France
Information uploaded as at June 2026
AT A GLANCE
France is gradually integrating AI into its criminal justice system, with the Cour de Cassation playing a leading role, though deployment remains cautious, experimental, and largely supportive rather than decision-making. Law enforcement uses AI for operational support (e.g. AI-guided online complaints, speech recognition and translation tools like RosetIA, automated transcription, and offence-classification tools such as PredNatinf), and has piloted predictive policing systems (e.g. PredVol, PAVED, Smart Police), though many initiatives have been limited or discontinued amid concerns about legality, bias, and effectiveness. Facial recognition is tightly restricted by law but permitted in certain judicial databases, while broader video analytics—temporarily authorised (excluding facial recognition) for the Paris 2024 Olympics—were deemed of limited but real operational value and remain subject to legal scrutiny. Prosecutors and courts are piloting AI for case management, translation (TRAUNE), document extraction (ÉPOPÉE), anonymisation of judgments (LABEL), and legal research and drafting support, while French law explicitly prohibits predictive justice tools aimed at forecasting individual judicial decisions. Defence lawyers widely use both general and specialised AI tools, supported by national training initiatives and bar-led partnerships.
In France, there is no standalone statutory regime specifically governing the use of AI in criminal proceedings; instead, the primary binding framework is the EU AI Act, supplemented by domestic law. Professional and institutional bodies have issued their own guidance for practitioners, including the Conseil d'Etat's Charter for the Use of AI within the Administrative Jurisdiction and the French National Bar Council's Practical Guide on the Use of Generative Artificial Intelligence Systems, while the Ministry of Justice has set out a broader strategic roadmap for AI adoption across the justice system. In addition, existing general laws — including Law No. 78-17 of 6 January 1978 on Computer Technology, Data Files, and Civil Liberties (as amended), the Law Enforcement Directive as transposed into French law, the GDPR, and provisions of the Criminal Code addressing deepfakes (Articles 226-8 and 226-8-1) and evidence tampering (Article 434-4) — may limit the use of AI and AI-generated material in criminal proceedings. French courts have also, in a series of recent cases, examined the lawfulness of automated video analytics and algorithmic processing of CCTV footage in public spaces, including decisions of the Conseil Constitutionnel, the Conseil d'Etat, and the Administrative Tribunals of Caen and Grenoble.
Use
France is beginning to integrate AI into its criminal justice system through several projects, with the Cour de Cassation (the supreme court for civil and criminal cases in France) playing a central role. While AI deployment remains at an early and largely experimental stage as at June 2026, there is a clear intention to progressively incorporate AI tools across all phases of criminal proceedings.
Law enforcement
French police have experimented with a range of AI tools designed to support law enforcement. In September 2020, the French National Gendarmerie (a branch of the French Armed Forces placed under the jurisdiction of the Ministry of Interior) created a DataLab to develop innovative AI tools for law enforcement purposes.
As a precaution, French law enforcement have generally relied on pilot deployments before considering nationwide or permanent use. In some instances, deployments have been restricted or halted by judicial or administrative authorities on the grounds that they lacked an adequate legal basis or operated in breach of existing law.
Operational support
The National Gendarmerie is currently developing an AI-assisted system to improve online criminal complaint processing. Its goal is to transform the existing online pre-complaint service, where victims start a report online and then go to a police station to finalise it, into a fully online complaint system without the victim having to go to the precinct in-person. The AI component will act as an interactive ‘dialogue agent’, guiding victims through the complaint submission process by categorising the type of offence (such as criminal damage), and identifying missing information needed to transform the report into a formal police record.
RosetIA is an automatic speech recognition tool used by French law enforcement to provide high-quality transcription and multilingual translation. It uses OpenAI Whisper technology to help identify different speakers in recordings and automatically transcribe audio and video files in 94 languages. It is also able to translate these transcripts. RosetIA can also retrain the model, improving transcription quality for less-resourced languages.
Other transcription and translation tools currently in use in France include:
- Parole is another AI-powered transcription tool, used to transcribe custodial hearings.
- An automatic transcription tool for interviews with minor victims is currently being tested in three Family Protection Units (Maisons de protection des familles) in France.
- Since 2024, an automatic translation tool has been implemented within the Plainte en ligne (online criminal complaints) system for complaints filed in foreign languages.
Predictive analytics
French law enforcement agencies have been experimenting with predictive policing for over a decade.
Smart Police (Edicia) is a software suite launched in the mid-2010s and used by municipal police forces to support day-to-day operations, including field reporting via mobile devices and the production of near real-time operational statistics. Reporting also describes a 'predictive' component that is able to anticipate routine or unusual risk situations by drawing on internal police records and other contextual information. This information serves to support, rather than replace, human decision-making.
Marseille’s ‘Big Data for Public Safety’ (Big data de la tranquillité publique) project aims to anticipate the occurrence of dangerous events or situations through the analysis of data collected from public services operating within the city.
PAVED is a predictive tool that was developed within the National Gendarmerie to estimate the risk of vehicle theft and burglary at a geographic level. It was developed in the mid-2010s and tested between 2017 and 2019 in multiple departments. While it was initially presented as a candidate for wider rollout, reporting indicates that the project was subsequently put on hold, with doubts expressed internally about performance and operational value.
Concerns have been raised by French civil society groups regarding the risk of profiling and discriminatory impacts, as well as limited transparency and uncertain effectiveness, of AI systems in France. A common criticism is that these systems may identify correlations in recorded data without demonstrating causal relationships, which may lead to misleading risk signals and overconfident operational decisions.
Data review and analysis
An additional use of AI in law enforcement relates to facial recognition for the identification of criminal suspects. While facial recognition drones, police body cameras, and facial recognition through public camera feeds are barred under French law (see below) since 2013, the Judicial Records Processing System (Traitements des Antecedents Judicaires) has included a module allowing the national police and National Gendarmerie , upon request, to compare photographs with images from video surveillance systems or social media. In 2019, there were approximately 375,000 requests carried out under the Judicial Records Processing System.
In late 2023, the investigative outlet Disclose revealed that the French National Police, the National Gendarmerie , and several municipalities (including Nice and Marseille) have been using undocumented features of BriefCam, a video-analysis platform used to search, filter, and summarise CCTV footage at scale. While the government officially opposed public facial recognition, police were allegedly using the software’s 'Face Matching' module to search archives without the required declarations to data protection authorities. Administrative litigation has since led several tribunals to order the cessation of specific municipal BriefCam deployments. Concurrently, the French Data Protection Authority (CNIL) has conducted audits and issued formal notices, citing significant deficiencies in governance, documentation, and compliance with privacy standards.
More broadly, the use of augmented cameras for event detections became especially visible around the Paris 2024 Olympic and Paralympic Games, when Parliament adopted a dedicated framework—Article 10 of Law No. 2023-380 of 19 May 2023—authorising, on an experimental basis and until 31 March 2025, real-time algorithmic processing of video images in narrowly defined, high-risk contexts. Official procurement documentation indicates that the Ministry of the Interior contracted multiple providers of these technologies, such as Wintics, Videtics, and ChapsVision. The goal was to automatically detect anomalous events that could pose a security risk and to alert the police immediately. Facial recognition was explicitly prohibited. After the Olympic Games, the government-mandated evaluation committee submitted its report in January 2025. The report characterised the operational value of the experiment as real but limited, and emphasised the importance of procedural safeguards and careful assessment of effectiveness in practice.
The cameras used in the Paris 2024 Olympic and Paralympic Games were found to be accurate at detecting people entering prohibited zones and identifying mass gatherings, but less accurate at detecting people falling or objects left abandoned. The Senate Law Commission published its own oversight report in February 2025, reaching a similar bottom line: the experiment was significant in part because it placed a clearer legal framework around emerging practices, but it did not generate sufficiently strong evidence—positive or negative—to justify immediate normalisation, and it recommended continuing evaluation before any permanent regime.
