The CNIL has already issued over 50 million euros in fines in 2026: what it signals for AI
Free fined 42 million euros, France Travail fined 5 million: the CNIL showed in Q1 2026 that it enforces for real. Its new AI powers change the picture.
More than 50 million euros in fines had already been issued by the CNIL over the first quarter of 2026, with particular attention paid to personal data processing, subcontracting, and data transfers. Two sanctions stood out especially this year, Free, fined 42 million euros, and France Travail, fined 5 million euros, both for specific security failures, missing multi-factor authentication and overly broad access rights to sensitive databases.
These amounts concern large organizations, and an SMB might reasonably feel far removed from this level of risk. That would be an incomplete reading of the situation. The failures sanctioned, missing strong authentication, poorly controlled access rights, are not mistakes specific to large organizations, they are configuration oversights found just as often in much smaller structures, simply with less media visibility when caught.
What changes the picture for 2026 and beyond is the CNIL's new role. It has been designated the reference authority for enforcing the AI Act in France, cementing its status as a central player in digital regulation and granting it expanded oversight powers over artificial intelligence. These new powers push the ceiling for possible sanctions to 35 million euros or 7% of global turnover, a level that in theory applies to any company, with no size threshold.
The CNIL's 2025-2028 strategic plan sets four priority areas, artificial intelligence, protecting minors, cybersecurity, and everyday digital uses. For 2026, the focus specifically targets auditing AI systems and multi-factor authentication for access to sensitive databases, exactly the two failures that cost Free and France Travail a combined 47 million euros. Artificial intelligence and data scraping now rank among the regulator's new priority enforcement areas.
This context concretely changes the nature of the risk for an SMB using AI tools with no documented framework. No past inspection guarantees anything for the future, especially in an environment where the regulator has explicitly made AI a priority and demonstrated, within the first quarter alone, its willingness to impose heavy sanctions for failures found. An SMB connecting an AI tool to its customer data or HR files, without checking who can access it and under what authentication level, exposes itself to the same kind of failure sanctioned at Free and France Travail.
Two simple checks, drawn directly from these sanctions, let an SMB reduce its exposure without mobilizing a substantial compliance budget. The first is enabling multi-factor authentication on any access to a database holding sensitive information, customer, HR, financial. The second is limiting access rights to only those who genuinely need it for their role, rather than granting broad access for management convenience.
This is what the Framing step of the IMPACT method should now explicitly incorporate, a review of access rights and authentication for every AI tool connected to sensitive data, drawing directly on the failures sanctioned by the CNIL as a concrete checklist rather than a generic theoretical one. A five-business-day diagnostic checks your access rights and authentication before any audit.
Let's take action
Ready to structure your AI transformation?
Free 30-minute diagnostic to identify your top priorities and estimate concrete ROI for your organization.
Book my free diagnostic →Related articles

The Digital Omnibus is now in force: what actually changes for SMB AI governance
The Digital Omnibus officially entered into force in late July 2026. What was conditional is now settled, and a new prohibition appears. Here is what it means for French SMBs and mid-sized companies.

Are your AI vendor contracts compliant? What the DPA needs to cover
The absence of a data processing agreement with an AI publisher puts a company in immediate GDPR violation. A governance risk rarely checked, unlike the tool's usage itself.

The three real barriers to AI in SMBs, and they aren't the ones you think
Data misuse, lack of skills, difficulty finding a use case: Bpifrance Le Lab ranks the real barriers to AI adoption. Team resistance only comes after.