Everything You Need to Know About the Artificial Intelligence Law in France and Its Challenges

The European regulation on artificial intelligence (AI Act) is not limited to a risk level classification. Since the adoption of the “Digital Omnibus” regulation in July 2026, the implementation timeline has been significantly reshaped, delaying deadlines that many companies believed were imminent. Understanding this framework requires integrating these recent changes, which redistribute compliance priorities for French operators.

Digital Omnibus and AI Act deadline postponements: what changed in 2026

The regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026, and coming into effect three days later, introduced substantial delays. The obligations for high-risk AI systems listed in Annex III (recruitment, education, credit, insurance, public services) have been postponed from August 2, 2026, to December 2, 2027.

Systems integrated into products already subject to sectoral regulation (Annex I, notably medical devices) benefit from an even broader postponement, until August 2, 2028. This delay reflects the complexity of aligning the AI Act with existing regulatory frameworks.

For French companies that had initiated compliance projects based on the initial deadline of August 2026, this postponement alters the roadmap. It does not exempt them from preparing technical documentation and risk management procedures, but it provides additional time to stabilize internal processes. A comprehensive file on the law on artificial intelligence in France details these regulatory implications.

Team of professionals discussing the regulatory issues of the European AI law in a meeting room

Transparency obligations effective since August 2026

While the Digital Omnibus has postponed the heaviest obligations, the transparency requirements of Article 50 have been in effect since August 2, 2026. Specifically, any AI system interacting with individuals must indicate that it is an AI. Generated content (text, image, audio, video) must be marked as such when it concerns matters of public interest.

We observe a persistent ambiguity regarding national governance. The CNIL has published initial guidelines, but not all sectoral regulatory authorities have been formally designated. This situation creates operational uncertainty for companies deploying generative AI systems aimed at the public.

Alignment with GDPR

The AI Act does not replace the GDPR. The two texts overlap: an AI system processing personal data remains subject to the obligations of the General Data Protection Regulation, in addition to the specific requirements of the AI Act. The CNIL retains its role as regulator for the personal data aspect, which implies double reporting for certain high-risk systems.

General Purpose AI models and specific obligations for providers

General Purpose AI (GPAI) models are subject to a dedicated regime. Since August 2, 2025, GPAI model providers must comply with enhanced transparency obligations, including the publication of detailed technical documentation and a copyright compliance policy.

GPAI models presenting systemic risk are subject to additional constraints:

  • Conducting model assessments including adversarial testing to identify vulnerabilities
  • Notifying the European Commission of serious incidents within deadlines defined by the regulation
  • Implementing cybersecurity measures proportionate to the model’s power

The threshold for classification as a systemic risk is not determined by a simple performance metric. The Commission may designate a model as presenting systemic risk based on qualitative criteria, allowing for significant discretion.

Sanctions and compliance: what companies in France risk

The sanction regime of the AI Act is graduated. The most serious infractions (deployment of prohibited systems, such as social scoring or subliminal behavioral manipulation) expose companies to fines that can reach a percentage of the company’s global annual revenue. Failures to meet transparency or technical documentation obligations result in lower, but still significant, penalties.

Compliance is not limited to ticking regulatory boxes. It requires structured internal governance: a register of deployed AI systems, continuous risk assessment, traceability of algorithmic decisions. Companies that outsource the development of their AI systems remain responsible under the regulation if they deploy them.

Prohibited AI practices since February 2025

Since February 2, 2025, prohibitions on unacceptable risk practices have already been in effect. Among the prohibited systems:

  • Social scoring systems by public authorities or on their behalf
  • Systems exploiting vulnerabilities related to age, disability, or economic status
  • Biometric categorization systems based on sensitive characteristics (ethnic origin, sexual orientation)
  • Real-time remote biometric identification systems in public spaces, except for strictly regulated exceptions

Software developer consulting AI compliance guidelines in his home workspace

France’s positioning in the implementation of the AI Act

France has adopted a stance that attempts to reconcile regulation and support for the national AI ecosystem. The CNIL plays a leading role in assisting companies, but the national governance architecture remains incomplete at this stage. Sectoral authorities (health, finance, transport) have not all clarified their scope of intervention regarding the AI Act.

We recommend that concerned companies not wait for the complete stabilization of the institutional framework to begin their compliance work. The transparency obligations are already enforceable, and the deadlines granted by the Digital Omnibus for high-risk systems do not exempt them from documenting risk analyses and mitigation measures now.

The European regulatory framework on AI will continue to evolve through delegated acts and guidelines from the Commission. Companies that have structured their internal governance in advance will be better positioned to absorb these adjustments without operational disruption.

Everything You Need to Know About the Artificial Intelligence Law in France and Its Challenges