Although the Paris 2024 framework was designed as temporary and exceptional, post-Games debates quickly shifted toward whether and how such analytics should be extended. That push has met meaningful legal resistance. In Nice, the Conseil d’Etat held on 30 January 2026 ('Commune de Nice' v CNIL, Case No. 506370) that systematic algorithmic processing of public-space CCTV images (in that case, cameras placed near schools to read car licence plates) is not authorised 'in the current state of the law' under the general legal regime for public-space video-surveillance.
PredNatinf is an AI tool that generates a list of relevant elements of the criminal offence based on a short summary of the facts. When law enforcement officers observe an incident or receive a complaint, they must identify the relevant criminal offence(s) and the appropriate legal qualification(s). Such qualification is essential, as it determines how the investigation is conducted and how the criminal procedure will proceed. The project was experimented, has been approved, and as at June 2026, has been deployed.
The Tool for the Detection of Child Sexual Abuse Images is an AI-based system developed to assist investigators in identifying child sexual abuse material during digital investigations. Its primary goal is to facilitate the analysis of large volumes of data while significantly reducing investigators’ exposure to traumatic content. The system operates through a two-step technical process:
- Images are converted into numerical representations that eliminate the need to look directly at the content.
- A machine learning model analyses the data to distinguish between illegal images and lawful material. The system does not make autonomous decisions: it flags potentially illegal content, while investigators retain full control and make the final determination.

Prosecutors
Case management
TRAUNE is a machine translation tool trialled at the Ministry of Justice, with plans to expand to automatic transcription as at June 2026.
As at June 2026, the French Ministry of Justice is exploring AI-enabled case management tools to streamline prosecutorial and court workflows as part of a broader effort to modernise information handling in criminal justice. In particular, the Ministry reports an experiment with an internal tool called Albert, developed within the government to support administrative services by handling large volumes of information, retrieving relevant material and producing summaries. The tool has been tested within the Paris Court of Appeal’s Prosecution Service (Parquet Général) and other prosecutor offices within the jurisdiction.
Another initiative is Mon Assistant Pénal, a tool being built under the sponsorship of the Paris Procureure générale, and co-led by the cross-government AI incubator ALLiaNCE and the Ministry of Justice’s incubator. The project entered its construction phase in May 2025. It is intended to reduce time spent on repetitive, low-value tasks (especially reading and synthesising bulky case files) by allowing prosecutors to upload digital or digitised case files, detect the type of offences involved, generate a rapid structured overview using predefined questions tailored to offence categories, highlight relevant passages directly in a PDF reader, and enable users to interrogate the file to locate information efficiently.
Courts
Since 2019, French courts, in conjunction with the Ministry of Justice, have actively sought to adopt AI and high-tech solutions to meet modern judicial needs without compromising their technological sovereignty. The approach has been exploratory yet cautious, adhering to strict guardrails established by the judiciary itself. As at June 2025, most adopted tools are administrative or supportive in nature, designed to assist judges with low-risk tasks such as case management, translation, and transcription.
In April 2025, the Cour de Cassation released a report identifying its specific needs regarding AI and found that AI could meaningfully assist the Court in four key areas:
- Structure and enrichment: Processing incoming documentation more effectively by automatically identifying normative references and legal precedents.
- Analysis of submissions: Finding connections between different cases, facilitating preliminary file analysis, and mapping key legal issues.
- Documentary search and dissemination: Enhancing database search capabilities to better disseminate case law internally, to lower courts, and to the public.
- Drafting assistance: Providing support for standardised writing styles and ensuring compliance with data entry standards.
The Court explicitly said that it had identified no needs regarding judicial decision-making.
Case management
French courts are currently piloting experimental projects to implement AI within their case management system.
The ÉPOPÉE project consists of a tool enabling the extraction and use of data embedded in PDF case documents. Using AI, this tool aims to help process large volumes of data contained in case files more accurately and efficiently.
RAUNE is an AI-based automatic translation tool currently piloted by the Judicial Tribunal of Paris (Tribunal Judiciaire de Paris) and the Ministry of Justice (see above). It is designed to support judicial proceedings requiring multilingual communication.
LABEL (for Logiciel d’Anonymisation d’une Base Enrichie Labellisée or Software for Anonymising an Enriched Certified Database) is a tool developed by the Cour de Cassation to redact sensitive personal data from court rulings, enabling their publication as open data pursuant to Article L111-13 of the Judicial Organisation Code (implemented by decree No. 2020-797 of 29 June 2020). Developed within the Court’s innovation laboratory, it uses natural language processing algorithms and machine learning to automatically redact names, first names, and indirect identifiers such as social security numbers, bank account numbers, dates of birth, addresses, licence plates, and email addresses. The Court has reported continuous improvements since deployment, including the commissioning in 2024 of a more robust GPU-based model and a separate 'reliability' algorithm designed to automatically flag decisions requiring human review because of doubt about the automatic pseudonymisation outcome.
Legal research, analysis and drafting support
Doctrine is a French platform providing access to case law, legislative texts, and legal commentary. This is available to French magistrates. It has an AI-powered conversational tool to assist with legal research and drafting.
Lefebvre-Dalloz is a database and editorial platform providing legal texts and commentaries, and offers ‘GenIA-L’, an AI-based tool trained to answer legal questions via a chatbot, analyse documents, draft legal content, and provide reliable summaries.
French judges also have access to Lexis360 for legal research.
The French Ministry of Justice has also developed its own tools. For example, NATINFO is a tool developed by the Ministry to provide magistrates and law clerks with information and guidance on criminal qualifications.
The ‘Divergences’ Project is an AI solution that is under development by the Cour de Cassation as at June 2026, which aims to help detect differences in interpretation between chambers or sections within the Cour de Cassation rulings. The tool produces candidate signals, which court officials then review to determine whether a genuine divergence exists and suggest further action.
In May 2025, the French Ministry of Justice announced plans to deploy a secure and sovereign AI assistant for magistrates and ministry staff. The assistant was designed to support document search, summarisation, drafting and transcription tasks while remaining under human supervision. The initiative formed part of the Ministry's broader AI strategy and was subsequently deployed in May 2026 as ‘Mon Assistant Justice.’
Decision-making support
As at February 2026, there are no reports of AI being used for high-risk operations, such as predictive justice or autonomous decision-making. On the contrary, France appears to largely reject these specific applications. Since 2019, French law (Article 33 of the Justice Reform Act) has explicitly prohibited using AI for predicting decisions, permitting analytics only at an institutional level.
There have, however, been explorative efforts to use AI and algorithmic processing in decision-making in other ways. DataJust is a Ministry of Justice-led project launched in 2020, authorising the Ministry to carry out automated processing to develop an algorithm in the field of bodily injury compensation. The aim is to extract structured information from appellate decisions (such as amounts claimed and offered, settlement evaluations, and amounts awarded) in order to support public policy evaluation and potentially develop an indicative compensation reference framework for judges. However, the Ministry abandoned its internal development of the algorithm in 2022, citing the project’s complexity.
From the outset, DataJust attracted significant criticism. The Conseil National des Barreaux raised concerns about the implications of algorithmic tools in this domain. Civil society actors also challenged the underlying rationale, arguing that the initiative normalised large-scale processing of judicial decision data and risked a creep toward 'predictive justice'. The Conseil d’Etat ultimately upheld the decree that allowed for the creation of the tool in Decision No. 440376 (30 December 2021), rejecting the applications for annulment.
Predictice is an AI tool that analyses past case law to provide predictive insights for legal cases. French magistrates involved in pilot programmes with Predictice reported that the software did not offer additional value compared to existing analytical tools.

