The CNIL issued draft guidelines to align AI training datasets with GDPR. Key principles include purpose limitation (clear, specific goals), data minimization, storage limits, and the need for a legal basis (e.g. consent or legitimate interest). Vague goals like “AI development” aren’t valid. The CNIL recommends ethics committees and traceable governance. Reuse of data requires compatibility with original purpose. This aims to balance innovation with data protection.