Skip to content
ISC ParisAI Use Charter

Staff guide, version 3.0.1, in force since September 2026

Which tool, which data,who signs

Three questions cover most working days. This guide answers them for support functions and managers: what you may hand to an AI, with which tool, under which condition, and who remains accountable for what comes out.

All campuses. Administrative staff, support functions and managers.

The four rules everything else follows from

  1. Approved tools for sensitive data

    No internal, confidential or personal data goes to a tool the AI Transformation Office has not approved.

  2. Human control before circulation

    AI proposes, you validate. The signature and the responsibility for the output remain yours.

  3. Transparency about use

    Where AI has contributed significantly to a deliverable, you say so to the recipients concerned.

  4. The right tool for the job

    A light model for a simple task, a powerful one when the task warrants it. Restraint is part of professional standards.

Your documents, four categories

The right to use AI is read from the data first, not from the tool. Find your document in the middle column, the row gives you the regime.
Classification from the V3 staff guide, section 5. It applies on every campus.
CategoryYour everyday documentsTool allowedDetail
PublicWebsite, brochures, press releases, news already published.Any toolNo tool restriction. Proofreading before circulation still applies.
InternalMeeting notes, minutes, ongoing projects, unpublished working material.AITO-approved toolsThe list is reviewed quarterly by the AI Transformation Office, annex A5.
ConfidentialBudgets, contracts, strategy, competitive intelligence.Approved tools plus your manager’s authorisationBoth conditions together, never one or the other.
PersonalHR data, student files, applicants, alumni.Prohibited outside an approved toolEffective pseudonymisation within the meaning of Article 4(5) GDPR does not remove personal data status. Anonymisation within the meaning of Recital 26 is rarely achievable and requires prior validation by the Data Protection Officer.

The chain of questions

Four questions in this order, and you stop at the first yes. This is the decision tree from the guide, unfolded.
  1. Does my task involve personal data?

    Yes

    Stop

    Pseudonymisation required, approved tool and a documented legal basis. Without all three, the use is prohibited.

    No

    Move on to the next question.

  2. Does my task involve confidential data?

    Yes

    Conditional

    AITO-approved tools only, plus your manager’s authorisation.

    No

    Move on to the next question.

  3. Does my task involve internal data?

    Yes

    Restricted

    AITO-approved tools only.

    No

    Move on to the next question.

  4. Does my task involve public data only?

    Yes

    Allowed

    Every tool is allowed.

In every case

  • Read and validate before circulating.
  • Declare the use where the AI contribution is significant.
  • Pick the right tool for the job.

If the doubt persists, write to aito@iscparis.com. The charter does not settle every particular case, and nobody expects you to guess.

Match a data type with a tool

Department by department

A quick read on common uses. These tables do not replace the chain of questions and do not exhaust particular cases.

Human resources

UseStatusCondition
Drafting job advertsAllowedTailoring and proofreading are mandatory.
CV screeningRestrictedAssistance only, human decision, traceability.
InterviewsRestrictedPre-selection at most, then 100% human.
Performance reviewsProhibitedAI neither grades nor ranks people.
Compiling metricsAllowedAggregated and anonymised data.
Designing internal trainingAllowedEducational validation before release.

Communications and marketing

UseStatusCondition
Content writingAllowedValidation before release.
AI-generated visualsAllowedLabel “Image generated by AI” where relevant.
Social mediaRestrictedHuman validation of every post.
Replies to commentsRestrictedFirst-line FAQ only, human escalation within 2 hours.
Photo retouchingAllowedMinor retouching only, no misleading transformation.

Any content intended for external audiences goes through manager validation before release.

Administration and student services

UseStatusCondition
Answering student FAQ emailsAllowedSay it is AI-assisted where relevant, with human escalation planned within 24 hours.
Handling individual student filesProhibitedPersonal data, unless an approved tool is used with effective pseudonymisation.
Calculations and formattingAllowedDouble checking is mandatory.
Meeting minutesAllowedParticipants validate before circulation.
Processing applicationsRestrictedAssistance only, human decision.

