Six in ten French companies still have no formal framework for their use of artificial intelligence. The figure comes from the third edition of the Data & AI Barometer that Coface published on 5 October 2026, conducted with Les Echos Etudes among 900 decision-makers. Only 17% of the companies surveyed have defined, formalised and communicated an AI usage policy to their employees.

The study comes two months after 2 August 2026, the date from which national market surveillance authorities supervise the "AI literacy" obligation set out in Article 4 of the AI Act. That article was rewritten this summer by omnibus Regulation 2026/1744. It still requires companies that deploy AI tools to take measures to develop the AI literacy of their staff, and a written usage policy is the first way to keep a record of those measures.

A self-reported barometer, published by a credit insurer

Coface is a credit insurer that also sells business information services. The barometer's presentation page links to its Urba360 tool. The results are based on statements by decision-makers: companies "report" whether or not they are advanced, with no external measurement of their actual use.

As of 6 October 2026, the page published by Coface does not specify the fieldwork period or the breakdown of respondents by sector or size. The full study can only be downloaded after filling in a form (first name, last name, email address, company, country). The figures below are those from the public page.

35% of companies have no framework and no plans for one

The governance section distinguishes several situations. 35% of companies have no oversight framework and do not plan to set one up. A further quarter are considering the issue without having formalised any rules. Coface adds the two groups together to reach 60% of companies without a formal framework.

Indicator (Data & AI Barometer 2026)Share
No framework, no plans35%
Under consideration, no formal rulesa quarter
Total without a formal framework60%
Policy defined, formalised and communicated to employees17%
No structured use of AI28%
Little or no progress in using AI to manage risk56%
Advanced or very advanced in that same use17%
Data considered reliable and relevant67% (49% in 2025)

The table contains two 17% figures that do not measure the same thing. The first concerns governance (a written policy that has been circulated). The second relates to the maturity of use: the share of companies that say they are advanced in using AI to manage risk. The introduction of the page phrases it as the use of AI "for decision-making". Between the 60% without a framework and the 17% with a communicated policy, the public page does not describe the situation of the remaining companies.

The obstacles cited overlap with the governance issue: data security and regulatory compliance (41%), lack of internal maturity (31%), and trust in AI-generated analyses (30%).

Large companies: nearly three times as likely to say they are advanced

The barometer notes a gap by size. Companies with revenue above 100 million euros are "nearly three times as likely" to report being advanced in their use of AI as those with revenue below 10 million euros. The page does not give the percentages for each bracket.

The gap is consistent with other measurements of smaller businesses, such as the survey reported by ActuIA on 1 October finding that 40% of French very small businesses and SMEs use AI, but only 19% pay for it. The two studies have neither the same population nor the same methodology and cannot be added together.

Article 4 of the AI Act: the obligation rewritten by Regulation 2026/1744

In its 2024 version, Article 4 of Regulation (EU) 2024/1689 applied to providers and deployers. It required them to take measures "to ensure, to their best extent, a sufficient level of AI literacy" of their staff. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from the third day thereafter, i.e. 27 July, replaces that wording. Companies must now "take measures to foster the development of AI literacy" of their staff and of the persons who use the systems on their behalf. The new text adds that the obligation "does not require" them to ensure "a specific level of AI literacy of an individual".

Recital 8 of Regulation 2026/1744 justifies the change by the "additional compliance burden, in particular for small companies". The obligation itself remains. The criteria are those of the original text: the technical knowledge, experience, education and training of the persons concerned, the context in which the systems are used, and the persons on whom the systems are to be used.

Article 4 has applied since 2 February 2025, together with the rest of Chapter I of the regulation (Article 113). The European Commission's AI literacy questions and answers, updated on 27 July 2026, states that its supervision falls to national market surveillance authorities, which exercise it from 2 August 2026. The regulation sets no fine ceiling specific to Article 4: the amounts provided for in Article 99 apply to other obligations. Article 99(1) was also rewritten by Regulation 2026/1744. Under it, Member States lay down the rules on penalties and other enforcement measures applicable to infringements of the regulation. These may include "administrative fines, warnings and non-monetary measures". When imposing penalties, Member States take into account the interests of SMEs and small mid-cap companies.

The same FAQ states that no certificate is required and that organisations may keep an internal record of training. A company whose employees draft or translate texts with ChatGPT is covered: its teams must be informed of the risks specific to the tool, such as hallucinations. The obligations for high-risk systems follow a different timetable, detailed in ActuIA's article on the postponement of high-risk obligations to December 2027 and in ActuIA's status update ahead of 2 August 2026.

A minimum usage policy in five sections

The regulation does not impose any policy template, and the Commission's FAQ states that no particular governance structure is required to comply with Article 4. The grid below is the editorial team's own reading, built from the minimum steps listed by the Commission and the obstacles cited in the barometer. These steps cover a general understanding of AI, the company's role as provider or deployer, the risks of the systems used, and the level and context of the staff.

  • Scope: list of authorised tools, the business accounts to be used and the permitted uses by job function.
  • Prohibited data: personal data of customers or employees, information covered by trade secrets, confidential documents. This is the direct answer to the first obstacle cited (41%).
  • Human validation: mandatory review of any AI output before it is sent to a customer, published or used for a decision.
  • Traceability: a register of deployed tools and completed training, which serves as evidence of the "measures" taken under Article 4.
  • Training: content adapted to each person's role and level, as the text provides.

Deploying AI tools that change working conditions also raises the question of informing and consulting employee representatives. For high-risk systems used in the workplace, Article 26 of the AI Act provides that workers' representatives and the affected workers must be informed. This obligation will apply to Annex III systems from 2 December 2027. The case of RATP, the Paris public transport operator, detailed in ActuIA's article on the consultation of the works council (CSE), shows how the issue can arise in France.

More reliable data, lagging governance

The barometer sets two trajectories side by side. Confidence in data has risen by 18 points in a year, to 67%, and two thirds of decision-makers consider it up to date enough for their risk management. Yet only 58% consider this data well integrated into their business tools, and 51% consider it harmonised across departments or subsidiaries. According to Nesrin Gonin, Director of Information Services for Western Europe and Africa at Coface, companies "have not yet created the framework needed to fully exploit the potential of AI".

In the editorial team's view, this gap has a practical consequence. The governance lag identified by Coface is also a documentation lag: a company with no written policy and no training register will struggle to show a supervisory authority what measures it has taken. The issue is neither unique to France nor new in 2026, since Capgemini already counted governance among the challenges of generative AI adoption in 2025.

The revised Article 4 also tasks the Commission with publishing practical examples of compliance on its single information platform, and the European AI Board with adopting recommendations setting common objectives. The regulation sets them no deadline.