How to Create a HACCP Plan
Learn how to create a HACCP plan step by step, from hazard analysis and CCPs to critical limits, monitoring, corrective actions, verification, and records.
Learn how the EU AI Act affects French businesses, including 2026 transparency duties, risk categories, penalties, regulators, and practical compliance steps.
The EU AI Act has turned artificial intelligence from a general technology-governance concern into a defined compliance responsibility for French businesses. Organisations must now understand where AI is being used, which legal role they perform, how each system should be classified and what evidence will be required to demonstrate responsible oversight.
The EU AI Act is the European Union’s risk-based legal framework for the development, supply and professional use of artificial intelligence. It determines which AI practices are prohibited, which systems are considered high-risk, which applications require transparency and which low-risk uses remain largely outside its mandatory control framework.
It is what makes an AI recruitment system legally different from a spelling assistant. It is why a customer chatbot may require a clear disclosure before a conversation begins. It is what connects the design and use of AI with risk management, technical documentation, data governance, human oversight and fundamental rights. It is also why AI compliance cannot be left entirely to IT teams or external software providers.
In this blog, you will learn how the EU AI Act applies to French businesses, what changed under the July 2026 AI Omnibus, which obligations are already relevant, how French authorities will supervise compliance and what practical steps your organisation should take.
This article provides general educational information and does not replace legal advice relating to a particular organisation, contract, product or AI system.
The EU AI Act is the common name for Regulation (EU) 2024/1689, which establishes harmonised rules for artificial intelligence throughout the European Union. It entered into force on 1 August 2024 and applies directly in EU Member States, including France.
Unlike a law that imposes the same requirements on every technology, the EU AI Act follows a risk-based model. The level of regulation depends mainly on what the AI system is intended to do, the context in which it is used and the potential harm it could create.
An AI system used to filter spam usually presents limited consequences for individuals. A system used to rank job candidates, determine access to education, assess a person’s creditworthiness or support medical decisions can influence rights, opportunities, safety and access to essential services. The AI Act therefore places stronger obligations on the second group.
The regulation is designed to support trustworthy and human-centred AI while protecting health, safety and fundamental rights. It also aims to create more consistent AI regulations across the EU so that businesses do not face completely different rules in every Member State.
For organisations in France, the EU AI Act sits alongside other legal duties. These may include the General Data Protection Regulation, the French Data Protection Act, employment law, consumer protection, cybersecurity requirements, product-safety legislation, intellectual-property law and sector-specific regulations.
This overlap matters because an AI system can fall outside the high-risk category under the AI Act while still creating serious privacy, employment, consumer or security risks. Compliance must therefore be assessed across the full legal and operational environment rather than through the AI Act alone.

The EU AI Act does not apply only to technology companies that build artificial intelligence models. It can affect any French organisation that develops, purchases, integrates, distributes or professionally uses an AI system.
A recruitment agency may use AI to screen applications. A retailer may use a chatbot to respond to customers. A bank may use automated tools to assess fraud or creditworthiness. A manufacturer may integrate AI into machinery or safety components. A communications agency may publish synthetic images, audio or video. An employer may allow staff to use generative AI for research, drafting, analysis or customer support.
Each of these situations can create a different combination of responsibilities. The organisation may be a provider for one system, a deployer for another and a distributor or product manufacturer in a separate business line.
This is why the first compliance question should not be limited to whether the company develops AI. French businesses need to ask where AI influences their employees, customers, products, services, communications and decisions.
An organisation that does not know which AI systems it uses cannot classify them reliably. It cannot identify prohibited practices, implement appropriate transparency or determine whether future high-risk obligations apply. It also cannot provide regulators, customers or business partners with credible evidence of oversight.
The responsibilities imposed by the AI Act depend partly on the organisation’s role in the AI value chain. A company should determine its role for each individual system rather than assigning one status to the entire business.
A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
A French software business that creates an AI recruitment platform and sells it to employers may be a provider. A company may also assume provider responsibilities if it substantially modifies another system, changes its intended purpose or markets the system under its own identity in circumstances covered by the regulation.
