No company needs to develop its own artificial intelligence to fall under the scope of the European AI Act. Simply using a tool that integrates AI is enough to trigger real obligations, even for an SME that has never heard of AI compliance.
A safety plateau that AI promises to overcome
In 2024, France recorded 549,614 workplace accidents resulting in time off, including 764 fatalities, according to the annual report on occupational risks from the French National Health Insurance Fund (Assurance Maladie). This figure has stagnated for several years despite traditional prevention tools such as safety briefings, signage, and quarterly audits. Many QHSE departments are now turning to artificial intelligence to break through this plateau by cross-referencing volumes of data that the human eye cannot process at the same scale. However, this adoption comes with a precise legal framework that must be understood before deploying any tool.
Using an AI tool is enough to make you subject to the regulations
Regulation (EU) 2024/1689, which entered into force on August 1, 2024, distinguishes between several roles in the AI value chain. The provider develops a system and places it on the market. The deployer uses it within the scope of a professional activity, according to Leto, a law firm specializing in digital law. Most French companies fall into this second category as soon as they use an AI-based recruitment tool, a customer chatbot, or a predictive analysis system applied to workplace safety.
An existing requirement that is often overlooked
One point deserves to be highlighted above all else. The requirement for AI literacy set out in Article 4 of the regulation has been in effect since February 2, 2025, not 2026. This article requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff, without imposing a specific format or minimum training duration, according to an analysis byOttho. A company whose teams use AI tools without training on the associated risks may therefore already be in breach, well before the deadline most commonly cited.
What changed on August 2, 2026
August 2, 2026, marked the full entry into force of the obligations concerning high-risk AI systems, following a transition period, according to Quillet Digital. A manager who integrates an AI-based HR management tool, or who deploys a predictive analysis system to anticipate workplace accidents, bears a responsibility from this date that they cannot entirely delegate to their technology provider. AI systems used in the context of employment and worker management, including for health and safety, fall into the high-risk category of the regulation.
Your concrete obligations as a deployer
A deployer's obligations remain lighter than those of a provider, but they are very real :
- Use the system in accordance with the instructions provided by the supplier
- Ensure human oversight for decisions that affect individuals, a principle often summarized as: AI proposes, humans dispose
- Maintain usage logs when a high-risk system is deployed
- Inform the individuals concerned when they are interacting with an automated system, pursuant to Article 50
- Conduct a fundamental rights impact assessment before deploying any high-risk system
A chatbot deployed on a website must explicitly inform the user that they are interacting with an automated system from the very beginning of the conversation, notes Malibellule. Company size does not grant any general exemption from this transparency obligation.
The risk of shadow AI
AI usage that goes unrecorded within a company, often referred to as shadow AI, represents the most underestimated exposure for French SMEs, according to Maison Graciet. A generic tool used freely by marketing teams, a copilot integrated into business software without formal validation, or a voice assistant tested without oversight often escape any inventory, even though compliance requires knowing precisely which AI systems are actually in use.
Data already sensitive under GDPR
A specific point regarding QHSE services deserves to be highlighted. The data processed (health records, accidents, work stoppages, and disabilities) considered sensitive data under Article 9 of the GDPR. Any use of an AI system on this type of data requires heightened vigilance : employee consent is almost never the appropriate legal basis due to the subordination inherent in the employer-employee relationship, and a data protection impact assessment becomes systematically necessary before any automated processing.
We detail all these issues, including the appropriate legal bases, anonymization and pseudonymization methods, and the connection to the AI Act, in our white paper on AI and workplace safety, which explores the tension between predictive performance and the ethical imperatives inherent to this subject.
Structuring your compliance with a regulatory monitoring tool
Identifying the AI tools actually used within the organization, tracking regulatory deadlines, and documenting human oversight measures represents a new burden for QHSE departments already stretched by other obligations. The Symaveille regulatory monitoring module tracks normative developments applicable to your business and alerts you as soon as a text impacts your obligations ; a principle directly applicable to monitoring the AI Act.



