Skip to content
Monday, July 20, 2026
Policy

Policy

Policy coverage with in-house analysis.

Policy

France Calls for Urgent AI Regulation on Three Pillars

France's foreign ministry is calling for urgent AI regulation built on three principles: investment and innovation, digital sovereignty, and ethical considerations. The push references the European Commission's February 2020 White Paper on Artificial Intelligence.

Source: Read full story at GOUV

In-house analysis

The contrast is clear: private labs own the capability, but regulators will own the accountability rules. Who pays for compliance is the next question.

Policy

US and Germany Deepen Military AI Cooperation

The United States and Germany are expanding AI integration across their military sectors. The move signals a coordinated allied push to embed AI capabilities into defense operations and planning.

Source: Read full story at Forklog

In-house analysis

The signal is not the cooperation announcement. The signal is which operators win the infrastructure contracts when allied military AI moves from policy to procurement.

Policy

EU Rewrites AI Law to Shield German Industrial Giants

EU ambassadors agreed to exempt machinery from the AI Act, a direct win for Germany. The deal also delays high-risk AI restrictions by more than a year and grants a grace period for content watermarking rules.

Source: Read full story at Politico

In-house analysis

The AI Act launched as a single rulebook. It is becoming a patchwork. Operators in manufacturing should move now; operators in other sectors should watch which exemption comes next.

Policy

Germany's AI Election Rules Are Missing as Campaigns Accelerate

AI is reshaping German election campaigns with no clear rules governing its use. Experts warn the unregulated landscape threatens democratic trust during Germany's super election year.

Source: Read full story at Facebook

In-house analysis

No rules means no accountability. The party that deploys AI fastest gains reach; the voter absorbs the cost. Germany's election cycle is the stress test regulators are not ready for.

Policy

Mistral CEO: No Sovereign AI Means No Real Army

Mistral CEO Arthur Mensch told Brussels policymakers that European militaries risk being 'turned off' if they rely on foreign AI systems. He argued AI now carries the strategic weight of nuclear deterrence.

Source: Read full story at Politico

In-house analysis

Capability without sovereign control is a liability. If the Commission's package creates hard procurement rules, distribution moves to domestic operators and Mistral is first in line.

Policy

France CNIL Sets Rules on Deepfakes and Illegal AI Content

France's CNIL has issued guidance targeting deepfakes and illegal AI-generated content. The regulator is drawing a compliance line for operators producing or distributing synthetic media.

Source: Read full story at DataGuidance

In-house analysis

Regulating the output, not the model, changes who pays. Platform operators and content distributors carry the new burden, not the labs building the underlying systems.

Policy

France CNIL Launches AI Traceability Tool for Compliance

France's data protection authority, CNIL, has launched an AI traceability tool. The tool is designed to help organizations track and document AI systems for regulatory compliance.

Source: Read full story at DataGuidance

In-house analysis

Capability without a paper trail is a liability. CNIL just handed regulators the tool to prove it.

Policy

France's CNIL Sets Rules for Scraping Personal Data in AI Training

CNIL published two how-to sheets on June 19, 2025, covering legitimate interest and web scraping for AI training datasets. The regulator stops short of banning scraping but demands case-by-case assessment and calls for specific legislation.

Source: Read full story at Hogan Lovells

In-house analysis

Capability is not the constraint here, compliance is. Labs that scrape at scale now face a documented standard, and the regulator has flagged that existing law is not enough.

Policy

EU Tightens AI Oversight With Biometrics, GPAI Taskforce Moves

Three EU regulatory actions landed in January: Prague's High Court authorized live biometric identification at airports, the European Commission stood up a GPAI Signatory Taskforce, and France's CNIL released an open-source model genealogy tracking tool.

Source: Read full story at Dentons

In-house analysis

Voluntary becomes mandatory when regulators write the interpretive documents. GPAI providers now face a compliance floor built inside a forum they chose to join.

Policy

France Regulators Open Consultation on AI in Healthcare

France's CNIL and HAS have launched a public consultation on a draft guide for AI use in healthcare. The joint effort signals coordinated regulatory pressure on clinical AI operators in France.

Source: Read full story at DataGuidance

In-house analysis

Two regulators, one document: the compliance burden consolidates. Operators who ignore the consultation phase will inherit the outcome others negotiated.

Policy

France Builds Tool to Audit AI Models for GDPR Compliance

France's CNIL is launching PANAME, an 18-month project to build privacy auditing tools for AI models. Partners include ANSSI, PEReN, and the IPoP project under PEPR Cybersecurity.

Source: Read full story at CNIL

In-house analysis

Regulators are building the audit infrastructure, not waiting for industry to supply it. Labs that cannot demonstrate privacy resistance will face compliance exposure with no neutral tool to reach for.

Policy

France's CNIL Publishes English AI Guidance Sheets

France's CNIL has released an English version of its AI how-to sheets. The guidance gives non-French operators direct access to the regulator's AI compliance framework.

Source: Read full story at DataGuidance

In-house analysis

Regulators publishing in English is not courtesy. It removes the language barrier as an excuse for non-compliance. Non-EU operators now have less cover.

Policy

CNIL Clears Legitimate Interest for AI Training Data

France's CNIL confirmed AI model training on publicly scraped personal data can meet GDPR's legitimate interest standard. Copyright, database rights, and deployment-phase liability remain unresolved.

Source: Read full story at Skadden

In-house analysis

GDPR clarity at the training stage is real, but it is plumbing, not a palace. Deployment-phase liability, copyright, and database rights are where the next legal battles land.

Policy

Twenty DPAs Sign Joint AI Data Governance Statement in Seoul

Twenty data protection authorities signed a joint statement on trustworthy AI data governance at the Global Privacy Assembly in Seoul, September 2025. Signatories span four continents, including the ICO, CNIL, and Australia's OAIC.

Source: Read full story at CNIL

In-house analysis

A joint statement is not enforcement. The consequence is who moves first to translate shared principles into binding national guidance, and which operators get caught flat-footed.