Contents
Join our newsletter
Cybersecurity tips, analyses and news delivered to your inbox every month! 
Learn more about our privacy policies.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
All articles
8
min
ISO 42001 and AI Governance

AI Compliance in the Workplace: Requirements, Frameworks, and Penalties

Generative and domain-specific artificial intelligence has spread throughout organizations at a pace that compliance functions are struggling to keep up with. Chatbots, scoring tools, and co-pilots integrated into office suites: uses are multiplying, often without formal approval, creating a “shadow AI” phenomenon that is difficult to map. At the same time, the regulatory framework is becoming increasingly complex (GDPR, the European AI Act, industry-specific standards), leaving CISOs, DPOs, and CIOs at small and medium-sized enterprises (SMEs) and mid-market companies uncertain about their actual level of enterprise AI compliance.

AI Compliance in the Workplace

Enterprise AI compliance refers to the set of legal and regulatory obligations that an organization must meet whenever it designs, deploys, or uses an artificial intelligence system, whether it is off-the-shelf or developed in-house. It encompasses both the protection of personal data processed by these systems and the management of risks specific to AI (bias, opacity, robustness). For an SME or mid-sized company, AI compliance is therefore not limited to the GDPR: it requires a comprehensive review of multiple regulations that apply simultaneously, depending on the nature of the system and the company’s industry.

What regulatory frameworks apply to the use of AI in business?

The AI Act: The European Framework

Regulation (EU) 2024/1689, known as the AI Act, is the central piece of legislation governing AI compliance at the European level. It adopts a risk-based approach and classifies AI systems into four categories: unacceptable (prohibited), high, limited, and minimal, with Article 6 specifically setting out the rules for classifying high-risk systems. High-risk systems—such as automated recruitment, credit scoring, and certain HR or healthcare applications—are subject to stricter requirements: risk management, technical documentation, human oversight, and registration in a European database.

Article 4 of the regulation also imposes an AI training requirement (“AI literacy”): providers and deployers must ensure that their staff and those responsible for using AI systems have a sufficient level of competence, taking into account their technical knowledge, experience, and the context of use. This is a directly enforceable requirement for all SMEs and mid-sized companies, regardless of their AI risk level. In the event of a violation, Article 99 provides for a graduated system of penalties,ranging up to 35 million euros or 7% of global revenue for prohibited practices, with intermediate thresholds at 15 million euros/3% and 7.5 million euros/1% depending on the nature of the violation. The implementation timeline is phased through 2027, but AI literacy requirements and prohibitions are already in effect. For more information on risk classification, roles, and obligations, see our article “Understanding the AI Act.”

The GDPR: The "Personal Data" Component Remains a Key Element

Whenever an AI system processes personal data—which is the case for virtually all business applications— the GDPR continues to apply in full. The CNIL reiterates that the collection and use of data via an AI system must comply with the regulation’s standard principles: legal basis, data minimization, transparency toward data subjects, and respect for their rights. It provides an assessment framework that allows organizations to evaluate the maturity of their AI systems with regard to the GDPR on their own.

Since 2024–2025, the CNIL has published a specific section dedicated to AI, with recommendations that outline how to determine the applicable legal framework, define the roles of stakeholders, conduct impact assessments, and incorporate data protection by design into the system. The CNIL has clarified that it may impose administrative fines of up to 20 million euros or 4% of global annual revenue in the event of a GDPR violation in an AI context.

ISO 42001: The Voluntary Standard That Provides a Framework for AI Governance

ISO/IEC 42001:2023 is the first international standard dedicated to an artificial intelligence management system (AIMS). It applies to any organization, regardless of size, that provides or uses AI-based products or services, and structures governance around a Plan-Do-Check-Act (PDCA) cycle covering risk assessment, data quality, explainability, and human oversight. Unlike the AI Act, it is voluntary, but it provides a solid foundation for anticipating regulatory requirements: European authorities are, in fact, using this standard as a basis for developing future harmonized standards applicable to high-risk systems.

For an SME or mid-sized company deploying AI on a large scale, seeking guidance toward ISO 42001 certification allows you to demonstrate clear governance, build credibility with customers and partners, and seamlessly integrate with an existing ISO 27001 certification. Learn more about our ISO 42001 certification support services.

Sector-specific frameworks: HDS, DORA, NIS2

Certain sectors impose an additional layer of regulation. In the healthcare sector, any hosting of personal health data—including by a clinical AI or diagnostic assistance system—requires HDS certification, issued by a COFRAC-accredited body for a three-year period with an annual surveillance audit. This certification is based on the ISO/IEC 27001 standard, supplemented by additional requirements specific to health data, and the ANS (Agence du Numérique en Santé) publishes the reference documentation for the applicable PGSSI-S standard.