Providers normally face the broadest responsibilities because they influence system design, testing, documentation, instructions, performance and post-market monitoring.
A deployer uses an AI system under its authority in a professional context. Most organisations that purchase commercial AI tools for internal or customer-facing use will act primarily as deployers.
A French employer using an AI-supported candidate-ranking tool is a deployer. The same is true of a retailer operating an automated customer assistant or a financial organisation using AI to support a regulated business process.
Deployers do not automatically inherit every provider obligation, but they remain responsible for how the system is used. They may need to follow instructions, establish human oversight, monitor outputs, maintain records and provide disclosures to affected individuals.
An importer places an AI system from a provider outside the EU onto the European market. A distributor makes an AI system available within the supply chain.
These operators must verify that the appropriate provider steps have been completed. They should not continue supplying a system where there are reasonable grounds to believe that it does not comply with applicable requirements.
A manufacturer may become responsible when an AI system is placed on the market or put into service together with a regulated product under the manufacturer’s name.
This role is particularly relevant to French businesses producing machinery, medical devices, protective equipment, toys or other products governed by EU product-safety legislation. AI compliance should be integrated into the existing product conformity process rather than treated as a separate review at the end of development.
The EU AI Act organises AI systems into four broad levels of risk: unacceptable risk, high risk, transparency risk and minimal or no risk. The classification depends on the intended purpose and context of use, not simply on whether the technology is technically advanced.
Unacceptable-risk practices are prohibited because they conflict with EU values or create an excessive threat to safety and fundamental rights.
The prohibited categories cover specified forms of harmful manipulation, exploitation of vulnerability, social scoring, certain biometric practices, untargeted facial-image scraping, individual criminal-risk prediction based solely on profiling and emotion recognition in workplaces or educational institutions.
The rules contain detailed wording, conditions and exceptions. A company should therefore avoid relying on a simplified online list when assessing a sensitive system. Suspected prohibited uses should be escalated to qualified legal, compliance and data-protection personnel.
High-risk systems are permitted, but they are subject to extensive requirements because they may significantly affect safety, rights or access to important opportunities and services.
The AI Act identifies two main routes to high-risk status. The first covers AI embedded in certain regulated products under Annex I. The second covers specified sensitive uses under Annex III, including employment, education, biometrics, critical infrastructure and access to essential services.
A system should not be classified as high-risk simply because it uses machine learning. Equally, an organisation should not assume that a system is low-risk merely because it was purchased from a reputable supplier. The purpose, business process and effect on individuals must be examined.
Some AI applications are not prohibited or high-risk but can mislead people if the artificial nature of the interaction or content is hidden.
Article 50 addresses systems that interact directly with individuals, generate synthetic content, create deepfakes or expose people to certain emotion-recognition and biometric-categorisation technologies.
These transparency obligations are especially important from August 2026 because they affect widely used applications such as customer chatbots and generative content tools.
Many ordinary AI systems will fall into the minimal or no-risk category. Examples may include spam filters, basic recommendation features and low-impact productivity tools.
The AI Act does not impose a detailed mandatory control framework on most systems in this category. Other legal and contractual obligations may still apply, particularly where personal data, confidential information, employee monitoring, intellectual property or cybersecurity are involved.

The Article 50 transparency duties are among the most immediate compliance responsibilities for French businesses. They are intended to help people recognise when they are interacting with AI or viewing material that has been artificially generated or manipulated.
Providers of qualifying systems must design them so that individuals are informed when they are interacting directly with AI, unless the nature of the interaction would already be obvious to a reasonably informed and observant person.
A French retailer using a customer-service chatbot should normally give a clear notice at the beginning of the interaction. The disclosure should appear before or when the conversation begins and should not be hidden inside a lengthy privacy policy or general terms of service.
A simple statement such as “You are communicating with an AI-powered assistant” may provide a clearer experience than technical language that ordinary customers cannot understand.
The business should also consider what happens when the automated assistant cannot resolve a problem. Transparency is more meaningful when customers understand how to reach a human representative and how to challenge an incorrect response.
