GDPR Compliance Software for French SMEs: The Complete Guide
Discover how to choose the best GDPR compliance software for French SMEs. Compare features, pricing, implementation, and CNIL compliance requirements.
Generative AI transparency, penalties, high-risk obligations postponed: the complete picture of the AI Act as of 2 August 2026 and the compliance actions to launch now.
2 August 2026 was supposed to be the "big bang" of the European regulation on artificial intelligence. For two years, consultancies and law firms presented this date as the moment when the full weight of the AI Act's obligations would land on businesses. The reality, as of July 2026, is more nuanced — and that is exactly what makes preparation tricky.
The Digital Omnibus legislative package, definitively approved by the European Parliament on 16 June and by the Council on 29 June 2026, has postponed the heaviest obligations — those covering high-risk AI systems — to December 2027 (Source: DLA Piper). But make no mistake: 2 August 2026 remains a very real deadline. Transparency obligations, the activation of the penalty regime, and the end of the transition period for general-purpose AI models all take effect on that date.
This guide separates what applies, what has been postponed, and what your business must do concretely to achieve AI compliance in 2026.
The essential point in one sentence: on 2 August 2026, it is not the "high-risk" obligations that arrive, but the Article 50 transparency rules, the enforcement powers, and mandatory compliance for large AI models — and this affects far more French businesses than most people realize.
The AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024 with a staggered application schedule (Source: EUR-Lex). Two milestones are already behind us. Since 2 February 2025, AI practices presenting unacceptable risk (social scoring, behavioral manipulation, certain forms of biometric surveillance) have been banned, and the AI literacy obligation — staff training under Article 4 — already applies.
Since 2 August 2025, providers of general-purpose AI models (GPAI) such as GPT, Claude, Gemini or Mistral have been subject to their own documentation and transparency obligations (Source: European Commission). 2 August 2026 marks the third wave. It is the general application date of the regulation — the one that switches on the institutional machinery and the penalties.
This is the point generating the most confusion in legal and compliance departments right now. The Digital Omnibus postpones the application of obligations for high-risk AI systems under Annex III (recruitment, credit scoring, education, biometrics...) from 2 August 2026 to 2 December 2027, and those for AI embedded in regulated products (Annex I) to 2 August 2028 (Source: White & Case).
The reason is pragmatic: the CEN-CENELEC harmonized standards and the notified bodies needed for certification were simply not ready. Imposing obligations without the tools to comply with them would have created major legal uncertainty. But this postponement is narrow. Here is what remains unchanged on 2 August 2026:
The Article 50 transparency obligations (chatbots, deepfakes, AI-generated content) apply as originally scheduled
The penalty regime and national governance become fully operational
GPAI models placed on the market before August 2025 must be in full compliance
The Article 5 prohibitions and the training obligation have been in force since February 2025
The high-risk postponement is not a general reprieve. Businesses that ease off on inventorying and classifying their AI systems in 2026 will find themselves in December 2027 with a few weeks to do work that takes months.
Also worth noting: the Digital Omnibus introduces a new prohibited practice targeting systems that generate non-consensual intimate imagery ("nudifiers") and child sexual abuse material, applicable from 2 December 2026 (Source: European Parliament).
If your business remembers only one thing from this article, make it this. Article 50 of the regulation, applicable on 2 August 2026, imposes generative AI transparency obligations that affect the vast majority of French businesses — far beyond software vendors alone.
Concretely, from that date:
Chatbots and virtual assistants: anyone interacting with an AI system must be clearly informed (a visible notice such as "You are chatting with an AI assistant" is sufficient)
AI-generated or manipulated content: deepfakes and artificial content distributed to the public must be labeled as such
Emotion recognition and biometric categorization: exposed individuals must be informed
Machine-readable marking of content (Article 50(2)): providers of generative systems must embed machine-readable markers — with a grace period until 2 December 2026 for systems already on the market before August 2026 (Source: Gibson Dunn)
Take a common example. A French SME that has deployed a customer-service chatbot on its Shopify or WordPress site is a "deployer" within the meaning of the regulation. Its obligation is far from insurmountable: display the information notice, verify that the chatbot vendor handles the technical marking, and document this point in its internal register. The cost is marginal; the absence of the notice, however, becomes sanctionable.
Prepare for the EU AI Act in 2026
Understand the transparency rules, enforcement risks, AI system classification, staff training duties, and compliance actions that French businesses must address before 2 August 2026. Earn a recognized PDF certificate — free with the course. Self-paced, role-ready, and built to make you hireable.
Learn More →Until now, the AI Act has largely lacked enforcement muscle at the national level. 2 August 2026 activates the penalty regime provided for in the regulation, and the amounts are calibrated on the GDPR model — only stricter (Source: service-public.fr).
The scale is organized in three tiers:
Up to €35 million or 7% of worldwide turnover for engaging in prohibited practices
Up to €15 million or 3% of worldwide turnover for breaches of other obligations, including Article 50 transparency
Up to €7.5 million or 1% of worldwide turnover for supplying incorrect information to authorities
A protective mechanism exists for SMEs and startups: the lower of the percentage and the fixed amount applies, whereas large companies face the higher of the two. This asymmetry, set out in Article 99, makes compliance proportionate — but not optional.
For French businesses, the practical question is simple: who will knock on the door in the event of an inspection? France has opted for a sector-based model, whose governance scheme was published by the Ministry of the Economy (Source: Direction générale des Entreprises).
Under this framework, the DGCCRF handles operational coordination and acts as the single point of contact with the European Commission. The CNIL occupies a central position on everything involving personal data, biometrics, employment and prohibited practices — a scope the government further strengthened in early 2026 by positioning it as the pivot of national AI regulation (Source: Next). Arcom covers generated content and deepfakes, the ACPR covers finance, and ANSSI provides technical support on cybersecurity.
For a DPO or compliance officer, the consequence is direct: the reflexes acquired with the GDPR are the best starting point. The CNIL will wear both hats on many cases, and an AI system processing personal data will fall under both regulations simultaneously — they stack, rather than replace one another.
The compliance process is not mysterious. Here is the approach any French business can apply right now, whatever its size.
Step 1 — Map all your AI systems. Take stock of every tool that embeds AI: chatbots, scoring, CV screening, content generation, predictive CRM — including employees' "shadow AI" use of ChatGPT or Copilot. Without an inventory, no classification is possible; it is the equivalent of the GDPR record of processing activities.
Step 2 — Classify each system by risk level. The regulation distinguishes four levels: unacceptable (banned), high risk (Annex III — obligations postponed to December 2027 but to be anticipated), limited risk (transparency mandatory from August 2026) and minimal risk (no specific obligation). For most SMEs, everyday uses fall under limited or minimal risk.
Step 3 — Deploy transparency notices before 2 August. Add the "AI" disclosure to your chatbots, label AI-generated content intended for the public, and verify contractually that your vendors handle the technical marking. This is the most urgent and least costly action in the entire process.
Step 4 — Formalize your team training. The AI literacy obligation (Article 4) has already applied since February 2025. Document who uses which tools, train those employees on the risks, and keep the evidence — training eligible for OPCO funding makes this workstream accessible even to small structures.
Step 5 — Prepare for high risk without waiting for December 2027. If you use AI in recruitment, employee evaluation or credit granting, launch your gap analysis in 2026: technical documentation, human oversight, traceability, data governance. The postponement buys you time; it does not lower a single substantive requirement.
AI compliance is following the same curve as the GDPR in 2018: those who started twelve months before the deadline experienced it as a project; those who waited experienced it as a crisis.