The EU AI Act in France
How Regulation (EU) 2024/1689 applies in France, and the 10 AI instruments France has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
France’s own AI instruments
10 records tracked for France, beyond the EU-level Act above.
France AI Act Adaptation Bill
France · 2025
France - Digital Space Regulation (2024-449)
France · 2024 · 21 May 2024
France - Biometric Recognition Bill (n°505)
France · 2023
France - Electronic Identification Service (2022-676)
France · 2022 · 28 Apr 2022
France - National Investment Strategy
France · 2021 · 12 Oct 2021
France - Mobile Authentication System (2019-452)
France · 2019 · 16 May 2019
France - National AI Strategy
France · 2018 · 28 Mar 2018
France - Algorithmic Decision Rights (2017-330)
France · 2017 · 1 Sep 2017
France - Reference Data Provision (2017-331)
France · 2017 · 1 Apr 2017
France - Digital Republic Law (2016-1321)
France · 2016 · 9 Oct 2016
National authority in France
Named in France’s own records, not inferred.
Per France - Digital Space Regulation (2024-449)
- CNIL (Commission Nationale de l'Informatique et des Libertés) — Data protection oversight, new investigative competences and recommendations on IA and data processing.
- ARCOM (Autorité de régulation de la communication audiovisuelle et numérique) — Age verification, audiovisual referentials and platform supervision for audiovisual content.
- ARCEP (Autorité de régulation des communications électroniques et des postes) — Cloud market oversight and cooperation with CNIL under implementing decrees.
Per France - Biometric Recognition Bill (n°505)
- Commission Nationale de l'Informatique et des Libertés (CNIL) — National data protection authority; supervisory, inspection and sanctioning powers regarding personal data processing and technical safeguards.
- Commission Nationale de Contrôle des Techniques de Renseignement (CNCTR) — Advisory and control body for intelligence techniques; provides mandatory advice for intelligence-related authorisations and oversight.
- Ministry of the Interior / Prime Minister's Office — Responsible for authorising certain operational uses (prime-ministerial authorisations for first-circle intelligence services) and for reporting to Parliament.
- Judicial authorities (procureur de la République / juge d'instruction) — Grant time-limited authorisations for a posteriori exploitation in judicial investigations; maintain procedural control and oversight.
Per France - Electronic Identification Service (2022-676)
- Ministry of the Interior (Ministère de l'Intérieur) — Joint controller; responsible for execution of the decree and oversight of SGIN implementation.
- Agence nationale des titres sécurisés (ANTS) — Joint controller and operational authority responsible for the technical implementation, maintenance and operation of SGIN.
- Commission Nationale de l'Informatique et des Libertés (CNIL) — French data protection authority supervising GDPR compliance and empowered to investigate and sanction data-protection breaches.
Per France - National Investment Strategy
- Secrétariat général pour l'investissement (SGPI) — Central coordination and oversight of France 2030 on behalf of the Prime Minister
- Bpifrance — Implementing financier (grants, equity, loans) and delivery partner for enterprise support
- Agence Nationale de la Recherche (ANR) — Funding agency for research projects and R&D consortia under thematic calls
- ADEME (Agence de l'environnement et de la maîtrise de l'énergie) — Implementing agency for decarbonisation, industrial transition and environmental projects
- Caisse des Dépôts et Consignations (CDC) — Public investor partner and long-term financer for strategic infrastructure projects
- GENCI (Grand Équipement National de Calcul Intensif) — Partner for national computing infrastructure and supercomputing projects (AI infrastructure)
Per France - Mobile Authentication System (2019-452)
- Ministry of the Interior (Ministère de l'Intérieur) — Authorising ministry; controller responsible for policy, oversight and conventions
- Agence nationale des titres sécurisés (ANTS) — Operational implementer / technical operator of ALICEM
- Commission Nationale de l'Informatique et des Libertés (CNIL) — Data-protection supervisory authority; opinion provider and enforcement body under GDPR/French law
- Conseil d'État (Council of State) — Highest administrative court for judicial review of the Decree and administrative litigation
Per France - National AI Strategy
- Prime Minister / French Government — Commissioner/recipient of the mission report and coordinator of national strategy implementation
- Commission nationale de l'informatique et des libertés (CNIL) — Data protection and privacy regulator; referenced for enforcement and ethical guidance
- La Documentation française / Vie-publique — Official repository and publisher of the report text and metadata
- Ministry of Higher Education, Research and Innovation — Policy and research funding coordination, engagement with academic research capacities
- Ministry of Economy and Finance / Direction générale des entreprises — Industrial policy, public procurement and industry engagement in AI strategy
Per France - Algorithmic Decision Rights (2017-330)
- Prime Minister / French Government — Responsible authority for issuing the decree and coordinating execution
- Legifrance (Journal Officiel) — Official publisher of the decree text
- Commission d'accès aux documents administratifs (CADA) — Independent administrative body for review of refusals of communication; first recourse for requesters
- Ministry of Economy and Finance (France) — One of the ministers charged with execution per Article 4 of the decree
Per France - Reference Data Provision (2017-331)
- Prime Minister / Direction de l'information légale et administrative (DILA) — Overall supervising authority and issuer of implementing arrêté; coordinates central service obligations and publishes technical rules.
