Staff guide, version 3.0.1, in force since September 2026
Which tool, which data,who signs
Three questions cover most working days. This guide answers them for support functions and managers: what you may hand to an AI, with which tool, under which condition, and who remains accountable for what comes out.
All campuses. Administrative staff, support functions and managers.
The four rules everything else follows from
Approved tools for sensitive data
No internal, confidential or personal data goes to a tool the AI Transformation Office has not approved.
Human control before circulation
AI proposes, you validate. The signature and the responsibility for the output remain yours.
Transparency about use
Where AI has contributed significantly to a deliverable, you say so to the recipients concerned.
The right tool for the job
A light model for a simple task, a powerful one when the task warrants it. Restraint is part of professional standards.
Your documents, four categories
| Category | Your everyday documents | Tool allowed | Detail |
|---|---|---|---|
| Public | Website, brochures, press releases, news already published. | Any tool | No tool restriction. Proofreading before circulation still applies. |
| Internal | Meeting notes, minutes, ongoing projects, unpublished working material. | AITO-approved tools | The list is reviewed quarterly by the AI Transformation Office, annex A5. |
| Confidential | Budgets, contracts, strategy, competitive intelligence. | Approved tools plus your manager’s authorisation | Both conditions together, never one or the other. |
| Personal | HR data, student files, applicants, alumni. | Prohibited outside an approved tool | Effective pseudonymisation within the meaning of Article 4(5) GDPR does not remove personal data status. Anonymisation within the meaning of Recital 26 is rarely achievable and requires prior validation by the Data Protection Officer. |
The chain of questions
Does my task involve personal data?
YesStop
Pseudonymisation required, approved tool and a documented legal basis. Without all three, the use is prohibited.
NoMove on to the next question.
Does my task involve confidential data?
YesConditional
AITO-approved tools only, plus your manager’s authorisation.
NoMove on to the next question.
Does my task involve internal data?
YesRestricted
AITO-approved tools only.
NoMove on to the next question.
Does my task involve public data only?
YesAllowed
Every tool is allowed.
In every case
- Read and validate before circulating.
- Declare the use where the AI contribution is significant.
- Pick the right tool for the job.
If the doubt persists, write to aito@iscparis.com. The charter does not settle every particular case, and nobody expects you to guess.
Match a data type with a toolDepartment by department
Human resources
| Use | Status | Condition |
|---|---|---|
| Drafting job adverts | Allowed | Tailoring and proofreading are mandatory. |
| CV screening | Restricted | Assistance only, human decision, traceability. |
| Interviews | Restricted | Pre-selection at most, then 100% human. |
| Performance reviews | Prohibited | AI neither grades nor ranks people. |
| Compiling metrics | Allowed | Aggregated and anonymised data. |
| Designing internal training | Allowed | Educational validation before release. |
Communications and marketing
| Use | Status | Condition |
|---|---|---|
| Content writing | Allowed | Validation before release. |
| AI-generated visuals | Allowed | Label “Image generated by AI” where relevant. |
| Social media | Restricted | Human validation of every post. |
| Replies to comments | Restricted | First-line FAQ only, human escalation within 2 hours. |
| Photo retouching | Allowed | Minor retouching only, no misleading transformation. |
Any content intended for external audiences goes through manager validation before release.
Administration and student services
| Use | Status | Condition |
|---|---|---|
| Answering student FAQ emails | Allowed | Say it is AI-assisted where relevant, with human escalation planned within 24 hours. |
| Handling individual student files | Prohibited | Personal data, unless an approved tool is used with effective pseudonymisation. |
| Calculations and formatting | Allowed | Double checking is mandatory. |
| Meeting minutes | Allowed | Participants validate before circulation. |
| Processing applications | Restricted | Assistance only, human decision. |
Technical and IT services
| Use | Status | Condition |
|---|---|---|
| Code generation | Allowed | Review, tests and security validation are mandatory. |
| Technical documentation | Allowed | Factual verification. |
| User support | Allowed | First line, human escalation where needed. |
| Log analysis | Allowed | Pseudonymised data, approved tool. |
| Security incident detection | Restricted | Coordinated with the AITO and the Data Protection Officer. |
Finance, executive and strategic functions
| Use | Status | Condition |
|---|---|---|
| Preparing material for governing bodies | Allowed | Approved tools, systematic sign-off by the line manager before circulation. |
| Summarising internal strategy documents | Restricted | Approved tools only, no external transmission. |
| Sending a strategy, a budget or an M&A project to an unapproved tool | Prohibited | No exception. |
| Preparing financial communications | Restricted | Approved tools, sign-off by the Finance Department, figures checked at source. |
| Generating strategic scenarios | Allowed | Approved tools, raw material to challenge, never a conclusion. |
The sensitivity of these files calls for a conservative stance: when in doubt, do not use AI and ask the Executive Committee.
