Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

AI and Law5 min read

Legal limits on the use of AI in business (2026)

AI Act, GDPR, penalties and deadlines: business AI is strictly regulated in 2026. Risk classification, CE marking, transparency, human oversight: what must be done by 2…

Published: 17 February 2026 — AI and Law. Widespread business use of AI is entering an era of compliance. Since the AI Act entered into force on 1 August 2024, obligations have been phased in, with a critical milestone on 2 August 2026 for high-risk systems. The aim: secure use without stifling innovation, backed by substantial penalties (EUR-Lex; European Commission — Digital Strategy).

What the AI Act permits, restricts and prohibits

Four risk levels

  • Unacceptable risk (prohibited): social scoring, behavioural manipulation and emotion recognition at work/in schools, among other practices (Service Public Entreprendre; Entreprises.gouv — Who is covered).
  • High risk: AI deployed in sensitive sectors (recruitment, water/gas/electricity infrastructure management, education, health, public services, justice). Enhanced obligations: CE marking, technical documentation, risk management, logging and human oversight (European Commission).
  • Limited risk: transparency requirements (e.g. indicating that a person is interacting with a chatbot) (Service Public Pro).
  • Minimal risk: voluntary good practices.

The detailed framework, including classification annexes, is available in the official text (EUR-Lex) and national summaries (Entreprises.gouv — Digital regulation; Préfecture de l’Ain — AI Act).

2024–2026 deadlines and penalty scale

  • 1 August 2024: AI Act enters into force (Service Public Entreprendre).
  • 2 February 2025 (6 months): prohibitions apply (unacceptable-risk practices) (European Commission).
  • 2 August 2025 (12 months): enhanced transparency obligations for certain general-purpose AI (GPAI) and preparation of compliance ecosystems.
  • 2 August 2026 (24 months): full application of obligations for high-risk systems (CE marking, documentation, post-market monitoring, etc.) (EUR-Lex).

Administrative penalties: up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for other infringements; up to €7.5 million or 1% for inaccurate information supplied to authorities (caps adapted for SMEs) (EUR-Lex; Entreprises.gouv).

The combined AI Act x GDPR framework: data, biometrics and DPIAs

The AI Act does not replace the GDPR: both apply cumulatively. Any processing of personal data by AI must remain lawful, minimised and secure; using special categories (biometrics, health) requires a robust legal basis and enhanced safeguards (CNIL — AI; CNIL).

  • DPIA: mandatory for many AI use cases (large-scale profiling, biometrics). Coordinate it with the AI Act risk assessment.
  • Transparency: clear disclosure of AI use, information for individuals and avenues for redress.
  • Data governance: quality, bias, traceability, deletion. Repurposing contrary to the original purpose is prohibited.

Applicable texts are available through Légifrance and practical guides from national authorities (Entreprises.gouv).

Classifying and mapping your AI: a practical method

1) Inventory systems and use cases

  • IT/procurement inventory of solutions (SaaS, APIs, general-purpose models, low-code tools) and business uses (HR, marketing, operations, finance).
  • Identify personal/special-category data processing and transfers outside the EU.

2) Classify by AI Act risk level

  • Unacceptable: stop deployment.
  • High risk: initiate full compliance (see below).
  • Limited risk: implement transparency obligations (e.g. chatbot notices).
  • Minimal: apply good practices (logs, human validation).

3) Check providers and the compliance chain

  • Request AI Act documentation (EU declaration of conformity, CE marking for high risk, GPAI information).
  • Verify registration of stand-alone high-risk systems in the EU database before placing them on the market, and assessment reports (European Commission).
  • Contractual clauses: audit rights, incident notification, subcontracting, intellectual property and trade secrets (INPI).

Need a contractual framework and roadmap? Explore AI and law resources and Discover the Initial journey.

Key requirements for high-risk systems

If you are a “provider” or “deployer” of a high-risk system, anticipate the following points by 2 August 2026 (Service Public Entreprendre; Entreprises.gouv):

  • Risk management system: identification, analysis, mitigation and monitoring of risks throughout the lifecycle.
  • Data governance: quality, relevance, representativeness; bias management; retention and traceability.
  • Comprehensive technical documentation: model description, training, performance, limitations, cybersecurity.
  • Traceability and automatic logging: event logs relevant to audits and investigations.
  • Robustness, accuracy and cybersecurity: documented levels; testing and validation; post-market monitoring.
  • Effective human oversight: defining authorisations and options to stop/suspend operation.
  • CE marking and EU declaration of conformity; registration in the EU database for the stand-alone systems concerned.
  • Serious-incident procedure and cooperation with the European AI Office.

Details appear in the regulatory framework and its annexes (EUR-Lex; European Commission).

Contracts, procurement and supplier compliance

  • Due diligence: verify status (provider/deployer/importer/distributor), conformity assessment and standards used.
  • Essential clauses: AI Act/GDPR obligations, audit rights, logs and exit arrangements, intellectual property (outputs, models, datasets), warranties against infringement and violation of trade secrets (INPI).
  • GPAI transparency: information on generated content (marking, deepfake detection) and use restrictions.

For ready-to-use clause templates, contact us: Explore AI and law resources.

Common uses and areas requiring attention

  • Recruitment: considered high-risk. Require CE marking, HR oversight, fairness testing and impact documentation.
  • Internal/external chatbots: mandatory transparency; watch for data leaks and factual errors. Set rules for prompts and logging (CNIL).
  • Biometrics and emotion recognition: targeted prohibitions and increased GDPR requirements; avoid use in workplace/education settings (Service Public Entreprendre).
  • Content generation: monitor IP (copyright, trade marks) and trade secrets; implement appropriate filters and notices (INPI).

For 2026 trends and choices, see also Big média – Bpifrance.

A 90-day action plan towards 2 August 2026

Days 1–30: scoping

  • Map AI systems and classify by risk.
  • GDPR/DPIA assessment; identify sensitive data.
  • Appoint an AI lead; internal usage policy.

Days 31–60: compliance

  • High-risk requirements: risk management system, logs, human oversight.
  • Contracts: AI Act/GDPR clauses, audit rights, use restrictions.
  • Transparency: chatbot notices, synthetic-content marking.

Days 61–90: validation and evidence

  • Testing, robustness and bias; remediation plans.
  • Technical file, declaration of conformity, CE preparation.
  • Post-market processes: monitoring, incidents, updates.

Further reading: read more AI and law analyses and Discover the Initial journey.

Further reading

See our related guides: European AI Act: complete guide, GDPR and AI: legal obligations and Civil liability and AI.

Further reading

Related resources

Frequently asked questions

FAQ

What are the main legal limits on AI in 2026?

Prohibitions on unacceptable-risk uses (e.g. social scoring), strict obligations for high-risk AI (CE marking, logs, human oversight), transparency for limited risks, and cumulative GDPR compliance.

Which critical deadlines should I remember?

2 February 2025 for the prohibitions; 2 August 2025 for transparency/GPAI obligations; 2 August 2026 for full application of high-risk obligations.

What penalties apply for non-compliance?

Up to €35 million or 7% of turnover for prohibited practices; €15 million or 3% for other infringements; €7.5 million or 1% for inaccurate information supplied to authorities (caps adapted for SMEs).

What should I do now to comply?

Map and classify your AI, carry out DPIAs, require providers’ compliance documentation, implement logs and human oversight, and prepare CE marking for high-risk systems.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles