Skip to content
ISC ParisAI Use Charter

Institutional evidence, position as of 7 September 2026

AI Actand governance

What the European regulation requires of a business school, what ISC Paris has in place to meet it, and where the timeline stands. This page is written first for those who have to check: partners, accreditation auditors, supervisory bodies, journalists, employers.

The position of ISC Paris

ISC Paris undertakes to comply with the AI Act and is bringing itself into compliance on a dated schedule. The school does not declare itself compliant, and will not do so until the obligations are actually met.

No page on this site claims more than that. What follows describes a framework at work: its deadlines, its procedures, and what still lies ahead.

Position set out in the ISC Paris AI Act compliance framework, annex A1 to the charter, version 1.0.

This page completes the common core of the charter. Where the common core and a page diverge, the more protective provision applies.

Read the common core

The regulation’s timeline

Four deadlines are behind us, one is still ahead. These are the dates of the European regulation, not those of ISC Paris.
  1. Deadline passed

    2 February 2025

    AI literacy and bans

    Two sets of rules become applicable: the AI literacy duty on deployers, and the prohibited practices. Emotion recognition in education is banned from this date.

    Articles 4 and 5

  2. Deadline passed

    2 August 2025

    General-purpose models

    Rules on general-purpose AI models come into application. For a school, they are watched at the level of the vendors behind the tools in use.

    General-purpose AI models

  3. Deadline passed

    24 July 2026

    High-risk uses postponed

    The regulation known as the Digital Omnibus is published in the Official Journal of the European Union and enters into force three days later. It postpones by sixteen months the requirements applying to high-risk systems under Annex III, education included.

    Regulation (EU) 2026/1744

  4. Deadline passed

    2 August 2026

    General application

    The regulation applies generally, transparency obligations included. This is the deadline that set the pace of internal preparation.

    General application of the regulation

  5. You are here

    7 September 2026

    Today

    The date this page was last updated. Version 3.0 of the charter came into force at the start of the September 2026 academic year.

    Charter V3.0

  6. Ahead

    2 December 2027

    High-risk uses

    The full requirements on high-risk uses under Annex III, which covers education and vocational training, become applicable. This date follows the July 2026 postponement; the initial deadline was 2 August 2026.

    Annex III, point 3, postponed by Regulation (EU) 2026/1744

Deadlines under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026. Restated in the common core of the charter, Legal framework section, and in the compliance framework, annex A1.

What the regulation changes for a school

Two main consequences for ISC Paris, stated as such in the common core of the charter.

AI literacy

Every member of staff who uses AI at work must have received training suited to their role. ISC Paris is putting that training in place, for staff and students alike, and refreshes the content every year.

Sensitive uses

Some uses fall into a regulated category: admissions, scoring of assessments, examinations. They follow a reinforced procedure: approval by the AI Transformation Office, impact assessment, human oversight, traceability.

A duty of means

Article 4 requires a sufficient level of AI literacy to be ensured as far as possible. It is a duty of means, not of result. The Commission guidelines that will set the exact perimeter, contractors and subcontractors included, are still awaited.

What is banned, everywhere

Four practices have been outside the reach of any authorisation since 2 February 2025. Neither the charter, nor the AI Transformation Office, nor any department can lift one of them.
  1. Emotion recognition

    In education and in the workplace. Banned since 2 February 2025.

    Carve-out in the regulationExcept on strictly framed medical or safety grounds.

  2. Social scoring

    Outright ban under Article 5.

  3. Exploiting vulnerabilities

    Vulnerabilities linked to age, disability or social circumstances.

  4. Biometric categorisation

    Where it infers sensitive data.

None of these uses may be deployed, tested or trialled at ISC Paris, in any form whatsoever.

Article 5 of the regulation, as restated by the ISC Paris compliance framework.

Mapping the sensitive uses

ISC Paris keeps a list of its AI uses liable to fall under the high-risk category. The mechanism is public. Its content is not.

Annex III of the regulation classifies several uses in education and vocational training as high risk, along with uses in human resources management. Every listed use carries a responsible department, a compliance officer and a state of progress. The list is a live document: reviewed, corrected, extended.

  1. List

    The use is classified against Annex III and against the outright bans. Where there is doubt, the AI Transformation Office decides.

  2. Assess the impact

    Before any deployment, a fundamental rights impact assessment under Article 27 documents the risks, the mitigation measures and the human oversight arrangements.

  3. Enter the register

    The tool is entered in the AI tools register: approved use, data categories accepted, hosting, status of the impact assessment, named owner.

  4. Review

    Annual review at the least, brought forward in the event of an incident, a major system update or a regulatory change.

Internal rule

Where the impact assessment is not complete, the use concerned is suspended. The procedure is not bypassed by the calendar.

What this page does not publish

The compliance status, use by use. The framework that carries it is an internal document with restricted circulation, held by the AI Transformation Office together with human resources, legal affairs and the Data Protection Officer. A reasoned request can be sent to aito@iscparis.com.

