Law & governance · From use to decision

Govern AI through what it actually changes.

Describe the use, identify applicable rules, involve the right people, and decide on a documented, reversible and monitored pilot.

The starting point is not the tool’s name. Duties depend on the task being changed, the people concerned, the data used and the possible consequences of a system output.

Dated official sourcesFour distinct frameworksNo automatic green light
What holds the whole together
Thomas Cole’s The Architect’s Dream, a vast landscape bringing together several monumental architectural styles
Thomas Cole
The Architect’s Dream · 1840

These architectures seem to form a stable whole, yet their equilibrium depends on how each part fits with the others. The work reminds us that governance holds only through clear responsibilities, effective routes for challenge and sustained attention to the system’s real effects. View the artwork ↗

1 useContext-specific qualificationThe same technology may fall under different rules depending on the task and its effects.
4Frameworks to examineThe AI Act, GDPR, labour law and prevention duties may all apply.
5Decision gatesFrom a demonstrated need to real-world monitoring, with the ability to stop.
0Universal approvalNo single document is sufficient to authorise every use of a system.

01 / Qualify the use

Describe the system’s practical power before looking for the rule.

Qualification starts neither from the provider’s brand nor from the word “assistance”. It starts from the activity, the data and the actual reach of the output.

01

Which task is being changed?

Write, summarise, recommend, classify, recruit, assign a task, monitor or contribute to a decision.

02

Who is concerned?

Applicants, workers, professionals, patients or service users — and the data used to describe or evaluate them.

03

What reach does the output have?

A revisable draft, priority order, score, activity monitoring or a decision producing a significant effect.

04

How can human control be recovered?

The reviewer’s competence and authority, ability to challenge, fallback solution and suspension conditions.

02 / Identify the frameworks

Four sets of rules answering different questions.

Examining them separately avoids two errors: believing a system that is “not high-risk” presents no issue, or asking the DPO alone to decide the whole project.

01
Progressive application

EU Artificial Intelligence Act

Qualify the system, use, organisation’s role and corresponding duties.

Starting questionIs the use prohibited, subject to a transparency duty or classified as high-risk?

For a high-risk system used at work, the deployer must in particular organise competent human oversight, monitor operation and inform worker representatives and affected workers.

Explore the official text ↗
02
In force

GDPR & CNIL

Define the purpose, lawful basis, necessary data, retention period and people’s rights.

Starting questionWhich personal data enters or leaves the system, or is used to make a decision?

In particular, examine whether a DPIA is required and the safeguards around a decision based solely on automated processing that produces legal or similarly significant effects.

CNIL DPIA method ↗
03
In force

Labour Code & works council

Make consequences for employment, organisation, working conditions and activity monitoring visible.

Starting questionDoes the project change work enough to require information or consultation before the decision?

The file must arrive early enough and contain sufficiently precise information for the opinion to still influence the project.

Article L. 2312-8 ↗
04
In force

Prevention & occupational risk assessment

Assess the effects of change on physical and mental health in the work as it will actually be organised.

Starting questionDoes the project change workload, autonomy, monitoring, responsibilities, skills or work collectives?

The assessment must lead to prevention measures and be reviewed when the project or conditions of use change.

Article L. 4121-3 ↗
Remember

GDPR compliance does not establish AI Act compliance; applying the AI Act removes neither social dialogue nor the duty to prevent occupational risks.

03 / Read by use case

The first useful document depends on what the system does.

This matrix guides analysis. It replaces neither precise project qualification nor legal advice tailored to the situation.

