The charter tools, version 3.0.1
Start fromthe task
Four tools for the four questions people actually ask. They apply what the common core says, nothing more. Where the charter does not decide, they send you to the AI Transformation Office rather than guess.
By the task
- This data, in this toolI have a document and I want to hand it to an AIA green, amber or red light, with the exact reference in the charter.Who it is forStaff, facultyWhat it asksFour questions at mostYou leave withThe applicable regime, its conditions, and the passage of the common core behind it.
- Which level applies to my workI have work to submit: how far may I go?Three questions, the applicable level and what it permits.Who it is forStudentsWhat it asksThree questionsYou leave withYour level, from N0 to N4, and the statement it expects.
- AI use statement builderI used AI and I have to declare itA block to copy, ready to paste at the end of a document.Who it is forEveryoneWhat it asksFour fields to fill inYou leave withThe text of your statement, ready to copy.
- Syllabus blockI am setting a brief and I must state the levelThe level and its conditions, worded for an assessment brief.Who it is forFacultyWhat it asksOne level to choose, from N0 to N4You leave withThe block to paste into your assessment brief.
What no tool decides
Getting a tool approved when it is not on the list
You write to the AI Transformation Office. The procedure takes four to eight weeks depending on the complexity of the deployment and the level of risk.
Common core, AITO-approved tools.
Obtaining authorisation for confidential data
Our tools tell you that prior authorisation is required, on top of an approved tool. They do not grant it: you ask for it, and before you send anything.
Common core, data classification.
A high-risk use: admissions, grading, examinations
These uses fall into a regulated category. They follow a reinforced procedure: AITO validation, impact assessment, human oversight, traceability.
Common core, legal framework; AI Act Compliance Framework, annex A1.
Deciding that a dataset is anonymous
Effective pseudonymisation does not remove personal data status. On rich text, anonymisation is rarely achievable, and validating it falls to the Data Protection Officer.
Common core, data classification; GDPR, Article 4(5) and Recital 26.
An incident is reported, not forgotten
Personal data sent to an unapproved tool, content published without checking, a shared account. The charter is plain on this point: an isolated breach, reported and corrected, will always be treated more favourably than one hidden and persistent.
Common core, sanctions, graduated principle.