← Back to blog
Artificial intelligenceGenerative AICybersecurityCompliance

AI Use Policy: What France Num Changes in Practice

Published on October 8, 2026•by Pierre Coulanges•7 min read
AI Use Policy: What France Num Changes in Practice
Photo: KOBU Agency / Unsplash

AI often entered the business before its rules of use were written: individual accounts, assistants embedded in software and automations connected to the CRM. France Num’s new guidance does not create an additional legal obligation, but it sends a clear message to business leaders: an effective policy must now be translated into operational controls.

What just happened

On 16 September 2026, France Num published guidance recommending that companies explicitly address generative AI in their IT policy, including rules on approved tools, data and human validation, in “Charte informatique : un outil indispensable pour encadrer les usages numériques”. On 17 September, the 2026 France Num Barometer reported that 40% of French small businesses already used at least one AI solution, while 39% had experienced a cybersecurity incident during the previous twelve months. The publication is practical guidance, not a new law or a standalone regulatory deadline. It nevertheless comes after the AI literacy obligation became applicable on 2 February 2025 and its supervision began in August 2026, according to the European Commission’s AI Literacy Questions and Answers.

Why this may — or may not — affect you

You are directly concerned if an employee or contractor uses AI to draft proposals, summarise contracts, analyse applications, generate code, process customer requests or prepare decisions. The risk is not limited to the generated output: prompts, attachments, conversation histories and active connectors may also expose internal information.

The level of risk increases when an AI agent can take action in a business application. An assistant that suggests an email is not equivalent to an agent allowed to create an order, modify a CRM record or send a document. In the second case, the written rule must be backed by technical permissions, action logs and human approval.

You are less affected in the short term if no employee or contractor uses AI, your software has no embedded AI feature and no deployment is planned. However, checking administration consoles is still necessary because software vendors may activate AI functions without a formal internal project.

The policy’s legal status also varies. It may remain educational guidance or become enforceable against employees. In French companies where internal regulations are mandatory, including organisations with at least 50 employees, rules creating permanent employee obligations must follow the applicable CSE consultation, publication, filing and labour-inspector procedures. They take effect at least one month after the final formality, as explained by the French Ministry of Labour’s guidance on internal regulations.

What this changes in practice

The first change is the end of vague instructions such as “do not enter sensitive data into AI”. Employees must be able to decide whether a specific document may be used, in which tool and subject to which approval.

An effective policy should make verifiable decisions:

Operational area What the policy must decide Control to implement Evidence to retain
Approved tools Which assistants, accounts and extensions may be used Professional accounts, allowlists and central authentication Tool catalogue and internal owner
Input data Which documents and fields are permitted or prohibited Masking, removal of unnecessary data or transfer blocking Data classification and associated rule
Generated output Who verifies content before communication or decision Approval step within the workflow Validator identity and timestamp
Connected agents Which applications and actions are accessible Dedicated service account and least-privilege permissions Logs of calls, errors and changes
Incidents Who must be notified of an error, leak or unexpected action Reporting channel and rapid access suspension Incident ticket and corrective decision

For sales and marketing teams, this means identifying which materials AI may prepare and which require review before publication. Prices, contractual commitments, customer references and technical claims should not be communicated solely on the basis of generated output.

For finance and administration, the policy must state whether an invoice, bank account number, contract or cash-flow spreadsheet may be submitted to the tool. In its guidance on deploying generative AI, the French data protection authority recommends starting from a defined need, specifying permitted and prohibited uses, checking whether the provider may reuse submitted data and maintaining human intervention.

For HR, using AI to help draft a job advertisement should not be confused with a system that ranks candidates or recommends employment decisions. The latter requires a separate project, including legal analysis, documented criteria and a challenge procedure. A general clause in an IT policy does not make such a system compliant.

Consider an illustrative scenario: an agent reads a support inbox, classifies each request, prepares a reply and updates the CRM. The policy defines which data categories may be processed and requires approval before sending. The workflow enforces those rules through a restricted service account, an approval screen and action logging. This is how written guidance becomes a controllable system.

The policy does not replace an AI use register, which documents systems and owners, or company-level AI governance. It tells users what they may do; the supporting documents organise accountability, controls and decisions.

What to do by 15 December 2026

The following dates are recommended internal targets, not additional statutory deadlines.

  • By 16 October — CEO or managing director: appoint an operational sponsor and require every new AI tool or agent to be declared before it connects to company data. Deliverable: a decision note naming the owner, declaration channel and authority to suspend access.
  • By 30 October — IT and business managers: inventory the assistants, extensions, embedded features and automations actually in use. Record the owner, purpose, account type, processed data, connectors and validation method. Deliverable: an actionable catalogue rather than a simple list of brands.
  • By 13 November — HR, DPO and management: draft the rules from the inventory. The document must distinguish unrestricted, approval-based and prohibited uses. HR must also decide whether the policy remains informative or should follow the procedure required to make it enforceable.
  • By 30 November — IT: configure the corresponding controls, including professional accounts, authentication, restricted permissions, log storage and blocking of unauthorised connectors. Deliverable: a control sheet for each approved tool, including test results.
  • By 15 December — HR and managers: explain the rules applicable to each role and retain evidence of AI literacy actions. The Commission states that no specific training format or certificate is required, while internal records of guidance and training can document the company’s approach in its AI Literacy Questions and Answers.

What you can ignore for now

You do not automatically need to create an AI committee, appoint an “AI Officer” or purchase a certification. The European Commission confirms that no specific governance structure or certificate is required to meet the AI literacy obligation. You must, however, be able to demonstrate measures consistent with your actual uses and risks.

You also do not need to ban all free tools as a matter of principle. Research based on public information does not present the same risk as analysing a customer contract. A policy based on data categories, permitted actions and approvals will be more usable than a blanket ban that pushes employees towards accounts invisible to IT.

Nor must every internal draft carry an “AI-generated” label. The Article 50 transparency obligations, applicable since 2 August 2026, cover defined situations rather than imposing universal labelling, as clarified by the Commission’s Questions and Answers on AI Act transparency obligations.

Finally, do not start a documentation project disconnected from the tools. A comprehensive policy that cannot be enforced will not prevent errors or data leaks.

Our view at D1 Consulting

France Num’s publication confirms that AI controls can no longer rely solely on individual caution. The answer, however, should not be an isolated legal document. A rule becomes effective when it corresponds to an actual control in Microsoft 365, n8n, Make, Power Automate, the CRM or the ERP.

Our method starts with observed uses. We produce an inventory of tools and agents, a matrix connecting data, actions and approvals, and a target architecture covering service accounts, permissions, logs and human approval points. These elements then support the policy, incident procedure and acceptance tests.

Our Automation & Process Optimisation service designs and secures AI workflows and agents. When several departments, vendors or regulatory constraints are involved, our IT Project Management service provides project scoping, arbitration, testing and controlled deployment.

👉 Book a free 30-minute diagnostic and receive a practical list of controls for your priority AI use cases.

An automation or digital transformation project?

Let's discuss your challenges and see how we can support you.

Contact us