Published: 17 February 2026 — AI and Law. Widespread business use of AI is entering an era of compliance. Since the AI Act entered into force on 1 August 2024, obligations have been phased in, with a critical milestone on 2 August 2026 for high-risk systems. The aim: secure use without stifling innovation, backed by substantial penalties (EUR-Lex; European Commission — Digital Strategy).
What the AI Act permits, restricts and prohibits
Four risk levels
- Unacceptable risk (prohibited): social scoring, behavioural manipulation and emotion recognition at work/in schools, among other practices (Service Public Entreprendre; Entreprises.gouv — Who is covered).
- High risk: AI deployed in sensitive sectors (recruitment, water/gas/electricity infrastructure management, education, health, public services, justice). Enhanced obligations: CE marking, technical documentation, risk management, logging and human oversight (European Commission).
- Limited risk: transparency requirements (e.g. indicating that a person is interacting with a chatbot) (Service Public Pro).
- Minimal risk: voluntary good practices.
The detailed framework, including classification annexes, is available in the official text (EUR-Lex) and national summaries (Entreprises.gouv — Digital regulation; Préfecture de l’Ain — AI Act).
2024–2026 deadlines and penalty scale
- 1 August 2024: AI Act enters into force (Service Public Entreprendre).
- 2 February 2025 (6 months): prohibitions apply (unacceptable-risk practices) (European Commission).
- 2 August 2025 (12 months): enhanced transparency obligations for certain general-purpose AI (GPAI) and preparation of compliance ecosystems.
- 2 August 2026 (24 months): full application of obligations for high-risk systems (CE marking, documentation, post-market monitoring, etc.) (EUR-Lex).
Administrative penalties: up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for other infringements; up to €7.5 million or 1% for inaccurate information supplied to authorities (caps adapted for SMEs) (EUR-Lex; Entreprises.gouv).
The combined AI Act x GDPR framework: data, biometrics and DPIAs
The AI Act does not replace the GDPR: both apply cumulatively. Any processing of personal data by AI must remain lawful, minimised and secure; using special categories (biometrics, health) requires a robust legal basis and enhanced safeguards (CNIL — AI; CNIL).
- DPIA: mandatory for many AI use cases (large-scale profiling, biometrics). Coordinate it with the AI Act risk assessment.
- Transparency: clear disclosure of AI use, information for individuals and avenues for redress.
- Data governance: quality, bias, traceability, deletion. Repurposing contrary to the original purpose is prohibited.
Applicable texts are available through Légifrance and practical guides from national authorities (Entreprises.gouv).
Classifying and mapping your AI: a practical method
1) Inventory systems and use cases
- IT/procurement inventory of solutions (SaaS, APIs, general-purpose models, low-code tools) and business uses (HR, marketing, operations, finance).
- Identify personal/special-category data processing and transfers outside the EU.
2) Classify by AI Act risk level
- Unacceptable: stop deployment.
- High risk: initiate full compliance (see below).
- Limited risk: implement transparency obligations (e.g. chatbot notices).
- Minimal: apply good practices (logs, human validation).
3) Check providers and the compliance chain
- Request AI Act documentation (EU declaration of conformity, CE marking for high risk, GPAI information).
- Verify registration of stand-alone high-risk systems in the EU database before placing them on the market, and assessment reports (European Commission).
- Contractual clauses: audit rights, incident notification, subcontracting, intellectual property and trade secrets (INPI).
Need a contractual framework and roadmap? Explore AI and law resources and Discover the Initial journey.
Key requirements for high-risk systems
If you are a “provider” or “deployer” of a high-risk system, anticipate the following points by 2 August 2026 (Service Public Entreprendre; Entreprises.gouv):
- Risk management system: identification, analysis, mitigation and monitoring of risks throughout the lifecycle.
- Data governance: quality, relevance, representativeness; bias management; retention and traceability.
- Comprehensive technical documentation: model description, training, performance, limitations, cybersecurity.
- Traceability and automatic logging: event logs relevant to audits and investigations.
- Robustness, accuracy and cybersecurity: documented levels; testing and validation; post-market monitoring.
- Effective human oversight: defining authorisations and options to stop/suspend operation.
- CE marking and EU declaration of conformity; registration in the EU database for the stand-alone systems concerned.
- Serious-incident procedure and cooperation with the European AI Office.
Details appear in the regulatory framework and its annexes (EUR-Lex; European Commission).
Contracts, procurement and supplier compliance
- Due diligence: verify status (provider/deployer/importer/distributor), conformity assessment and standards used.
- Essential clauses: AI Act/GDPR obligations, audit rights, logs and exit arrangements, intellectual property (outputs, models, datasets), warranties against infringement and violation of trade secrets (INPI).
- GPAI transparency: information on generated content (marking, deepfake detection) and use restrictions.
For ready-to-use clause templates, contact us: Explore AI and law resources.
Common uses and areas requiring attention
- Recruitment: considered high-risk. Require CE marking, HR oversight, fairness testing and impact documentation.
- Internal/external chatbots: mandatory transparency; watch for data leaks and factual errors. Set rules for prompts and logging (CNIL).
- Biometrics and emotion recognition: targeted prohibitions and increased GDPR requirements; avoid use in workplace/education settings (Service Public Entreprendre).
- Content generation: monitor IP (copyright, trade marks) and trade secrets; implement appropriate filters and notices (INPI).
For 2026 trends and choices, see also Big média – Bpifrance.
A 90-day action plan towards 2 August 2026
Days 1–30: scoping
- Map AI systems and classify by risk.
- GDPR/DPIA assessment; identify sensitive data.
- Appoint an AI lead; internal usage policy.
Days 31–60: compliance
- High-risk requirements: risk management system, logs, human oversight.
- Contracts: AI Act/GDPR clauses, audit rights, use restrictions.
- Transparency: chatbot notices, synthetic-content marking.
Days 61–90: validation and evidence
- Testing, robustness and bias; remediation plans.
- Technical file, declaration of conformity, CE preparation.
- Post-market processes: monitoring, incidents, updates.
Further reading: read more AI and law analyses and Discover the Initial journey.
Further reading
See our related guides: European AI Act: complete guide, GDPR and AI: legal obligations and Civil liability and AI.
Further reading
Related resources
Frequently asked questions
FAQ
What are the main legal limits on AI in 2026?
Prohibitions on unacceptable-risk uses (e.g. social scoring), strict obligations for high-risk AI (CE marking, logs, human oversight), transparency for limited risks, and cumulative GDPR compliance.
Which critical deadlines should I remember?
2 February 2025 for the prohibitions; 2 August 2025 for transparency/GPAI obligations; 2 August 2026 for full application of high-risk obligations.
What penalties apply for non-compliance?
Up to €35 million or 7% of turnover for prohibited practices; €15 million or 3% for other infringements; €7.5 million or 1% for inaccurate information supplied to authorities (caps adapted for SMEs).
What should I do now to comply?
Map and classify your AI, carry out DPIAs, require providers’ compliance documentation, implement logs and human oversight, and prepare CE marking for high-risk systems.
References
Sources used
- AI Act: what changes for businesses — Service Public Entreprendre
- Digital regulation in France: progress and ...
- The European regulation on artificial intelligence: who is covered
- The European regulation on artificial intelligence (AI Act)
- AI legislation — European Commission — Digital Strategy
- New AI trends: what will transform 2026 | Big média
- CNIL — Artificial intelligence
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.