Skip to content
ISC ParisAI Use Charter

The charter tools, version 3.0.1

Start fromthe task

Four tools for the four questions people actually ask. They apply what the common core says, nothing more. Where the charter does not decide, they send you to the AI Transformation Office rather than guess.

What no tool decides

Four situations where the charter calls for a human decision. No form replaces it, ours included.
  1. Getting a tool approved when it is not on the list

    You write to the AI Transformation Office. The procedure takes four to eight weeks depending on the complexity of the deployment and the level of risk.

    Common core, AITO-approved tools.

  2. Obtaining authorisation for confidential data

    Our tools tell you that prior authorisation is required, on top of an approved tool. They do not grant it: you ask for it, and before you send anything.

    Common core, data classification.

  3. A high-risk use: admissions, grading, examinations

    These uses fall into a regulated category. They follow a reinforced procedure: AITO validation, impact assessment, human oversight, traceability.

    Common core, legal framework; AI Act Compliance Framework, annex A1.

  4. Deciding that a dataset is anonymous

    Effective pseudonymisation does not remove personal data status. On rich text, anonymisation is rarely achievable, and validating it falls to the Data Protection Officer.

    Common core, data classification; GDPR, Article 4(5) and Recital 26.

Write to the AITO

An incident is reported, not forgotten

Personal data sent to an unapproved tool, content published without checking, a shared account. The charter is plain on this point: an isolated breach, reported and corrected, will always be treated more favourably than one hidden and persistent.

Common core, sanctions, graduated principle.