Qualify the system and its level of risk.
Usage, role of the organisation, prohibitions, transparency, high risk, supervision and monitoring.Use not classified as “high risk” may nevertheless raise other issues.
Workplace AI law · AI Act · GDPR · CSE · DUERP
Deploying artificial intelligence in an organisation is not a matter of a single text. Depending on the use, the data processed and the effects of the system on employees, several frameworks can be combined: AI Act, GDPR, Labour Code, social dialogue and prevention of occupational risks.
Governing AI based on what it really changes. The starting point is not the name of the tool. The obligations depend on the transformed task, the people involved, the data used and the possible consequences of the system’s output.
Direct answer
In France, the deployment of artificial intelligence at work does not fall within a single framework. The employer must examine the use with regard to the European regulation on artificial intelligence (AI Act), the General Data Protection Regulation (GDPR), the Labour Code and its obligation to prevent occupational risks. Depending on the system and its effects, this may in particular involve information or consultation of the Social and Economic Committee (CSE), a data protection impact analysis (DPIA), an update of the Single Occupational Risk Assessment Document (DUERP), human supervision and documented monitoring. Compliance with one framework does not constitute compliance with others.
Use not classified as “high risk” may nevertheless raise other issues.
The DPIA depends on the characteristics of the processing and the level of risk.
Information or consultation of the CSE depends on the context and the effects.
The DUERP is updated in the situations provided for by the applicable framework.
To remember. The obligations do not depend on the brand of the software, but on the function performed by the system, the data processed and its actual influence on the work or decisions.
01 / Determine the applicable rules
Write, summarize, recommend, classify, recruit, assign a task, monitor or contribute to a decision.
Candidates, employees, managers, professionals or users — directly or via a score, an alert or a recommendation.
Nature of the data, purpose, location, recipients, retention period, reuse and subcontractors.
Simple reviewable draft, order of priority, score, control of activity or result likely to produce a significant effect.
Skill, time and authority to control, challenge, correct, suspend use and return to a fallback.
02 / Examine the frameworks
A single project may fall under several sets of rules. Examining them separately allows you to identify the obligations, those responsible and the relevant official sources.
An AI at work project can simultaneously fall under the AI Act, the GDPR, the Labour Code and the obligation to prevent occupational risks.
First prohibited practices and first applicable AI literacy provisions.
General application of the AI Act, transparency obligations of Article 50 and supervisory powers, subject to specific deadlines.
Application of the rules relating to high-risk systems in Annex III, including certain uses linked to the employment and management of workers.
Application of the rules relating to high-risk systems integrated into regulated products in Annex I.
The AI Omnibus entered into force on July 27, 2026. The obligations already applicable should not be confused with the delayed schedule of high-risk systems. The qualification of a project remains to be verified in the consolidated text and with regard to its precise use.
Regulation (EU) 2024/1689, modified by the AI Omnibus, distinguishes in particular prohibited practices, transparency obligations and high-risk AI systems.
A system which is not classified "high risk" may nevertheless fall under the GDPR, the Labour Code and the obligation of prevention.
The General Data Protection Regulation (GDPR) applies when the processing of personal data falls within its scope.
The need for a data protection impact assessment (DPIA) depends on the risks of the processing; using AI does not automatically require one.
The Social and Economic Committee (CSE) must be able to understand the possible consequences of the project on employment, organisation, working conditions, recruitment or control of activity.
The answer depends in particular on the workforce, the nature of the system, the importance of the project and its effects. The information must be transmitted early enough so that the dialogue can still influence the project.
The Single Occupational Risk Assessment Document (DUERP) records the results of the employer’s risk assessment.
The analysis must focus on the work actually organized, including cognitive load, value conflicts, social relationships and psychological safety. The DUERP is updated in the situations provided for by the applicable framework.
Evaluate the effects of an AI project on work and psychosocial risks.
Compliance with the GDPR does not constitute compliance with the AI Act; the application of the AI Act does not exempt either from social dialogue or from the obligation to prevent occupational risks.
03 / Read by use case
Yes. A writing assistant, a recruiting tool, and a performance monitoring system do not raise the same questions.
