France Builds Tool to Audit AI Models for GDPR Compliance

France's data protection authority CNIL, alongside ANSSI, PEReN, and the IPoP project of PEPR Cybersecurity, is launching PANAME: a software library for auditing AI model privacy. The project runs 18 months. Reporting comes from CNIL directly.
The trigger is a December 2024 EDPB opinion stating that GDPR applies, in many cases, to AI models trained on personal data, because those models can memorize that data. To exit GDPR scope, developers must demonstrate resistance to privacy attacks. That standard now has teeth, and tools to meet it do not yet exist at industrial scale. Research exists, but mostly at the experimental level, built for academic publication rather than compliance workflows.
PANAME is the institutional answer to that gap. CNIL will also publish recommendations to help AI operators document their compliance analysis. Watch for the software library to become a reference standard that regulators elsewhere adopt. Any lab training on European personal data needs a credible audit path. That path is now being built by the regulators themselves.