- CNIL (Commission Nationale de l'Informatique et des Libertés) — Data protection authority responsible for ensuring that publication of datasets complies with data-protection rules and for authorizations/controls where personal identifiers are used.
- Data.gouv.fr (French open data portal / central service) — Operational catalogue and portal for many published reference datasets; supports indexing and public access.
Per France - Digital Republic Law (2016-1321)
- Commission nationale de l'informatique et des libertés (CNIL) — Data protection supervisory authority; guidance, monitoring and enforcement for privacy-related provisions.
- Autorité de régulation des communications électroniques, des postes et de la distribution de la presse (ARCEP) — Sectoral regulator with competencies relevant to net neutrality and communications infrastructure referenced by the law.
Penalties in France
As stated in France’s own records.
Per France - Biometric Recognition Bill (n°505)
- Administrative sanctions by the CNIL, including fines and orders to suspend or cease processing.
- Obligatory destruction of unlawfully processed biometric data and systems remediation orders.
- Potential criminal liability under existing penal provisions for unauthorised capture, illegal processing or abuses by public agents.
- Judicial remedies and compensation claims available to individuals harmed by unlawful identification or data processing.
- Parliamentary orders and political accountability measures, including requests for supplementary information and reports.
Per France - Electronic Identification Service (2022-676)
- Processing or security failures that infringe GDPR obligations may lead to administrative sanctions and corrective measures by the CNIL under EU and national law.
- Contractual remedies, liability and sanctions applicable under public procurement and maintenance contracts entered into by ANTS for SGIN implementation.
- Internal administrative or disciplinary measures for officials or designated agents who misuse access in breach of the decree or internal policies.
- Civil liability for affected data subjects where unlawful processing causes demonstrable harm (subject to French civil law and GDPR principles).
Per France - National Investment Strategy
- Suspension of payment instalments for non-compliance with contractual milestones.
- Mandatory repayment/recovery of grants or advances used ineligible or contrary to contractual terms.
- Termination of funding agreements for material breach, with potential clawback of funds.
- Administrative exclusion from future public programmes and competitive calls run under France 2030.
- Referral to judicial authorities in cases suggesting fraud or criminal wrongdoing under French law.
- Reputational impacts through public disclosure of sanctions or funding recoveries.
Per France - Mobile Authentication System (2019-452)
- Administrative fines and measures under the GDPR (up to applicable statutory maximums depending on the infringement) enforceable by CNIL.
- CNIL orders to bring processing into compliance (suspension, corrective measures, publicity of decisions).
- Civil liability for damages caused by unlawful processing or data breaches (claims by affected individuals).
- Contractual remedies and liability for vendors and processors per agreements with ANTS/Ministry.
- Judicial remedies including administrative annulment actions (as exercised by La Quadrature du Net) and appeals to the Conseil d'État.
Per France - National AI Strategy
- The Villani Report itself does not set new penalties; it proposes preparatory work for liability and potential legislative reforms.
- Existing enforcement mechanisms (e.g., GDPR enforcement by the CNIL) remain applicable for data protection breaches.
- Any future penalties or administrative sanctions would require subsequent legislation or updates to sectoral regulatory frameworks.
Per France - Algorithmic Decision Rights (2017-330)
- The decree does not establish new criminal or administrative fines; enforcement is through existing administrative remedies.
- Failure to comply may result in CADA opinions finding unlawful refusal to communicate and subsequent administrative litigation.
- Administrative courts can annul illegal refusals and may order communication and impose astreintes (daily fines) for non-compliance with judicial injunctions.
- Potential separate liability exposures under data-protection law (CNIL actions) or trade-secret laws where applicable.
Per France - Reference Data Provision (2017-331)
- Administrative remedies and enforcement through administrative channels for non-compliance with publication obligations.
- Potential CNIL sanctions or legal consequences where publication breaches data-protection obligations.
- Judicial review and corrective orders available through administrative courts.
- Reputational and operational consequences (mandated correction, injunctions) under administrative law.
Per France - Digital Republic Law (2016-1321)
- Administrative sanctions and corrective measures as provided by sectoral regulators (e.g., CNIL, ARCEP) for breaches within their remits.
- Fines and other pecuniary penalties where the law or implementing decrees specify such sanctions.
- Criminal sanctions for certain privacy-related offenses amended or created by the law (as specified in the penal provisions of the consolidated texts).
- Judicial and administrative remedies available to affected individuals and organizations, including appeals against regulatory decisions.
France overview
The full picture of AI regulation in France, beyond just the EU AI Act.
France AI regulation overview →