CNIL's Q&A on the Use of Generative AI Systems

18 July 2024

Many organisations are considering deploying or using generative AI systems and are seeking guidance on the necessary measures to put in place. This Frequently Asked Questions (FAQ) offers initial answers to their queries.

Generative” artificial intelligence refers to the class of systems capable of creating content (text, computer code, images, music, audio, videos, etc.). These systems can be classified as general purpose AI systems when they can perform a whole range of tasks. This is especially true for systems based on large language models (LLMs). Designing these systems requires vast amounts of data from diverse sources (Internet, licensed third-party contents, conversations generated by human trainers, user interactions, synthetic data, etc.).

To learn more about the compliance requirements for developing these systems when they involve personal data, the CNIL provides recommendations on how to design them in compliance with the GDPR.

1. What are the benefits of generative AI?


2. What are the limitations and risks of generative AI systems?


3. What approaches are available today to use generative AI (off-the-shelf models, fine-tuning, RAG, etc.)?


4. How to choose your generative AI system?


5. Which deployment method should be preferred (on premise, API, cloud)?


6. How should a generative AI system be implemented and managed?


7. How can end-users of these systems be trained and made aware of the risks?


8. What governance should be implemented for these systems?


9. How to ensure that the use of a generative AI system complies with the GDPR?


10. How to ensure compliance of the use of a generative AI system with the European AI Act?