AI literacy
Every member of staff who uses AI at work must have received training suited to their role. ISC Paris is putting that training in place, for staff and students alike, and refreshes the content every year.
Institutional evidence, position as of 7 September 2026
What the European regulation requires of a business school, what ISC Paris has in place to meet it, and where the timeline stands. This page is written first for those who have to check: partners, accreditation auditors, supervisory bodies, journalists, employers.
The position of ISC Paris
ISC Paris undertakes to comply with the AI Act and is bringing itself into compliance on a dated schedule. The school does not declare itself compliant, and will not do so until the obligations are actually met.
No page on this site claims more than that. What follows describes a framework at work: its deadlines, its procedures, and what still lies ahead.
Position set out in the ISC Paris AI Act compliance framework, annex A1 to the charter, version 1.0.
This page completes the common core of the charter. Where the common core and a page diverge, the more protective provision applies.
Read the common coreDeadline passed
2 February 2025
Two sets of rules become applicable: the AI literacy duty on deployers, and the prohibited practices. Emotion recognition in education is banned from this date.
Articles 4 and 5
Deadline passed
2 August 2025
Rules on general-purpose AI models come into application. For a school, they are watched at the level of the vendors behind the tools in use.
General-purpose AI models
Deadline passed
24 July 2026
The regulation known as the Digital Omnibus is published in the Official Journal of the European Union and enters into force three days later. It postpones by sixteen months the requirements applying to high-risk systems under Annex III, education included.
Regulation (EU) 2026/1744
Deadline passed
2 August 2026
The regulation applies generally, transparency obligations included. This is the deadline that set the pace of internal preparation.
General application of the regulation
You are here
7 September 2026
The date this page was last updated. Version 3.0 of the charter came into force at the start of the September 2026 academic year.
Charter V3.0
Ahead
2 December 2027
The full requirements on high-risk uses under Annex III, which covers education and vocational training, become applicable. This date follows the July 2026 postponement; the initial deadline was 2 August 2026.
Annex III, point 3, postponed by Regulation (EU) 2026/1744
Deadlines under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026. Restated in the common core of the charter, Legal framework section, and in the compliance framework, annex A1.
Every member of staff who uses AI at work must have received training suited to their role. ISC Paris is putting that training in place, for staff and students alike, and refreshes the content every year.
Some uses fall into a regulated category: admissions, scoring of assessments, examinations. They follow a reinforced procedure: approval by the AI Transformation Office, impact assessment, human oversight, traceability.
A duty of means
Article 4 requires a sufficient level of AI literacy to be ensured as far as possible. It is a duty of means, not of result. The Commission guidelines that will set the exact perimeter, contractors and subcontractors included, are still awaited.
In education and in the workplace. Banned since 2 February 2025.
Carve-out in the regulationExcept on strictly framed medical or safety grounds.
Outright ban under Article 5.
Vulnerabilities linked to age, disability or social circumstances.
Where it infers sensitive data.
None of these uses may be deployed, tested or trialled at ISC Paris, in any form whatsoever.
Article 5 of the regulation, as restated by the ISC Paris compliance framework.
Annex III of the regulation classifies several uses in education and vocational training as high risk, along with uses in human resources management. Every listed use carries a responsible department, a compliance officer and a state of progress. The list is a live document: reviewed, corrected, extended.
The use is classified against Annex III and against the outright bans. Where there is doubt, the AI Transformation Office decides.
Before any deployment, a fundamental rights impact assessment under Article 27 documents the risks, the mitigation measures and the human oversight arrangements.
The tool is entered in the AI tools register: approved use, data categories accepted, hosting, status of the impact assessment, named owner.
Annual review at the least, brought forward in the event of an incident, a major system update or a regulatory change.
Internal rule
Where the impact assessment is not complete, the use concerned is suspended. The procedure is not bypassed by the calendar.
What this page does not publish
The compliance status, use by use. The framework that carries it is an internal document with restricted circulation, held by the AI Transformation Office together with human resources, legal affairs and the Data Protection Officer. A reasoned request can be sent to aito@iscparis.com.
| Route | What it covers | Indicative time |
|---|---|---|
| Fast route | Tools already approved by a recognised public framework, or already deployed at ISC Paris. Consistency check and acknowledgement of receipt. | 72 working hours |
| Standard route | Tools outside the high-risk category, handling public or internal data only. Simplified data protection and security audit, approval by the AI Transformation Office. | 2 to 4 weeks |
| High-risk route | Uses falling under Annex III: admissions, scoring, exam invigilation, automated marking. Impact assessment, IT audit, sign-off by the Data Protection Officer, approval by the AI Transformation Office and the executive committee. | 4 to 8 weeks, extendable |
A referral can be suspended: a practice that is plainly prohibited, data the school does not control, insufficient guarantees from the provider, or a residual risk judged unacceptable and impossible to mitigate. Any decision to block is given in writing with reasons, and can be reopened on new evidence.
Where personal data has been breached, notification to the French data protection authority follows its own 72-hour deadline.
AI Transformation Office
For editorial arbitration and contested cases, the office widens to two standing guests.
Data Protection Officer
GDPR compliance, impact assessments, register of processing activities. Where GDPR analysis diverges from that of the AI Transformation Office, the Officer’s view prevails.
IT department
Security, hosting, technical integration of deployed tools.
Human resources
Uses within the HR remit, rollout of the training policy.
The data controller under the GDPR remains ISC Paris, represented by its management. The Officer advises and audits, and does not carry compliance in its place. A quarterly meeting formalises the cooperation between the two functions.
“The charter must be dynamic without being unstable.”
ISC Paris publishes its request volumes, the types of model used and the main observed uses every year. The undertaking sits in the text of the charter, not in a supporting speech.
The figures below describe the sector, not the school. ISC Paris will publish its own figures in 2027, from an internal survey run in June 2026 across its three populations.
| Figure | What it says | Source |
|---|---|---|
| 89% | of business school students, teachers and staff use generative AI at least once a week | See the Future Study 2026 |
| 6% and 4% | of teachers, then of students, consider themselves expert in generative AI | See the Future Study 2026 |
| 73% and 46% | of higher education institutions report having an AI policy; only 46% cover classroom use | See the Future Study 2026 |
| 362 | AI incidents documented worldwide in 2025, up 55% on 2024 | AI Index Report 2026, Stanford HAI |
| 40 out of 100 | the transparency of large models, measured at 58 out of 100 in 2024 | AI Index Report 2026, Stanford HAI |
Requests for detail on this framework, including from accreditation bodies, partners and journalists, go to the AI Transformation Office. The official PDF remains the text that prevails.