A Rule Without a Referee
Since August 2, 2026, any company operating in France that runs a customer-facing chatbot, publishes AI-generated news content, or distributes synthetic media has been legally bound by Article 50 of the EU AI Act — the provision requiring that people be told when they're talking to a machine, that AI-generated content carry machine-readable marks, and that deepfakes be visibly labeled (European Commission, Digital Strategy). Penalties for non-compliance reach €15 million or 3% of global annual turnover, whichever is higher, under Article 99(4) of the Regulation (artificialintelligenceact.eu, Article 99).
There is, however, no French authority currently empowered to bring that case. France was required to designate its national competent authorities under the AI Act by August 2, 2025 — a full year before Article 50's obligations became enforceable. It has not done so. The government's draft scheme, published September 9, 2025, splits oversight across roughly seventeen sectoral bodies, with CNIL (data protection), DGCCRF (consumer affairs) and Arcom (audiovisual/digital content) handling the bulk of AI use cases (MIAI/ai-regulation.com). But the legal vehicle meant to formalize that plan — Article 24 of the DDADUE bill, France's omnibus EU-adaptation law — cleared the Senate on February 18, 2026 and was still moving through National Assembly committee as of the most recent parliamentary record (Assemblée nationale, dossier législatif DLR5L17N53140). Thirteen months after the designation deadline, the enforcement gap is not a rounding error — it is the default state.
The Case the Regulation Is Actually Making
It's worth taking the underlying obligation seriously before criticizing the rollout. Article 50 targets real harms: chatbots that pose as human customer-service agents to extract information users wouldn't otherwise share, synthetic audio and video used in romance scams and financial fraud, and AI-generated "news" articles seeded into public debate without any disclosure that a human editor never touched them. France's own Constitutional Council has shown this year that it will strike down AI-and-platform rules it considers disproportionate — it voided the under-15 social media ban in August 2026 on free-expression grounds (EFF) — so a transparency mandate that survived EU-level negotiation and simply requires labeling, not blocking or removing content, sits on comparatively solid footing. Disclosure requirements are the least invasive tool available for the deepfake and synthetic-media problem, and honest companies mostly comply with disclosure rules voluntarily once they exist, because the reputational cost of getting caught concealing AI use is now high on its own.
Why an Unenforced Rule Is Worse Than No Rule
But a transparency law with no functioning enforcer doesn't split the difference between regulation and deregulation — it delivers the worst features of both. Consumers get no practical recourse: if a chatbot fails to disclose it's a bot, there is today no French agency positioned to receive that complaint and act on it with authority, because none has been formally handed enforcement power under the AI Act. Compliant businesses, meanwhile, absorbed real engineering and legal cost to meet an August 2 deadline — labeling systems, disclosure banners, provenance metadata — while facing genuine uncertainty about which regulator's specific interpretive guidance they should be building toward. CNIL, DGCCRF and Arcom don't share identical enforcement postures or risk tolerances; a company optimizing for CNIL's approach to biometric transparency may be solving a different problem than one preparing for DGCCRF's consumer-protection lens.
This is a legislative capacity failure, not a policy disagreement — France chose the substance of the EU rule (it had no real choice; Article 50 was already in the Regulation) and just failed to execute the administrative step of designation on time. Fragmenting AI oversight across roughly seventeen bodies, several with overlapping jurisdiction, was always going to be slower to stand up than a single clear regulator, and the DDADUE bill's slog through committee — introduced under accelerated procedure in November 2025 and still not law nine months later — is the predictable cost of that design choice.
What Should Happen Next
The fix here isn't to soften Article 50's substance; it's to finish the administrative job. The National Assembly should pass Article 24 of the DDADUE bill before year-end and give CNIL clear lead authority for cross-cutting AI transparency complaints — mirroring the pivot role it already plays in the government's own draft scheme — rather than leaving three agencies to sort out turf informally. Until that happens, France is asking companies to bear real compliance cost for a rule that, in practice, currently polices itself. That undermines confidence in AI regulation generally: it hands ammunition to critics who say EU AI rules are more symbolic than substantive, and it does nothing for the consumers Article 50 was written to protect. A credible transparency regime needs both a rule and a regulator on the same start date — Brussels supplied the rule; Paris still owes the regulator.