The obligations do not depend on the brand of the software but on the function performed by the system. The matrix guides the analysis without replacing the qualification of the project.
| Intended use | Questions to consider first | Effects on the work to be documented | First deliverable |
|---|---|---|---|
|
01Research, synthesis and rewriting General support |
Confidentiality, data submitted, source reliability and transparency. | Check time, plausible errors, productivity expectations and fallback solution. | Usage note, input rules and human verification protocol. |
|
02Recruitment, pre-selection and mobility Employment · sensitive use |
AI Act, bias, non-discrimination, data, the actual human role and informing candidates. | Invisible criteria, review workload, ability to challenge and liability. | AI Act qualification, data mapping, impact analysis and social-dialogue dossier. |
|
03Task planning and allocation Work management |
Influence on access to tasks, schedules, evaluation and decisions. | Autonomy, intensification, fairness, workarounds and decision margins. | Before/after mapping, challenge procedures and pilot protocol. |
|
04Activity and performance monitoring Surveillance |
Purpose, necessity, proportionality, prior information, access and consequences. | Feeling of surveillance, unrealistic goals, behaviours and psychosocial risks. | Proportionality test, DPIA if necessary, social dialogue and prevention. |
|
05Health, medical fitness or medical data Specialized analysis |
Health data, professional secrecy, security, separation of roles and sectoral framework. | Clinical liability, trust, errors, time pressure and continuity. | Legal, clinical, technical and organisational analysis before any pilot. |
Limit. Certain uses related to employment and worker management are among the sensitive areas of the AI Act, but the qualification depends on the precise function of the system and the applicable rules and exceptions.
04 / Distribute responsibilities
Management, HR, the CSE, the DPO, prevention teams, professional groups, purchasing and security each contribute different evidence to the same decision file.
This pathway indicates a starting point. Stakeholders then compare their analyses before a decision is made.
Describe the problem, the alternatives, the expected result and the person who will make the decision to launch, modify or stop the pilot.
Identify the displaced tasks, the criteria likely to influence an HR decision and the skills necessary to verify or challenge.
Examine the need, the alternatives, the people concerned, the power of the system, the data, the objectives and the follow-up of the pilot.
Map the data, qualify the role of the organisation, check rights and determine what impact analyses are necessary.
Examine load, autonomy, conflicts of values, surveillance, skills and collectives, then propose prevention measures.
Check the intended uses, limits, data, subcontracting, incident management and the real possibility of leaving the solution.
05 / Decide
Useful governance designates responsibilities, disagreements, avenues of appeal and the authority capable of suspending use.
06 / Social dialogue
The timing and content of the dialogue depend on the applicable framework. A supplier demonstration is not enough to describe future work.
When the project enters a case of information or consultation, the CSE must receive sufficiently precise elements and early enough to understand the effects and formulate a useful opinion.
Legal reference. The exact obligations depend in particular on the workforce, the nature of the project, its importance and its effects. See also article L. 2312-38 of the Labour Code on recruitment methods, automated personnel management and activity control.
07 / Prepare a pilot
These eight documents make the project open to discussion, traceable and reversible. Checking them does not constitute certification or evidence of compliance.
08 / Quick Answers
An artificial intelligence project at work may simultaneously fall under the European regulation on artificial intelligence, the GDPR, the Labour Code and the obligation to prevent occupational risks. The applicable rules depend on the actual use, the data processed, the people concerned and the effects of the system.
This depends in particular on the workforce, the nature of the project and its consequences on employment, organisation, working conditions or control of the activity. When the applicable framework provides for information or consultation of the CSE, this must take place early enough so that the opinion can still influence the project.
Certain uses linked to employment and management of workers appear in Annex III of the AI Act. Qualification depends on the precise function of the system as well as the conditions and exceptions of the regulation. After the AI Omnibus, the corresponding rules apply from December 2, 2027; this does not suspend other obligations already applicable, in particular in terms of data, social dialogue and prevention.
The GDPR applies when the processing of personal data falls within its scope. The use of AI does not deviate from any of the usual obligations relating to the purpose, legal basis, minimisation, security, information and rights of individuals.
Risk assessment must take into account work transformations likely to affect health or security. The DUERP must be updated in the situations provided for by the applicable framework; the mere presence of an AI therefore does not automatically trigger an update.
These uses are particularly sensitive and may simultaneously fall under the AI Act, the GDPR, labour law, non-discrimination, social dialogue and prevention. They require precise qualification, effective human supervision and avenues for challenge.
Using a system does not automatically transfer responsibility to the provider or model. The organisation must define the roles, human validation, avenues for contestation, termination conditions and the person who makes the final decision.
09 / Sources and updates
AI law is evolving. The links below allow you to compare each qualification with the text in force and the precise context of the organisation.