AI Act 2026: CNIL becomes supervisory authority with penalties up to €35M

By Pierre-Louis Roquet, Attorney at the Lyon Bar | 2 mai 2026 | Reading time : 8 min
CNIL Commission controls artificial intelligence AI Act 2026 sanctions fines

The entry into force of the AI Act places the CNIL at the heart of French artificial intelligence regulation. Formidable penalties for non-compliant companies.

## The AI Act strengthens CNIL's powers: a major regulatory turning point February 12, 2026 will remain a key date: the government submitted a historic amendment to the 1978 law to designate the CNIL as the national supervisory authority for the AI Act. This institutional transformation marks a break with the fragmented approach that prevailed until then. The CNIL has been designated as the reference authority for the application of the AI Act in France, consolidating its status as a key player in digital regulation. This designation is accompanied by considerably expanded control and sanctioning powers, which radically transform compliance challenges for French companies. Far from being a mere extension of its GDPR missions, this evolution grants the CNIL autonomous jurisdiction over artificial intelligence systems, with direct implications for any organization that develops, deploys, or uses algorithmic solutions. ## Which AI systems concern your company? [The AI Act frames the development, commercialisation, and use of AI systems in Europe](/fr/blog/ai-act-2026-obligations-entreprises-ia-generative-chatbots) according to 4 risk levels. This classification determines your legal obligations and the penalties incurred. **Unacceptable risk systems (prohibited since February 2025)** Penalties for prohibited practices — social scoring, subliminal manipulation, exploitation of vulnerabilities — have been applicable since February 2, 2025. These systems expose their users to immediate fines. **High-risk systems (obligations since August 2026)** Obligations for high-risk AI apply since August 2, 2026, for systems used in biometrics, critical infrastructures, education, employment, or justice. This category notably concerns: - Candidate sorting and HR scoring tools - Credit scoring and financial assessment systems - Assisted medical diagnostic solutions - Fraud detection algorithms A HR management software that includes a candidate scoring module, a B2B credit-scoring solution, an internal fraud detection tool: these are all concrete examples where the deploying SME becomes responsible under the AI Act. **Limited risk systems** [Chatbots fall into the “limited risk” category](/fr/blog/ai-act-2026-obligations-entreprises-ia-generative-chatbots). The main obligation is to inform users that they are interacting with an AI. A simple obligation but strictly controlled by the CNIL.
**Do you have a question on this topic?** Maître Pierre-Louis Roquet, a business law *avocat* in Lyon, provides you with reactive and expert support. [Contact the firm](/fr/qui-suis-je) to discuss it.
## CNIL sanctions: up to 35 million euros in fines Fines range from 7.5 million euros (or 1.5% of global turnover) for inaccurate information, to 35 million euros (or 7% of global turnover) for the use of prohibited AI practices. Its restricted committee can issue injunctions, daily penalty payments up to 100,000 euros, and fines up to 35 million euros or 7% of global turnover. The sanction regime is organized into three levels:
Type of Infringement Maximum Amount Percentage of Global Turnover
Inaccurate information to authorities €7.5 M 1.5%
Non-compliance high-risk systems €15 M 3%
Prohibited practices €35 M 7%
For a company with 10 billion euros in global turnover, violating prohibited practices could result in a fine of 700 million euros. This amount significantly exceeds the penalties provided by the GDPR. Penalties can be cumulative: GDPR up to €20M or 4% of global turnover + AI Act up to €35M or 7% of global turnover = Theoretical total up to €55M for the same infringement. ## How to prepare your company for CNIL controls? CNIL already has solid experience in GDPR control, and its investigation and sanction framework will also apply to breaches of the AI Act. Companies that have already been audited for GDPR know that these procedures are serious and demanding. **Step 1: Exhaustive inventory of AI systems** The inventory of tools used is therefore the first essential step in any serious compliance process. Document all tools that integrate algorithmic functionalities, including third-party SaaS solutions. **Step 2: Classification according to risk levels** Each identified system must be evaluated according to the AI Act grid. CNIL will have the authority to verify and challenge these evaluations if it considers that a company minimizes the risks of its product. **Step 3: Technical documentation and human oversight** The deployer must establish a risk management system throughout the AI system's lifecycle, ensure effective human oversight of its automated decisions, and maintain a documented register of uses. **Step 4: Team training** The obligation of “AI literacy” (minimum training for teams handling AI) is also active. This requirement concerns all employees who interact with AI systems as part of their activity.
