The EU AI Act in France

How Regulation (EU) 2024/1689 applies in France, and the 10 AI instruments France has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

France’s own AI instruments

10 records tracked for France, beyond the EU-level Act above.

National authority in France

Named in France’s own records, not inferred.

Per France - Digital Space Regulation (2024-449)

  • CNIL (Commission Nationale de l'Informatique et des Libertés)Data protection oversight, new investigative competences and recommendations on IA and data processing.
  • ARCOM (Autorité de régulation de la communication audiovisuelle et numérique)Age verification, audiovisual referentials and platform supervision for audiovisual content.
  • ARCEP (Autorité de régulation des communications électroniques et des postes)Cloud market oversight and cooperation with CNIL under implementing decrees.

Per France - Biometric Recognition Bill (n°505)

Per France - Electronic Identification Service (2022-676)

Per France - National Investment Strategy

Per France - Mobile Authentication System (2019-452)

Per France - National AI Strategy

Per France - Algorithmic Decision Rights (2017-330)

Per France - Reference Data Provision (2017-331)

Per France - Digital Republic Law (2016-1321)

Penalties in France

As stated in France’s own records.

Per France - Biometric Recognition Bill (n°505)

  • Administrative sanctions by the CNIL, including fines and orders to suspend or cease processing.
  • Obligatory destruction of unlawfully processed biometric data and systems remediation orders.
  • Potential criminal liability under existing penal provisions for unauthorised capture, illegal processing or abuses by public agents.
  • Judicial remedies and compensation claims available to individuals harmed by unlawful identification or data processing.
  • Parliamentary orders and political accountability measures, including requests for supplementary information and reports.

Per France - Electronic Identification Service (2022-676)

  • Processing or security failures that infringe GDPR obligations may lead to administrative sanctions and corrective measures by the CNIL under EU and national law.
  • Contractual remedies, liability and sanctions applicable under public procurement and maintenance contracts entered into by ANTS for SGIN implementation.
  • Internal administrative or disciplinary measures for officials or designated agents who misuse access in breach of the decree or internal policies.
  • Civil liability for affected data subjects where unlawful processing causes demonstrable harm (subject to French civil law and GDPR principles).

Per France - National Investment Strategy

  • Suspension of payment instalments for non-compliance with contractual milestones.
  • Mandatory repayment/recovery of grants or advances used ineligible or contrary to contractual terms.
  • Termination of funding agreements for material breach, with potential clawback of funds.
  • Administrative exclusion from future public programmes and competitive calls run under France 2030.
  • Referral to judicial authorities in cases suggesting fraud or criminal wrongdoing under French law.
  • Reputational impacts through public disclosure of sanctions or funding recoveries.

Per France - Mobile Authentication System (2019-452)

  • Administrative fines and measures under the GDPR (up to applicable statutory maximums depending on the infringement) enforceable by CNIL.
  • CNIL orders to bring processing into compliance (suspension, corrective measures, publicity of decisions).
  • Civil liability for damages caused by unlawful processing or data breaches (claims by affected individuals).
  • Contractual remedies and liability for vendors and processors per agreements with ANTS/Ministry.
  • Judicial remedies including administrative annulment actions (as exercised by La Quadrature du Net) and appeals to the Conseil d'État.

Per France - National AI Strategy

  • The Villani Report itself does not set new penalties; it proposes preparatory work for liability and potential legislative reforms.
  • Existing enforcement mechanisms (e.g., GDPR enforcement by the CNIL) remain applicable for data protection breaches.
  • Any future penalties or administrative sanctions would require subsequent legislation or updates to sectoral regulatory frameworks.

Per France - Algorithmic Decision Rights (2017-330)

  • The decree does not establish new criminal or administrative fines; enforcement is through existing administrative remedies.
  • Failure to comply may result in CADA opinions finding unlawful refusal to communicate and subsequent administrative litigation.
  • Administrative courts can annul illegal refusals and may order communication and impose astreintes (daily fines) for non-compliance with judicial injunctions.
  • Potential separate liability exposures under data-protection law (CNIL actions) or trade-secret laws where applicable.

Per France - Reference Data Provision (2017-331)

  • Administrative remedies and enforcement through administrative channels for non-compliance with publication obligations.
  • Potential CNIL sanctions or legal consequences where publication breaches data-protection obligations.
  • Judicial review and corrective orders available through administrative courts.
  • Reputational and operational consequences (mandated correction, injunctions) under administrative law.

Per France - Digital Republic Law (2016-1321)

  • Administrative sanctions and corrective measures as provided by sectoral regulators (e.g., CNIL, ARCEP) for breaches within their remits.
  • Fines and other pecuniary penalties where the law or implementing decrees specify such sanctions.
  • Criminal sanctions for certain privacy-related offenses amended or created by the law (as specified in the penal provisions of the consolidated texts).
  • Judicial and administrative remedies available to affected individuals and organizations, including appeals against regulatory decisions.

France overview

The full picture of AI regulation in France, beyond just the EU AI Act.

France AI regulation overview →