Providers of systems that generate synthetic audio, images, video or text may need to ensure that outputs contain machine-readable markings that allow the artificial origin of the material to be detected.
This obligation is mainly directed at system design. However, businesses using generative tools should still verify whether the chosen provider supports the required technical marking and whether the marks remain intact during editing, export and publication.
Removing metadata or technical markings during a communications workflow could undermine compliance, even where the original system generated them correctly.
Deployers that generate or manipulate deepfake content must generally disclose that the material has been artificially generated or altered.
The disclosure should be visible, understandable and appropriately connected to the content. Businesses should not assume that a small generic notice elsewhere on a website will always be sufficient.
Creative, artistic, satirical and fictional works may receive specific treatment, but the disclosure should still avoid misleading the audience about the nature of the content.
AI-generated or manipulated text published to inform the public about matters of public interest may require disclosure where it has not been subject to appropriate human review or editorial control.
This is relevant to media organisations, public-affairs teams, companies publishing regulatory updates and businesses using AI to produce news-style content.
The existence of a human editor should be documented through a real workflow. Merely allowing an employee to click an approval button without checking sources, accuracy and context is unlikely to provide meaningful editorial control.
Individuals must be informed when they are exposed to qualifying emotion-recognition or biometric-categorisation systems.
These technologies require particular caution because some uses are prohibited and others may involve sensitive personal data. A French employer considering emotion analysis in the workplace should obtain specialist advice before procurement or testing rather than relying on the supplier’s marketing description.
For practical guidance, organisations should consult the European Commission’s Article 50 transparency guidelines.
The AI Omnibus delayed the main high-risk application dates, but the substantive requirements remain central to long-term AI compliance.
Annex III identifies sensitive areas in which certain AI systems can be classified as high-risk. These include biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, justice and democratic processes.
For French businesses, employment-related AI deserves particular attention. Systems used to recruit candidates, filter applications, evaluate workers, allocate tasks, monitor performance or influence promotion and dismissal may fall within the high-risk framework when the legal conditions are met.
Creditworthiness and certain insurance applications are also important. A system that influences whether an individual receives access to an essential financial service can create significant economic and fundamental-rights consequences.
The Annex III requirements are scheduled to apply from 2 December 2027. Organisations using potentially covered systems should use the transition period to establish evidence and improve contractual access to supplier documentation.
The second high-risk route concerns AI used as a safety component of a regulated product, or AI that is itself a regulated product requiring third-party conformity assessment.
This route may apply to products such as machinery, medical devices, lifts, toys and personal protective equipment, depending on the specific EU legislation and the function of the AI component.
The main obligations for this category are scheduled to apply from 2 August 2028. French manufacturers should connect the AI review with existing product-design, quality-management and conformity-assessment processes well before that date.
The exact responsibility depends on whether the organisation is a provider, deployer, importer, distributor or manufacturer. However, the high-risk framework generally centres on risk management, data quality, documentation, traceability, human oversight, technical performance and lifecycle monitoring.
Providers will need a structured risk-management system that identifies known and reasonably foreseeable risks throughout the lifecycle. The process must lead to actual control decisions rather than a static list of theoretical concerns.
Training, validation and testing data must be subject to appropriate governance. This includes examining relevance, representativeness, possible errors and the risk of discriminatory outcomes. Data quality should be assessed in the context of the system’s intended purpose and affected population.
Technical documentation must explain how the system works at a level sufficient to demonstrate compliance. It should cover intended purpose, design choices, limitations, testing, performance, risk controls and changes made after initial release.
Record-keeping capabilities are important because organisations may need to reconstruct what happened when a system produced a disputed decision or harmful outcome. Logs should be accessible, appropriately protected and retained for a justified period.
Human oversight must be designed into the system and operational process. The reviewer should understand the system’s limitations, recognise warning signs, intervene when necessary and have authority to reject or reverse an output.
High-risk systems must also meet appropriate standards for accuracy, robustness and cybersecurity. A system that performs well in a controlled demonstration but fails when data or operating conditions change may create unacceptable operational risk.
General-purpose AI models can perform a wide range of tasks and can serve as a foundation for many downstream systems. The obligations for providers of these models began to apply in August 2025.
