Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

AI and Law6 min read

European AI Act: a complete guide for French startups

Understand the AI Act (EU 2024/1689) and prepare for compliance by August 2026: risks, GPAI, CE marking, checks, fines and a startup roadmap.

Regulation (EU) 2024/1689 – risk-based approach, GPAI and high-risk obligations, CE marking, sandboxes, penalties and a compliance roadmap.

The essentials in 30 seconds

  • Entry into force: 1 August 2024. Prohibitions from 2 February 2025, GPAI obligations on 2 August 2025, full compliance for high-risk AI by 2 August 2026 (EUR-Lex, European Commission).
  • 4 risk levels: unacceptable (prohibited), high (strict framework), limited (transparency), minimal (voluntary good practice) (CNIL).
  • GPAI/generative AI: transparency and specific risk-management obligations from August 2025 (watermarking, documentation) (EU).
  • High risk: risk-management system, quality data, human oversight, logging, cybersecurity, conformity assessment and CE marking (Service Public Entreprendre).
  • Penalties: up to €35 million or 7% of worldwide turnover, depending on severity. Checks coordinated with national authorities (CNIL, sector regulators) (EU, CNIL).

Timeline and scope

The official text of the AI Act (EU 2024/1689) is available on EUR-Lex and presented by the European Union on Shaping Europe’s digital future. It entered into force on 1 August 2024.

  • 2 February 2025 (T+6 months): prohibitions on unacceptable-risk practices apply (CNIL).
  • 2 August 2025 (T+12 months): obligations for GPAI and generative AI (transparency, documentation, watermarking).
  • 2 August 2026 (T+24 months): full obligations for high-risk AI (conformity assessment, CE marking, EU database).

The regulation applies to providers and deployers of AI systems placed on the EU market or whose outputs are used in the EU, including outside the EU if the effect occurs in Europe (limited exceptions, e.g. defence). See the French government overview AI Act – AIN and Legifrance.

Map your AI systems and roles (a crucial first step)

  1. Inventory all your AI systems (internal/external products/features) and the data used.
  2. Determine your role for each system: provider (you develop/place on the market), deployer (you use), importer/distributor, authorised representative.
  3. Classify the risk according to the regulation’s lists (unacceptable / high / limited / minimal), particularly the use cases in Annex III (high risk).
  4. Identify whether the system involves GPAI or a generative model and whether obligations apply from 2025.

An internal register of AI systems and their risks facilitates audits and ongoing compliance. To move faster, see our contract templates and compliance packages: Explore AI and law resources.

Risk levels: practical implications

Unacceptable risk (prohibited from February 2025)

  • Biometric categorisation based on sensitive data (origin, orientation, etc.).
  • “Real-time” remote biometric recognition in public spaces for law-enforcement purposes (subject to strict statutory exceptions).
  • Emotion inference in workplaces and schools.
  • Creating facial-recognition databases through untargeted mass collection of images.

References: EUR-Lex, CNIL – AI.

High risk (strict framework, CE marking)

Common startup examples: recruitment/HR assessment, credit scoring, education, critical infrastructure management, software components in medical devices and product safety systems. For digital health, see the dedicated analysis G_NIUS digital health.

Limited risk

Targeted transparency obligations (e.g. informing users that they are interacting with AI, labelling deepfakes). References: EU, CNIL – Q&A.

Minimal risk

No specific legal obligation, but adoption of codes of conduct and good practice is recommended (security, ethics, GDPR).

GPAI and generative AI: obligations from August 2025

  • Transparency: clear information for users; identification of generated content (watermarking/deepfake labelling).
  • Technical documentation: description of the model, training process and known limitations; summary of content used for training where required.
  • GPAI risk management: enhanced requirements for models generating systemic risks (security, evaluation, reporting). References: EU, EUR-Lex.

Key obligations for high-risk AI (providers)

  1. Risk-management system (analysis, mitigation measures, continuous reassessment).
  2. Data governance and quality (relevance, representativeness, bias reduction).
  3. Technical documentation that is complete and kept up to date.
  4. Traceability and logging of relevant events.
  5. Transparency and instructions for use for professional users.
  6. Human oversight that is effective and defined.
  7. Performance, robustness and cybersecurity meeting applicable standards.
  8. Conformity assessment (notified body where required), CE marking and registration in the EU high-risk AI database.
  9. Post-market monitoring and reporting of serious incidents.

Business guide: Service Public – Entreprendre. Official overview: EU.

Deployer obligations (professional users)

  • Use compliant systems and follow the provider’s instructions.
  • Conduct an impact assessment where applicable (e.g. GDPR DPIA) and ensure human oversight.
  • Keep logs, monitor performance and report serious incidents.
  • Train teams and document internal controls. References: CNIL – AI.