Referring a case, and how long it takes

A procedure that is too heavy pushes people towards unapproved tools. Referrals are therefore handled through three routes, according to the level of risk.
Indicative times. Source: compliance framework, referral procedure for high-risk deployment.
RouteWhat it coversIndicative time
Fast routeTools already approved by a recognised public framework, or already deployed at ISC Paris. Consistency check and acknowledgement of receipt.72 working hours
Standard routeTools outside the high-risk category, handling public or internal data only. Simplified data protection and security audit, approval by the AI Transformation Office.2 to 4 weeks
High-risk routeUses falling under Annex III: admissions, scoring, exam invigilation, automated marking. Impact assessment, IT audit, sign-off by the Data Protection Officer, approval by the AI Transformation Office and the executive committee.4 to 8 weeks, extendable

When a referral is blocked

A referral can be suspended: a practice that is plainly prohibited, data the school does not control, insufficient guarantees from the provider, or a residual risk judged unacceptable and impossible to mitigate. Any decision to block is given in writing with reasons, and can be reopened on new evidence.

When something goes wrong

  1. Under 24 hReport to the AI Transformation Office and to the department compliance officer.
  2. Under 7 daysClassification of the incident: cause, perimeter, people affected.
  3. Under 30 daysRemediation plan: suspension of use, fix, training, update of the framework.
  4. Under 60 daysLessons learned and update of the compliance framework.

Where personal data has been breached, notification to the French data protection authority follows its own 72-hour deadline.

Governance

A named office, two seats added for contested decisions, three departments consulted within their remit.

AITO

AI Transformation Office

  • Coordinates the school’s AI policy.
  • Approves tools and keeps the register.
  • Organises training.
  • Monitors regulation and ethics.

The widened office

For editorial arbitration and contested cases, the office widens to two standing guests.

  • A designated faculty memberappointed by the academic departments
  • An elected studentappointed by the representative bodies

Consulted within their remit

  • Data Protection Officer

    GDPR compliance, impact assessments, register of processing activities. Where GDPR analysis diverges from that of the AI Transformation Office, the Officer’s view prevails.

  • IT department

    Security, hosting, technical integration of deployed tools.

  • Human resources

    Uses within the HR remit, rollout of the training policy.

The data controller under the GDPR remains ISC Paris, represented by its management. The Officer advises and audits, and does not carry compliance in its place. A quarterly meeting formalises the cooperation between the two functions.

A text revised every year

The cycle is written into the charter rather than improvised each summer. It produces a minor version in September and a structural overhaul every two years.
  1. JuneUsage survey among students, staff and faculty.
  2. June, JulyStudent focus group, faculty workshop, staff workshop.
  3. Summer, new termReview by the widened office, amendments folded in.
  4. SeptemberPublication of the minor version: corrections, adjustments, new examples.
  5. Every two yearsMajor revision, structural overhaul where needed.

“The charter must be dynamic without being unstable.”

The versions

  • 3.0September 2026In forceCommon core plus three role guides, principles of restraint and curiosity, explicit AI Act framing, widened governance, compliance framework.
  • 3.1June 2027AheadISC data from the internal survey of June 2026, adjustments from the consultation, new frequently asked questions.
  • 4.0September 2028AheadStrategic review in the light of experience and of regulatory change: Commission guidelines, ministry updates, AACSB.

What the school publishes

Transparency binds the institution as much as individuals. It is measured by what comes out.

A usage indicator, every year

ISC Paris publishes its request volumes, the types of model used and the main observed uses every year. The undertaking sits in the text of the charter, not in a supporting speech.

The ISC figures will come separately

The figures below describe the sector, not the school. ISC Paris will publish its own figures in 2027, from an internal survey run in June 2026 across its three populations.

See the Future Study 2026: CarringtonCrisp, 4Uni, EFMD and Full Fabric, n = 1,863 respondents, 40 countries. Sector figures, quoted for context.
FigureWhat it saysSource
89%of business school students, teachers and staff use generative AI at least once a weekSee the Future Study 2026
6% and 4%of teachers, then of students, consider themselves expert in generative AISee the Future Study 2026
73% and 46%of higher education institutions report having an AI policy; only 46% cover classroom useSee the Future Study 2026
362AI incidents documented worldwide in 2025, up 55% on 2024AI Index Report 2026, Stanford HAI
40 out of 100the transparency of large models, measured at 58 out of 100 in 2024AI Index Report 2026, Stanford HAI

What this charter does not do

A charter that claims a power to punish turns against the school the day it is used. This one rests on the texts that already exist.
  • StudentsThe ISC Paris academic regulations, adopted by the competent body. A breach is examined under the procedure they set out: adversarial process, disciplinary board, appeal.
  • StaffThe French Labour Code and the ISC Paris internal rules. No disciplinary sanction is issued outside the internal rules in force.
  • FacultyISC Paris statutes and specific procedures. The charter creates no new contractual or statutory obligations that have not been negotiated.

A precise question, an auditor’s request

Requests for detail on this framework, including from accreditation bodies, partners and journalists, go to the AI Transformation Office. The official PDF remains the text that prevails.