Artificial Intelligence in France

Regulatory guidance / voluntary codes in France

In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has published various guidelines and codes of practice. These are non-binding, as only the Court of Justice of the European Union has authoritative interpretation powers. Codes of practice are voluntary compliance tools which help demonstrate compliance with binding AI Act obligations.

The Commission has published the following guidelines:

The Commission has also published the following codes of practice:

Under Article 95 of the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct in order to adopt, on a non-binding basis, technical solutions and industry best practices. Because of this, it is expected that the AI Office will issue further codes of conduct for this purpose.

To provide organisations with support identifying and implementing AI literacy initiatives, on 4 February 2025 the Commission launched a repository of AI literacy practices.

In May 2024, the Council of Europe adopted the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework Convention) (CETS No. 225). The Framework Convention was opened for signature on 5 September 2024 in Vilnius, and the European Union signed the same day pursuant to Council Decision (EU) 2024/2218. It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy, and the rule of law, whilst being conducive to technological progress and innovation.

AI compliance in France

In France, many governmental reports and independent authorities’ guidelines have been issued on AI. The main ones impacting the AI framework are as follows.

  • In September 2017, Deputy Cédric Villani was tasked with leading a mission to implement a French and European AI strategy. This mission was presented in a report named ‘Making sense of artificial intelligence’ (Villani Report), which covers various aspects of AI, including economic policy, research, employment, ethics and social cohesion. Additionally, five annexes focus on the risks and opportunities of AI in specific areas: education; health; agriculture; transport; and defence and security. This report led to the French government building a national AI strategy in 2018, which was last updated on 7 February 2025.
  • In June 2020, the French Banking Authority (ACPR) issued a study on the 'Governance of artificial intelligence algorithms in the financial sector’ (ACPR AI Governance Study). This study highlights the need for AI algorithm evaluation and governance.
  • In February 2026, the French Autorité des Marchés Financiers (AMF), the authority in charge of regulating the French financial market, published an in-depth study over the uses, benefits and risks associated with artificial intelligence by financial market participants. The study highlights the importance of robust AI governance frameworks while noting that regulated entities increasingly rely on internal AI policies addressing data governance, human oversight, transparency and compliance with emerging AI-related regulatory requirements.
  • On 7 April 2022, the French national advisory commission on human rights (CNCDH) issued an ‘Opinion on the impact of AI on fundamental rights’ (CNCDH Opinion), which urges public authorities to establish a strong legal framework for AI. The document highlights how algorithms can perpetuate human biases and recommends measures for ensuring algorithmic transparency and fairness.
  • On 13 March 2024, the French Artificial Intelligence Commission (governmental body) published a report 'AI: our ambition for France' (French AI Commission Report) containing 25 recommendations to make France a major player in the AI technological revolution, notably by facilitating access to personal data (in particular health data) and adopting an ‘AI exception’ for public research.
  • On 28 November 2024, the French Senate’s Office for the Evaluation of Scientific and Technological Choices (OPECST) issued a wide‑ranging report called ‘ChatGPT, and after? Assessment and perspectives of artificial intelligence’ that traces the evolution and mechanics of AI (from symbolic systems to deep learning and Transformer‑based ‘foundation models’), assesses economic, societal, cultural, and security implications, benchmarks France’s national AI strategy against roughly 20 other jurisdictions, and surveys emerging models of national, EU, and global governance. The report culminates in 18 recommendations, including several to be advanced at forthcoming international AI fora, emphasising innovation, risk management, transparency, and democratic oversight to ensure AI serves the public interest while safeguarding sovereignty and fundamental rights (Senate Report).

The French national data protection authority (CNIL) has issued non-binding AI fact sheets (CNIL AI Fact Sheets) that focus on the development phase of AI systems and models and highlight the necessity to comply with privacy requirements during all stages of the development of AI systems. CNIL has also built tools and best practices to be followed for AI tools and models to be used in compliance with privacy laws, e.g., the risk assessment before the use of an AI system (CNIL AI Risk Assessment). In addition, the CNIL has published guidance on the use of generative AI systems with a related Q&A (CNIL Generative AI Guidance) that aims to help organisations deploy such systems responsibly.

The French agency on security of IT systems (ANSSI) published guidance on 29 April 2024 setting out security recommendations for generative AI systems (ANSSI Generative AI Security Guidance). This guidance sets out good practices to implement on the three stages of generative AI lifecycle: training; integration and deployment; and operational production. Such practices should be adapted to the choice of providers (for hosting, training, testing, etc.) and the sensitivity of the data used, as well as the criticality of the intended use case of the AI system.

On 12 July 2024, the French Competition Regulator (Autorité de la Concurrence) issued an opinion on the competitive functioning of the generative artificial intelligence sector. This opinion focuses on strategies by major digital players to consolidate market power in the design, training, and specialisation of large language models. Following this opinion, the Authority announced that it is opening an ex officio investigation to analyse the competitive functioning of the conversational agents (or chats) sector. The Authority also intends to examine the new issues that are emerging, particularly those linked to the use of conversational agents in the online retail sector, also referred to as ‘agentic commerce’, by launching in 2026 a public consultation.

The French High Council for Literary and Artistic Property (CSPLA), which acts as an observatory for the exercise and enforcement of copyright and neighbouring rights, was tasked with clarifying the EU AI Act transparency requirements for AI model providers (Article 53). Its findings were made public via a report published on 11 December 2024 (CSPLA Report).

In 2025, the CIGREF (a non-profit association bringing together major French companies and administrations) issued a set of five guides focusing on helping large organisations adopt AI responsibly and in compliance with the EU AI Act, offering practical guidance on key obligations, governance structures, legal issues, and contractual impacts. They also provided best practices and enterprise feedback on generative AI adoption, highlighting organisational readiness, risks, and responsible use patterns.

In February 2026, the French Government’s Information Service (SIG) published practical guidance for public sector communications teams on the responsible use of generative AI. It focuses on transparency, human oversight, data protection, accessibility, intellectual property and digital sovereignty.

Continue reading

  • no results

Previous topic
Back to top