5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

France

Keeping control when AI agents issue invoices into an irreversible national system

The moment an AI agent issues or processes French invoices, three things stop being technical and become legal: the status it emits, the coherence between the readable rendering and the structured data, and whatever authorised the issuance. Each carries a penalty or a liability. Nothing in the reform distinguishes an invoice issued by an employee from one issued by an automated process — the obligations fall on the taxable person, never on the mechanism. And the channel does not accept an undo: once an invoice is deposited on a plateforme agréée and routed, it is corrected, not withdrawn.

Also available in Français

How Barzel applies here Start free with BarzelVault

The French text is the legally binding one. This page is a working guide for a reader who does not read French; it is not a substitute for the instruments themselves, and wherever a decision turns on wording, the French wording governs.

What changes when an agent enters the chain?

The reform does not mention AI agents and will not. It describes obligations — issue in electronic form, transmit transaction data, route flows through an approved platform — and fines attached to their non-performance. Whether the performance falls to an employee, a batch job or an agent changes neither the obligation nor the amount; the only thing that changes is the speed at which an error replicates.

One architectural point first. The agent never transmits on its own. All B2B flows pass through a plateforme agréée (PA) — the official term since décret n° 2026-677 and the arrêté of 27 July 2026, formerly PDP. This vocabulary point matters more than it looks: English-language coverage, product documentation and RFP responses still say PDP almost universally, and a prompt or a tool description that names the wrong artefact is a prompt written against a system that no longer exists. An opérateur de dématérialisation (OD) is not registered and cannot transmit alone. The portail public de facturation no longer issues or receives: it keeps only the central annuaire (CGI, art. 289 bis) and the concentrateur (CGI, art. 242 nonies G). Our running corrections list, including the PDP point, is at corrections.

Why is the national channel irreversible, and what follows from that?

This is the property that separates French e-invoicing from most systems an agent is allowed to touch, and it is the reason the governance question is not academic.

Once an invoice is deposited on the issuing plateforme agréée, addressed through the annuaire and routed to the recipient's platform, there is no recall. The data has reached the concentrateur. The correction path is commercial: a corrective invoice or a credit note, which is itself an electronic invoice that must be issued, routed and reported like any other. A lifecycle status already emitted stays emitted. Nothing in the chain offers the equivalent of a deleted draft.

Three consequences for anyone automating into it:

  • Errors accumulate rather than resolve. A batch of a hundred wrong invoices produces a hundred corrective documents, each with its own routing and reporting, not one rollback.
  • The penalty scale is per document. At €50 per invoice for failure to issue in electronic form (CGI, art. 1737), the €15,000 annual cap arrives in three hundred documents. At €500 per transmission for failure to transmit e-reporting data (CGI, art. 1788 D), it arrives in thirty. An agent in a retry loop reaches either number faster than a person notices.
  • The counterparty sees it. Unlike an internal system, the failure mode is visible to customers and suppliers on the day it happens, and it is visible in a form they must respond to.

The design rule that follows is the one that applies to every irreversible system: the check has to sit before the call, because there is no meaningful check afterwards.

Why are statuses emitted by an agent legal qualifications?

Four statuses are mandatory: déposée, rejetée, refusée and encaissée. Rejetée is a technical rejection by a platform. Refusée is a commercial refusal by the recipient, and only three grounds are admitted: a regulatory non-conformity not caught by the receiving platform — typically the absence of the purchase order required under article L441-9 of the code de commerce — an unrecognised transaction, and a breach of contractual conditions preventing processing. The administration is explicit that refusée must not be used for a simple commercial dispute.

An agent processing an inbound flow does not have those categories. It has internal codes and a mapping table written by somebody who thought they were projecting acknowledgements. They were projecting declarations.

Condition detected internallyStatus a naive mapping emitsWhat the company is declaring
Purchase order missingRefuséeCorrect — non-conformity under art. L441-9
Price differs from the orderRefuséeA commercial refusal outside the three admitted grounds
Disagreement over the service deliveredRefuséePrecisely the case the administration excludes
Format the ERP cannot processRejetéeA technical rejection — which belongs to the platform, not to you

For the two middle cases the answer already exists: the recommended statuses — mise à disposition, prise en charge, approuvée, en litige, suspendue, complétée, paiement transmis — circulate between plateformes agréées without being reported to the administration. En litige exists for exactly this. Audit the mapping table for its own sake, and keep both the originating internal code and the status emitted in the trail; without that pair a mapping error is undetectable after the fact. The mechanics are in our note on the audit trail across ERP, plateforme agréée and recipient, and the definitions in the glossary.

Do the readable rendering and the structured data come from the same place?

The three base formats — Factur-X (hybrid, PDF/A-3 with embedded XML), UBL and CII — all rest on EN 16931. In the hybrid, the XML prevails; the PDF is only a rendering. If they diverge, the legally operative content is the one nobody read — and under French invoicing rules the gap can amount to two invoices for one transaction, with VAT stated in excess becoming a risk in its own right.

Hence a rule with no exception: both parts must be generated from a single source of data, in the same processing run. An agent that composes the readable rendering separately from the structured data reproduces exactly that defect — and it is the most probable failure mode, because a model is very good at producing a presentable document and indifferent to whether the numbers in it came from the same query. Note too that the spécifications externes stand at version 3.2 of 30 April 2026 and will keep moving: validation rules frozen at project date drift without anyone noticing. Our comparison of the three formats is at Factur-X, UBL and CII.

Where should the approval threshold live?

Outside the agent. If the model decides for itself whether its action requires validation, then everything that influences its context influences the threshold: the content of an inbound invoice, a supplier label, an instruction slipped into a free-text field. The threshold must be evaluated by a component the agent can neither consult nor modify, and which denies by default. The general treatment is in our note on approving AI agent actions before execution.