Technical and IT services

UseStatusCondition
Code generationAllowedReview, tests and security validation are mandatory.
Technical documentationAllowedFactual verification.
User supportAllowedFirst line, human escalation where needed.
Log analysisAllowedPseudonymised data, approved tool.
Security incident detectionRestrictedCoordinated with the AITO and the Data Protection Officer.

Finance, executive and strategic functions

UseStatusCondition
Preparing material for governing bodiesAllowedApproved tools, systematic sign-off by the line manager before circulation.
Summarising internal strategy documentsRestrictedApproved tools only, no external transmission.
Sending a strategy, a budget or an M&A project to an unapproved toolProhibitedNo exception.
Preparing financial communicationsRestrictedApproved tools, sign-off by the Finance Department, figures checked at source.
Generating strategic scenariosAllowedApproved tools, raw material to challenge, never a conclusion.

The sensitivity of these files calls for a conservative stance: when in doubt, do not use AI and ask the Executive Committee.

What is not open to discussion

Six moves are prohibited, whatever the urgency and whatever the good intention. No manager can order you to make them.
  • Sending HR data, employee files, salaries, appraisals or medical data to an unapproved AI tool.
  • Sending confidential or strategic financial data, budgets, forecasts or negotiations, to an unapproved tool.
  • Sending personal data about students or applicants to an unapproved tool.
  • Using an unapproved AI tool for internal data.
  • Letting AI take a decision affecting a person on its own.
  • Circulating AI output without human proofreading.

Four cases pass, under conditions

Recruitment
AI may assist initial screening. The decision is human. Anyone whose file is processed has the right to be told if AI contributed.
Staff appraisal
AI is not used to grade or rank people. It may compile objective, aggregated metrics.
External communications
Manager validation before release.
Pseudonymised data
Allowed on approved tools, provided the pseudonymisation is real and verified.

Validation tiers

The more a use weighs on people, the higher the control required. Three tiers, labelled M1 to M3 so they are not confused with the N0 to N4 scale used for academic assessment.
Any M3 deployment requires prior review by the AI Transformation Office and the production of the ISC AI Act Compliance Framework materials.
TierWhat it isExampleControl required
M1Task automationA simple, isolated, low-risk task. AI assists a one-off act.Drafting an email, formatting a document, translating a press release.AI charter and approved tools. No specific procedure.
M2Workflow augmentationA chain of actions, with systematic human supervision at every sensitive step.CV screening with human validation, lead qualification with proofreading.AI charter, approved tools, documented traceability, manager informed.
M3Institutional infrastructureDeployment embedded in an institutional process that affects people.An application pre-ranking tool rolled out for a whole intake.Mandatory referral to the AITO, ISC AI Act Compliance Framework (annex A1), FRIA analysis under Article 27 of the AI Act, compliance with Articles 12 to 14 (auditability, explainability, human oversight), continuous supervision. Go-live only after a favourable opinion.

ISC Paris undertakes to comply with the European regulation on artificial intelligence (EU 2024/1689) and to put in place the arrangements required by the applicable deadlines: AI literacy since 2 February 2025, full application on 2 August 2026.

Three procedures, depending on what you are starting

A one-off use

  1. Identify the type of data involved.
  2. Choose an approved tool if the data is internal or confidential.
  3. Choose the model that fits the task.
  4. Read and validate the output before circulating it.
  5. Mention the use of AI where the contribution is significant.

A new AI process

  1. Identify the need, the data involved, the potential impact on people.
  2. Refer to the AITO beforehand, all the more so at tier M2 or M3.
  3. Document it: objective, tool, data, controls, supervision.
  4. Train the people concerned before go-live.
  5. Review after three months: relevance, quality, restraint, incidents.

