AI Act · France
EU AI Act enforcement in France
France split AI Act supervision across six bodies. CNIL takes employment, biometrics and law enforcement — the ones most deployers hit.
Every tracker lists the DGCCRF as France's AI Act authority. For most deployers that is the wrong name to prepare for.
France did not appoint a regulator. It published a governance schema distributing the Act across six bodies, and the one with the broadest substantive reach is the CNIL — the data protection authority.
Who actually holds what
| Body | Role |
|---|---|
| CNIL | Broadest scope: biometrics, employment, law enforcement, border control. Exclusive competence over criminal risk prediction, facial recognition databases, workplace emotion inference and real-time biometric identification |
| DGCCRF | Single point of contact; represents the market surveillance authorities. Substantively: prohibited manipulative practices, and social scoring jointly with the CNIL |
| DGE | Single liaison office; represents France on the European AI Board |
| ACPR | Financial services |
| Arcom | Human-AI interaction and generated content |
| ANSSI and PEReN | Pooled technical expertise supporting all of the above |
The sentence that decides your preparation. If you use AI in hiring, promotion or workforce management in France, your regulator is the CNIL — not a market surveillance body, not a technical inspectorate. It has enforced GDPR for a decade, it has a settled position on automated decision-making under Article 22, and it will read the AI Act alongside that rather than as a separate regime.
Why that is harder than a technical regulator, and easier
Harder, because a data protection authority does not accept a conformity assessment as the end of the conversation. It asks about the individual: what was decided, on what basis, what the person was told, and what recourse they had. A technically impeccable system that cannot explain a single adverse decision in plain French is not in a strong position.
Easier, because you almost certainly already have the relationship. If your organisation processes personal data in France, the CNIL is a known quantity with published doctrine. The Article 26 deployer obligations — human oversight, log retention, informing affected people — map closely onto ground the CNIL has already covered.
The contrast with Germany is instructive for anyone operating in both. Germany routes most AI supervision to the Bundesnetzagentur, an engineering regulator whose habits come from electricity grids and telecoms, and keeps financial AI with BaFin. France routes its most sensitive categories to the privacy regulator. Same Regulation, same obligations, and two quite different rooms to sit in.
Where France stands
| Item | Position |
|---|---|
| Article 70 designation | Not complete — deadline was 2 August 2025 |
| Governance model | Published schema distributing supervision across six bodies |
| Single point of contact | DGCCRF |
| EU AI Board representation | DGE |
| High-risk obligations apply | 2 December 2027 (stand-alone) · 2 August 2028 (embedded) |
| Prohibitions in force since | 2 February 2025 |
What a French deployer should do now
- Identify which of the six bodies your use case reaches. Hiring, biometrics or anything touching law enforcement means the CNIL. Financial services means the ACPR. Content generation means Arcom. Preparing for the DGCCRF because a tracker named it is the common mistake.
- Bring your GDPR file to the AI Act file. If the CNIL is your supervisor, your existing Article 22 analysis, DPIAs and records of processing are the foundation, not a separate workstream. Organisations that run these as two projects duplicate work and produce inconsistent answers.
- Start the six-month log retention now. Article 26 requires deployers to retain system logs for at least six months. Logs not kept cannot be recreated, so the system needs to be running correctly by roughly mid-2027 to have a compliant record on the first day.
- Write the explanation before you need it. A CNIL-supervised regime will ask how an adverse decision is explained to the person affected. Drafting that after a complaint is the expensive way.
Questions
Who enforces the EU AI Act in France?
Six bodies, not one. The DGCCRF is the single point of contact and the DGE represents France on the European AI Board, but the CNIL holds the broadest substantive scope: biometrics, employment, law enforcement and border control. ACPR covers financial services and Arcom covers human-AI interaction and generated content. ANSSI and PEReN provide pooled technical expertise to all of them.
We use AI in recruitment in France. Who regulates us?
The CNIL. Employment sits in its scope, and it holds exclusive competence over workplace emotion inference. That is a materially different prospect from a technical regulator: the CNIL arrives with a decade of GDPR enforcement practice and a settled position on automated decision-making under Article 22, which it will read alongside the AI Act rather than separately.
What is the CNIL's exclusive competence?
Criminal risk prediction, facial recognition databases, workplace emotion inference and real-time biometric identification. These are the highest-sensitivity categories in the Act, and France has placed all of them with the data protection authority rather than distributing them.
Is the DGCCRF irrelevant then?
No, but its role is narrower than the headlines suggest. It is the single point of contact and represents the market surveillance authorities, and substantively it covers prohibited manipulative practices and — jointly with the CNIL — social scoring. For most high-risk deployer use cases, the CNIL is the body you will meet.
Has France completed its Article 70 designation?
Not as of the June 2026 count. France published a governance schema and has a legislative proposal, but designation was not complete. The AI Act applies regardless: it is a Regulation with direct effect, so high-risk obligations arrive on 2 December 2027 for stand-alone systems whether or not the French procedural layer has passed.
Related
Agent Trust Cloud
We publish this because the deployer side of the AI Act is widely misread, and France's six-body split is misread more than most. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. The platform is in development and is not sold as a subscription today; what is available now is a fixed-scope assessment of the agents and machine identities you already have.