Skip to content
ISC ParisAI Use Charter

Interactive tool

This data,in this tool

Four questions at most, and you know whether the data may go. The result carries a light, the conditions that apply and the passage of the common core behind it. Below the tool, the list of AITO-approved tools and the route for having a new one assessed.

Staff and faculty

What the tool does

  • It sorts your data into one of the four categories of the common core.
  • It returns a light, the conditions attached to it, and the exact reference in the charter.
  • It computes everything in your browser: nothing is sent, nothing is stored, no AI model is called.

What the tool does not do

  • It grants no authorisation. Confidential data still requires prior approval.
  • It does not replace the list held by the AI Transformation Office, the only one current at the minute you read it.
  • It does not settle what the charter leaves open: it sends you to aito@iscparis.com.

Question 1 of 4

Does this data identify a person, directly or indirectly?

Name, address, grade, student file, CV, health information, photo, phone number, internal identifier.

This result guides you, it does not cover you. If doubt remains, write to aito@iscparis.com before sending anything.

Four categories, four regimes

What you may hand to an AI depends first on the nature of the data. This classification applies everywhere, on every campus.

Public

Examples

Website, brochures, external communications, freely available information.

Any tool

The choice of tool is yours, within the principles of the charter. Verification before circulation still applies.

Internal

Examples

Course material, meeting notes, working documents, ongoing projects.

AITO-approved tools only

No further authorisation to request, but the tool must appear in the list below.

Confidential

Examples

Budgets, examinations, strategy, contracts, sensitive correspondence.

Approved tools plus prior authorisation

Both conditions together, never one or the other.

Personal

Examples

HR data, student files, health, identity.

Prohibited

Prohibited in any tool ISC Paris has not approved. The Data Protection Officer is consulted whenever personal data is involved.

Common core V3, data classification.

Golden rule

If you are unsure which category applies, treat the data as confidential. Doubt is settled before you send, never after.

Pseudonymising does not change the category

A student file with the name removed is still a student file. Effective pseudonymisation, within the meaning of Article 4(5) GDPR, does not remove personal data status: it does not authorise the use of an unapproved tool. Anonymisation within the meaning of Recital 26 is rarely achievable on rich text, and validating it falls to the Data Protection Officer.

Tools approved by the AITO

Only these tools may process internal or confidential data. For public information, the choice of tool remains yours.
Annex A5, list of AITO-approved tools, version 1.0, as it stood on 1 September 2026. Quarterly update: March, June, September, December.
ToolData acceptedHostingIndicative footprintStatus
Conversational assistants and productivity
ClaudeAnthropic, professional plan with training opt-outPublic, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved
ChatGPTOpenAI, professional or Edu plan with training opt-outPublic, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved
Microsoft Copilot 365ISC tenantPublic, internalEuropean Union, ISC tenantStandardApproved
GeminiGoogle, Workspace version with confidentiality guaranteesPublic, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved
PerplexityProfessional planPublic, internalUnited States, transfer covered (DPF, SCCs)StandardApproved
Audiovisual content creation
HeyGenAvatars and generated videoWritten consent of the people concerned is mandatory, for their image.Public, internalUnited States, transfer covered (DPF, SCCs)HeavyApproved with conditions
ElevenLabsSpeech synthesis and voice cloningWritten consent of the people concerned is mandatory, for their voice.Public, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved with conditions
Code and development
Claude CodeAnthropic command line interfaceNo confidential proprietary code without prior validation.Public, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved
OpenAI CodexCommand line or inside the editorNo confidential proprietary code without prior validation.Public, internalUnited States, transfer covered (DPF, SCCs)Standard to heavyApproved
Under assessment
Claude CoworkAnthropic, collaborative workspaceReferred to IT and to the Data Protection Officer. Approval expected before any deployment.To be determinedUnited StatesTo be assessedUnder assessment

Six conditions that apply to every tool

Professional plan

Team, Enterprise or Edu only. Never the free version, and never a personal account for ISC data other than public information.

Training opt-out

Enabled by default in the ISC configuration: no incoming data feeds model training.

Transfer outside the European Union

For tools hosted in the United States, the transfer is covered by the EU-US Data Privacy Framework and, in the alternative, by the European Commission standard contractual clauses.

Personal data

It remains subject to the opinion of the Data Protection Officer. No processing of sensitive data within the meaning of Article 9 GDPR without a prior impact assessment.

Image and voice

HeyGen and ElevenLabs require free, informed, written and revocable consent from the people concerned, with a consent register kept.

Source code

Claude Code and OpenAI Codex process neither proprietary code nor secrets, API keys and credentials included, without prior validation.

Not approved to date

These tools may not process internal or confidential data. Personal use on public information remains possible within the charter.

  • ChatGPT free version, with no training opt-out by default.
  • Consumer AI tools without documented GDPR guarantees.
  • Tools whose publisher has issued no clear retention policy.
  • Tools not entered in the AITO register.

A living list

Added

At any quarterly update.

Suspended

If the publisher changes policy: acquisition, amended terms of service, published security flaw.

Revoked

In the event of a serious incident or confirmed non-compliance.

Every change is emailed to all staff and published on the intranet, page AI Charter, approved tools.

Having a tool assessed

You have found a useful tool that does not appear above. Here is the route, and what it costs in time.

Pre-qualification

Will the tool process anything other than public information? If so, it must be approved. If not, use remains possible within the charter, use statement included.

Request

An email to aito@iscparis.com: the name of the tool and the link to its publisher, the intended use in one or two sentences, the type of data involved, the department or programme concerned.

Assessment

The AI Transformation Office takes one of the three routes below, with the Data Protection Officer and IT. Legal joins in for high-risk uses.

Decision

Approved, approved with conditions, refused, or redirected to an equivalent approved tool.

Registration

If approved, the tool joins the list at the next quarterly update, and the detailed internal register.

Three routes, three timeframes

Fast route

72 working hours

Tools already approved by the French Ministry of Higher Education, Renater, SecNumCloud or a European equivalent. Consistency check and acknowledgement of receipt.

Standard route

2 to 4 weeks

Tools with no high-risk use, public or internal data. Simplified GDPR and security audit, run by the Data Protection Officer and IT.

High-risk route

4 to 8 weeks

Extendable. Major deployments or high-risk uses within the meaning of Annex III of the AI Act. Fundamental rights impact assessment, data protection impact assessment where personal data is involved, IT audit, DPO signature, approval by the AITO and the executive committee.

The eight assessment criteria

Common to all three routes, examined in varying depth.

  • GDPR complianceBlocking
  • Data processing and retention termsBlocking
  • AI Act compliance where the use is high riskBlocking where applicable
  • Opt-out from training on user dataImportant
  • Hosting security: encryption, access, certificationsImportant
  • Technological sovereignty, European preferenceWeighted
  • Indicative environmental footprintWeighted
  • Financial stability of the publisherWeighted

Annex A5, tool approval procedure and criteria. The three routes are set out in the AI Act compliance framework, Annex A1 § 7.2.

A case the charter does not settle

The tool applies written rules, nothing more. Where none covers your situation, the answer is not invented: it is asked for, before anything is sent.