AI in Healthcare in France: CNIL and HAS Guidance on Best Practices, from Development to Use
min readThe deployment of artificial intelligence in the healthcare sector has accelerated in France in recent years, particularly since the arrival of ChatGPT in 2022. In response to this surge, two recent institutional publications provide structure to the applicable legal and operational framework: a practical factsheet from the CNIL on the development and evaluation of AI systems in healthcare, published on March 5, 2026, and a joint HAS-CNIL guide on the proper use of such systems in a care setting, dated February 16, 2026.
Development and Evaluation of AI Systems in Healthcare: A CNIL Compliance Framework
The factsheet published by the CNIL supplements the CNIL's general recommendations on AI, to account for sector-specific characteristics, and is addressed to data protection officers (DPOs), project managers, and more broadly all stakeholders wishing to use health data to develop or evaluate an AI system intended for the healthcare sector.
The CNIL distinguishes three key stages in the lifecycle of an AI system, some of which are optional:
The establishment of a health data warehouse (HDW)
This is an optional stage that requires anticipating subsequent uses, which may include the development of AI systems. In this regard, the CNIL recalls that the development of AI systems intended for the healthcare sector is treated as research, a study, or an evaluation in the field of health. This doctrine relies directly on the GDPR's broad interpretation of the concept of scientific research, covering in particular the development and demonstration of technologies. Furthermore, processing operations carried out using data from such a warehouse constitute separate data processing activities that may fall within the next stage.
The creation of a database specifically dedicated to the development of an AI system
Again, this constitutes processing falling within the scope of research, a study, or an evaluation in the field of health within the meaning of the GDPR and the French Data Protection Act (Loi Informatique et Libertés). In this regard, the CNIL pragmatically "considers that the various data operations carried out in this context may be envisaged within the framework of a more general purpose corresponding to the development of an AI system, which includes its validation, particularly in terms of performance." Accordingly, processing pursued for the purpose of deploying an AI system intended to constitute a Medical Device encompasses the purposes of database preparation, model training and optimization, clinical and technical performance validation, up until the obtaining of the authorizations or certificates required for market placement.
The evaluation of the system's deployment in the sector
"notably on care pathways, professional practices, or epidemiological surveillance," constitutes research, a study, or an evaluation in its own right, subject to prior formalities.
Operational Recommendations for Deployers: A Joint HAS-CNIL Guide
The joint HAS-CNIL guide targets healthcare professionals and healthcare establishments, acting in their capacity as "deployers" within the meaning of the European AI Act (AI Act), i.e., natural or legal persons using an AI system under their own authority in a professional context. The guide follows a chronological approach from the internal organization prior to deployment through to the end of the lifecycle and decommissioning, addressing the regulatory obligations applicable at each stage.
Regarding the stage of AI system acquisition and contractualization, the key points of vigilance are organized around the following phases and associated actions:
- Prior to contractualization, obtaining complete and clear information about the AI system, including intended use, development conditions, performance, limitations and biases, eligible patient populations, operating principles, human oversight, elements necessary for proper functioning, procedures in case of malfunction, data flows, and environmental impact;
- Verifying the regulatory compliance of the AI system, including medical device (MD) status in light of its intended use, GDPR compliance, health data hosting (HDS) certification, and identification of subprocessors;
- Verifying interoperability with the existing information system;
- During contractualization, formalizing a RACI matrix between the AI system provider and the deployer, providing for appropriate SLAs, planning a proof of concept (POC), performance thresholds, and reversibility conditions, while ensuring the involvement of the DPO and paying particular attention to the governance of data processing, data reuse, storage within the EEA, and sovereignty.
On the training front, graduated recommendations are made, including general AI awareness training for all professionals, in-depth training for key profiles such as the DPO or the head of information systems, and mandatory specific training prior to any use of an AI system.
The drafting of a dedicated AI charter formalizes the commitment of professionals and should include prohibited practices and potentially a catalog of approved uses presenting a minimal level of risk.
It is recalled that the deployer is required to inform data subjects when using a high-risk AI system, to notify persons who interact directly with an AI system (e.g., a chatbot), and to provide GDPR-compliant information where the processing involves personal data and to respond to requests to exercise data subject rights.
Finally, the guide addresses generative AI systems, the use of which must be limited to reasoned use. In this respect, it is recommended to control the use of these tools through staff awareness of risky uses and the promotion of the usage charter.
European Framework and Implementation Monitored by Authorities
These two publications are set within the context of the progressive entry into application of the AI Act. The majority of the AI Act's obligations will become applicable from August 2, 2026, in particular the rules relating to high-risk AI systems listed in Annex III, while the rules relating to high-risk AI systems falling under Annex I – which include medical devices – will enter into application from August 2, 2027, unless deferred pursuant to the Omnibus on AI, if adopted.
It should be recalled that AI is one of the four pillars of the CNIL's 2025–2028 strategic plan, which notably provides for "auditing and inspecting AI systems and protecting individuals," "under both the GDPR and the AI Act," and that the HAS, for its part, has integrated digital and AI-related risk management into the sixth cycle of healthcare establishment certification since 2024.
These joint initiatives aim to promote the readability of the trust framework for AI in healthcare – designed to reconcile technological innovation, patient safety, and the protection of fundamental rights – and its implementation, in compliance with the forthcoming regulatory deadlines...