France has opened an approval pathway, not every street
A U.S. robotics company has a delivery vehicle ready for export. Its navigation software can respond to obstacles, and a French retailer wants to run a pilot. The commercial question is no longer just whether the machine works. It is which approvals and operating arrangements the proposed service requires.
The French Order of July 28, 2026, Article 8 and Annexes 3 and 4 added to the Order of August 17, 2016, published on August 7 and effective on August 8, 2026, establishes technical requirements for national small-series type approval and individual approval of certain fully automated L-category vehicles.
The vehicles covered are electric and not designed to accommodate occupants. This is a targeted route for unoccupied delivery vehicles, not general authorization for autonomous robots or passenger vehicles.
The government describes operation on roads, excluding sidewalks, with remote supervision and locally defined areas or routes within the vehicle’s approval limits. Its stated purpose is to allow development without waiting for international and EU harmonization to be completed. Source: French Ministry of Transport, announcement of August 7, 2026 on autonomous delivery robot approval.
For a U.S. business, French homologation means regulatory vehicle approval. It should not be confused with unrestricted road access or automatic permission to expand the same service across Europe.
Cybersecurity is already part of the vehicle approval dossier
A navigation vulnerability can become a physical safety problem. Compromised software might interfere with routing, disable a fleet or prevent the vehicle from reaching a safe state.
The French order’s annexes incorporate UN Regulation No. 155 on cybersecurity and No. 156 on software updates. Associated management systems must be assessed, with certification or audit arrangements varying between small-series and individual approval.
This matters when a manufacturer prices an export project. Cybersecurity documentation and update management are part of the vehicle approval work, not optional services to negotiate after the first delivery.
Does the Cyber Resilience Act necessarily cover a delivery robot?
The scope analysis comes first. Commission Delegated Regulation (EU) 2025/1535, Article 1 excludes products falling within Regulation (EU) No 168/2013 from the CRA, with an exception for certain L1e vehicles designed to pedal.
That does not mean every vehicle described as “L-category” under French national law receives the exemption. Regulation (EU) No 168/2013, Article 2(2)(j) excludes vehicles without at least one seating position from that EU vehicle regulation.
A seatless delivery robot using the French national pathway therefore needs a separate CRA assessment. The vehicle, any separately marketed components and the relevant sectoral exclusions must be considered. A national classification or compliance with vehicle cybersecurity requirements does not, by itself, establish a CRA exemption.
For U.S. counsel, this is the distinction to preserve: “a regulated vehicle” is not a sufficient answer to “which EU product cybersecurity regime applies?”
Reporting started in 2026, before the main 2027 requirements
For in-scope products, Regulation (EU) 2024/2847, Cyber Resilience Act, Articles 14, 69 and 71 separates the reporting start date, September 11, 2026, from general application on December 11, 2027, including the main essential requirements and conformity-assessment framework.
Article 14 addresses actively exploited vulnerabilities and severe incidents affecting product security. It does not require identical reporting for every software defect.
| Trigger | Early warning | Follow-up notification | Final report |
|---|---|---|---|
| Actively exploited vulnerability | Within 24 hours of becoming aware | Within 72 hours of becoming aware | Within 14 days after a corrective or mitigating measure becomes available |
| Severe incident affecting product security | Within 24 hours of becoming aware | Within 72 hours of becoming aware | Within one month after the follow-up notification |
Summary table based on European Commission, “Cyber Resilience Act - Reporting obligations”. Reports are due without undue delay and within these maximum periods.
Reports go through ENISA’s Single Reporting Platform to the relevant coordinating CSIRT and ENISA. Article 14 also covers products already placed on the market; this should not be confused with the transitional treatment of other requirements.
Consider a manufacturer learning on Friday evening that attackers are exploiting a navigation flaw. Waiting until Monday to begin regulatory triage may already miss the early-warning deadline. The manufacturer needs an escalation process that works outside ordinary office hours, including across U.S. and European time zones.
Who is the manufacturer when several businesses are involved?
The company operating the fleet is not automatically the CRA manufacturer. A business that has a product developed or manufactured and markets it under its own name or trademark may qualify, even if another company assembles the hardware. Source: European Commission, “The Cyber Resilience Act - Summary of the legislative text”.
A U.S. supplier and its European commercial partners should identify those roles before contracting. The agreement should cover incident escalation, information needed for notifications, security updates, fleet safety measures, evidence retention and cooperation with authorities.
Those clauses can allocate work and commercial risk between the parties. They do not change the legal identity of the actor responsible for a regulatory duty merely by assigning the task to someone else.
The practical procurement question is therefore not just “Who owns the robots?” It is “Which entity can obtain the information and take the action required when the fleet becomes unsafe?”
Cameras create a separate data-protection workstream
A robot may process identifiable images of bystanders or information linked to delivery recipients. The fact that a camera is useful for navigation does not authorize unrestricted recording, retention or reuse. Purpose limitation, data minimization and a lawful basis remain relevant under GDPR, Articles 5 and 6, official French text reproduced by the CNIL.
Privacy by design, processor arrangements and appropriate security must also be assessed. A data protection impact assessment is required where the processing is likely to create a high risk, not simply because the device is called a robot: GDPR, Articles 25, 28, 32 and 35, official French text reproduced by the CNIL.
For a U.S. vendor, the data-flow map should distinguish on-device processing, the fleet operator’s systems and any remote support or hosting. Vehicle approval and CRA reporting do not replace the GDPR assessment.
Will the opening favor European manufacturers or foreign suppliers?
The French pathway sets product-approval conditions; it does not allocate the market to domestic manufacturers. French, other European, U.S. and Chinese suppliers may seek opportunities, subject to the requirements applicable to their products and roles.
It is too early to infer an industrial winner from the legal framework alone. Relevant evidence would include approvals obtained, actual deployments, production capacity and the ability to provide maintenance and software support over time.
Further uses, such as autonomous inspection or transport between industrial facilities, could develop. They are not automatically authorized by the delivery-vehicle order and would need their own regulatory assessment.
The market-access opportunity and the cybersecurity obligations should therefore be evaluated together rather than presented as a choice between innovation and regulation.
The practical takeaway for in-house counsel
Before a French launch, the legal file should connect four decisions: the vehicle’s approval route, the permitted operating environment, the applicable cybersecurity regime and the contractual allocation of incident-response tasks.
This is not solely a technical certification exercise. It affects launch schedules, supplier selection, data processing and the cost of supporting a fleet.
French approval creates an opportunity to deploy. It does not guarantee unrestricted market access, ongoing cybersecurity compliance or commercial success. For U.S. companies, those distinctions belong in the market-entry plan before the first shipment.
Can a U.S. company use the French delivery-robot pathway?
A U.S. supplier can assess it for qualifying vehicles, but must satisfy the applicable approval, operating and supply-chain requirements. Being authorized for a U.S. deployment does not establish compliance in France.
Does French approval allow sidewalk operation or EU-wide deployment?
Not automatically. The French framework described here concerns road use, excludes sidewalks and retains operating restrictions. National approval should not be treated as an unrestricted European operating license.
Are all L-category delivery robots exempt from the CRA?
No. The exclusion depends on the scope of EU Regulation No 168/2013. Seatless vehicles are excluded from that regulation, so a national L-category label alone does not resolve CRA applicability.
Must a manufacturer wait until 2027 to report a vulnerability?
No. Article 14 reporting applies from September 11, 2026 for in-scope products and qualifying events, including products already placed on the market.
