Skip to content

AI Act · France

EU AI Act enforcement in France

France split AI Act supervision across six bodies. CNIL takes employment, biometrics and law enforcement — the ones most deployers hit.

Every tracker lists the DGCCRF as France's AI Act authority. For most deployers that is the wrong name to prepare for.

France did not appoint a regulator. It published a governance schema distributing the Act across six bodies, and the one with the broadest substantive reach is the CNIL — the data protection authority.

Who actually holds what

BodyRole
CNILBroadest scope: biometrics, employment, law enforcement, border control. Exclusive competence over criminal risk prediction, facial recognition databases, workplace emotion inference and real-time biometric identification
DGCCRFSingle point of contact; represents the market surveillance authorities. Substantively: prohibited manipulative practices, and social scoring jointly with the CNIL
DGESingle liaison office; represents France on the European AI Board
ACPRFinancial services
ArcomHuman-AI interaction and generated content
ANSSI and PEReNPooled technical expertise supporting all of the above

The sentence that decides your preparation. If you use AI in hiring, promotion or workforce management in France, your regulator is the CNIL — not a market surveillance body, not a technical inspectorate. It has enforced GDPR for a decade, it has a settled position on automated decision-making under Article 22, and it will read the AI Act alongside that rather than as a separate regime.

Why that is harder than a technical regulator, and easier

Harder, because a data protection authority does not accept a conformity assessment as the end of the conversation. It asks about the individual: what was decided, on what basis, what the person was told, and what recourse they had. A technically impeccable system that cannot explain a single adverse decision in plain French is not in a strong position.

Easier, because you almost certainly already have the relationship. If your organisation processes personal data in France, the CNIL is a known quantity with published doctrine. The Article 26 deployer obligations — human oversight, log retention, informing affected people — map closely onto ground the CNIL has already covered.

The contrast with Germany is instructive for anyone operating in both. Germany routes most AI supervision to the Bundesnetzagentur, an engineering regulator whose habits come from electricity grids and telecoms, and keeps financial AI with BaFin. France routes its most sensitive categories to the privacy regulator. Same Regulation, same obligations, and two quite different rooms to sit in.

Where France stands

ItemPosition
Article 70 designationNot complete — deadline was 2 August 2025
Governance modelPublished schema distributing supervision across six bodies
Single point of contactDGCCRF
EU AI Board representationDGE
High-risk obligations apply2 December 2027 (stand-alone) · 2 August 2028 (embedded)
Prohibitions in force since2 February 2025

What a French deployer should do now

  • Identify which of the six bodies your use case reaches. Hiring, biometrics or anything touching law enforcement means the CNIL. Financial services means the ACPR. Content generation means Arcom. Preparing for the DGCCRF because a tracker named it is the common mistake.
  • Bring your GDPR file to the AI Act file. If the CNIL is your supervisor, your existing Article 22 analysis, DPIAs and records of processing are the foundation, not a separate workstream. Organisations that run these as two projects duplicate work and produce inconsistent answers.
  • Start the six-month log retention now. Article 26 requires deployers to retain system logs for at least six months. Logs not kept cannot be recreated, so the system needs to be running correctly by roughly mid-2027 to have a compliant record on the first day.
  • Write the explanation before you need it. A CNIL-supervised regime will ask how an adverse decision is explained to the person affected. Drafting that after a complaint is the expensive way.

Questions

Who enforces the EU AI Act in France?

Six bodies, not one. The DGCCRF is the single point of contact and the DGE represents France on the European AI Board, but the CNIL holds the broadest substantive scope: biometrics, employment, law enforcement and border control. ACPR covers financial services and Arcom covers human-AI interaction and generated content. ANSSI and PEReN provide pooled technical expertise to all of them.

We use AI in recruitment in France. Who regulates us?

The CNIL. Employment sits in its scope, and it holds exclusive competence over workplace emotion inference. That is a materially different prospect from a technical regulator: the CNIL arrives with a decade of GDPR enforcement practice and a settled position on automated decision-making under Article 22, which it will read alongside the AI Act rather than separately.

What is the CNIL's exclusive competence?

Criminal risk prediction, facial recognition databases, workplace emotion inference and real-time biometric identification. These are the highest-sensitivity categories in the Act, and France has placed all of them with the data protection authority rather than distributing them.

Is the DGCCRF irrelevant then?

No, but its role is narrower than the headlines suggest. It is the single point of contact and represents the market surveillance authorities, and substantively it covers prohibited manipulative practices and — jointly with the CNIL — social scoring. For most high-risk deployer use cases, the CNIL is the body you will meet.

Has France completed its Article 70 designation?

Not as of the June 2026 count. France published a governance schema and has a legislative proposal, but designation was not complete. The AI Act applies regardless: it is a Regulation with direct effect, so high-risk obligations arrive on 2 December 2027 for stand-alone systems whether or not the French procedural layer has passed.

Related

Agent Trust Cloud

We publish this because the deployer side of the AI Act is widely misread, and France's six-body split is misread more than most. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. The platform is in development and is not sold as a subscription today; what is available now is a fixed-scope assessment of the agents and machine identities you already have.

 

The French governance distribution on this page — the six bodies and their respective scopes, including the CNIL's exclusive competences — is drawn from published legal commentary on France's official governance schema, read on 2026-09-23. France had not completed its Article 70 designation and the allocation may change on enactment. No French implementing law, bill number or national sanctions framework is cited here, because none was confirmed in the sources consulted. AI Act dates were verified against Regulation (EU) 2026/1744 and the European Commission's regulatory framework page.

A reference, not legal advice, and not advice on French law.

Last reviewed 2026-09-23. Published by Agent Trust Cloud, a Globixera company based in Michigan, United States — globixera.com. Engineering and support are US-based.