Defence
According to a study by the French National Bar Council, 62% of French lawyers have already experimented with generative AI in their professional practice. The Wolters Kluwer Future Ready Lawyer Report indicates that 80% of law firms in France use AI tools.
Administrative support
Translation tools including AI options, such as DeepL, are widely used by lawyers in France.
Legal research, analysis and drafting support
French lawyers use both general purpose AI, such as ChatGPT and Claude, and specialised AI integrated into their usual platforms such as LexisNexis, Dalloz and HectorAI.
The Paris Bar Association has signed several agreements with legal AI tools providers:
|
Jarvis Legal |
In February 2025, a partnership with LexisNexis to provide around 14,000 Paris-based lawyers with free access to Jarvis Legal, an AI-enhanced law firm management software developed by LexisNexis. |
|
Doctrine AI |
A partnership to provide 14,000 Paris-based lawyers with access to the Doctrine AI tool. |
|
Mistral AI |
A partnership to provide the Paris Bar employees with Le Chat tool. |
|
JiminiAI |
A partnership to provide small-scale law firms with three-months free access to Jimini AI generative platform. |
|
Lefebvre Dalloz |
A partnership to provide around 14,000 Paris-based lawyers with GenIA-L Lefebvre-Dalloz’s AI-based legal research tool. |
Victims
Victims have direct standing in French criminal proceedings through the institution of the partie civile. Under Article 2 of the Code of Criminal Procedure, individuals and entities who have personally suffered direct harm from a criminal offence may seek compensation within the criminal proceedings. Furthermore, pursuant to Article 85 of the Code of Criminal Procedure, victims may file a plainte avec constitution de partie civile, enabling them in certain circumstances to trigger a judicial investigation even where the public prosecutor has not initiated proceedings.
Administrative support
Victims have access to an automatic translation tool, implemented within the ‘Plainte en ligne’ (online criminal complaints) system for complaints filed in a foreign language in 2024 (Decree No. 2024-563 of 18 June 2024 on the scope of complaints sent electronically and the terms and conditions for the use of a machine translation tool in the processing of complaints sent electronically). The victim can complete the complaint form in one of the languages offered, and the elements of the form that result from the use of the automatic translation tool are disclosed in the final complaint report. The elements written by the victim in the original language are also appended to the report.
Furthermore, SAUJ (Service d’accueil unique du justiciable) serves as a virtual front desk where citizens can receive information and access their cases.
TRAINING
As at June 2026, there is no mandatory, systematic training available for French law enforcement agencies on the responsible use of AI, though law enforcement agencies have increasingly been publishing guidelines and awareness initiatives.
For judges, in June 2025, the French Ministry of Justice published a Report on ‘AI in the Service of Justice: Strategy and Operational Solutions’. The Report sets out a pragmatic roadmap for integrating AI into the French justice system, calling for a dedicated training system.
France’s National Bar Council launched a National AI Training Plan in 2025, integrating mandatory AI ethics modules into regional bar schools. This was supplemented by a free e-learning path on the Skilia platform, which successfully enrolled over 10,000 legal professionals in its first two months.
Most legal technology firms also offer training to lawyers to help them become familiar with the functioning of their AI tools.

REGULATION
In France, AI is regulated at the European level through AI-specific legislation, and in particular the EU AI Act. The obligations set forth by EU legislation complement domestic French frameworks designed to provide safeguards to criminal investigation procedures and ensure data protection in a growingly digital landscape. These regulations are supplemented by soft law in the form of guidelines and good practices.
AI Regulations
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is a key part of the legal framework regulating the use of AI across the EU. It entered into force on 1 August 2024, and sets out a comprehensive legal framework aiming to ‘guarantee safety, fundamental rights and human-centric AI’. The EU AI Act is being phased between 2025 and 2030. France is obliged to implement and comply with the provisions of the Act, which set out a harmonised legal framework for ‘the development, the placing on the market, the putting into service, and the use’ of AI systems across the EU.
The EU AI Act introduces a risk-based approach, categorising AI systems into four levels of risk, banning ‘unacceptable-risk’ systems, and imposing strict obligations on high-risk systems. The rules on prohibited uses have applied since 2 February 2025, the rules on general-purpose AI models and the designation of competent national authorities have applied since 2 August 2025 while obligations related to the use of high-risk AI systems, intend to be introduced at a later date.
The EU AI Act includes explicit references to AI systems related to the administration of justice, and to criminal proceedings. These are mainly classified as high-risk given ‘their potentially significant impact on . . . the rule of law, individual freedoms . . . the right to an effective remedy and to a fair trial’ as well as the right to defence and the presumption of innocence, particularly if ‘such AI systems are not sufficiently transparent, explainable [or] documented’. The Act highlights the potential ‘difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation’.
|
EU AI Act’s risk-based approach |
|
Unacceptable risk (prohibited) |
|
AI systems posing ‘a clear threat to safety, livelihood and rights of people’ are prohibited. This includes uses in law enforcement and criminal justice such as (1) assessing or predicting an individual’s criminal offence risk ‘based solely on the profiling of a natural person or on assessing their personality traits and characteristics’; (2) undertaking ‘untargeted scraping of the internet or CCTV footage’ to build or expand facial recognition databases; and (3) deploying ‘real-time remote biometric identification systems in public spaces or biometric categorisation to infer race, religion or other protected characteristics’ although narrow exceptions exist. |
|
High-risk (subject to strict obligations) |
|
AI systems that ‘can pose serious risks to health, safety or fundamental rights’ are deemed ‘high-risk’ under article 6. This includes the use of AI (1) to assess the risks of persons ‘becoming the victim of criminal offences’, (2) to assess the risk of persons ‘offending or re-offending’ in certain circumstances and to profile persons during investigations or prosecutions, (3) to evaluate the reliability of evidence ‘in the course of investigations or prosecution of criminal offences’, (4) for remote biometric identification, biometric categorisation in certain circumstances, and emotion recognition, and (5) ‘to assist judicial authorities in researching and interpreting facts and law’ and ‘applying the law to the facts’ (emphasis added). AI systems used for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases are not considered high-risk. High-risk AI systems are subject to strict obligations for developers, providers and users, including risk assessment; human oversight, the use of high-quality training data and ensuring explainability, accuracy, robustness and cybersecurity. When AI systems assist judicial decision-making, the persons concerned must be informed about the use of AI systems, and be provided with explanations about the role of AI in the decision-making process. |
|
Limited risk (subject to transparency obligations) |
|
This category refers to the risk associated with a need for transparency around the use of AI such as chatbots. Specific disclosure obligations apply for this category. |
|
Minimal risk (no requirements) |
|
Minimal risk or no risk AI systems are not subjected to any requirements. |
Articles 51-56 of the EU AI Act establish a specific regime for ‘general-purpose AI models’, defined in article 3(63) as models trained on large datasets capable of performing a wide range of tasks. They typically include large language models (LLMs) that can be integrated into legal research platforms, drafting tools or judicial support systems. Providers of such models must:
- maintain technical documentation;
- provide information to downstream integrators;
- comply with EU copyright law; and
- publish a summary of training data.
Under articles 55-56, additional obligations apply to general-purpose AI models presenting systemic risk, including risk assessment, mitigation measures and incident reporting. The framework is particularly relevant to the judicial sector given that courts and prosecutors may rely on external LLM-based tools rather than developing their own systems.
Several non-binding guidelines have already been published by the European Commission to provide further directions when implementing the AI Act:
- Guidelines on prohibited artificial intelligence (AI) practices (published on 04 February 2025) provide legal explanations and practical examples of AI practices that are deemed unacceptable and hence prohibited by Article 5 of the AI Act, due to their potential risks to European values and fundamental rights. The guidelines specifically address practices such as harmful manipulation, social scoring, and real-time remote biometric identification, among others.
