Regulator & compliance
The CNIL's role in the EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) is enforced by national market surveillance authorities. In France, the CNIL is the reference authority for overseeing AI systems — it is already competent whenever a system processes personal data. Being audit-ready means being able to present an up-to-date inventory, risk classification and documentation at any time.
Market surveillance
The AI Act requires each Member State to designate authorities that oversee AI systems placed on the market or used in the EU: prohibited practices, transparency obligations, high-risk requirements. In France, the CNIL plays a central role in this framework, with powers of investigation, injunction and sanction.
AI and personal data
Most AI systems process personal data, so the GDPR applies alongside the AI Act. The CNIL already supervises these processing operations (legal basis, minimisation, DPIA) and publishes AI-specific guidance. A single inspection can cover both regulations at once.
Audits, inspections and fines
During an inspection, the authority can request the inventory of your AI systems, their risk classification, the technical documentation and governance measures. AI Act fines can reach €35M or 7% of worldwide turnover for prohibited practices.
How to stay ready at all times
- Keep an up-to-date inventory of the AI systems and agents used across your projects and tools.
- Classify every system by its AI Act risk level (minimal, limited, high, prohibited).
- Generate and keep the expected documentation: AI Act report, DPIA, records.
- Automate recurring scans to detect any new AI introduced in your organisation.
Fulfai automates exactly these four points: your file is ready to present at any time.
This page is provided for information purposes only and does not constitute legal advice.