Conformity procedure and CE marking

  1. Compliant design plus incorporation of harmonised standards/common specifications.
  2. Internal conformity assessment or assessment by a notified body, as applicable.
  3. Preparation of the EU declaration of conformity + CE marking.
  4. Registration in the EU high-risk AI database and ongoing updates.

Practical reminders: EUR-Lex, Service Public Entreprendre.

SMEs/startups: simplified requirements, sandboxes and support

  • National regulatory sandboxes for supervised experimentation.
  • Simplified forms and documentation, support with assessment costs, sector-specific codes of conduct.
  • AI Office and Service Desk at European level for cross-cutting questions (EU), national points of contact: AI Act – AIN.

Penalties, checks and sector coordination

In the event of non-compliance, maximum penalties can reach €35 million or 7% of worldwide turnover (prohibited practices), with lower levels for other breaches. See the official EU overview and the CNIL Q&A.

National authorities (e.g. CNIL) coordinate with sector regulators. Examples: health (see G_NIUS), finance (prudential and market rules — AMF), general business obligations (Service Public Pro).

Startup roadmap to 2 August 2026

T-18 months

  • Map AI systems, roles and risks; gap analysis against the AI Act.
  • Launch the risk-management system and data governance.
  • Design the architecture for logging, human oversight and cybersecurity.

T-12 months

  • Draft technical documentation; conformity-assessment protocol.
  • Pilot in a sandbox if eligible; capability, robustness and bias testing.
  • Prepare for GPAI/generative obligations (labelling, data summaries).

T-6 months

  • Finalise the conformity assessment; select a notified body if required.
  • Draw up the EU declaration, affix the CE marking and prepare EU registration.
  • Train teams and put oversight and logs into production.

T-0 and beyond

  • Post-market monitoring, incident management and regular audits.
  • Continuously update documentation, standards and security patches.

Move faster with our AI-first packages and playbooks: Discover the Initial journey. To explore the AI and law framework further: read more analyses.

Typical use cases and points to watch

HR startup (CV screening, matching)

  • Probably high risk (employment/education). Require representative data, bias testing and human oversight before decisions.
  • Transparency towards candidates and access to a remedy.

MedTech (AI-assisted diagnosis)

  • High risk and potentially subject to medical-device regulation. Coordinate AI and health compliance (G_NIUS).

Fintech (credit scoring, fraud prevention)

  • High risk. Decision traceability, explanations and human control. Coordinate with market/consumer rules (AMF).

Generative SaaS (assistant, image/text)

  • GPAI obligations: content labelling, training summaries, output safety, rights and licence management.

Integrate the AI Act into governance and IP

  • AI register (inventory, risks, controls, incidents).
  • Internal policies (data, prompts, security, human approval, use of third-party GPAI).
  • Contracts (AI clauses with clients/providers, liability, audit, data). See our templates: Explore AI and law resources.
  • Intellectual property: patents/software, trade secrets, managing licences for training content (INPI).

Short FAQ

What are the key dates for my startup?

Prohibitions: 2 February 2025. GPAI/generative AI: 2 August 2025. High risk (CE, EU database): 2 August 2026. Ref. EUR-Lex, EU.

How do I know whether my AI is “high risk”?

Check the Annex III categories (recruitment, credit, health, etc.). If in doubt, document the analysis and seek advice. Ref. Service Public Entreprendre.

Do I need CE marking?

Yes, if you are a provider of high-risk AI. Assessment procedure + EU declaration + registration. Ref. EUR-Lex.

What penalties apply for breaches?

Up to €35 million or 7% of worldwide turnover depending on severity, with lower levels for other breaches. Ref. EU, CNIL.

Further reading

See our related guides: GDPR and AI: legal obligations for businesses, The legal limits of AI in business and Civil liability and AI.

Further reading

Related resources

Frequently asked questions

FAQ

What are the main AI Act deadlines for a French startup?

Prohibitions on unacceptable-risk practices on 2 February 2025, GPAI/generative obligations on 2 August 2025, full high-risk AI compliance (assessment, CE marking, registration) by 2 August 2026.

How do I determine whether my system is high risk?

Map your uses and compare them with the Annex III categories (recruitment, credit, health, infrastructure, education, etc.). If uncertain, document the risk analysis and seek specialist advice.

What obligations apply to generative AI and GPAI from 2025?

Transparency towards users, labelling generated content (deepfakes), technical documentation and, depending on the risk profile, enhanced risk-management and security measures.

Is CE marking mandatory for all AI?

No. It concerns high-risk AI (providers). It requires conformity assessment, an EU declaration, affixing the CE marking and registration in the European database.

What penalties apply for non-compliance?

Up to €35 million or 7% of worldwide turnover for certain serious violations, and lower caps for other breaches. The CNIL and sector regulators may carry out checks.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles