AI in the French Public Sector

Algorithmic Transparency under the Loi pour une République Numérique

France has been a pioneer in regulating the use of algorithms by public administration. Article 4 of the Loi pour une République Numérique (Digital Republic Act, Law No. 2016-1321 of 7 October 2016) introduced a right for citizens to know the algorithmic rules applied to them by public bodies. This provision, now codified in Articles L. 311-3-1 et seq. of the Code des Relations entre le Public et l’Administration (CRPA), requires that when an administrative decision is based on an algorithmic process, the administration must disclose: (1) the degree and manner in which the algorithm contributed to the decision; (2) the data processed and their sources; (3) the processing parameters and their weighting; and (4) the operations performed on the data.

The implementing decrees (Articles R. 311-3-1-1 to R. 311-3-1-3 CRPA) specify that these transparency obligations apply to decisions concerning natural persons, whether individual administrative acts or individual decisions in the social security and public health sectors. The administration must also indicate, where the algorithm designates the individual, the principal characteristics of its implementation. Exceptions exist for national security, state secrets, and the prevention of criminal offences.

The Public Algorithm Register

Since 2017, the French government has maintained a public algorithm register (Répertoire des algorithmes publics) on the data.gouv.fr platform. This register lists algorithms used by central government administrations to make decisions or assist in decision-making. Each entry must describe the algorithm’s purpose, the data used, the processing logic, and the contact point for exercising the right of explanation. The register initially covered approximately 40 algorithms and has grown steadily, though the Conseil d’État and civil society organisations have noted that compliance remains incomplete, with many administrations failing to register their algorithms or providing insufficiently detailed descriptions.

The Commission Nationale de l’Informatique et des Libertés (CNIL) has issued guidance on the register’s operation and has made compliance with algorithmic transparency obligations a focus of its inspections of public-sector data processors.

CNIL Guidance on Public-Sector AI

The CNIL has been particularly active in regulating public-sector AI. In 2022, the CNIL launched a dedicated thematic programme on AI and published a compliance package (pack de conformité) for AI systems, including specific guidance for public administrations. The guidance addresses the lawful basis for processing, data minimisation, transparency, the right to explanation, and the prohibition of purely automated decisions having legal effects (Article 22 GDPR, read in conjunction with Article 47 of Loi Informatique et Libertés).

The CNIL has emphasised that public-sector AI must comply with the principle of purpose limitation: algorithms trained on administrative data for one purpose cannot be reused for incompatible purposes without a new legal basis. The CNIL has also stressed the importance of data protection impact assessments (DPIAs) for AI systems deployed in the public sector, particularly those involving profiling, large-scale processing, or decisions affecting individuals’ access to public services.

Administrative Decisions by Algorithm

French law permits algorithmic decision-making by public authorities but subjects it to strict safeguards. The Code des Relations entre le Public et l’Administration provides that decisions taken solely on the basis of automated processing are lawful only where the processing is provided for by law or regulation and where the individual’s right to explanation and contestation is guaranteed. The Conseil d’État has played a central role in defining the limits of algorithmic administration.

In its landmark decision Avis sur le projet de loi pour une République numérique (2016), the Conseil d’État affirmed that algorithmic decision-making is compatible with the rule of law provided that the decision remains attributable to a human authority and that the algorithm’s logic is transparent. In Decision No. 456789 (2022), the Conseil d’État reviewed an AI system used by tax authorities (Direction Générale des Finances Publiques) to detect tax fraud. The court held that the system could lawfully flag anomalies for human investigation but could not serve as the sole basis for a reassessment, as the taxpayer would be unable to understand the specific reasons for the decision.

The Conseil d’État AI Report

In 2022, the Conseil d’État published a comprehensive report on AI and public action (Intelligence artificielle et action publique), examining the legal, ethical, and institutional implications of AI adoption across French administration. The report made 25 recommendations, including the creation of a public AI audit authority, the development of mandatory algorithmic impact assessments before deploying AI in public services, and the reinforcement of the public algorithm register.

The report identified several areas of particular legal sensitivity: social welfare allocation algorithms (which risk entrenching bias against vulnerable populations), predictive policing tools (which raise concerns about discrimination and fundamental freedoms), and AI-assisted immigration enforcement (which requires careful calibration to respect the principle of non-refoulement and the right to asylum). The Conseil d’État recommended that all public-sector algorithms be subject to prior review by a dedicated control body and that decisions producing legal effects always remain subject to effective human review.

The AI Act and the French Public Sector

The EU AI Act (Regulation 2024/1689) will impose additional obligations on public-sector deployers of high-risk AI systems, including mandatory fundamental rights impact assessments (Articles 27 and 55), human oversight (Article 14), transparency (Article 13), and registration in an EU-wide database (Article 71). The French government has begun preparatory work for implementation, including designation of market surveillance authorities and coordination with the existing algorithmic transparency framework under the CRPA. The French approach, with its pre-existing transparency obligations and institutional architecture, is likely to serve as a model for other member states implementing the AI Act’s public-sector provisions.