NACH
·Tarek Nachnouchi

The CNIL has already issued over 50 million euros in fines in 2026: what it signals for AI

Free fined 42 million euros, France Travail fined 5 million: the CNIL showed in Q1 2026 that it enforces for real. Its new AI powers change the picture.

More than 50 million euros in fines had already been issued by the CNIL over the first quarter of 2026, with particular attention paid to personal data processing, subcontracting, and data transfers. Two sanctions stood out especially this year, Free, fined 42 million euros, and France Travail, fined 5 million euros, both for specific security failures, missing multi-factor authentication and overly broad access rights to sensitive databases.

These amounts concern large organizations, and an SMB might reasonably feel far removed from this level of risk. That would be an incomplete reading of the situation. The failures sanctioned, missing strong authentication, poorly controlled access rights, are not mistakes specific to large organizations, they are configuration oversights found just as often in much smaller structures, simply with less media visibility when caught.

What changes the picture for 2026 and beyond is the CNIL's new role. It has been designated the reference authority for enforcing the AI Act in France, cementing its status as a central player in digital regulation and granting it expanded oversight powers over artificial intelligence. These new powers push the ceiling for possible sanctions to 35 million euros or 7% of global turnover, a level that in theory applies to any company, with no size threshold.

The CNIL's 2025-2028 strategic plan sets four priority areas, artificial intelligence, protecting minors, cybersecurity, and everyday digital uses. For 2026, the focus specifically targets auditing AI systems and multi-factor authentication for access to sensitive databases, exactly the two failures that cost Free and France Travail a combined 47 million euros. Artificial intelligence and data scraping now rank among the regulator's new priority enforcement areas.

This context concretely changes the nature of the risk for an SMB using AI tools with no documented framework. No past inspection guarantees anything for the future, especially in an environment where the regulator has explicitly made AI a priority and demonstrated, within the first quarter alone, its willingness to impose heavy sanctions for failures found. An SMB connecting an AI tool to its customer data or HR files, without checking who can access it and under what authentication level, exposes itself to the same kind of failure sanctioned at Free and France Travail.

Two simple checks, drawn directly from these sanctions, let an SMB reduce its exposure without mobilizing a substantial compliance budget. The first is enabling multi-factor authentication on any access to a database holding sensitive information, customer, HR, financial. The second is limiting access rights to only those who genuinely need it for their role, rather than granting broad access for management convenience.

This is what the Framing step of the IMPACT method should now explicitly incorporate, a review of access rights and authentication for every AI tool connected to sensitive data, drawing directly on the failures sanctioned by the CNIL as a concrete checklist rather than a generic theoretical one. A five-business-day diagnostic checks your access rights and authentication before any audit.

Let's take action

Ready to structure your AI transformation?

Free 30-minute diagnostic to identify your top priorities and estimate concrete ROI for your organization.

Book my free diagnostic →

Related articles