Content intended for external audiences

  1. AI-assisted production.
  2. Proofreading by the author.
  3. Manager validation.
  4. Mention of the AI contribution where significant.
  5. Release.

Admissions and recruitment

The point of maximum vigilance. Processing applications may, in certain configurations, fall under high-risk uses within the meaning of the AI Act, Annex III, access to education. The rules below apply strictly.
UseStatusCondition
AI screening or pre-ranking of application filesRestrictedAssistance only. Human decision mandatory. Traceability of every decision. No automated score may be held against an applicant.
Standard replies to information requestsAllowedApproved tool, say it is AI-assisted where relevant.
Help drafting qualitative feedbackAllowedTailoring and proofreading are mandatory.
Final admission or rejection decisionProhibited if automatedHuman decision, reasoned, explainable.
Deploying an AI tool inside the processConditionalMandatory referral to the AITO beforehand, FRIA process under the AI Act Compliance Framework, annex A1, before go-live.
  • Any applicant whose file is processed with AI assistance has the right to be told.
  • No applicant may be rejected on the sole basis of an automated score.
  • The same rule holds for internal recruitment: AI assists the screening, it does not decide.

Sanctions: what the charter does not do

The charter creates no disciplinary regime of its own. It sets professional expectations; sanctions come from elsewhere.

An inappropriate use, once observed, first leads to a conversation, to understand, support and correct. The charter is there to protect, not to punish.

Any disciplinary sanction derives exclusively from the ISC Paris internal rules and is applied through the procedures they set out: prior interview, adversarial procedure, right of appeal, in strict compliance with the French Labour Code, in particular Articles L.1321-1, L.1331-1 and L.1332-2. The internal rules set the scale and the terms of any sanction.

Indicative scale, for guidance. The final assessment belongs to the disciplinary procedure conducted under the internal rules.
Type of breachFirst responseApplicable procedure
First minor breach, isolated, self-declaredReminder of the rules, supportConversation with the manager
Repeat or significant breachResponse under the internal rulesHR procedure under the internal rules
Established or serious misconduct: deliberate leak, concealment, harm to peopleResponse under the internal rules and the Labour CodeLegal procedure, employment law

The chain of responsibility counts

Responsibility for a collective or organisational breach does not fall mechanically on the end user. Where a non-compliant deployment was requested, ordered or knowingly tolerated by a manager, the disciplinary procedure takes the management chain into account.

Your rights

  • The right to an explanation, to dialogue, and to assistance from a staff representative.
  • The right to training where the breach stems from a gap in knowledge.
  • An adversarial procedure, respected.
  • Appeal to HR, then through the channels set out in the internal rules and the Labour Code.

Refuse, report, be protected

The right to say no exists, and it is written down. It has a flip side, also written down: protection covers good faith only.

Refuse

You cannot be sanctioned for refusing to carry out an instruction that is manifestly contrary to the charter or to the law.

Your manager asks for an AI use that looks contrary to the charter.
Voice your doubts with the text in hand. If the disagreement persists, ask the AITO or HR.
Your manager asks you to deploy an unapproved AI tool.
Refuse the deployment and send the request to the AITO. This rule protects the institution, your manager and you.

Be protected

  • Confidentiality: the reporter’s identity is shared only with the people strictly needed to handle the case.
  • No retaliation: no adverse measure will be taken against someone who reported in good faith.
  • Support: the reporter may be followed up by the AITO or HR, on request.

Protection in line with whistleblower status, French Sapin II Act, provisions applicable to the private sector.

The flip side: established abuse

The reporting mechanism is not an instrument for settling scores. A report found to be manifestly abusive, defamatory or made in established bad faith exposes its author to the applicable disciplinary procedure and, where relevant, to the consequences provided by law, in particular Article 226-10 of the French Criminal Code, false accusation.