- Guidelines on AI system definition (published on 06 February 2025) explain the practical application of the legal concept of AI to assist providers and other relevant persons in determining whether a software system constitutes an AI system. The guidelines elaborate on each of the seven elements of the definition of an AI system provided by Article 3(1) AI Act : (1) machine-based system, (2) autonomy, (3) adaptiveness, (4) AI system objectives, (5) inferencing how to generate outputs using AI techniques, (6) outputs that can influence physical or virtual environments, (7) interaction with the environment.
- Other guidelines are currently being developed by the European Commission. For instance, the Commission has issued Draft guidelines on the classification of high-risk AI systems, setting out the Commission’s interpretation of certain concepts that are relevant for classification purposes, and contain practical examples of AI systems that should or should not be classified as high-risk. High-risk uses of AI systems may include, for example, tools for the assessment of an individual’s risk of offending or reoffending, generating risk scores, profiling identified persons, or otherwise supporting operational law-enforcement decision-making. The Guidelines emphasise that classification depends on the system’s intended purpose and practical use, rather than solely on how it is labelled by the provider.
Although new, the EU AI Act echoes several key-principles already well established within the French legal system:
|
Respect of human dignity |
Widely protected by the Conseil constitutionnel (French constitutional court, ensuring that laws, elections and referenda are constitutional) and its case-law (Decision no. 94-343/344 DC of 27 July 1994). Human dignity requires that individuals are never treated merely as objects or means, and that their physical, moral, and psychological integrity is respected. Any use of AI by public authorities must therefore ensure that automated decision-making does not result in the dehumanisation or instrumentalisation of individuals. |
|
Transparency and accountability |
Article 15 of the 1789 Declaration of the Rights of Man and of the Citizen (‘Déclaration des droits de l’Homme et du Citoyen’) guarantees citizens the right to hold public authorities accountable. In this context, public authorities must ‘be able to explain, in detail and in an intelligible format, to the person in question’ how the AI processing was carried out in relation to them (Conseil constitutionnel, Decision n°2018-765 of 12 June 2018, §71). |
|
Equality and non-discrimination |
Enshrined in Article 1 of the French Constitution as well as in the Conseil constitutionnel case-law (e.g. Decision no. 2007-557 DC of 15 November 2007 prohibiting ethnic-based statistics). The principle of equality prohibits discrimination based on sensitive criteria such as ethnicity or gender. AI algorithms must be designed and deployed in a manner that avoids biased or discriminatory outcomes. |
|
Privacy |
Protected by Articles 2 and 4 of the Declaration of the Rights of Man and of the Citizen (‘Déclaration des droits de l’Homme et du Citoyen’) and by paragraph 10 of the Preamble of the 1946 Constitution (with constitutional value). AI systems involving the processing of personal data, such as facial recognition technologies or automated profiling tools, must respect privacy, limit data collection to what is strictly necessary, and ensure the security of sensitive information. |
|
Protection of personal data |
Recognised by the Conseil constitutionnel as ‘a legal requirement under the Constitution’ (Decision no. 2004-499 DC of 29 July 2004). AI systems processing personal data must comply with legal and constitutional data-protection standards. |
In terms of governance and enforcement of the EU AI Act, the Act adopts a two-pronged approach. At the EU-level, according to Articles 64-69 of the AI Act, the AI Office of the European Commission and an AI Board (Article 65) are the main actors. The AI Office enjoys enforcement powers with respect to obligations of general-purpose AI models (Article 88 et seqq.). The AI Board assists the European Commission and the member States in facilitating coherent applications of the AI Act, and therefore contributes to the coordination among national authorities (Article 66(a)).
At the French level, the AI Act will be enforced by the following administrative authorities, which ensure that prohibited practices are not implemented. Penalties may be made public:
|
Administrative authority |
Penalties |
AI systems and practices overseen by the authority |
|
National Commission on Informatics and Libraries (CNIL) |
Can impose various penalties: formal warnings, injunctive measures, withdrawal of certification, administrative fines (up to 4% of the company’s global annual turnover or up to €20 million, whichever is higher). |
AI systems prohibited under Article 5(1)(d) to (h) of the AI Act – namely predictive policing, the creation or development of facial recognition databases through non-targeted harvesting, the inference of emotions in the workplace and educational institutions, biometric categorisation, and real-time remote biometric identification for law enforcement purposes – are overseen by the CNIL. Practices prohibited under Article 5(1)(c) of the AI Act, relating to social evaluation, classification, or rating, are within the scope of the CNIL and the DGCCRF, reflecting both the fundamental rights and consumer protection dimensions of these prohibitions. In addition, the CNIL will be responsible for monitoring high-risk AI systems using biometric data (Annex III(1)), law enforcement (Annex III(6)), and migration, asylum, and border control (Annex III(7)). Regarding limited-risk AI systems, supervisory and enforcement powers are shared between several authorities, namely the CNIL, the ARCOM, and the DGCCRF. |
|
Regulatory Authority for Audiovisual and Digital Communication (ARCOM) |
Can impose several types of penalties: suspension of services or broadcasts, reduction of licence duration, withdrawal of licence, administrative fines (up to 5% of the company’s turnover excluding tax), publication of the penalties. |
AI systems prohibited under Article 5(1)(a) of the AI Act, relating to the use of subliminal techniques that are deliberately manipulative or misleading, are overseen by the ARCOM. Regarding limited-risk AI systems, supervisory and enforcement powers are shared between several authorities, namely the CNIL, the ARCOM, and the DGCCRF. |
|
General Direction for Competition, Consumer Affairs, and Fraud Control (DGCCRF) |
Can issue sanctions: injunctive measures, administrative fines (up to €15,000 for a natural person and €75,000 for a legal person), publication of the penalties. |
AI systems prohibited under Article 5(1)(b) of the AI Act, relating to the exploitation of vulnerabilities of specific persons or groups, are supervised by the DGCCRF. Practices prohibited under Article 5(1)(c) of the AI Act, relating to social evaluation, classification, or rating, are within the scope of the CNIL and the DGCCRF, reflecting both the fundamental rights and consumer protection dimensions of these prohibitions. Regarding limited-risk AI systems, supervisory and enforcement powers are shared between several authorities, namely the CNIL, the ARCOM, and the DGCCRF. |
|
Conseil d’Etat (French highest administrative court), Cour de Cassation and Cour des comptes (State body which supervises the financial affairs of public bodies and local authorities, and monitors the way public funds are used) |
Relevant judicial penalties under French law (no specific AI penalties are applied). |
AI systems that are put into service or used by judicial authorities for the purpose of administering justice (Annex III (8) (a) AI Act) are supervised by these bodies, each acting within the scope of its respective jurisdiction. |
Other European Regulations and Guidelines
At the European level, the AI Act coexists with additional regulations and guidelines:
|
Ethics Guidelines for Trustworthy Artificial Intelligence (2019) |
Prior to the adoption of the AI Act, the High-Level Expert Group on AI set up by the European Commission presented the non-binding Ethics Guidelines for Trustworthy Artificial Intelligence on 8 April 2019. These guidelines provide a framework to achieve trustworthy AI based on fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (EU Charter). The Guidelines put forward a set of seven key requirements that AI systems should meet in order to be deemed trustworthy:
|
|
European Declaration on Digital Rights and Principles for the Digital Decade |
The European Commission adopted on 26 January 2022 the European Declaration on Digital Rights and Principles for the Digital Decade. This Declaration is non-binding, but affirms the commitment of European institutions to ‘ensuring transparency’ in AI, guaranteeing the quality of data, preventing these tools from being used to predetermine individuals' choices, and providing safeguards to protect individuals' fundamental rights. Chapter III specifically declares that everyone shall be able to make ‘free and informed choices in the digital environment, while being protected from risks and harm to their health, safety, and fundamental rights’. |
|
Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law |
The Council of Europe adopted in May 2024 the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which is the ‘first-ever international legally binding treaty’ regulating AI. The Convention establishes rules relating to respect for fundamental rights at all stages of the AI systems lifecycle, which must be transposed into the domestic law of the signatory states. The Convention establishes seven fundamental principles for AI systems development: human dignity and individual autonomy (art. 7), transparency and oversight (art. 8), accountability and responsibility (art. 9), equality and non-discrimination (art. 10), privacy and personal data protection (art. 11), reliability (art. 12) and safe innovation (art. 13). The Convention applies across all public and private uses of AI where human rights may be affected, including within law enforcement, prosecution and judicial activities. It mandates risk and impact assessments to mitigate potential harms and provides safeguards such as the right to challenge AI-driven decisions. The Convention has been signed on 5 September 2024 by France (as part of EU signature), but has not yet come into force. Once it is in force, France will be required to ensure that individuals affected by AI systems can be informed when AI is being used, obtain sufficient information about how an AI-assisted decision was reached, challenge both the use of the AI system and decisions based on it, and lodge complaints before competent authorities. France will also need to provide effective legal and procedural safeguards where the use of AI significantly affects individuals’ rights or freedoms. Furthermore, France will be required to establish a framework requiring the assessment of risks that AI systems may pose to human rights, democracy and the rule of law, and to ensure that appropriate mitigation measures are adopted and kept under review throughout the AI system’s lifecycle. The state must also retain the ability to restrict, suspend or prohibit particularly harmful AI applications where necessary to protect fundamental rights and democratic values. |
|
European Ethical Charter on the use of AI in the judicial systems and their environment |
Similarly, the European Ethical Charter on the use of AI in the judicial systems and their environment has been adopted by the Council of Europe’s European Commission for the Efficiency of Justice (CEPEJ) in December 2018. It lays out five non-binding basic principles relating to the use of AI in judicial systems:
|
Guidelines for Practitioners
As at June 2026, though French professional bodies have issued a range of guidelines for practitioners on the responsible use of AI, France has not adopted or otherwise publicly engaged with the UNESCO Guidelines for the Use of AI Systems in Courts and Tribunals (2025).
