and, jointly with the cybersecurity agency ANSSI, a technical project called PANAME (Privacy Auditing of AI Models) to build audit tooling for assessing whether a model processes personal data, including through the memorisation of training data. Its LINC research and innovation laboratory is also carrying out explainability research launched in 2024, with initial findings due to be published on the LINC website. None of this is binding law; it signals future enforcement priorities rather than a present obligation.

How CNIL guidance sits alongside the EU AI Act

None of the CNIL's recommendations amend or supersede the EU AI Act, Regulation (EU) 2024/1689 as amended by the Digital Omnibus, which applies in France directly without national transposition. The CNIL is explicit that the AI Act does not replace the GDPR: where a system both processes personal data and falls within the AI Act's scope, for example as a high-risk AI system under Annex III, both frameworks apply cumulatively, one addressing data protection, the other AI-specific risk management and oversight.

The Digital Omnibus, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, deferred the AI Act's standalone Annex III high-risk obligations to 2 December 2027 and the Annex I embedded high-risk obligations to 2 August 2028, but left the Article 50 general transparency obligations, on disclosing AI-generated content and informing people when interacting with an AI system, on their original timetable, applicable from 2 August 2026. Those duties sit close to territory the CNIL has already worked through its own transparency recommendations, and organisations should expect its GDPR-based notice practices and the AI Act's Article 50 duties to be read together in France rather than as unrelated checklists.

The CNIL has also argued that data protection authorities are well placed to supervise high-risk AI systems given the overlap with GDPR supervision, a position set out on its page AI Act: data protection authorities want to be in charge of high-risk systems. That advocacy has not yet translated into a finalised French designation. The AI Act required member states to designate national market surveillance authorities by 2 August 2025, and France missed that deadline. A proposal from the Direction generale des Entreprises published on 9 September 2025 set out a decentralised model spanning roughly seventeen market surveillance authorities, with the CNIL covering around fifteen categories of AI use case, the consumer and competition authority DGCCRF around fourteen, and the broadcasting regulator ARCOM around seven. Reporting from the MIAI institute's tracking of the designation process notes that the provisions meant to formalise this scheme were subsequently withdrawn from the legislative vehicle carrying them through the French Parliament, leaving the designation unresolved well into 2026. Until it is confirmed, the CNIL's GDPR powers remain the most concrete lever French authorities have over AI systems that process personal data.

The financial sector overlay: ACPR, Banque de France and the AMF

Financial services carry an additional supervisory layer on top of the CNIL's data protection work and the AI Act itself. The Autorite de Controle Prudentiel et de Resolution, the banking and insurance supervisor housed within the Banque de France, has examined AI governance in financial institutions since a discussion paper on the governance of AI algorithms published in 2020, work it continues to build on as the AI Act's obligations phase in, described on the ACPR's page on governance of artificial intelligence in finance. Its focus has centred on model explainability, governance of internal models such as credit scoring, and AI's role in anti-money-laundering and fraud detection.

The Autorite des Marches Financiers, which supervises asset managers and market participants, published a study in February 2026 on AI adoption among French financial market actors, describing broad and growing use of AI tools across the sector. Neither the ACPR nor the AMF has issued AI rules overriding the GDPR or the AI Act; both operate through existing prudential and conduct powers, but firms should expect AI use cases touching credit decisions or algorithmic trading to draw scrutiny from sectoral supervisors as well as the CNIL.

Practical implications for organisations operating in France

For an organisation developing or deploying AI with any French nexus, the CNIL's recommendations function as the most detailed available roadmap for near-term compliance, even though large parts of the French AI Act supervisory map remain unsettled. In practice that means treating the CNIL's guidance and the binding GDPR obligations it interprets as the operational baseline, then layering the AI Act's own requirements on governance, documentation and, where applicable, conformity assessment, on top.

  • Document the legal basis for personal data used in AI training, including scraped data, and if relying on legitimate interest, complete and retain the CNIL's three-part balancing test rather than asserting the basis informally.
  • Build transparency notices that account for AI training even where individual notice is impractical, and be ready to justify why a general notice was sufficient for a given data source.
  • Establish a documented process for handling access, rectification, objection and erasure requests against AI systems, including a reasoned basis for any refusal grounded in genuine technical difficulty rather than convenience.
  • Treat the determination of whether a model falls within GDPR scope as a first step in any AI audit or impact assessment, using the CNIL's own analytical approach as a starting reference.
  • Track the DGE's proposed market surveillance allocation and the French legislative process, since the eventual AI Act authority, likely the CNIL for personal-data-related use cases, will inherit enforcement responsibility once designations are confirmed.
  • Financial institutions should map AI use cases against ACPR and AMF expectations in parallel with GDPR and AI Act compliance, particularly for credit, anti-money-laundering and customer-facing algorithmic tools.

The overall picture is a data protection authority moving well ahead of the still-unsettled AI Act institutional architecture in France. The CNIL's recommendations are not a substitute for AI Act compliance, and organisations should continue to monitor the primary sources below as the national designation process concludes and as the CNIL's sectoral work on health, education and employment is published.

Primary sources

Related articles