
The design
France's data-protection authority, the CNIL, publishes a standing set of AI guidance documents rather than a single rule. Its AI how-to sheets, described on its own site as the CNIL's 'first recommendations on the application of the GDPR to the development of artificial intelligence systems,' walk a developer through building a training dataset that includes personal data. A companion document, the Q&A on the Use of Generative AI Systems, addresses deployment: choosing an off-the-shelf model, fine-tuning it, or connecting it to a retrieval system. Both apply to any AI system processing personal data of people in France, conversational companion products included; neither names a specific company or product.
What the evidence says
These documents record the CNIL's own reading of existing GDPR obligations as applied to AI, not a court's or a fine's finding against any operator. The Q&A states that generative models 'are not knowledge bases' and can produce plausible-seeming 'hallucinations,' and recommends checking a system's safety, relevance, robustness, and freedom from bias before adopting it. It also flags a risk relevant to companion products: a consumer service reached through a personal email address can let a provider reuse a user's conversation as training data unless that reuse is disabled, a distinction the CNIL asks organisations to actively manage rather than assume away.
What it asks of people
The documents place the compliance burden on whoever builds or deploys the system, not the individual user. A deploying organisation is asked to run a risk analysis before launch, secure personal data submitted to the model, and train end users to treat outputs critically rather than reproduce them unverified. For a companion-app user, the guidance offers no direct new right beyond what GDPR already provides; its relevance lies in what it says the operator should already be doing, which a user cannot confirm from the app alone.
Privacy and safeguards
As living guidance rather than a decision, the how-to sheets and the Q&A describe what the CNIL considers good practice, not a finding about what any AI company is doing. They do not name Replika, Character.AI, or any other companion product, and this entry attributes no company-specific finding to them. What they supply is a checklist a reader can hold up against a product's own privacy documentation: whether it discloses reusing conversations for training, states retention periods, or explains how outputs were filtered for safety.
- Does a companion app's privacy policy state whether conversations are reused to train or fine-tune its models?
- Does the app distinguish a personal account from a business one, and does that choice affect data reuse under this guidance?
- Has the operator published anything resembling a risk analysis, or only marketing language about safety?
Read as intended, CNIL's AI guidance is a measuring stick a reader can hold against any conversational AI product operating in France, not a verdict on any one of them, a distinction worth keeping since other entries in this archive describe regulatory findings rather than standards.
Sources & reading trail
CNIL's own description of its AI how-to sheets as first recommendations on applying GDPR to AI system development.
Source published: Not established · Retrieved: 16 September 2026
States generative models are not knowledge bases, describes hallucination risk, and flags training-data-reuse risk for consumer accounts.
Source published: Not established · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.