Conseil d’Etat Charter for the Use of AI within the Administrative Jurisdiction (2025)
In December 2025, the Conseil d’Etat, the highest administrative court in France, issued the Charter for the Use of AI within the Administrative Jurisdiction, which targets the administrative judiciary only. The Charter is organised around seven principles, centred on the exclusivity of human judgment and systematic human control:
- Ensuring that human-decision making remains exclusive
- Ensuring systematic human oversight
- Guaranteeing fairness and non-discrimination in the use of AI systems
- Guaranteeing the strategic autonomy of AI systems developed by the administrative judiciary
- Ensuring transparency regarding the use of AI
- Protecting data security and confidentiality
- Ensuring environmentally sustainable use of AI.
The Charter prohibits using AI for functions that constitute the judicial act, including interpreting legal rules or case law, establishing or assessing facts, applying legal norms to an individual case, conducting legal reasoning, or proposing a judicial solution. It also highlights the practical risks associated with reliance on probabilistic outputs, particularly the tendency for AI suggestions to shape professional reasoning, and draws attention to the possibility of hallucinations, such as fabricated citations or non-existent case law. On this basis, the Charter requires verification of AI outputs and affirms that the responsibility for any adopted content remains entirely with the human user.
For publicly available generative AI tools, the Charter adopts a controlled-permissive stance: access is not categorically prohibited, but use is constrained by strict confidentiality and security requirements. In particular, the Charter prohibits uploading any material subject to confidentiality obligations (including professional confidentiality and the confidentiality of deliberations) and warns against disclosures that would place judicial materials under the control of third-party private actors.
The administrative courts commit, in the Charter, to publicly disclose which internal AI systems it has developed, their intended use, and the human oversight safeguards put in place. Any AI system developed must provide for third-party access to system documentation, auditability of the system and explainability of its operation, in compliance with applicable regulation (particularly the EU AI Act). If AI is ever used to generate administrative communications sent to users of the public justice service (such as letters, emails, or certificates), users should be informed of that use. The information should explain, in clear and simple terms, how the AI was used and specify that the content has been reviewed and verified by a human.
French National Bar Council, Practical Guide on the Use of Generative Artificial Intelligence Systems (2024)
The French National Bar Council published a Practical Guide on the Use of Generative Artificial Intelligence Systems on 19 September 2024. It is designed to help lawyers understand and progressively integrate AI into their professional practice. The guide explains what generative AI is, how it functions, and how it can be applied to legal work, such as automating research, drafting documents, and other routine tasks, while also outlining the risks and limitations associated with these technologies. These risks include the production of mistakes and design biases that may lead to discrimination, and threats to client confidentiality. The guide provides practical advice and recommends the following good practices:
- Prompting AI accurately, by defining clear and precise objectives, by including contextual information, and by benefiting from specific training.
- Improve generated results, by assessing mistakes and hallucinations risks and setting transparency obligations.
- Guarantee the protection of attorney-client privilege and personal data of clients, by redacting clients’ name, confidential information and strategic elements of the casefile, and by pseudonymising personal data.
In June 2025, the French National Bar Council released an ‘IA Juridiques’ comparator tool, which helps lawyers to select software that meets the strict data residency and security requirements of the EU AI Act. This tool should be understood as a practical extension of the September 2024 Practical Guide, providing a self-assessment and comparison framework designed to help lawyers evaluate and select legal software enhanced by one or more layers of generative AI. The comparator focuses in particular on data sovereignty, confidentiality and security of client data, the risk of reuse of client data by large language models, compliance with lawyers’ professional and ethical duties and the available functionalities and practical capabilities of the tool.
Conseil d’Etat, Report on ‘Embracing AI for Better Public Service’ (2022)
In August 2022, the Conseil d’Etat released a Report on ‘Embracing AI for Better Public Service’. The Report was commissioned by former Prime Minister Jean Castex in 2021, proposing a landscape of AI technology in the public sector. The Conseil d’Etat called for public services to comply with the EU AI Act. It highlighted the dangers of deploying high-risk systems, emphasising the need to adopt robust legislation that provides for the automated analysis of images taken in public places. The Report also recommends considering a proper legal framework on web scraping, which consists of analysing people’s publicly available online data, and argues that it is essential to adopt guidelines for the public sector to anticipate the entry into force of the EU AI Act, which was still in draft form at the time of the Report.
The Conseil d’Etat also emphasised the need to create judicial procedures to enable those who are victims of a wrongful decision by the administration due to an AI system to resolve their issue, and that the administration can be held liable for its decisions if they can be proven to have caused harm to citizens.
The Conseil d’Etat identifies transparency as a core principle governing the use of AI in public administration. Transparency encompasses a right of access to system documentation, a duty to inform individuals when AI has significantly influenced an administrative decision affecting them, and a requirement of explainability. Public authorities must be able to understand and explain how AI-generated outcomes are produced, including in individual cases. However, the report recognises that absolute explainability should not be a precondition for the deployment of public-sector AI systems, provided that adequate levels of understanding, accountability, and human oversight are ensured.
Regional guidelines on judiciary’s use of AI
Moreover, there are several non-binding European-level guidelines that address the judiciary’s use of AI, most notably the European Ethical Charter on the use of AI in judicial systems and their environment adopted by the European Commission for the Efficiency of Justice (CEPEJ) of the Council of Europe (discussed above).
