From the journal

CNIL publishes new AI guidelines and action plan for GDPR compliance

The CNIL has released new guidelines and an action plan for organizations developing AI systems, emphasizing GDPR compliance and privacy protection.

1 min read

The CNIL published new content on artificial intelligence on an unspecified date. The document outlines key principles and initial recommendations for organizations involved in AI development to ensure compliance with the General Data Protection Regulation (GDPR).

The CNIL's action plan aims to deploy AI systems that prioritize individuals' privacy. This plan aligns with the EU-U.S. Terminology and Taxonomy for AI, which identifies 65 terms to harmonize risk-based approaches between the two regions.

The guidelines apply to organizations developing AI systems, emphasizing the need to respect individuals' privacy rights and comply with GDPR.

The material does not specify a deadline for compliance or implementation of the recommendations.

Source: CNIL, official publication, retrieved 2026-08-12

AI Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.