• news-banner

    Expert Insights

Available in other languages:

AI in Healthcare in France: CNIL and HAS Guidance on Best Practices, from Development to Use

min read

The deployment of artificial intelligence in the healthcare sector has accelerated in France in recent years, particularly since the arrival of ChatGPT in 2022. In response to this surge, two recent institutional publications provide structure to the applicable legal and operational framework: a practical factsheet from the CNIL on the development and evaluation of AI systems in healthcare, published on March 5, 2026, and a joint HAS-CNIL guide on the proper use of such systems in a care setting, dated February 16, 2026.

Development and Evaluation of AI Systems in Healthcare: A CNIL Compliance Framework

The factsheet published by the CNIL supplements the CNIL's general recommendations on AI, to account for sector-specific characteristics, and is addressed to data protection officers (DPOs), project managers, and more broadly all stakeholders wishing to use health data to develop or evaluate an AI system intended for the healthcare sector.

The CNIL distinguishes three key stages in the lifecycle of an AI system, some of which are optional:

The establishment of a health data warehouse (HDW)

This is an optional stage that requires anticipating subsequent uses, which may include the development of AI systems. In this regard, the CNIL recalls that the development of AI systems intended for the healthcare sector is treated as research, a study, or an evaluation in the field of health. This doctrine relies directly on the GDPR's broad interpretation of the concept of scientific research, covering in particular the development and demonstration of technologies. Furthermore, processing operations carried out using data from such a warehouse constitute separate data processing activities that may fall within the next stage.

The creation of a database specifically dedicated to the development of an AI system

Again, this constitutes processing falling within the scope of research, a study, or an evaluation in the field of health within the meaning of the GDPR and the French Data Protection Act (Loi Informatique et Libertés). In this regard, the CNIL pragmatically "considers that the various data operations carried out in this context may be envisaged within the framework of a more general purpose corresponding to the development of an AI system, which includes its validation, particularly in terms of performance." Accordingly, processing pursued for the purpose of deploying an AI system intended to constitute a Medical Device encompasses the purposes of database preparation, model training and optimization, clinical and technical performance validation, up until the obtaining of the authorizations or certificates required for market placement.

The evaluation of the system's deployment in the sector

"notably on care pathways, professional practices, or epidemiological surveillance," constitutes research, a study, or an evaluation in its own right, subject to prior formalities.

Operational Recommendations for Deployers: A Joint HAS-CNIL Guide

The joint HAS-CNIL guide targets healthcare professionals and healthcare establishments, acting in their capacity as "deployers" within the meaning of the European AI Act (AI Act), i.e., natural or legal persons using an AI system under their own authority in a professional context. The guide follows a chronological approach from the internal organization prior to deployment through to the end of the lifecycle and decommissioning, addressing the regulatory obligations applicable at each stage.

Regarding the stage of AI system acquisition and contractualization, the key points of vigilance are organized around the following phases and associated actions:

  • Prior to contractualization, obtaining complete and clear information about the AI system, including intended use, development conditions, performance, limitations and biases, eligible patient populations, operating principles, human oversight, elements necessary for proper functioning, procedures in case of malfunction, data flows, and environmental impact;
  • Verifying the regulatory compliance of the AI system, including medical device (MD) status in light of its intended use, GDPR compliance, health data hosting (HDS) certification, and identification of subprocessors;
  • Verifying interoperability with the existing information system;
  • During contractualization, formalizing a RACI matrix between the AI system provider and the deployer, providing for appropriate SLAs, planning a proof of concept (POC), performance thresholds, and reversibility conditions, while ensuring the involvement of the DPO and paying particular attention to the governance of data processing, data reuse, storage within the EEA, and sovereignty.

On the training front, graduated recommendations are made, including general AI awareness training for all professionals, in-depth training for key profiles such as the DPO or the head of information systems, and mandatory specific training prior to any use of an AI system.

The drafting of a dedicated AI charter formalizes the commitment of professionals and should include prohibited practices and potentially a catalog of approved uses presenting a minimal level of risk.

