RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 160 retrospective records ↗
Love With Machines

The archive / Regulation & litigation

Regulation & litigation / Companion note · Entry note · prepared 16 September 2026

France's privacy regulator wrote AI guidance, not a ruling

CNIL's AI how-to sheets and generative-AI FAQ set general GDPR guidance for any AI system, not a finding about one company.

Visual published with the cited source for this record: France's privacy regulator wrote AI guidance, not a ruling
Visual published with the cited source, shown for identification of the record. Credit: cnil.fr · source page ↗ Rights: owner-review-pending.

The design

France's data-protection authority, the CNIL, publishes a standing set of AI guidance documents rather than a single rule. Its AI how-to sheets, described on its own site as the CNIL's 'first recommendations on the application of the GDPR to the development of artificial intelligence systems,' walk a developer through building a training dataset that includes personal data. A companion document, the Q&A on the Use of Generative AI Systems, addresses deployment: choosing an off-the-shelf model, fine-tuning it, or connecting it to a retrieval system. Both apply to any AI system processing personal data of people in France, conversational companion products included; neither names a specific company or product.

What the evidence says

These documents record the CNIL's own reading of existing GDPR obligations as applied to AI, not a court's or a fine's finding against any operator. The Q&A states that generative models 'are not knowledge bases' and can produce plausible-seeming 'hallucinations,' and recommends checking a system's safety, relevance, robustness, and freedom from bias before adopting it. It also flags a risk relevant to companion products: a consumer service reached through a personal email address can let a provider reuse a user's conversation as training data unless that reuse is disabled, a distinction the CNIL asks organisations to actively manage rather than assume away.

What it asks of people

The documents place the compliance burden on whoever builds or deploys the system, not the individual user. A deploying organisation is asked to run a risk analysis before launch, secure personal data submitted to the model, and train end users to treat outputs critically rather than reproduce them unverified. For a companion-app user, the guidance offers no direct new right beyond what GDPR already provides; its relevance lies in what it says the operator should already be doing, which a user cannot confirm from the app alone.

Privacy and safeguards

As living guidance rather than a decision, the how-to sheets and the Q&A describe what the CNIL considers good practice, not a finding about what any AI company is doing. They do not name Replika, Character.AI, or any other companion product, and this entry attributes no company-specific finding to them. What they supply is a checklist a reader can hold up against a product's own privacy documentation: whether it discloses reusing conversations for training, states retention periods, or explains how outputs were filtered for safety.

  • Does a companion app's privacy policy state whether conversations are reused to train or fine-tune its models?
  • Does the app distinguish a personal account from a business one, and does that choice affect data reuse under this guidance?
  • Has the operator published anything resembling a risk analysis, or only marketing language about safety?

Read as intended, CNIL's AI guidance is a measuring stick a reader can hold against any conversational AI product operating in France, not a verdict on any one of them, a distinction worth keeping since other entries in this archive describe regulatory findings rather than standards.

Sources & reading trail

AI system development: specific recommendations ↗

CNIL's own description of its AI how-to sheets as first recommendations on applying GDPR to AI system development.

Source published: Not established · Retrieved: 16 September 2026

CNIL's Q&A on the Use of Generative AI Systems ↗

States generative models are not knowledge bases, describes hallucination risk, and flags training-data-reuse risk for consumer accounts.

Source published: Not established · Retrieved: 16 September 2026

Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.