Other non-binding initiatives have given rise to guidelines for justice system professionals and for lawyers, or may serve as useful benchmarks and standards to be upheld in professional practice:
|
Sector |
Title |
Contents |
|
Council of Bars and Law Societies of Europe |
Considerations on the Legal Aspects of Artificial Intelligence (2020) |
According to the Council of Bars and Law Societies of Europe, for the sake of transparency and in order to enable individuals to defend their rights, it seems appropriate that the persons impacted by the use of an AI system should be duly informed that AI is being used and that data concerning the individual may be considered by an automated system. |
|
Council of Bars and Law Societies of Europe |
Guide on the Use of Artificial Intelligence-Based Tools by Lawyers and Law Firms in the EU (2022) |
The Guide emphasises that lawyers should have at least a general understanding of how AI tools function. Where such understanding is lacking, this should be clearly communicated to clients and taken into account in the provision of legal services. Ultimately, under existing professional rules, lawyers remain fully responsible for the quality of their services and the outcomes for their clients, even where AI tools are used. |
|
Court of Justice of the EU |
While the AI Strategy does not address the disclosure of AI use, it emphasises that once AI solutions, procedures, methods and governance are put in place, staff awareness and knowledge level should ensure that the reasoning behind AI algorithms should be clear and understandable, both for those created in-house and those acquired. |
|
|
European Bars Federation |
The Guidelines explain that lawyers should maintain transparent communication with their clients regarding the use of generative AI in their legal practice. Lawyers should clearly explain the fact that they use it, as well as the purpose of such use, benefits, limitations, and guarantees, ensuring that clients understand the role of this technology in legal matters. |
|
|
Council of Europe |
Use of Generative AI by Judicial Professionals in a Work-Related Context (2024) |
The aim of this note is to give some preliminary thought to what judges and other public sector justice professionals can expect from the use of generative AI tools in a judicial context. The Council reiterated that it is essential, in particular in the context of justice, to be transparent about the use of generative AI as the relationship with the litigant is based on trust. |
Criminal procedure rules
Within French criminal procedure, Article 47 of the French Data Protection Act (Law No. 78-17 of 6 January 1978, as amended) prohibits judicial decisions assessing a person's conduct from being based solely on automated processing intended to evaluate aspects of that person's personality. Thus the prohibition that decisions are based on automated personality profiling applies to any AI or algorithmic system that processes personal data or behavioural indicators and could influence the outcome of a criminal procedural decision and covers all procedural stages where court decisions may be issued, including:
-
decisions relating to prosecution and indictment,
-
pre-trial detention, judicial supervision and bail,
-
assessment of criminal liability, and
-
determination of guilt and sentencing.
In addition, AI systems used by police, prosecutors and judicial authorities are subject to the data protection regime implementing Directive (EU) 2016/680 (the Law Enforcement Directive), including requirements relating to lawfulness, accuracy, purpose limitation and safeguards for data subjects.
More generally, any AI-assisted criminal decision-making remains subject to constitutional fair-trial guarantees, judicial reasoning requirements, and principles of human oversight, transparency and accountability.
Deepfakes and Synthetic Media
Since the adoption of Law No. 2024-449 on 21 May 2024 (Loi SREN) , Article 226-8 of the French Criminal Code criminalises the creation or publication of AI-generated audio or visual content depicting a real person without their consent where the AI nature of the content is not obvious or clearly disclosed, with aggravated penalties for online diffusion. Article 226-8-1 of the Criminal Code separately establishes a specific offence for sexual deepfakes, subject to higher penalties, including where the content is published online or involves a minor.
Furthermore, in French criminal law, the general provision addressing tampering with evidence is Article 434-4 of the French Criminal Code, which criminalises any act committed with the intent to obstruct the discovery of the truth by altering the scene of a crime or offence, whether through the alteration, falsification or erasure of traces or evidence.

Data protection legislation
In addition to the EU AI Act, EU data protection regulations must be observed with regard to the use of AI in criminal proceedings. The EU AI Act does not seek to affect existing EU law governing the processing of personal data (according to Article 2 No. 7 AI Act and Recital 10). Data protection law governing the use of personal data may be relevant with regard to various stages of the AI lifecycle. Personal data can be relevant during AI development (e.g., collection and use of data for training) and AI use (e.g., personal data as input data).
On 25 January 2012, the European Commission presented the Data Protection Reform package, proposing a directive (LED) and a regulation (GDPR). On 27 April 2016, the European Parliament and the Council adopted:
- The Law Enforcement Directive (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data (‘LED’).
- The General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’).
The GDPR remains the primary regulation for ‘general’ processing of data, but the LED is the lex specialis for criminal matters, since it governs processing ‘for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties’. These regulations have distinct scopes of application that are intended to be complementary.
In both regulations, ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 3 (1) LED and Article 4 (1) GDPR). As at June 2026, this term also includes pseudonymised data as indicated by Article 4 (5) GDPR. Recital 26 sentence 2 GDPR points out that identifiability should (still) be recognised in view of pseudonymised personal data that could be assigned to a natural person based on additional information.
EU Directive 2016/680, Law Enforcement Directive (LED) (2016)
The directive has been fully transposed by France by law No. 2018-493 of 20 June 2018 on the protection of personal data and decree No. 2018-687 of 1 August 2018 implementing Computer Technology and Civil Liberties Law (see below).
The directive governs the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, and prosecution of criminal offenses or the execution of criminal penalties.
The rights of data subjects are recognised but may be limited in order to ensure the proper conduct of investigations, prevention, and the prosecution of offenses. These rights include the right to information, the right of access (often exercised indirectly through the supervisory authority), and the right to rectification or erasure. As such, the directive imposes obligations on data controllers that are comparable to those of the GDPR, but creates additional obligations that are specific to the criminal context:
- There must be a clear distinction among categories of data subjects: those suspected of committing or planning a criminal offense, those who have been convicted, victims of crimes, and individuals who may be at risk of becoming victims. It also covers third parties connected to a crime, such as potential witnesses, people who can provide information, and contacts or associates of the individuals mentioned above, as set out in Article 6.
- The processing of special categories of personal data is strictly regulated under Article 9(2) of the GDPR and requires the data subject's consent, which shall be freely given and well-informed, or a legitimate purpose. But the LED establishes a specific exception for criminal matters: Article 10 permits the processing of sensitive data without consent when it is strictly necessary, provided that appropriate safeguards are implemented.
- The LED also addresses automated individual decision-making. A decision ‘based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her’, is prohibited unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the data subject´s rights and freedoms of , at least the right to obtain human intervention on the part of the controller (Article 11 (1)). The EU legislator specifies that this right to intervention comprises the right to express his or her point of view, to obtain an explanation of the decision reached after such assessment or to challenge the decision (Recital 38). Furthermore, such decisions shall not be based on special category data, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union memberships, as well as genetic data, biometric data, data concerning health or a natural person’s sex life or sexual orientation, unless suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place (Article 11 (2)). The LED further prohibits profiling resulting in discrimination against natural persons on the basis of special category data (Article 11 (3)).
- In order to protect individuals’ rights during criminal investigations, Articles 13 and 14 provide for information and access rights, while allowing limitations where their exercise could undermine ongoing investigations or prosecutions.
- Article 16 complements these safeguards by providing the right to request the rectification of inaccurate data and the erasure of data, and in the event of refusal, the possibility of lodging a complaint with a supervisory authority or seeking judicial remedy.
- Finally, Articles 27 and 29 impose obligations relating to risk assessment and data security, requiring competent authorities to assess the impact of high-risk processing operations and to implement appropriate technical and organisational measures throughout the criminal procedure.
Regulation (EU) 2016/679, General Data Protection Regulation (GDPR)
The GDPR protects fundamental rights in the digital landscape by imposing obligations on data controllers and processors upon all processing of personal data. Hence, in the area of criminal justice, the GDPR is relevant for (i) the processing of personal data collected by competent authorities for the purposes set out above but intended to be further processed for other purposes, (ii) processing by public bodies for other purposes from the outset (this includes, e.g., archiving conducted by criminal justice authorities), and (iii) any processing by natural persons or private entities (Article 9 (1) and (2) LED, Article 2 (1) GDPR, Recital 19 to GDPR).