What is not open to discussion
- Sending HR data, employee files, salaries, appraisals or medical data to an unapproved AI tool.
- Sending confidential or strategic financial data, budgets, forecasts or negotiations, to an unapproved tool.
- Sending personal data about students or applicants to an unapproved tool.
- Using an unapproved AI tool for internal data.
- Letting AI take a decision affecting a person on its own.
- Circulating AI output without human proofreading.
Four cases pass, under conditions
- Recruitment
- AI may assist initial screening. The decision is human. Anyone whose file is processed has the right to be told if AI contributed.
- Staff appraisal
- AI is not used to grade or rank people. It may compile objective, aggregated metrics.
- External communications
- Manager validation before release.
- Pseudonymised data
- Allowed on approved tools, provided the pseudonymisation is real and verified.
Validation tiers
| Tier | What it is | Example | Control required |
|---|---|---|---|
| M1Task automation | A simple, isolated, low-risk task. AI assists a one-off act. | Drafting an email, formatting a document, translating a press release. | AI charter and approved tools. No specific procedure. |
| M2Workflow augmentation | A chain of actions, with systematic human supervision at every sensitive step. | CV screening with human validation, lead qualification with proofreading. | AI charter, approved tools, documented traceability, manager informed. |
| M3Institutional infrastructure | Deployment embedded in an institutional process that affects people. | An application pre-ranking tool rolled out for a whole intake. | Mandatory referral to the AITO, ISC AI Act Compliance Framework (annex A1), FRIA analysis under Article 27 of the AI Act, compliance with Articles 12 to 14 (auditability, explainability, human oversight), continuous supervision. Go-live only after a favourable opinion. |
ISC Paris undertakes to comply with the European regulation on artificial intelligence (EU 2024/1689) and to put in place the arrangements required by the applicable deadlines: AI literacy since 2 February 2025, full application on 2 August 2026.
Three procedures, depending on what you are starting
A one-off use
- Identify the type of data involved.
- Choose an approved tool if the data is internal or confidential.
- Choose the model that fits the task.
- Read and validate the output before circulating it.
- Mention the use of AI where the contribution is significant.
A new AI process
- Identify the need, the data involved, the potential impact on people.
- Refer to the AITO beforehand, all the more so at tier M2 or M3.
- Document it: objective, tool, data, controls, supervision.
- Train the people concerned before go-live.
- Review after three months: relevance, quality, restraint, incidents.
Content intended for external audiences
- AI-assisted production.
- Proofreading by the author.
- Manager validation.
- Mention of the AI contribution where significant.
- Release.
Admissions and recruitment
| Use | Status | Condition |
|---|---|---|
| AI screening or pre-ranking of application files | Restricted | Assistance only. Human decision mandatory. Traceability of every decision. No automated score may be held against an applicant. |
| Standard replies to information requests | Allowed | Approved tool, say it is AI-assisted where relevant. |
| Help drafting qualitative feedback | Allowed | Tailoring and proofreading are mandatory. |
| Final admission or rejection decision | Prohibited if automated | Human decision, reasoned, explainable. |
| Deploying an AI tool inside the process | Conditional | Mandatory referral to the AITO beforehand, FRIA process under the AI Act Compliance Framework, annex A1, before go-live. |
- Any applicant whose file is processed with AI assistance has the right to be told.
- No applicant may be rejected on the sole basis of an automated score.
- The same rule holds for internal recruitment: AI assists the screening, it does not decide.
Sanctions: what the charter does not do
An inappropriate use, once observed, first leads to a conversation, to understand, support and correct. The charter is there to protect, not to punish.
Any disciplinary sanction derives exclusively from the ISC Paris internal rules and is applied through the procedures they set out: prior interview, adversarial procedure, right of appeal, in strict compliance with the French Labour Code, in particular Articles L.1321-1, L.1331-1 and L.1332-2. The internal rules set the scale and the terms of any sanction.
| Type of breach | First response | Applicable procedure |
|---|---|---|
| First minor breach, isolated, self-declared | Reminder of the rules, support | Conversation with the manager |
| Repeat or significant breach | Response under the internal rules | HR procedure under the internal rules |
| Established or serious misconduct: deliberate leak, concealment, harm to people | Response under the internal rules and the Labour Code | Legal procedure, employment law |
The chain of responsibility counts
Responsibility for a collective or organisational breach does not fall mechanically on the end user. Where a non-compliant deployment was requested, ordered or knowingly tolerated by a manager, the disciplinary procedure takes the management chain into account.
Your rights
- The right to an explanation, to dialogue, and to assistance from a staff representative.
- The right to training where the breach stems from a gap in knowledge.
- An adversarial procedure, respected.
- Appeal to HR, then through the channels set out in the internal rules and the Labour Code.