For financial institutions, the DORA regulation requires the securing of IT systems, regular resilience testing, and oversight of IT service providers, including those providing AI components. The NIS2 Directive, meanwhile, extends cybersecurity obligations to a much broader range of small and medium-sized enterprises (SMEs) and mid-sized companies operating in critical sectors, requiring them to report a cyberattack to ANSSI within 24 hours and subjecting them to fines of up to 10 million euros or 2% of revenue.

My company uses AI—am I compliant? Self-Assessment Guide

Map Your AI Usage

The first step is to create a comprehensive registry of the AI systems in use, whether they are developed in-house or integrated into third-party SaaS solutions. The CNIL now recommends that this registry include a specific “AI” section detailing the model, its version, the training data, and the legal basis for their use.

Determine Your IA Act Risk Level

Each system must be classified on the AI Act risk scale—minimal, limited, high, or unacceptable—based on the classification criteria set forth in Article 6 and Annex III of the regulation. This risk level determines the extent of the documentation and human oversight requirements that must be implemented.

Check Your AI-Specific GDPR Obligations

The goal is to verify that each data processing operation has a clear legal basis, that a Data Protection Impact Assessment (DPIA) has been conducted where necessary, and that data subjects can exercise their rights (right to information, right to object, right to an explanation of an automated decision).

Audit the governance of the data feeding your AI systems

The quality and traceability of training data are a key focus: the CNIL requires documentation of data collection and management procedures, security measures, and the results of bias tests.

How Can I Make My Business AI-Compliant? A 6-Step Roadmap

A structured approach makes it possible to gradually secure the company’s entire AI environment:

AI Compliance Roadmap: 6 Steps

  • Inventory and registry of AI systems, including detected instances of shadow AI.
  • Risk analysis combining the AI Act classification matrix and a GDPR-compliant data protection impact assessment (DPIA) for the processing of personal data.
  • Establishment of governance: AI committee, designated AI liaison, internal policy on AI use.
  • Technical documentation and transparency toward users and affected individuals.
  • Team formation, a requirement directly stipulated in Section 4 of the AI Act.
  • Ongoing monitoring and periodic audits of biases, security, and document compliance.

Would you like to develop this roadmap with expert guidance?

Get support with AI compliance →

Penalties: What Your Company Risks in the Event of Noncompliance

The financial risks are now substantial and cumulative. Under the AI Act, Article 99 provides for fines of up to 35 million euros or 7% of global revenue for prohibited practices, with thresholds of 15 million euros/3% and 7.5 million euros/1% for other violations, and specific caps in place for SMEs. Under the GDPR, the CNIL may impose fines of up to 20 million euros or 4% of global annual revenue, accompanied by orders to cease processing. In addition, depending on the sector, there are NIS2 penalties (up to 10 million euros or 2% of revenue) and the consequences of failing to obtain HDS certification for healthcare providers, which may result in a contractual prohibition on hosting sensitive data.

FAQ: Frequently Asked Questions from Businesses About AI Compliance

Are ChatGPT, Gemini, Claude, or Perplexity compliant with the GDPR when used in a business setting?
The use of tools such as ChatGPT, Gemini, Claude, or Perplexity is not prohibited in and of itself, but it must be accompanied by safeguards: an identified legal basis, no collection of sensitive personal data without proper oversight, and verification of the provider’s processing conditions. The CNIL recommends a case-by-case analysis based on the purpose and type of data transmitted.

Does the AI Act apply to all companies?
Yes, the regulation applies to any provider or deployer of an AI system on the European market, regardless of its size, but the scope of the obligations varies significantly depending on the risk level of the system in use. SMEs benefit from specific support measures provided for in the regulation, particularly through regulatory sandboxes.

Is ISO 42001 certification mandatory for businesses?
No, ISO 42001 certification remains voluntary. However, it is recognized by the European Commission and has already been adopted by companies such as Microsoft, AWS, and Anthropic: it serves as the benchmark standard for governing AI and effectively preparing for the AI Act.

How can I tell if my use of AI is “high-risk”?
You should refer to the list of use cases in Annex III of the AI Act, supplemented by the classification criteria in Article 6: uses related to hiring, employee evaluation, credit, or certain medical devices are among the most common high-risk categories in businesses.

What should I do if my employees are using AI tools “in the shadows” (unauthorized or unverified use)?
It is essential not to limit yourself to a blanket ban—which is often counterproductive—but rather to define a clear governance framework, secure data, train teams, and regularly audit detected usage. A study by Sharp Europe, which surveyed 2,500 SME executives in 10 European countries—including 250 in France—reveals that 35% of employees use AI tools without their management’s knowledge, and 34% of executives view unregulated AI use as a risk to their company.

Your ISO certification project deserves personalized support. Let’s take stock of the situation together.

Let's discuss your ISO project →
More content

Our latest Blog posts