Obligations placed on data controllers include: lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; transparency and information duties; security obligations; data protection impact assessments. The GDPR also grants basic rights to data subjects such as access, rectification and erasure of personal data.
Several aspects of criminal proceedings are subject to the following provisions of the GDPR:
- Article 10 requires the processing of personal data relating to criminal convictions and offences to be carried out ‘only under the control of official authority’, and to provide for ‘appropriate safeguards for the rights and freedoms of data subjects.
- Paragraph 1 of Article 22 prohibits any decision that produces legal or similar effects based exclusively on automated data processing. This serves as a key safeguard against ‘algorithmic judges’ or fully automated sanctions.
- Paragraph 1 of Article 35 provides that the controller must carry out a data protection impact assessment prior to any processing likely to pose a high risk to the rights and freedoms of individuals, particularly when new technologies are involved. A single assessment may cover multiple similar processing operations presenting comparable risks.
On 6 and 25 May 2018 respectively, the GDPR and the LED were implemented across all EU Member States. France amended its Computer Technology and Civil Liberties Law (see below) to align with this new legal framework. The CNIL is in charge of enforcing this new legal framework by imposing various penalties: formal warnings, injunctive measures, withdrawal of certification, administrative fines (up to 4% of the company’s global annual turnover or up to €20 million, whichever is higher). These penalties may be made public.
EU AI Act (Regulation (EU) 2024/1689)
Acknowledging both existing data privacy regulations and the relevance of personal data in the AI context, the EU AI Act contains several provisions addressing the use of such data in the course of complying with broader obligations under the AI Act:
- The EU AI Act provides a (narrow) legal basis for the processing of special category personal data in the context of training or testing a high-risk AI system. Where such processing is strictly necessary for the purpose of ensuring bias detection and correction in relation to a high-risk system, the providers of such systems may exceptionally process special category data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. Exceptional circumstances exist where (in addition to the requirements for such processing set out in the LED or the GDPR) certain cumulative conditions are met, including where there are technical limitations and state-of-the-art security measures, including pseudonymisation, as well as strict security safeguards (cf. Article 10 No. 5 sentence 2 AI Act, (6)).
- The data sets for training, validation, and testing of AI systems shall be subject to appropriate data governance and management practices that, in the case of personal data, shall also concern the original purpose of the data collection (Article 10 No. 2 (b) AI Act).
- Where applicable, deployers of high-risk AI systems shall use the information provided for such systems under their transparency obligation (cf. Article 13 AI Act) for conducting a data protection impact assessment under the LED or the GDPR (Article 26 No. 9 AI Act).
Law No. 78-17 of 6 January 1978 on Computer Technology, Data Files, and Civil Liberties
Article 47 of Law No. 78-17 of 6 January 1978 on computer technology, data files, and civil liberties (‘Computer Technology and Civil Liberties Law’), as modified by Ordinance No. 2018-1125 of 12 December 2018, prevents court decisions from being based on automated personality profiling.
The Computer Technology and Civil Liberties Law provides the legal framework governing the processing of personal data in France. Before the GDPR came into force, it served as the country’s primary data protection legislation, establishing fundamental principles such as lawfulness, purpose limitation, proportionality, and data retention, recognising individuals’ rights to access, correct, or object to the use of their data, and assigning oversight responsibilities to the CNIL, France’s national data protection authority.
Following the GDPR’s entry into force in May 2018, the law was amended through Ordinance No. 2018-1125 of 12 December 2018 and supplemented in 2019 to remove provisions that were inconsistent with the GDPR, and specify national rules in areas where the GDPR allows Member States discretion – such as the CNIL’s enforcement powers, public sector data processing, sanctions, and the handling of minors’ data.
Cybersecurity Laws
EU AI Act (Regulation (EU) 2024/1689)
For high-risk AI systems, the EU AI Act requires resilience against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting system vulnerabilities (Article 15 (5)), which is confirmed by the underlying Recital 76, emphasising the crucial role of cybersecurity.
EU Cybersecurity Act (2019) and EU Cyber Resilience Act (2024)
As regards the demonstration of compliance with the AI Act’s cybersecurity requirements for high-risk AI systems, two other European regulations may be relevant:
|
EU Cybersecurity Act (‘CSA’) - Regulation (EU) 2019/881 |
Aims to achieve a high level of cybersecurity, cyber resilience and trust within the EU and sets forth a framework for the establishment of voluntary European cybersecurity certification schemes for so-called ICT products, i.e., an element or a group of elements of a network or information system (Articles 1 (1) (b), 2 (13) CSA). Where high-risk AI systems are also ICT products, compliance with the cybersecurity requirements laid down in the EU AI Act can be presumed by demonstrating certification under the CSA in so far as such certification covers the AI Act’s respective requirements (Articles 42 No. 2, 15 No. 1, 5 AI Act). Concerning law enforcement and criminal justice, this would be particularly relevant for high-risk AI-enabled software, for instance allowing for biometric identification. In January 2026, the European Commission announced a Proposal for a Regulation for the EU Cybersecurity Act (‘The Cybersecurity Act 2’) aiming at, inter alia, further simplifying the certification process. |
|
Cyber Resilience Act (‘CRA’) - Regulation (EU) 2024/2847 |
Whereas the CSA establishes a voluntary certification framework, the CRA aims at ensuring that digital products and services are secure by design, resilient against threats, and able to maintain security throughout their life cycle, and sets out mandatory cybersecurity requirements for products with digital elements made available on the market. With most of its provisions applying from December 2027, the CRA will concern a wide range of products placed on the EU market, including AI-enabled software. For high-risk AI systems, compliance with the CRA requirements shall also be deemed to satisfy the AI Act’s cybersecurity requirements in so far as those requirements are covered under the CRA (Recital 51 to the CRA). |
EU NIS2 Directive (2016) and Implementing Legislation
At the domestic level, France is (as at June 2026) in the process of transposing the EU NIS2 Directive (Directive (EU) 2022/2555) (through the Projet de loi Résilience (Critical Infrastructure Resilience and Cybersecurity Bill)), which imposes strict risk management, incident notification, and security obligations on critical entities and public bodies.
In particular, the EU NIS2 Directive establishes a high common level of cybersecurity across the EU, requiring entities subject to the framework to implement comprehensive cybersecurity risk management measures, covering access control, supply chain security, physical security of network systems, and human resources security, while management bodies are personally accountable for approving and overseeing such measures. On incident reporting, the Directive introduces a tiered architecture requiring an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and further reports as the situation develops. At governance level, Member States must establish national cybersecurity strategies, designate competent authorities, and set up Computer Security Incident Response Teams.
Human Rights
Human rights provisions applicable in France may also limit the use of AI in criminal proceedings. In particular:
|
The right to a fair trial |
Protected by:
|
|
Equality before the law |
Protected by:
|
|
Right to privacy |
|
Moreover, the Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law deserves special mention as a multilateral initiative, being the first legally binding international treaty specifically designed to regulate AI. Opened for signature in September 2024, its primary objective is to ensure that as AI technologies evolve, they do not erode the fundamental pillars of modern society: human rights, democratic integrity, and the rule of law. As at June 2026, the Convention has not yet entered into force, as the minimum number of five ratifications has not been reached yet. Thus, the Convention currently has no binding effect in France. The Convention focuses on the lifecycle of AI systems, from design to decommissioning, and mandates adherence to seven fundamental principles: human dignity, transparency, accountability, equality, privacy, reliability, and safe innovation. It requires signatories to establish independent oversight bodies and provide clear legal remedies for individuals who suffer harm due to AI systems.
