FRANCE Law and Practice Contributed by: Jérôme Philippe, Laéna Bouafy, Thomas Retière and Annabelle Hamelin, Freshfields
streamline incident reporting to extend the supervi - sory authority notification deadline to 96 hours. The CNIL actively sanctions organisations for funda - mental IT hygiene failures. Enforcement is increasingly driven by a close collaboration with ANSSI. In 2024, the CNIL published an updated “Practice guide for the security of personal data” that heavily integrates ANSSI’s recommendations. In practice, the CNIL treats ANSSI’s guidelines as the legal “state of the art” during investigations and enforcement procedures. As an illustration, in January 2026, the CNIL levied a record cumulative fine of EUR42 million against tel - ecoms operators FREE MOBILE and FREE following a massive data breach affecting 24 million subscribers in October 2024. The CNIL, notably applying Article 32 of the GDPR, cited severe negligence, including weak VPN authentication (lack of MFA) and ineffective intrusion detection systems, directly benchmarking the companies’ failures against the expected ANSSI standards. 6.2 Cybersecurity and AI Cybersecurity obligations for AI are rapidly evolving, driven by the AI Act and intersecting heavily with exist - ing data protection frameworks. Security-by-Design and Component Security The AI Act mandates that “high-risk” AI systems achieve declared levels of accuracy, robustness and cybersecurity before being placed on the market and throughout their life cycle. This embeds a strict security-by-design expectation, requiring resilience against adversarial attacks, data poisoning and model manipulation. General purpose AI (GPAI) models presenting system - ic risks face additional burdens, including mandatory adversarial testing and robust cybersecurity protec - tions. Incident-Reporting Requirements Under the AI Act, the primary duty to track, document and formally report serious incidents rests with the providers of high-risk AI systems and GPAI models with systemic risk. They must report incidents, includ - ing severe cybersecurity breaches or malfunctions, to
the competent market surveillance authorities or the European AI Office (for GPAI models) without undue delay. Other operators, such as deployers, have a related duty to inform the provider and competent authorities of any serious incidents they identify. The European Commission’s “Digital Omnibus” pro - posal aims to streamline this landscape by introducing a single-entry point for incident reporting, effectively unifying notification obligations under the AI Act, the NIS2 Directive and the GDPR. Interaction With General Cybersecurity and Data Protection The AI Act clearly states that its application is without prejudice to that of the GDPR. The texts are there - fore complementary, and certain resources developed within the framework of the GDPR can be used as a basis for compliance with the AI Act (in particular, data protection impact assessments). In France, the CNIL published recommendations in 2024 and 2025 concerning the development of AI sys - tems. Aligning with EDPB Opinion 28/2024, the CNIL emphasises that AI models generally fall within the scope of the GDPR due to the memorisation capabili - ties of models trained on personal data. The CNIL has dedicated practical how-to sheets to guide profes - sionals, including on ensuring the security of AI devel - opment, which outlines the precise risks and meas - ures to consider during the design phase to guarantee that AI systems are built in a secure environment. Governance and Threat Landscape in France With regard to governance, the French government has recently proposed a decentralised regulatory model for AI, with the DGCCRF acting as the cen - tral operational co-ordinator. Control responsibilities would be divided among sectoral authorities (mainly the CNIL, Arcom and DGCCRF). The CNIL in particu - lar would play a major role, being responsible for the oversight and enforcement of most prohibited prac - tices and obligations relating to high-risk AI systems falling under Annex III of the AI Act. However, the CNIL would not have any role in relation to high-risk AI sys - tems covered under Annex I of the EU AI Act. ANSSI and the Pôle d’Expertise de la Régulation Numérique would provide pooled technical support. This govern -
137 CHAMBERS.COM
Powered by FlippingBook