Intended useQuestions to examine firstEffects on work to documentFirst deliverable
01Monitoring, synthesis, rephrasing
General assistance
Confidentiality, data sent to the provider, source reliability and transparency towards recipients.Review time, new plausible errors, productivity expectations and maintaining the ability to work without the tool.Use note, input rules and human review protocol.
02Recruitment, screening, mobility
Employment · potentially high-risk
Scope of Annex III, any exception, bias, personal data, the actual role of human intervention and information for applicants.Hidden criteria, review workload, ability to challenge and responsibility for the decision.AI Act qualification, data mapping, impact assessment and social dialogue file.
03Scheduling and task allocation
Work management
The system’s influence on access to tasks, schedules, assessment and decisions concerning workers.Autonomy, intensification, fairness of allocation, workarounds and management discretion.Before-and-after work mapping, challenge rules and pilot protocol.
04Activity and performance monitoring
Monitoring
Purpose, necessity, proportionality, prior information, data access and consequences of the score or alert.Sense of surveillance, behavioural changes, unrealistic targets, relationships with management and psychosocial risks.Necessity and proportionality test, DPIA where required, consultation and prevention measures.
05Health, fitness for work or medical data
Specialised analysis
Health data, professional secrecy, possible qualification as a medical device, separation of roles and security.Clinical responsibility, trust, hard-to-detect errors, time pressure and recovery capacity during unavailability.Legal, clinical, technical and organisational analysis before any pilot.

Why “potentially high-risk”? Employment and worker-management uses are among the sensitive areas in the AI Act, but qualification depends on the system’s precise functions and the Regulation’s exceptions. The provider cannot decide this question alone for the deploying organisation.

04 / Start from your role

One project, different responsibilities.

Choose your role to display the first work to undertake. The aim is not to split the law into silos, but to know who contributes which part of the file.

This pathway indicates a starting point, not an exhaustive list of duties. Stakeholders must compare their analyses before the decision.

Decision and responsibility

Start from the work need, not from a tool already selected.

Describe the problem to solve, alternatives considered, expected outcome and the person accountable for launching, modifying or stopping the pilot.

05 / Organise the decision

Governance that also names who can say no.

Each stakeholder examines one part of the project. The final decision must make trade-offs, disagreements, continuation conditions and the authority able to suspend use visible.

Project leadershipDescribes the need and scope, and owns the decision.
Legal counsel & DPOQualify the frameworks, processing and rights.
CSEExamines consequences for employment and work.
OHS service & preventionProvide insight into effects on activity and health.
Professionals & managementTest actual use, errors and workarounds.
Procurement & securityDocument the provider, access and reversibility.

06 / Prepare social dialogue

A file that genuinely supports understanding and discussion of the project.

A commercial demonstration describes neither the new work organisation nor the constraints that arise when the tool is used in imperfect situations.

Before the decision

Make the project open to influence.

  • need, uses and alternatives examined
  • population and tasks concerned
  • provider documentation and data used
  • expected organisational change
During the pilot

Document trade-offs.

  • human intervention and appeal rules
  • review workload and production targets
  • incidents, errors and workarounds
  • conditions for immediate suspension
After the pilot

Return with evidence.

  • gaps between planned and actual work
  • effects on health, autonomy and skills
  • corrections actually implemented
  • reasoned decision to continue, modify or stop

07 / Assemble the file

Eight concrete documents before authorising a pilot.

The list below helps identify what is missing. Completing it is neither certification nor proof of compliance.

08 / Verify sources

Official, dated texts linked to the question they inform.

AI law changes rapidly. Links lead to official texts and methods so the framework can be checked at the time of decision.

01
European CommissionRegulatory framework and official AI Act timeline.
Open ↗
02
EUR-LexRegulation (EU) 2024/1689 on artificial intelligence.
Read the text ↗
03
EUR-LexAI Omnibus entered into force on 27 July 2026.
Read the text ↗
04
CNILDetermine whether a data protection impact assessment is required.
Open ↗
05
Labour CodeArticle L. 2312-8 on works council responsibilities.
Legifrance ↗
06
Labour CodeArticle L. 2312-38 on recruitment methods, automated management and monitoring.
Legifrance ↗
07
Labour CodeArticle L. 4121-3 on occupational risk assessment.
Legifrance ↗

Independent monitoring

Follow the law without losing sight of real work.