Refuse, report, be protected
Refuse
You cannot be sanctioned for refusing to carry out an instruction that is manifestly contrary to the charter or to the law.
- Your manager asks for an AI use that looks contrary to the charter.
- Voice your doubts with the text in hand. If the disagreement persists, ask the AITO or HR.
- Your manager asks you to deploy an unapproved AI tool.
- Refuse the deployment and send the request to the AITO. This rule protects the institution, your manager and you.
Be protected
- Confidentiality: the reporter’s identity is shared only with the people strictly needed to handle the case.
- No retaliation: no adverse measure will be taken against someone who reported in good faith.
- Support: the reporter may be followed up by the AITO or HR, on request.
Protection in line with whistleblower status, French Sapin II Act, provisions applicable to the private sector.
The flip side: established abuse
The reporting mechanism is not an instrument for settling scores. A report found to be manifestly abusive, defamatory or made in established bad faith exposes its author to the applicable disciplinary procedure and, where relevant, to the consequences provided by law, in particular Article 226-10 of the French Criminal Code, false accusation.
A report that turns out to be partly unfounded stays protected as long as it was made in good faith: doubt benefits the reporter. The person reported has the right to be informed, unless that risks destruction of evidence or obstruction of the investigation, the right to an adversarial procedure and the right to assistance from a staff representative.
Incident: the first moves
You sent sensitive data to an unapproved tool
- Stop using it at once, and do not interact with the tool again in the same session.
- Document it: which tool, which data, what date and time, how many requests.
- Report without delay to your manager and to aito@iscparis.com.
- Keep the traces: screenshots, copies of the prompts, exports where possible.
- Do not patch it up alone. Undocumented self-correction makes things worse.
You suspect a data leak
- Alert the AITO immediately, subject line “SUSPECTED LEAK, AI”, and the Data Protection Officer.
- Touch nothing: delete no message, no screenshot, no session.
- Document what you saw: who, what, where, when, source, available evidence.
- Do not spread it beyond what is strictly necessary, your direct manager and the AITO.
You observe a manifestly non-compliant use
- Talk to the person concerned first, where that is possible.
- If it goes beyond you, or if you fear retaliation, refer it to the AITO or HR.
The clocks that start running
| Step | Deadline |
|---|---|
| Acknowledgement of a report | Within 24 working hours |
| Notification to the CNIL where required, Article 33 GDPR | Within 72 hours |
| Joint investigation by the DPO, IT and the AITO into a suspected leak | Within 7 working days |
| Corrective measure | Within 30 days |
For an urgent situation, write straight to aito@iscparis.com with the subject line: URGENT, AI INCIDENT.
Psychological distress: a separate route
Emotional dependence or distress linked to AI use goes neither through the AITO nor through your manager. Such reports are health data within the meaning of Article 9 GDPR: they are handled exclusively by the University Health Service, under medical confidentiality. In a crisis, 3114, the French national suicide prevention line, answers around the clock, free and anonymously.
The AI incident kit, annex A4, sets out the full procedure, the contacts and the reporting form.
Restraint and training
A light model for a simple task
The heaviest models are kept for the uses that warrant them: complex analysis, long reasoning, demanding creative work. To reword a sentence or fix a typo, a modest model is enough.
No needless high definition
A thumbnail does not need a 4K image. An internal note does not need layout generated image by image.
A published indicator
ISC Paris undertakes to publish an aggregated indicator of its AI use every year: volume, types of models used, main uses. It takes effect with version 3.1.
Training
Since 2 February 2025, Article 4 of the AI Act has required organisations using AI to ensure a sufficient level of AI literacy among the people concerned. ISC Paris meets that obligation through its training plan.
One core course, mandatory for everyone, then further courses according to your role. They are taken online, at your own pace, in video micro-modules of twelve to fifteen minutes.
| Course | Duration | Audience |
|---|---|---|
| Using AI safely at work | 1 h | All staff, mandatory |
| The AI Act in two hours, for decision-makers | 2 h | Managers, leadership, heads of department |
| The AI Act for data protection officers | 6 h 30 | Compliance, data protection, legal |
| The AI Act: five costly misconceptions | 45 min | Discovery, open access |
Each course awards a personal certificate, after a final quiz passed at 80 per cent. That certificate is the individual, datable proof that the training required by Article 4 has actually been received.
See the courses on the ISC Paris academy
The AI Transformation Office supports departments: identifying use cases, setting up secure processes, training teams. Monthly sessions, hands-on workshops, drop-in hours.
A case this guide does not settle?
Write to aito@iscparis.com rather than guess. A question asked always costs less than data sent to the wrong place.
Source: ISC Paris AI Use Charter, staff guide, version 3.0.1, September 2026, and annex A4, AI incident kit. The official French PDF prevails.