Analysis

AI in healthcare: the HAS + CNIL guidance, decoded for your practice

The HAS's first usage keys, the joint HAS + CNIL draft guide: what these texts actually ask of a medical practice, the checklist to get started, and what they leave open.

Published July 18, 2026

Within a few months, French health professionals received their framework for using AI: the HAS's first usage keys for generative AI in healthcare on 30 October 2025, then a joint HAS + CNIL draft guide in March 2026. Neither text bans anything. Both say the same thing in institutional language: use AI, but with method. Here is the translation into the language of a practice.

What came out, and when

  • 7 October 2025: the Académie nationale de médecine adopts its report Artificial intelligence and medical liability (report 25-12), on how obligations are shared between the provider of an AI system and its deployer - that is, you.
  • 30 October 2025: the HAS publishes its first usage keys, with a deliberate opening message: yes to generative AI, with responsible use. The heart of the text is the A.V.E.C. framework.
  • 5 March 2026: the HAS and the CNIL publish their draft guide "Accompagner le bon usage des systèmes d'intelligence artificielle en contexte de soins": ten sheets following the life of an AI system from acquisition to retirement, two cross-cutting sheets (governance, generative AI), for every actor in care, hospitals and independent practices alike. Public consultation ran from 5 March to 16 April 2026; the final version is expected.

What the texts actually say

Reasoned use, not prohibition. The HAS's A.V.E.C. framework comes down to four moves: Apprendre (learn how the tool works, its limits and its confidentiality rules before using it), Vérifier (judge whether the use is relevant, reread every generated output), Estimer (measure over time the effect on quality and organisation), Communiquer (talk about it with patients, peers and the team). The acronym is the message - avec is French for "with": AI is practised with the professional, never in their place.

Every output gets checked. In both texts, generated content is a working draft. Nothing enters a patient record, a letter or a consultation report without the practitioner rereading it.

The patient is informed. The C of Communiquer includes the patient: when AI contributed to a document that concerns them, they must be able to know. The HAS + CNIL draft extends this requirement, in line with the GDPR and the European AI regulation.

A governed life cycle. The draft guide treats an AI system as a full cycle: choosing it, integrating it, monitoring it, retiring it. Translation: a written usage policy, however short, rather than a collection of individual habits.

No new liability regime. The guides create none: the physician remains responsible for their decisions. The Académie's report details obligations split between provider and deployer, with no transfer of liability to the tool. The Ordre des médecins has held this line since 2018: AI that assists the decision, never AI that takes it. Decoded: whatever comes out of the machine binds whoever signs it.

The practice checklist

  1. Take stock of actual usage. Nine out of ten health professionals say they use AI, 84% of them via ChatGPT (ACSEL 2025 barometer). Start with reality: who uses what, on which data, with which account.
  2. Get patient data out of consumer accounts. A tool used without a contract tells you neither where the data goes nor what it feeds. Medical secrecy has no exception for drafts.
  3. Qualify your tools. Where do the models run, under which jurisdiction, does your data train them, is there an audit trail, a reversibility clause. A provider that answers in writing passes the first cut.
  4. Inform your patients. A clear notice, decided once for the practice, beats a silence you would have to justify later.
  5. Validate every document. The practitioner's review before a text enters the record is the core of the HAS framework.
  6. Keep a trace. Preserve the ability to say who generated what, on which file, when - somewhere other than in memories.

What the guides do not settle

Tool certification. Neither text labels solutions: there is no reference scheme saying "this tool is fit for a practice". The sorting remains yours - hence the checklist above.

The status of consumer AI. The texts frame professional use; they do not settle the case of the general-purpose assistants already embedded in daily habits, precisely where actual usage concentrates.

The edge cases of liability. The split between provider and deployer remains to be refined by implementing texts and case law. The Académie speaks of a possible sharing; until it is defined, whoever signs carries it.

Our takeaway

Read back what the guides ask for: human verification, patient information, governance, traceability. For an instance you own, that list is less a compliance effort than a description of the architecture: agents running in France, on your data, preparing documents without ever signing them, logging every action. That is what we build for practices: our agents for healthcare. And for the consumer AI already woven into daily habits, our clear-eyed guide to ChatGPT in medicine takes the question head on.

Frequently asked questions

Does the HAS ban generative AI for physicians?

No. Its October 2025 position says the opposite: generative AI can help, provided it is used responsibly - that is what the A.V.E.C. framework is for.

Is the HAS + CNIL guide mandatory?

It is a good-practice guide, and the version published in March 2026 is a draft submitted to consultation. It does not have force of law, but it clarifies obligations that already apply on their own: the GDPR, medical secrecy and the European AI regulation.

Who is liable when the AI gets it wrong?

The physician remains responsible for their decisions: neither the HAS nor the CNIL creates a derogatory regime. The European regulation distributes obligations between provider and deployer (Académie de médecine, report of 7 October 2025), but nothing transfers your liability to the tool.

Does an AI-generated consultation report need to be reread?

Yes, every time: generated content is a draft; the practitioner's validation is what makes it a document.