Regulation

France's CNIL publishes AI action plan to align systems with GDPR

On May 16, France's data protection authority CNIL published an AI action plan setting out guidance and clearer rules to ensure AI—especially generative systems like ChatGPT and Dall‑E—respects privacy while developing rapidly.

On May 16, the French data protection authority CNIL published an action plan for artificial intelligence with the aim of setting out guidance and clearer rules so that AI systems — especially generative AI solutions such as ChatGPT and Dall‑E — do not pose risks to data protection while the technology develops at high speed.

Four priority areas

The CNIL action plan provides guidance to achieve four main objectives:

  1. Understanding how AI systems work and their effects on people

    • This includes principles of fair and transparent data processing and the protection of data that are publicly accessible on the web. The plan notes legal questions arising from AI‑generated outputs, since AI often builds on massive datasets and creates further content from them.
  2. Enabling and steering the development of AI systems that respect personal data protection

    • In this context, CNIL says a guide on data sharing and reuse will be made available soon. The plan states that from summer 2023 several accompanying publications will provide concrete recommendations.
  3. Supporting innovative market players developing AI in France and Europe

    • Support will primarily take the form of so‑called sandboxes. This year’s sandbox will focus on the use of artificial intelligence in the public sector, offering tailored advice to participants and effective help for innovative companies in achieving GDPR compliance in the AI domain.
  4. Auditing and monitoring AI systems to protect people

    • CNIL stresses that AI systems used for enhanced surveillance or fraud prevention should be subject to prior and subsequent audits, because such systems can affect rights and freedoms related to privacy.

Dialogue and preparation for European rules

The action plan also signals CNIL’s openness to dialogue with various European companies that develop or are considering developing AI systems. The aim is twofold: to establish clear rules for privacy‑protecting AI development for the highest level of data protection for European citizens, and to prepare for the implementation of the proposed European AI code, while supporting companies with further guidance.

Overall, CNIL’s plan prioritizes GDPR compliance and strong privacy protection while permitting innovation in a regulated, monitored environment.

Further details

CNIL has published the full materials and additional information on its website.