Back to Blog Next Article
July 20, 2026 Majda Skrijelj 7 min read France Context

AI Act Compliance for French SMEs: What You Must Do in 2026

Executive Summary
  • French SMEs are already subject to the EU AI Act (Regulation (EU) 2024/1689): there is no French-specific exemption or delay.
  • Two national bodies matter most for French companies: the CNIL (data protection, and increasingly AI oversight) and the DGE (Direction Générale des Entreprises, which coordinates AI Act implementation in France).
  • 26% of French VSEs/SMEs already use at least one AI tool, per the France Num 2025 Barometer: most have not documented their Article 4 obligations.
  • France has not created additional national AI Act obligations beyond the EU regulation, but the French enforcement context (the CNIL's assertive SME enforcement track record under GDPR) signals how AI Act enforcement is likely to unfold domestically.
  • This guide covers what French SMEs specifically need to know: the national enforcement landscape, available public resources, and a practical compliance path.
26%
France Num 2025

of French VSEs and SMEs now use at least one AI tool in their business, making them subject to deployer rules.

CNIL
Active Enforcement

issued 87 penalties totaling €486M in 2025, using simplified sanction audits for SMEs.

If you run an SME in France and your business uses any AI tool, you are already a "deployer" under the EU AI Act: obligations that took effect February 2, 2025 apply to you today, regardless of your company's size or sector.

France has no separate national AI Act. The regulation applies directly as EU law, but the way it will be enforced in France depends on French institutions: the CNIL, which already regulates data protection and is expected to play a central role in AI oversight given the overlap between AI systems and personal data processing, and the DGE, which coordinates France's national implementation of the AI Act and provides guidance for businesses. Understanding how these bodies operate (and what track record they have) is the most useful France-specific lens on AI Act compliance.

The French enforcement context: what the CNIL's GDPR record tells you

France does not yet have a large body of AI Act enforcement decisions: the regulation is too new. But the CNIL's approach to GDPR enforcement against SMEs is the closest available signal for how AI Act enforcement will likely unfold, since the CNIL is expected to be a lead authority for AI systems that process personal data (which is most of them).

Since 2023, the CNIL has run a simplified sanction procedure specifically aimed at smaller structures, with fines typically ranging from €3,000 to €20,000: deliberately proportionate to SME resources, but real and enforced. In 2025, the CNIL issued 87 penalties totaling €486 million across all company sizes. The pattern is consistent: French regulators pursue smaller companies routinely, not only large enterprises, and they scale the penalty to match, rather than exempting them.

For AI Act enforcement specifically, expect a similar posture once national market surveillance authorities complete their formal designation (expected through 2026): proportionate but real fines for SMEs, with enforcement escalating for repeat or willful non-compliance rather than for genuine first-time gaps addressed in good faith.

What the DGE and French public resources offer SMEs

The Direction Générale des Entreprises (DGE) coordinates AI Act implementation at the national level and is a useful source of French-language guidance, alongside these public resources SMEs should know:

  • France Num : the state's digital transformation program for SMEs, which publishes an annual barometer on digital and AI adoption among French VSEs/SMEs (the source of the 26% AI adoption figure) and provides accessible guidance on digital compliance topics.
  • CNIL : beyond enforcement, the CNIL publishes practical guidance on AI systems and data protection, including recommendations specifically aimed at SMEs without dedicated legal teams.
  • Bpifrance : while primarily a financing body, Bpifrance increasingly bundles compliance-readiness guidance (including AI-related) into its SME support programs, relevant if you are also seeking European funding (see the AI Act's interaction with programs like Horizon Europe or the EIC Accelerator).

None of these resources replace a dedicated compliance tool or legal counsel for classification-sensitive cases, but they are legitimate, free, French-language starting points: and citing them in your own compliance file demonstrates good-faith engagement with the national context, which matters if you are ever questioned by a regulator.

What French SMEs specifically need to do

The underlying five-step process (inventory, classify, train, document, monitor) is identical to what any EU SME needs to do: see our companion guide, How to Comply with the EU AI Act in 5 Steps . The French-specific additions are:

  1. Cross-reference your AI inventory against CNIL guidance , since French data protection oversight and AI Act oversight will likely be handled by the same authority for most SMEs (any AI tool processing customer or employee personal data triggers both GDPR and AI Act considerations simultaneously).
  2. Check French-specific sector obligations. Certain regulated French sectors (financial services under ACPR oversight, healthcare under HAS/ANS frameworks) layer additional sector rules on top of the AI Act baseline.
  3. Document in French as well as English if your compliance file may need to be shown to a French regulator, French investor, or French enterprise customer's procurement team: an English-only compliance file can slow down a French due-diligence process unnecessarily.
  4. Track the Digital Omnibus proposal specifically for its French implementation timeline : while the EU-level proposal suggests delaying certain high-risk deployer obligations to December 2027, French authorities may issue their own guidance on the transition period.

Quick reference: is your French SME affected?

Situation AI Act status
French SME using any AI tool (chatbot, CRM scoring, recruitment tool, etc.) Subject to Article 4 (AI literacy) and Article 5 (prohibited practices) obligations now
French micro-entreprise (fewer than 10 employees) No exemption: same obligations apply, proportionality applies only to certain high-risk deployer requirements
French SME already CNIL-registered / GDPR-compliant Good foundation, but GDPR compliance alone does not cover AI Act-specific requirements (risk classification, Article 4 training documentation)
French SME in HR, recruitment, or credit-adjacent sectors Higher likelihood of touching high-risk AI Act categories: prioritize risk classification (Step 2 of the 5-step process)
French SME seeking Horizon Europe / EIC / Bpifrance funding AI Act alignment evidence increasingly expected in funding due diligence

Frequently Asked Questions

Is there a French-specific AI Act text, or does the EU regulation apply directly?
There is no separate French AI Act. Regulation (EU) 2024/1689 applies directly as EU law across all member states, including France, without requiring national transposition legislation for most provisions. France's role is in enforcement coordination (via the DGE) and in overseeing the data-protection dimension of AI systems (via the CNIL).
Will the CNIL be the enforcement authority for the AI Act in France?
The CNIL is expected to play a central role for AI systems that process personal data, given the significant overlap between AI Act and GDPR concerns, but formal national market surveillance authority designations for the AI Act were still being finalized as of mid-2026.
Does being GDPR-compliant through the CNIL mean my French SME is also AI Act compliant?
No. GDPR and AI Act obligations overlap significantly but are not identical. A GDPR-compliant SME has a head start but still needs AI-specific risk classification, Article 4 AI literacy training and documentation, and technical documentation for any high-risk tools.
What French public resources are free and useful for AI Act compliance?
France Num publishes an annual barometer and general digital-compliance guidance for SMEs. The CNIL publishes AI-specific guidance alongside its GDPR resources. Bpifrance increasingly references compliance readiness in its SME support and funding programs.
My French SME already has a GDPR-focused DPO. Is that enough for the AI Act?
A DPO is a strong asset: much of the operational discipline transfers directly. However, the DPO role as defined under GDPR does not automatically cover AI-specific obligations like risk tier classification or Article 4 AI literacy training documentation.
Majda Skrijelj

Senior Compliance Officer currently at an international financial institution, Majda has over 20 years of experience at the intersection of governance, anti-corruption, and European regulatory risk (GDPR, AI Act).

Themio.ai is built for European SMEs, with specific attention to the French regulatory context: CNIL guidance, DGE coordination, and France Num data: alongside full AI Act , GDPR, and NIS2 coverage. Analysis completed in under two minutes, with 100% EU data hosting. Discover how →