GPAI providers may need to maintain technical documentation, provide information to downstream providers, adopt a policy for complying with EU copyright law and publish a sufficiently detailed summary of model training content. Providers of models with systemic risk face additional responsibilities relating to evaluation, risk mitigation, incident reporting and cybersecurity.
Most French businesses that subscribe to a commercial generative AI service are not automatically GPAI providers. They are more likely to be deployers of an AI system made available by another company.
That distinction does not remove organisational responsibility. Businesses still need to understand what employees are allowed to submit, whether customer or employee data are processed, how prompts are retained, whether uploaded information is used for training and how generated outputs are reviewed.
An approved generative AI service should therefore be accompanied by an internal use policy. The policy should define acceptable tasks, prohibited data, review expectations, intellectual-property precautions, disclosure requirements and escalation procedures.
The EU AI Act does not replace the RGPD. The two frameworks regulate different but frequently overlapping risks.
The AI Act focuses on AI-system safety, transparency, governance and fundamental rights. The RGPD regulates the collection and processing of personal data.
Where an AI system uses data about employees, customers, patients, applicants or website users, the organisation may need to comply with both laws. This is common in recruitment, customer profiling, fraud prevention, healthcare, education and personalised services.
A French organisation should identify the purpose of the processing, the lawful basis, the categories of data involved, the retention period and the people who receive access. It should also determine whether special-category data are processed, whether automated decision-making is involved and whether a data protection impact assessment is required.
Vendor questions should cover storage locations, international transfers, subprocessors, security controls, model training, deletion procedures and the handling of access or erasure requests.
The CNIL has confirmed that where personal data are used to develop AI, both the RGPD and AI Act may apply. Its AI and data-protection recommendations provide useful guidance on purpose limitation, lawful processing, data minimisation and dataset governance.
France has chosen a sector-based model involving several existing authorities rather than one regulator for every AI system.
The published French structure gives the Direction générale de la concurrence, de la consommation et de la répression des fraudes a central coordination role. The DGCCRF is intended to coordinate market-surveillance authorities and act as France’s single contact point under the AI Act.
The Commission nationale de l’informatique et des libertés has an important role where AI affects personal data and fundamental rights. Its responsibilities include supervision of several prohibited practices and specified high-risk systems involving areas such as employment, education, biometrics, migration and law enforcement.
Arcom is relevant to audiovisual and digital communications, including some synthetic-media and public-information obligations. The Autorité de contrôle prudentiel et de résolution is expected to oversee qualifying AI systems used by financial institutions for creditworthiness and certain insurance assessments.
Authorities already responsible for regulated products will supervise qualifying AI integrated into those products. This means a manufacturer may continue dealing with a familiar sector regulator, but the scope of review will expand to cover relevant AI requirements.
French organisations should monitor the official French AI Act authority framework, as the detailed governance structure depends on national implementation measures.
A successful compliance programme begins with visibility and ownership. French businesses do not need to purchase a complex governance platform before they understand the systems already in use.
A senior sponsor should be accountable for AI governance. Depending on the organisation, this may be the compliance director, general counsel, risk director, DPO, chief information officer or another executive.
The sponsor should have authority to require information from departments, stop unsafe deployments, approve policies and escalate significant risks. Without clear decision rights, AI governance can become an advisory exercise that business teams are free to ignore.
A cross-functional working group can support the sponsor. It may include compliance, legal, privacy, security, procurement, HR, product and internal audit. The group should have defined responsibilities and a regular review schedule.
The inventory should include systems that are purchased, developed internally, embedded in existing software or used informally by employees.
Common examples include chatbots, recruitment tools, recommendation engines, fraud systems, generative AI accounts, employee-monitoring tools, predictive maintenance, analytics platforms and AI features added to common workplace software.
Each record should identify the owner, provider, intended purpose, affected people, data categories, business process, deployment status and main risk concerns.
Shadow AI must also be considered. Employees may use consumer tools without procurement approval, which can create confidentiality, privacy and contractual risks that do not appear in official software registers.
