Bill no. 3149 would make market authorisation a mandatory step for general-purpose AI models and certain high-risk systems. Registered on 15 September 2026 at the National Assembly, it is presented by René Pilato, MP for Charente, and co-signed by 69 MPs from the La France Insoumise group, including its coordinator Manuel Bompard and its president Mathilde Panot. It would entrust this control to a new National Artificial Intelligence Authority (ANIA), with the power to impose sanctions of up to 7% of global turnover.

The text is a parliamentary initiative from an opposition group. It has a chance of being examined only if it is placed on the agenda, for example in a group's dedicated slot, and the legislative dossier mentions, as of 25 September, only the tabling and referral to the Economic Affairs Committee. It therefore stands primarily as a political position: it proposes, for AI, a prior authorisation regime where the European regulation relies on self-assessment by providers and market surveillance. The explanatory memorandum presents it as "complementary" to the AI Act; it cites the case of Grok and non-consensual sexual content to justify a national "protective foundation", and explicitly excludes employment, copyright and environmental footprint, referring them to future texts. The cost to the State would be offset by an additional tax on turnover generated in France by multinationals providing or deploying AI systems.

Authorisation for general-purpose models and Annex III systems

Article 15 would target systems and models made available to the public, free of charge or for payment, in the course of a commercial activity. Two categories would be concerned: general-purpose models, whether or not they present a systemic risk, and high-risk systems listed in Annex III of the European AI regulation. Systems developed or used for personal purposes, outside commercial activity, would be excluded.

The text would expressly exclude, for this authorisation, the exception in Article 6(3) of the AI Act. That exception allows, under certain conditions, not to classify as high-risk certain systems falling under Annex III when they do not present a significant risk to health, safety or fundamental rights, for example because they perform a narrow procedural or preparatory task. The proposal would therefore impose a national procedure even on systems benefiting from this European exception.

A new authorisation would be required after any substantial modification likely to affect the compliance of an authorised system or to change its risk profile. The details of the procedure would be set by decree in the Council of State, without the text itself setting a processing deadline. The ANIA would have eighteen members, including two MPs, two senators and the president of the CNIL (France's data protection authority) or their representative.

The point of friction with the AI Act

Article 88 of the AI Act confers on the Commission, through the European AI Office, exclusive powers of supervision and control over the obligations of providers of general-purpose models. The proposal acknowledges this: Article 15 would apply "without prejudice to the competences of the AI Office", and Article 17 provides for cooperation between the ANIA and that Office and the competent national authorities, through agreements. The text does not say how a national market authorisation, covering the same models, would fit with harmonised European rules that do not provide for one. That is the question the Economic Affairs Committee would have to resolve first if the text were examined.

A 7% ceiling for breaches of the French text

Article 22 would allow the president of the ANIA to remind a provider or deployer of their obligations, or to issue a formal notice to regularise their situation. The deadline could be reduced to twenty-four hours in case of emergency. If the breach persisted, a restricted panel could, after an adversarial procedure, impose a compliance order with a daily penalty of up to 100,000 euros, suspend the operation of the system or withdraw its authorisation.

The administrative fine would be capped at 7% of the total worldwide annual turnover of the previous financial year. Its amount would have to take into account the gravity and duration of the breach, its intentional nature, corrective measures, and the size and market share of the company. The text would exclude a second pecuniary administrative sanction for the same facts.

This rate recalls the highest ceiling in Article 99 of the AI Act, reserved for prohibited practices: 35 million euros or 7% of worldwide turnover, whichever is higher for companies, subject to the SME regime. Other obligations fall under a ceiling of 15 million euros or 3%. Article 101 also provides for 15 million euros or 3% for sanctions the Commission may impose on providers of general-purpose models.

The French proposal would retain a single proportional ceiling for breaches of its own obligations. It would not reproduce the different categories of European fines or their dual calculation in euros and percentage. The comparison therefore depends on the obligation breached and the category of company; SMEs benefit, under Article 99, from the lower of the two ceilings.

Short deadlines for incidents and data erasure

Article 23 would oblige providers and deployers to notify the ANIA of malfunctions or unexpected behaviour likely to harm the safety or health of persons, as well as results or behaviour contrary to legal obligations. The report would have to be made without delay, at the latest forty-eight hours after becoming aware of the event. The explanatory memorandum claims the model of aeronautical feedback.

The mechanism would protect the person making the report. It could not be used to establish their liability or to justify a sanction, except in cases of deliberate breach, gross negligence or intent to conceal. This protection concerns the use of the report; it does not constitute a general immunity for the facts reported.

Article 13 would introduce a maximum period of seven calendar days to erase personal data acquired during the operation of a system, subject to legal retention obligations. Data already incorporated into a model during its training would be excluded when their erasure is technically impossible. The provider or deployer would nevertheless have to stop reusing them for training and take reasonable measures to prevent their retrieval.

Articles 12 and 14 would also provide for machine-readable marking of synthetic content and periodic reminders of the artificial nature of the interaction when the realism of the system may create confusion. Article 4 would prohibit systems whose purpose is to simulate an emotional relationship, to substitute for social relationships or to foster emotional dependence.

HR decisions subject to documented human review

Article 11 would directly regulate professional uses. The employer could use AI to prepare decisions or facilitate their material execution, but would remain responsible for their obligations and the decisions taken. They could not delegate to it the powers conferred on them by the Labour Code, collective agreements, the contract or internal regulations.

A decision producing legal effects on an employee or candidate, or significantly affecting them, could not be based solely on the outputs of an AI system. The text cites recruitment, remuneration, professional evaluation and termination of contract. A natural person with the necessary skills and means would have to examine the individual situation, and the employer would have to keep a record of this examination, including if the system is used by a service provider.

The person concerned would have to be informed before the decision of the use of AI and of the main parameters used. A decision taken in violation of these rules would be null and void; in the event of a dispute, the employer would have to demonstrate that they complied with the human review requirement. The mechanism would thus require documenting how an algorithmic recommendation is involved in an HR decision.

French oversight still being organised

The creation of the ANIA would add to a French oversight organisation still being formalised. The list published by the European Commission, updated on 7 September and consulted on 25 September, designates the DGCCRF (France's Directorate-General for Competition, Consumer Affairs and Fraud Control) as the French contact point, with an asterisk indicating that the national designation decision is awaiting final adoption.

The path chosen by the government to apply the AI Act is another text, which would assign part of the oversight competences to the CNIL: the bill adapting to European Union law, adopted by the Senate on 18 February 2026, then transmitted to the National Assembly on 20 February. As of 25 September, its legislative dossier shows no vote in the National Assembly. Proposal no. 3149 proposes an additional authority, and a regime that this bill does not provide for.

Our articles will then appear first in Google Top Stories.