France Made Algorithmic Video Surveillance a Time-Limited Legal Experiment
France did not authorise a general facial-recognition system for the Paris Olympics. It created a bounded experiment in real-time event detection—and then extended that legal laboratory after the Games.
Article 10 of Law 2023-380, published on 20 May 2023, authorised algorithmic analysis of images from approved video-protection systems and aerial cameras for certain large sporting, recreational and cultural events. The purpose was to detect predefined events that might indicate terrorism or serious threats to personal safety and alert a human operator.
The original experiment ran to 31 March 2025. Law 2026-201 has since extended it to 31 December 2027 and added further governance provisions. That later history matters: what began as an Olympic exception became a longer test of how France regulates public-space computer vision.
Detection was separated from identification
The framework prohibits biometric identification and facial recognition. The algorithm is meant to identify events or patterns, not establish who a person is. The implementing decree listed events such as abandoned objects, weapons, movement against the expected direction, entry into sensitive areas, crowd movement and fires.
That boundary is technically meaningful but not sufficient on its own. A system can affect people without naming them. False alerts can direct police attention toward individuals or groups; training data can perform unevenly across environments; and a system optimised for one camera position may fail when deployed elsewhere.
The law therefore requires human control, risk management and safeguards against bias and misuse. An alert is an aid to operational decision-making, not an automated enforcement decision.
The legal object is the complete deployment
Compliance cannot be assessed from a vendor’s model card alone. The relevant system includes camera coverage, image quality, event definitions, thresholds, operator interface, retention, access, training and the operational response to an alert.
Each authorised use must be linked to a qualifying event and locations exposed to particular risks. Public information is required, subject to limited exceptions. Only authorised and trained agents may access alerts. The decree also controls the design phase and the circumstances in which real images can be used to improve detection.
For procurement teams, that means accuracy claims need context. A false-positive rate measured in a curated test set does not reveal how many alerts a busy transport hub will generate in an hour. Suppliers should provide results by scenario, environmental condition and deployment setting, while operators should measure whether alerts were useful and what action followed.
An experiment needs an exit and an evidence plan
Calling a system experimental should impose discipline. Before deployment, authorities need a hypothesis: which events should be detected, what benefit is expected, what error is tolerable and what less intrusive alternative exists? During use, they need data that can answer those questions.
A proper evaluation record should include:
- the number and type of algorithmic alerts;
- confirmed events, false alerts and missed events where measurable;
- operator workload and response times;
- performance differences between locations and conditions;
- complaints, security incidents and rights impacts; and
- changes made to models, thresholds or procedures.
The 2023 law required an evaluation mechanism. The 2026 extension strengthened that logic by providing for an independently chaired evaluation committee and participation by qualified independent figures. The extension should not be mistaken for a finding that the technology has already proved itself; it prolongs the period in which evidence must be gathered.
The lesson travels beyond policing
Organisations deploying video analytics in shops, factories, stadiums or transport cannot simply copy the Olympic legal basis. Their purposes, powers and applicable rules differ. But the French structure exposes questions every deployment should answer.
What event is the model detecting? What happens to a person after an alert? Can a human genuinely reject it? How is drift detected? Are people informed? Does the supplier retain footage? Can the customer reconstruct the reason for an operational response?
Those questions belong in the design and contract, not only in a privacy notice. Technical teams should keep model versions and threshold changes linked to the relevant impact assessment. Security teams should protect both video streams and alert data. Operational owners should test whether staff treat an alert as a prompt for verification rather than proof.
France’s experiment is important because it treats public-space AI as an institution, not an app. Authority, purpose, model behaviour, human action and evaluation all form part of the regulated system. That is a more demanding—and more honest—way to govern automated observation.
Official sources
- Légifrance: Article 10 of Law 2023-380, current consolidated version
- Légifrance: Law 2026-201 extending the experiment
- CNIL: Algorithmic or “augmented” cameras in public space
Continue the series
- Next in France: France’s SREN Law Regulates Cloud Lock-In
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