For each system, record whether the organisation acts as provider, deployer, importer, distributor or product manufacturer.
This analysis should consider branding, customisation, integration and changes to intended purpose. A company that significantly modifies a third-party system may assume responsibilities that were not expected during procurement.
The role assessment should be updated when the system or business model changes.
The classification record should explain whether the system is prohibited, potentially high-risk, subject to Article 50 or minimal risk.
A conclusion such as “low-risk” is not enough. The record should explain the system’s purpose, users, affected individuals and why the relevant prohibited or high-risk categories do not apply.
Uncertain systems should be escalated for specialist review. It is better to document uncertainty and obtain advice than to force a convenient classification without evidence.
Businesses should create a clear process for reporting and stopping suspected prohibited uses.
HR, procurement, marketing and product teams should understand that certain practices cannot be approved through ordinary business risk acceptance. A commercial benefit does not make a prohibited system lawful.
Supplier contracts should allow the organisation to suspend or terminate use where a system creates a prohibited practice or where the supplier fails to provide necessary compliance information.
Article 50 should be translated into specific operational tasks. Chatbot notices, deepfake labels, machine-readable markings and public-interest content reviews require different owners and technical solutions.
The business should test the customer experience on desktop and mobile devices. It should also retain screenshots, content-approval records and evidence of provider marking capabilities.
Transparency should be reviewed whenever a system is updated, a new communication channel is added or a different content format is introduced.
The AI inventory should be linked to the organisation’s record of processing activities.
Where personal data are involved, the DPO or privacy team should assess lawful basis, transparency, data minimisation, security, individual rights and the need for a DPIA.
This review should occur before procurement or deployment. Privacy teams cannot negotiate effective safeguards after the supplier has been selected and the system has become operationally essential.
AI procurement questionnaires should go beyond ordinary software-security checks.
The supplier should explain the system’s intended purpose, legal role, classification, data sources, testing, limitations, human-oversight features, incident process, update procedures and documentation.
Contracts should address audit rights, access to records, regulatory cooperation, material changes, security incidents, subcontracting, data use and termination assistance.
A statement that a product is “AI Act compliant” should not be accepted without supporting evidence.
Human oversight is not achieved simply by placing a person at the end of an automated process.
The reviewer must understand the decision context, receive enough information to identify errors and have authority to disagree with the system.
The procedure should explain when outputs require review, which warning signs trigger escalation, how overrides are recorded and when the system must be suspended.
Workload also matters. An employee cannot provide meaningful oversight if expected to review thousands of automated decisions without sufficient time or information.
AI systems can change because of model updates, new data, altered business processes or supplier modifications. A classification completed at procurement may no longer reflect the system used six months later.
Monitoring should cover incidents, complaints, overrides, inaccurate outputs, discriminatory patterns, security events and changes to intended use.
Material changes should trigger reassessment. The organisation should also record corrective actions and verify that the control solved the underlying problem.
Good documentation should allow another qualified person to understand what the system does, why it was approved and how it is controlled.
A proportionate governance file may include an AI inventory, role assessment, risk classification, impact assessment, DPIA, supplier review, human-oversight procedure, transparency evidence, approval record, incident process and monitoring reports.
Small organisations do not need to create unnecessarily complex documents. A structured record that is completed and regularly used is more valuable than a lengthy policy that does not reflect actual practice.
Documentation should also be consistent. If the supplier contract describes one intended purpose but the internal risk assessment describes another, the inconsistency may indicate that the organisation has not properly understood the deployment.
HR teams should prioritise tools used for recruitment, candidate ranking, performance management, scheduling, promotion and dismissal.
The review should examine whether the system influences employment opportunities, whether the underlying data are appropriate and whether candidates or workers can challenge an incorrect outcome.
Emotion recognition in the workplace requires particular caution because specified uses are prohibited.
Marketing teams should focus on generative content, deepfakes, public-interest information, consumer deception and intellectual property.
A content workflow should define when AI-generated material requires labelling, how source claims are checked and who holds editorial responsibility.