**Good to know:** According to a DGE study, the cost of compliance for an SME deploying high-risk systems ranges between 2,000 and 8,000 euros per year (including audit and training). This is a modest investment compared to potential penalties.
## Calendar of deadlines not to be missed Application is progressive: prohibitions since February 2025, GPAI obligations since August 2025, and full application on August 2, 2026.
Date Applicable Obligations
February 2025 Prohibition of unacceptable risk practices
August 2025 Obligations for general purpose AI models
**August 2026** **Full application for high-risk systems**
August 2027 Extension to regulated products (medical devices, toys)
The authority will focus its investigations on the growing use of artificial intelligence in candidate screening and selection. The CNIL has indicated that it will intensify its controls on HR systems from autumn 2026. ## Related articles - [AI Act CNIL sanctions companies: 2026 rules](/fr/blog/ai-act-cnil-sanctions-entreprises-2026) - [CNIL: strengthened artificial intelligence audit 2025-2028](/fr/blog/cnil-plan-strategique-2025-2028-audit-intelligence-artificielle) - [CNIL sanctions 2026: new AI Act and GDPR powers](/fr/blog/sanctions-cnil-2026-ai-act-rgpd) ## Key takeaways • **The CNIL has new control powers over AI** with penalties that can reach 35 million euros or 7% of global turnover • **Any company using AI systems is concerned**, from chatbots to scoring tools, according to a 4-level risk classification • **The critical deadline is August 2026** for high-risk systems: HR, credit, biometrics, health • **Compliance requires a complete inventory**, technical documentation, and effective human oversight • **CNIL controls are intensifying**, particularly on HR tools and automated decision systems ### Does my company need to comply with the AI Act before August 2026? Yes, if you use high-risk AI systems. Identify without delay whether your AI systems fall under Annex III of the AI Act and undertake the technical documentation, risk management, and European registration work to be in compliance before August 2, 2026. The obligation applies as soon as an algorithm influences decisions concerning employment, credit, health, or essential services. ### What are the penalties for non-compliance with the AI Act? Penalties can be very heavy, up to 35 million euros or 7% of annual turnover for the most serious infringements. The most serious violations — use of prohibited systems or non-compliance with high-risk systems — can result in fines up to 30 million euros or 6% of annual turnover. These amounts are cumulative with potential GDPR penalties. ### How does the CNIL control the application of the AI Act? As a market surveillance authority, it ensures compliance with obligations regarding prohibited practices: social scoring, behavioural manipulation, exploitation of vulnerabilities, facial recognition in public spaces. It will then regulate high-risk systems under Annex III, and as a notified body, it issues certificates of conformity for high-risk AI systems before their placement on the market. ### Which AI tools are considered high-risk? Automated recruitment tools, credit scoring systems, medical diagnostic solutions, fraud detection algorithms, and biometric systems. For high-risk AI, obligations are extended: detailed technical documentation, robustness tests, bias assessment in training data, implementation of human oversight, and continuous monitoring after deployment. ### Do SMEs benefit from exemptions for the AI Act? SMEs and startups benefit from explicit mathematical protection (Article 99): the amount retained is the lesser of the percentage of global turnover and the fixed amount in euros, whereas for large companies, the higher applies. The AI Act includes regulatory sandboxes where small companies can test their innovations under lighter supervision before market placement.
**Need support in business law?** I assist you in negotiating and securing your contracts, both in France and internationally. [Video conference consultation](/fr/qui-suis-je) · [Make an appointment](/fr/qui-suis-je)