The stakes are quantifiable. The first-offence relief removes any penalty for a first offence committed during the current calendar year and the three preceding ones, provided it is put right spontaneously or within thirty days of a first request from the administration. That is a single protection on a rolling four-year window. An agent that loops on a batch of low-value invoices spends it on errors nobody cares about and leaves nothing in reserve for the serious incident that follows.

For a group, add one thing the French-language treatment does not need to say: the threshold has to be evaluated per French SIREN, not per group. The obligation attaches to the unité légale, the penalty caps are per entity, and an approval policy expressed in group currency at group materiality will authorise, without anyone intending it, actions that are material for the French entity carrying the liability.

Is company size a rule or a parameter?

A parameter, and a dated one. Size is assessed at 1 January 2025, on the last financial year closed before that date, at the level of the unité légale identified by its SIREN. The date is frozen: it did not move with the timetable — reception for every taxable person and issuing plus e-reporting for GE and ETI since 1 September 2026, PME, TPE and micro-entreprises on 1 September 2027 as a single wave.

A system that treats this as a live rule, querying current headcount or turnover, will be wrong at the category boundaries: an entity that crossed a threshold in 2025 or 2026 still belongs to its original category. The criterion belongs in configuration, as a dated value with its justification attached — not in an agent's reasoning, and not in a prompt where a model may be asked to infer it. A group holding several French SIRENs will find them distributed across both waves, which is set out in what changed on 1 September 2026.

What does the tolérance de démarrage actually protect?

The fines have applied since 1 September 2026.

FailureAmountAnnual capBasis
Failure to issue in electronic form€50 per invoice€15,000CGI, art. 1737
Failure to transmit (e-reporting)€500 per transmission€15,000CGI, art. 1788 D
Failure to use a plateforme agréée€500 after a three-month formal notice, then €1,000 every three months——

The DGFiP has been explicit: the tolérance de démarrage is neither a postponement nor a suspension of the obligation. Penalties are simply not applied immediately, automatically and blindly to businesses of good faith engaged in a documented remediation process. What protects you is therefore not the calendar but the documentation — which, for automated issuance, comes down to four questions: what triggered the operation, on what data, under which policy and which version of it, and, where a threshold applied, who validated and what was put in front of them. An empty file at the moment of a check attracts no tolerance at all.

Does the AI Act change anything here before 2028?

Less than the headlines suggest, and not in the direction most readers assume. The AI Act, amended by regulation (EU) 2026/1744 of 8 July 2026, in force on 27 July 2026, postponed the obligations for high-risk systems under Annex III to 2 December 2027 and those under Annex I to 2 August 2028. The transparency obligations were not postponed: they have applied since 2 August 2026.

An invoicing agent is not necessarily a high-risk system. But the postponement relieves nothing that matters here, because none of the exposure described above comes from the AI Act. It comes from the French invoicing obligations, which apply to the entity regardless of what performs them.

What should a group outside France watch before 2027?

Two windows. The first is budgetary: the projet de loi de finances for 2027 had not been tabled as at 3 September 2026. Every previous slippage in this reform arrived through a loi de finances, and no measure has been announced concerning the 1 September 2027 deadline — but that is the window in which one would appear. Treat 2027 as a date to plan against with an explicit checkpoint after the PLF is published, not as a settled fact and not as a deferral to wait out. The entities affected are covered in the 2027 wave checklist.

The second is your own release calendar. An agent estate that was governed adequately at pilot volume is rarely governed adequately at production volume, and the French channel supplies no natural brake: nothing between the agent and the concentrateur will slow a loop down.

In practice

BarzelVault evaluates policy and approval thresholds outside the agent, ahead of execution, and issues signed audit receipts covering the trigger, the policy version applied and what was presented to the approver. It exposes nine tools, and it denies by default rather than reconstructing the decision afterwards.

How Barzel applies here

Frequently asked questions

Can an AI agent issue invoices on our behalf?

Nothing prohibits it: the obligations fall on the taxable person, not on the mechanism. But the agent never transmits alone — every B2B flow passes through a plateforme agréée.

Who is liable if an agent wrongly emits refusée?

The company. Only three grounds for refusal are admitted, and refusée must not be used to formalise a simple commercial dispute.

Can the approval threshold be managed by the agent itself?

No. If the model decides whether its action needs validation, everything that influences its context influences the threshold. Evaluate it outside, and deny by default.

Do we have to recalculate company size?

No. It is assessed at 1 January 2025 at the level of the unité légale. It is a dated configuration value, not a live rule.

Does the AI Act apply to an invoicing agent?

High-risk obligations are postponed to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Transparency obligations have applied since 2 August 2026.

Can an invoice already sent be recalled?

No. It is corrected commercially, by a corrective invoice or credit note that is itself an electronic invoice. There is no undo in the channel.

In practice

The control has to run before the invoice becomes irreversible.

An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.

338 days leftPME, TPE and micro-entreprises: issuing and e-reporting from 1 September 2027

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.

Related

Sources

  1. Décret n° 2026-677 and arrêté du 27 juillet 2026 (plateformes agréées), Journal officiel of 28 July 2026.
  2. CGI, art. 289 bis and art. 242 nonies G; art. 1737 and art. 1788 D; code de commerce, art. L441-9.
  3. impots.gouv.fr, Spécifications externes B2B, version 3.2 of 30 April 2026 (statuses and grounds for refusal).
  4. entreprendre.service-public.gouv.fr, news item of 20 February 2026 (penalty amounts).
  5. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689, in force 27 July 2026.
  6. AFNOR standards XP Z12-012, XP Z12-013 and XP Z12-014, and European standard EN 16931 — paywalled, with no free official full text; not linked.

This article is for information and does not constitute tax or legal advice. The French text is the binding one.