Banks, lenders, insurers and fintech businesses should assess systems used for creditworthiness, pricing, customer profiling, fraud and transaction monitoring.
These uses may be affected by the AI Act, RGPD, consumer law and sector supervision. The ACPR may also have a role depending on the organisation and use case.
Healthcare providers and medical-technology businesses should determine whether an AI system is part of a regulated medical device and whether health data are processed.
Patient safety, medical-device regulation, professional responsibility, cybersecurity and data protection must be considered together.
Manufacturers should identify AI embedded in machinery, robotics, quality controls, safety components and predictive maintenance.
The AI review should be incorporated into design, testing, quality management and conformity assessment rather than added immediately before launch.
The AI Act provides substantial maximum penalties.
Non-compliance with prohibited AI practices may lead to administrative fines of up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever threshold applies under the regulation.
Breaches of specified provider, deployer, importer, distributor and Article 50 obligations may lead to fines of up to €15 million or 3% of worldwide annual turnover.
Providing incorrect, incomplete or misleading information to authorities may lead to fines of up to €7.5 million or 1% of worldwide annual turnover.
For SMEs, including start-ups, the maximum is generally the lower of the fixed amount and turnover percentage. Regulators must also consider factors such as severity, duration, damage, cooperation, intent and the organisation’s technical and organisational measures.
Businesses should verify the final penalty framework against the consolidated AI Act and French implementing rules, particularly because the 2026 AI Omnibus amended parts of the regulation.
One of the most damaging mistakes is waiting until the high-risk deadline before beginning preparation. Classification, supplier negotiation, documentation and testing can take months, especially where an AI system is deeply connected to HR, finance or product operations.
Another common error is assuming that the supplier carries all responsibility. A provider may be responsible for design and technical documentation, but the French business controls the context in which the system is deployed.
Businesses also overlook AI features embedded in existing software. A familiar HR, CRM or productivity platform may add an AI function through an ordinary update, even though no separate AI product was purchased.
Transparency is often handled poorly. A chatbot disclosure hidden in a privacy policy does not give a user clear notice at the point of interaction.
Finally, organisations sometimes confuse human presence with human oversight. A reviewer who automatically accepts the system’s output does not provide meaningful control.
AI governance requires people who can translate legal requirements into practical decisions about procurement, risk, documentation, oversight and monitoring.
The Certificate in AI Risk Management can help professionals understand how to identify, assess and control risks connected to organisational AI use.
The AI Compliance Officer Training covers AI governance principles, EU AI Act concepts, RGPD considerations, CNIL expectations, documentation, vendor oversight and compliance-programme management.
Training does not make an organisation compliant by itself. However, informed employees are better able to identify risky systems, ask suppliers the right questions and maintain the records required for responsible oversight.
The EU AI Act already affects French businesses. Prohibited practices have applied since February 2025, obligations for providers of general-purpose AI models began in August 2025 and Article 50 transparency duties apply from 2 August 2026.
The AI Omnibus postponed the main Annex III high-risk requirements to 2 December 2027 and the Annex I product-related requirements to 2 August 2028. It did not create a general pause in AI compliance.
French organisations should prioritise system inventories, role assessments, prohibited-practice screening, Article 50 transparency, RGPD integration and supplier governance.
The strongest compliance programmes will connect AI governance with existing risk, privacy, security, procurement and audit processes rather than building a completely isolated framework.
EU AI Act compliance begins with understanding how artificial intelligence is actually used inside the organisation.
A French business cannot manage legal risk if AI systems remain hidden in individual departments, embedded in supplier software or used informally by employees. It needs a reliable inventory, clear ownership, documented classification and controls that match the real impact of each system.
The July 2026 AI Omnibus gives organisations more time to prepare for high-risk obligations, but the most immediate duties have not disappeared. Article 50 transparency, prohibited-practice screening, GPAI governance and existing data-protection responsibilities require attention now.
Businesses that use the transition period effectively will be better prepared for regulatory scrutiny and better positioned to deploy AI responsibly. The objective is not to produce paperwork for its own sake. It is to create evidence that AI systems are understood, controlled and used in a way that protects people and supports sound business decisions.