A report that turns out to be partly unfounded stays protected as long as it was made in good faith: doubt benefits the reporter. The person reported has the right to be informed, unless that risks destruction of evidence or obstruction of the investigation, the right to an adversarial procedure and the right to assistance from a staff representative.

Incident: the first moves

An AI incident calls for speed, never for concealment. Speed limits the damage, silence makes it worse.

You sent sensitive data to an unapproved tool

  1. Stop using it at once, and do not interact with the tool again in the same session.
  2. Document it: which tool, which data, what date and time, how many requests.
  3. Report without delay to your manager and to aito@iscparis.com.
  4. Keep the traces: screenshots, copies of the prompts, exports where possible.
  5. Do not patch it up alone. Undocumented self-correction makes things worse.

You suspect a data leak

  1. Alert the AITO immediately, subject line “SUSPECTED LEAK, AI”, and the Data Protection Officer.
  2. Touch nothing: delete no message, no screenshot, no session.
  3. Document what you saw: who, what, where, when, source, available evidence.
  4. Do not spread it beyond what is strictly necessary, your direct manager and the AITO.

You observe a manifestly non-compliant use

  1. Talk to the person concerned first, where that is possible.
  2. If it goes beyond you, or if you fear retaliation, refer it to the AITO or HR.

The clocks that start running

StepDeadline
Acknowledgement of a reportWithin 24 working hours
Notification to the CNIL where required, Article 33 GDPRWithin 72 hours
Joint investigation by the DPO, IT and the AITO into a suspected leakWithin 7 working days
Corrective measureWithin 30 days

For an urgent situation, write straight to aito@iscparis.com with the subject line: URGENT, AI INCIDENT.

Psychological distress: a separate route

Emotional dependence or distress linked to AI use goes neither through the AITO nor through your manager. Such reports are health data within the meaning of Article 9 GDPR: they are handled exclusively by the University Health Service, under medical confidentiality. In a crisis, 3114, the French national suicide prevention line, answers around the clock, free and anonymously.

Help and contacts

The AI incident kit, annex A4, sets out the full procedure, the contacts and the reporting form.

Restraint and training

Restraint is one of the five principles of the common core. So that it does not stay a word, three concrete trade-offs. And a training obligation that comes from the law.
  1. A light model for a simple task

    The heaviest models are kept for the uses that warrant them: complex analysis, long reasoning, demanding creative work. To reword a sentence or fix a typo, a modest model is enough.

  2. No needless high definition

    A thumbnail does not need a 4K image. An internal note does not need layout generated image by image.

  3. A published indicator

    ISC Paris undertakes to publish an aggregated indicator of its AI use every year: volume, types of models used, main uses. It takes effect with version 3.1.

Training

Since 2 February 2025, Article 4 of the AI Act has required organisations using AI to ensure a sufficient level of AI literacy among the people concerned. ISC Paris meets that obligation through its training plan.

One core course, mandatory for everyone, then further courses according to your role. They are taken online, at your own pace, in video micro-modules of twelve to fifteen minutes.

CourseDurationAudience
Using AI safely at work1 hAll staff, mandatory
The AI Act in two hours, for decision-makers2 hManagers, leadership, heads of department
The AI Act for data protection officers6 h 30Compliance, data protection, legal
The AI Act: five costly misconceptions45 minDiscovery, open access

Each course awards a personal certificate, after a final quiz passed at 80 per cent. That certificate is the individual, datable proof that the training required by Article 4 has actually been received.

See the courses on the ISC Paris academy

The AI Transformation Office supports departments: identifying use cases, setting up secure processes, training teams. Monthly sessions, hands-on workshops, drop-in hours.

A case this guide does not settle?

Write to aito@iscparis.com rather than guess. A question asked always costs less than data sent to the wrong place.

Source: ISC Paris AI Use Charter, staff guide, version 3.0.1, September 2026, and annex A4, AI incident kit. The official French PDF prevails.

Write to the AITO