On 17 August 2026, the French Data Protection Authority, the CNIL, updated its FAQs on the AI Act to reflect the amendments introduced by the Digital Omnibus, which entered into force on 27 July 2026. The update provides a particularly useful overview of the revised application timeline of the European Artificial Intelligence Regulation and further clarifies the relationship between the AI Act and the GDPR.
According to the timeline set out by the CNIL, the transparency obligations applicable to certain AI systems have applied since 2 August 2026. From 2 December 2026, further provisions will also apply, including the prohibition concerning AI systems generating child sexual abuse material and sexual deepfakes and, for the relevant systems placed on the market before 2 August 2026, the specific transparency obligations relating to the labelling of AI-generated content. The rules applicable to high-risk systems listed in Annex III will apply from 2 December 2027, while those concerning high-risk systems related to products covered by Annex I will apply from 2 August 2028.
The CNIL also stresses that the AI Act does not replace the GDPR, but complements it. Data protection law therefore continues to apply to the processing of personal data carried out both during the development and the deployment of AI systems. In many cases, the provider of an AI system or model will act as controller under the GDPR during the development phase, while the deployer using the system to process personal data will, in turn, generally act as controller in respect of the processing carried out during deployment.
Of particular significance is the CNIL’s emphasis on the need for an integrated reading of the two Regulations. The transparency, documentation, risk assessment and accountability obligations laid down by the AI Act may, in fact, contribute to compliance with the GDPR. By way of example, the CNIL highlights the relationship between the fundamental rights impact assessment required under the AI Act (FRIA) and the data protection impact assessment (DPIA), noting that the two assessments may be coordinated in order to avoid unnecessary duplication of compliance documentation.
Finally, the CNIL confirms that it retains its full powers and responsibilities under the GDPR in relation to the processing of personal data connected with AI systems and models, including where such systems and models are simultaneously subject to the AI Act.