French AI Enforcement: CNIL Audits, Algorithmic Transparency, and AI Liability
France has emerged as a leading jurisdiction for the regulation of artificial intelligence, with a combination of general data protection law, sector-specific regulation, and proactive enforcement by the Commission Nationale de l’Informatique et des Libertés (CNIL). French AI regulation is shaped by EU law, including the General Data Protection Regulation (GDPR) and the proposed EU AI Act, while also reflecting distinctive French priorities regarding algorithmic transparency, public service algorithms, and AI liability.
CNIL AI Audits
The CNIL has developed a specialised capacity for auditing AI systems. The authority has conducted investigations into the use of AI by both public and private entities, focusing on compliance with data protection principles. The CNIL’s AI audits examine whether AI systems have a lawful basis for processing personal data, whether they respect the principles of purpose limitation and data minimisation, and whether they comply with transparency and fairness requirements.
The CNIL has published guidance on AI auditing, setting out the methodology it uses to evaluate AI systems. The guidance covers data collection and preparation, model training and validation, model deployment and monitoring, and the governance of AI systems. The CNIL has also developed tools for auditing AI systems, including software for testing compliance with data protection requirements.
Algorithmic Transparency in Public Services
The Loi pour une République numérique (Law for a Digital Republic) of 2016 introduced specific requirements for algorithmic decision-making by public authorities. Under Article L. 311-3-1 of the Code des relations entre le public et l’administration, public authorities that use algorithms to make individual decisions must disclose the rules defining the algorithm and the main processing characteristics.
The transparency requirement applies when a public authority makes an individual decision based solely on algorithmic processing. The individual has the right to be informed that the decision was made by algorithm and to obtain an explanation of the algorithm’s functioning. The transparency obligation does not apply to algorithms used for internal administrative purposes or to algorithms whose disclosure would compromise public security.
AI Liability Under the Code Civil
AI liability in France is governed primarily by the general provisions of the Code civil on civil liability. Article 1240 (formerly 1382) imposes liability for fault (faute) that causes damage to another. Article 1242 imposes liability for things in one’s custody (garde de la chose), which has been extended to cover certain AI systems.
The application of traditional liability rules to AI systems raises complex questions. The identification of fault may be difficult when the harm is caused by the autonomous operation of an AI system. The garde de la chose regime, established by the Arrêt Jand’heur (1930), may apply to AI systems that cause physical damage. The concept of garde de la structure and garde du comportement, developed in the context of defective products, may provide a framework for allocating liability between AI developers and users.
Product Liability for AI
The EU Product Liability Directive (85/374/EEC), transposed into French law in Articles 1245-1 to 1245-17 of the Code civil, applies to defective AI products. The producer of a defective AI product is liable for damage caused by the defect. The claimant must prove the damage, the defect, and the causal relationship between them.
The application of product liability to AI systems raises particular challenges. The defect may be in the software rather than in the hardware, and the damage may be caused by the autonomous operation of the system rather than by a manufacturing flaw. French courts have applied product liability to software in certain cases, but the application to AI systems remains to be fully developed.
Sectoral AI Regulation
AI is regulated in several sectors through specific legislation. In healthcare, AI systems used for medical devices are subject to the Code de la santé publique and EU medical device regulations. AI systems used for diagnostic purposes must be certified as medical devices and must comply with requirements for safety, performance, and clinical evidence.
In finance, AI systems used by banks and insurance companies are subject to the Code monétaire et financier and the supervision of the Autorité de Contrôle Prudentiel et de Résolution (ACPR). The ACPR has published guidance on the use of AI in financial services, emphasising governance, transparency, and non-discrimination requirements. AI systems used for credit scoring, insurance pricing, and fraud detection are subject to specific regulatory requirements.
The EU AI Act
The proposed EU AI Act, which is expected to enter into force in the coming years, will establish a comprehensive regulatory framework for AI in the European Union. The AI Act classifies AI systems by risk level: unacceptable risk (prohibited), high risk (subject to strict requirements), limited risk (subject to transparency obligations), and minimal risk (unregulated).
France has been an active participant in the negotiation of the AI Act, advocating for strong enforcement powers for national supervisory authorities and for the protection of fundamental rights. The CNIL is expected to be designated as the national supervisory authority for AI in France, giving it responsibility for overseeing compliance with the AI Act.
Algorithmic Discrimination
French anti-discrimination law applies to AI systems that make or influence decisions affecting individuals. The Défenseur des droits (Defender of Rights) has the authority to investigate algorithmic discrimination and to bring cases before the courts. The Défenseur des droits has published guidance on preventing algorithmic discrimination, emphasising the importance of diverse training data, regular auditing, and human oversight.
The French approach to algorithmic discrimination emphasises transparency and explainability. AI systems used for decisions affecting individuals must be capable of explaining their decisions in terms that are understandable to the individuals affected. The requirement of explainability is particularly strict for AI systems used by public authorities and by entities providing essential services.
Future Developments
French AI law continues to evolve. The government has published national AI strategies that emphasise the development of trustworthy AI, investment in AI research, and the training of AI specialists. The CNIL has announced plans to increase its capacity for AI auditing and to develop new regulatory tools for AI governance. The implementation of the EU AI Act will further transform the French regulatory landscape, introducing new requirements for high-risk AI systems and strengthening enforcement.