It is recalled that the deployer is required to inform data subjects when using a high-risk AI system, to notify persons who interact directly with an AI system (e.g., a chatbot), and to provide GDPR-compliant information where the processing involves personal data and to respond to requests to exercise data subject rights.

Finally, the guide addresses generative AI systems, the use of which must be limited to reasoned use. In this respect, it is recommended to control the use of these tools through staff awareness of risky uses and the promotion of the usage charter.

European Framework and Implementation Monitored by Authorities

These two publications are set within the context of the progressive entry into application of the AI Act. The majority of the AI Act's obligations will become applicable from August 2, 2026, in particular the rules relating to high-risk AI systems listed in Annex III, while the rules relating to high-risk AI systems falling under Annex I – which include medical devices – will enter into application from August 2, 2027, unless deferred pursuant to the Omnibus on AI, if adopted.

It should be recalled that AI is one of the four pillars of the CNIL's 2025–2028 strategic plan, which notably provides for "auditing and inspecting AI systems and protecting individuals," "under both the GDPR and the AI Act," and that the HAS, for its part, has integrated digital and AI-related risk management into the sixth cycle of healthcare establishment certification since 2024.

These joint initiatives aim to promote the readability of the trust framework for AI in healthcare – designed to reconcile technological innovation, patient safety, and the protection of fundamental rights – and its implementation, in compliance with the forthcoming regulatory deadlines...

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • EU Packaging and Packaging Waste Regulation: Who Is Affected?

    Kerry Stares

    Quick Reads

    min read
  • Cristiana Felisi writes for We Wealth on when a parent can lose custody of their children

    Maria Cristiana Felisi

    In the Press

    min read
  • EU Packaging and Packaging Waste Regulation: Three Things You Need to Know

    Kerry Stares

    Quick Reads

    min read
  • Jersey Trade Mark Reform: What the New Regime Means for You

    Dewdney William Drew

    Quick Reads

    min read
  • New EU Packaging and Packaging Waste Regulation: Is Your Business Ready?

    Kerry Stares

    Quick Reads

    min read
  • Tessa Bartley comments in Legal Futures about our framework for choosing the right legal AI tools

    Tessa Bartley

    In the Press

    min read
  • A practical guide to choosing the right AI tools for your law firm: Five Insights that surprised us the most

    Tessa Bartley

    Quick Reads

    min read
  • Fraudsters in the Inbox: The Limits of Contractual Causation in Logix Aero v Siam Aero

    Natalya Stone

    Insights

    min read
  • In-House Insights: Next Gen Drinks Reception

    Events

    min read
  • Giorgia Ligasacchi writes in We Wealth about collectors, Matthew Wong's artworks, and the contemporary art scene

    Giorgia Ligasacchi

    In the Press

    min read
  • A practical guide to choosing the right AI tools for your law firm: Inside the framework

    Tessa Bartley

    Quick Reads

    min read
  • Charles Russell Speechlys Opens New York Office and Connecticut Practice

    Simon Ridpath

    News

    min read
  • Disputes Over Donuts: Sports Arbitration

    Jue Jun Lu

    Podcasts

  • Saudi Center for Commercial Arbitration issues update on arbitration in Saudi Arabia

    Peter Smith

    Insights

    min read
  • Charles Russell Speechlys shares practical framework for choosing the right legal AI tools

    Lesley O’Leary

    News

    min read
  • A practical guide to choosing the right AI tools for your law firm: The big idea

    Tessa Bartley

    Quick Reads

    min read
  • Sadie Pitman writes in CoStar about the development of hyperscale data centres

    Sadie Pitman

    In the Press

    min read
  • Annapaola Negri-Clementi featured in La Repubblica, MilanoFinanza, Corriere della Sera and others following appointment to board of cryptocurrency asset manager

    Annapaola Negri-Clementi

    In the Press

    min read
  • First Sanction Against a Health Data Warehouse Controller

    Marguerite Brac de La Perrière

    Insights

    min read
Back to top