As at June 2026, there does not appear to be a strong consensus in France that entirely new fundamental rights or criminal procedure rules are required to address AI use in criminal proceedings. Rather, the prevailing approach is to adapt and apply existing safeguards—such as the right to a fair trial, privacy protections, data protection rules, transparency requirements, and human oversight obligations—to AI-assisted decision-making. French institutions, including the Conseil d'Etat, the CNIL and the Conseil Constitutionnel, have nevertheless emphasised the need for clear legal bases, explainability, effective supervision and meaningful human control where AI systems are used in sensitive public-sector contexts.
Outlook
Ministry of Justice, ‘AI in the Service of Justice: Strategy and Operational Solutions’ (2025)
France is progressing toward a more structured phase of AI development within its judicial system, moving from isolated experiments toward a comprehensive strategy. The Ministry of Justice’s 2025 report ‘AI in the Service of Justice: Strategy and Operational Solutions’ sets out a clear roadmap for the coming years, centred on the deployment of secure, sovereign, and assistive AI tools to support magistrates and court staff, while explicitly excluding predictive justice models. The report argues that the opportunities created by AI require rapid, practical mobilisation, and it frames the policy around three complementary lines of effort:
- Widening access by deploying operational tools that can be integrated into day-to-day work;
- Preserving effective control over systems and secure hosting;
- Accompanying professionals through training and ethical safeguards.
The same report sets out a phased roadmap:
|
2025 |
‘Emergence and first deployments’ phase (including the progressive rollout of a secure assistant and the launch of initial awareness and training modules). |
|
2026-2027 |
Scale-up phase centred on stronger skills development, modular professional tools (including transcription and advanced file synthesis), and the build-out of a dedicated digital training campus. |
|
2027- |
The consolidation phase intended to make AI a durable pillar of the justice public service, including continuous learning programmes. |
The strategy prioritises specific and concrete areas of application – such as legal research, drafting assistance, transcription, translation, and document analysis – combined with strong governance, ethical safeguards, and human oversight.
Governance has also been formalised. On 1 December 2025, the Ministry created a dedicated programme directorate for artificial intelligence within the ministry’s central administration, explicitly designed to concentrate legal, technical, cybersecurity, and ethical expertise, to organise scaling and compliance, and to run structured change management for adoption in the professions.
European Commission’s Proposed Digital Omnibus Regulation (2025)
In November 2025, the European Commission published its Digital Omnibus Regulation Proposal, a reform package to simplify and streamline existing EU regulations concerning the digital space, including the GDPR and EU AI Act. Respective amendments to the LED are to follow.
Notably, the European Commission intends to amend the definition of the term ‘personal data’ in Article 4 (1) GDPR by stating that information is ‘not to be considered personal data for a given entity when it does not have means reasonably likely to be used to identify the natural person to whom the information relates.’ Accordingly, such an entity would not fall within the scope of the GDPR regarding the processing of such data. This approach is generally in line with recent CJEU case law establishing that existing additional information enabling an entity to identify the data subject does not as such mean that pseudonymised data are to be considered personal data in all cases and for every person. In other words, personal data can be pseudonymised for one entity and anonymised (and thus not identifiable) for another (CJEU, 4 September 2025, EDPS v SRB, C‑413/23 P). Such an amendment wording would, if implemented, significantly reshape the legal test to be conducted to assess applicability of the GDPR (i.e., the assessment of the existence of personal data) towards an entity-focussed approach and largely exclude pseudonymised data from the scope of the GDPR.
The European Commission, through its Digital Omnibus Regulation, also intends to clarify that the processing of personal data in the context of AI development may be carried out for purposes of a legitimate interest where appropriate (Article 6 (1) (f) GDPR). Such an amendment would address an issue that has been widely adopted since the emergence of LLMs, and which has also been subject to a dedicated Opinion of the European Data Protection Board (Opinion 28/2024).
CASES
Data protection
In Decision n°2018-765 of 12 June 2018 , the Conseil Constitutionnel found that a decision producing legal effects concerning a person or significantly affecting them – such as individual administrative decisions – taken solely on the basis of automated data processing to be lawful, as long as the legislator has provided appropriate safeguards to protect the rights and freedoms of individuals. Such safeguards include the mandatory explicit mention that an algorithm has been used and the main characteristics of this algorithm, the availability of administrative recourse and then judge review to challenge an algorithm-based decision, and the obligation for the data processor to always be in control of the ‘algorithmic processing and its changes in order to be able to explain, in detail and in an intelligible format, to the person in question how the data processing has been implemented to him/her’ (§70 - 71).
In a decision by the Conseil d’Etat in December 2020 (n° 446155, T, 22 December 2020) , it was held with regard to cameras used for administrative or judicial policing purposes, that the images constitute personal data and are therefore subject to the applicable legal framework depending on the purpose of the processing, in particular Title III of the Computer technology and civil liberties law, which transposes the LED.
In November 2023, the Administrative Tribunal of Caen (ordonnance Nos. 2303004-2303012, 22 November 2023) ruled on an emergency challenge brought by several applicants against the use of BriefCam’s 'augmented' video-analytics features by the Communauté de communes Cœur Côte Fleurie (Normandy). The applicants argued that these features could enable the individualisation and tracking of natural persons based on observable characteristics (such as body shape/size, skin or hair colour, apparent age and sex, clothing, appearance, and gait), and thus amounted to intrusive processing without a proper legal basis. The Tribunal ordered the inter-municipal authority to immediately cease using the contested functionalities and to delete the personal data processed via the software, finding that the municipal police were carrying out particularly intrusive processing (linked to physical characteristics and appearance) without a specific legislative framework and adequate safeguards.
In proceedings brought by La Quadrature du Net, the Administrative Tribunal of Grenoble (Judgment No. 2105328, 24 January 2025) annulled the City of Moirans’ decision to deploy BriefCam for algorithmic analysis of CCTV footage and required the municipality to end the use of the software. The Tribunal reaffirmed that automated video analytics—including retrospective analysis—constitute a distinct and more intrusive form of personal-data processing than ordinary video surveillance. It held that such processing cannot be treated as automatically covered by the general legal regime for public-space CCTV where the deployment lacks a sufficiently clear and specific legal basis, defined purposes, and appropriate safeguards.
In Commune de Nice' v CNIL (n° 506370 o 30 January 2026) the Conseil d’Etat decided on a decision of the CNIL that restricted the operation, by the City of Nice, of an algorithmic processing called 'zone d’intrusion – entrées des écoles', which continuously and automatically analysed public-street CCTV images in real time to detect vehicles illegally stopping or parking in front of school entrances during opening hours, and then alert municipal police so they could intervene. The legal issue was whether France’s general public-space CCTV regime (Code de la sécurité intérieure, Article L. 251-2) implicitly authorises this kind of systematic, automated (algorithmic) analysis of video feeds. The Conseil d’Etat held that it does not, and that no other provision in current law provides such authorisation, so the CNIL was entitled to conclude the processing could not lawfully be implemented, leading the Conseil to reject the City of Nice’s challenge to the CNIL decision.
Right to privacy
In a decision by the Conseil Constitutionnel in 2023 (Decision n°2023-850 of 17 May 2023), the Conseil considered the experimental use of algorithmic processing applied to video surveillance for the 2024 Olympic and Paralympic Games. The Conseil Constitutionnel ruled that, given the intrusive nature of such data processing, the protection of the right to privacy requires the implementation of ‘special safeguards’, and considered that the safeguards established by the legislator were adequate. Specifically regarding human control of such algorithms, the Conseil constitutionnel recalled that the ‘legislature has ensured that the development, implementation, and any changes to algorithmic processing remain under the permanent control and supervision of human beings’ (§45).