- French SMEs are already subject to the EU AI Act (Regulation (EU) 2024/1689): there is no French-specific exemption or delay.
- Two national bodies matter most for French companies: the CNIL (data protection, and increasingly AI oversight) and the DGE (Direction Générale des Entreprises, which coordinates AI Act implementation in France).
- 26% of French VSEs/SMEs already use at least one AI tool, per the France Num 2025 Barometer: most have not documented their Article 4 obligations.
- France has not created additional national AI Act obligations beyond the EU regulation, but the French enforcement context (the CNIL's assertive SME enforcement track record under GDPR) signals how AI Act enforcement is likely to unfold domestically.
- This guide covers what French SMEs specifically need to know: the national enforcement landscape, available public resources, and a practical compliance path.
If you run an SME in France and your business uses any AI tool, you are already a "deployer" under the EU AI Act: obligations that took effect February 2, 2025 apply to you today, regardless of your company's size or sector.
France has no separate national AI Act. The regulation applies directly as EU law, but the way it will be enforced in France depends on French institutions: the CNIL, which already regulates data protection and is expected to play a central role in AI oversight given the overlap between AI systems and personal data processing, and the DGE, which coordinates France's national implementation of the AI Act and provides guidance for businesses. Understanding how these bodies operate (and what track record they have) is the most useful France-specific lens on AI Act compliance.
The French enforcement context: what the CNIL's GDPR record tells you
France does not yet have a large body of AI Act enforcement decisions: the regulation is too new. But the CNIL's approach to GDPR enforcement against SMEs is the closest available signal for how AI Act enforcement will likely unfold, since the CNIL is expected to be a lead authority for AI systems that process personal data (which is most of them).
Since 2023, the CNIL has run a simplified sanction procedure specifically aimed at smaller structures, with fines typically ranging from €3,000 to €20,000: deliberately proportionate to SME resources, but real and enforced. In 2025, the CNIL issued 87 penalties totaling €486 million across all company sizes. The pattern is consistent: French regulators pursue smaller companies routinely, not only large enterprises, and they scale the penalty to match, rather than exempting them.
For AI Act enforcement specifically, expect a similar posture once national market surveillance authorities complete their formal designation (expected through 2026): proportionate but real fines for SMEs, with enforcement escalating for repeat or willful non-compliance rather than for genuine first-time gaps addressed in good faith.
What the DGE and French public resources offer SMEs
The Direction Générale des Entreprises (DGE) coordinates AI Act implementation at the national level and is a useful source of French-language guidance, alongside these public resources SMEs should know:
- France Num : the state's digital transformation program for SMEs, which publishes an annual barometer on digital and AI adoption among French VSEs/SMEs (the source of the 26% AI adoption figure) and provides accessible guidance on digital compliance topics.
- CNIL : beyond enforcement, the CNIL publishes practical guidance on AI systems and data protection, including recommendations specifically aimed at SMEs without dedicated legal teams.
- Bpifrance : while primarily a financing body, Bpifrance increasingly bundles compliance-readiness guidance (including AI-related) into its SME support programs, relevant if you are also seeking European funding (see the AI Act's interaction with programs like Horizon Europe or the EIC Accelerator).
None of these resources replace a dedicated compliance tool or legal counsel for classification-sensitive cases, but they are legitimate, free, French-language starting points: and citing them in your own compliance file demonstrates good-faith engagement with the national context, which matters if you are ever questioned by a regulator.
What French SMEs specifically need to do
The underlying five-step process (inventory, classify, train, document, monitor) is identical to what any EU SME needs to do: see our companion guide, How to Comply with the EU AI Act in 5 Steps . The French-specific additions are:
- Cross-reference your AI inventory against CNIL guidance , since French data protection oversight and AI Act oversight will likely be handled by the same authority for most SMEs (any AI tool processing customer or employee personal data triggers both GDPR and AI Act considerations simultaneously).
- Check French-specific sector obligations. Certain regulated French sectors (financial services under ACPR oversight, healthcare under HAS/ANS frameworks) layer additional sector rules on top of the AI Act baseline.
- Document in French as well as English if your compliance file may need to be shown to a French regulator, French investor, or French enterprise customer's procurement team: an English-only compliance file can slow down a French due-diligence process unnecessarily.
- Track the Digital Omnibus proposal specifically for its French implementation timeline : while the EU-level proposal suggests delaying certain high-risk deployer obligations to December 2027, French authorities may issue their own guidance on the transition period.
Quick reference: is your French SME affected?
| Situation | AI Act status |
|---|---|
| French SME using any AI tool (chatbot, CRM scoring, recruitment tool, etc.) | Subject to Article 4 (AI literacy) and Article 5 (prohibited practices) obligations now |
| French micro-entreprise (fewer than 10 employees) | No exemption: same obligations apply, proportionality applies only to certain high-risk deployer requirements |
| French SME already CNIL-registered / GDPR-compliant | Good foundation, but GDPR compliance alone does not cover AI Act-specific requirements (risk classification, Article 4 training documentation) |
| French SME in HR, recruitment, or credit-adjacent sectors | Higher likelihood of touching high-risk AI Act categories: prioritize risk classification (Step 2 of the 5-step process) |
| French SME seeking Horizon Europe / EIC / Bpifrance funding | AI Act alignment evidence increasingly expected in funding due diligence |
Frequently Asked Questions
Themio.ai is built for European SMEs, with specific attention to the French regulatory context: CNIL guidance, DGE coordination, and France Num data: alongside full AI Act , GDPR, and NIS2 coverage. Analysis completed in under two minutes, with 100% EU data hosting. Discover how →