Skip to content
ISC ParisAI Use Charter

Reference text

The common core

The text that applies to everyone at ISC Paris, on every campus. This page gives the full reading of it, section by section, with the anchors you need to point someone at one precise paragraph.

What you are reading here

A reading for the screen, faithful to the text and rewritten to be findable. The official French PDF of version 3.0.1 remains the document that prevails. Where this page and the PDF differ, the PDF wins.

Contents of this page

How the framework is built

One common core, three role guides, five annexes. The core sets the shared rules; the guides say what each population does with them; the annexes carry the working documents.

The text you are reading

Common core

Principles, legal framework, data classification, authorisation levels, use statement, approved tools, governance. It applies to everyone, whatever their status or campus.

Three role guides

Five annexes

  • A1. AI Act compliance frameworkRestricted circulation. Maintained by the AITO with HR, legal affairs and the Data Protection Officer.
  • A2. Syllabus template, levels N0 to N4For assessment briefs.
  • A3. AI use statement templateReady to paste, available on the intranet.
  • A4. AI incident kitWhat to do when a use goes wrong.
  • A5. List of AITO-approved toolsReviewed quarterly, reproduced further down this page.

Internal working documents, available from the AI Transformation Office and on the ISC Paris intranet.

The more protective provision prevails

Where the common core and a role guide diverge, the more protective provision applies. The rule cuts both ways: a guide may tighten the core, it may never loosen it.

The five principles

One sentence each. Everything else in the charter is the manual. They are set out in full on the home page, with their practical consequences.
  1. TransparencyYou use AI. You say so.
  2. ResponsibilityAI proposes. A human validates. A human answers for it.
  3. CautionCheck before you circulate. Doubt by default.
  4. RestraintThe right tool for the job. No more than that.
  5. CuriosityLearn, explore, challenge, adjust.

Read the five principles in full

Four categories of data

What you may hand to an AI depends first on the nature of the data. This classification applies wherever you work with AI.
The light and the word say the same thing. Colour never carries the meaning alone.
SignalCategoryExamplesPermitted AI use
AllowedPublicWebsite, brochures, external communications, freely available information.Any tool
ConditionalInternalCourse material, meeting notes, working documents, ongoing projects.AITO-approved tools only
ConditionalConfidentialBudgets, examinations, strategy, contracts, sensitive correspondence.Approved tools and prior authorisation, both together
ProhibitedPersonalHR data, student files, health, identity.Prohibited in any tool not approved by ISC Paris

Pseudonymising is not enough

Effective pseudonymisation, within the meaning of Article 4(5) GDPR, does not remove personal data status: it is not enough to authorise the use of an unapproved tool. Anonymisation within the meaning of Recital 26 is rarely achievable on rich text data, and validating it falls to the Data Protection Officer. A student file with the name deleted is still a student file.

Test a piece of data in a tool

Five authorisation levels

ISC Paris uses a five-level scale that applies to every academic assessment. The level appears on each brief.
Scale aligned with the AI Assessment Scale (Perkins, Furze, Roe and MacVaugh, 2024).
LevelNameDescriptionPermitted AI intensity
N0No AINo AI assistance. Controlled environment.0 / 4
N1PreparationAI for brainstorming and research. Final output produced without AI.1 / 4
N2AssistanceAI for specific tasks, rewording or structure. Statement mandatory.2 / 4
N3CollaborationAI embedded in the process. Critical thinking and validation required.3 / 4
N4ExplorationCreative use of AI. Command of the tool is assessed.4 / 4

By default

Submitted work at N2. Invigilated exams at N0 or N1. Where the brief says nothing, the default level applies. In case of doubt, the student asks the teacher before starting.

Find the level that applies to a piece of work

AI use statement

Any output that used AI includes a statement. It is short. It is honest. It protects its author.

Four mandatory items

  1. Tools usedName, and version where known.
  2. Parts of the work concernedOutline, rewording, analysis, code, illustrations.
  3. Nature of the assistanceIdeation, drafting, translation, checking, generation.
  4. Checks carried outSources, figures, consistency.
The template
AI USE STATEMENT

Tool(s): [Claude 3.5, ChatGPT-4, Mistral Large]
Parts concerned: [outline, rewording of the introduction, data analysis]
Nature of the assistance: [structuring, translation, checking]
Checks: [sources verified on Google Scholar, figures confirmed against INSEE]

The ready-to-paste template (annex A3) is available on the ISC Paris intranet.

Build a statement

Approved tools

Only tools approved by the AI Transformation Office may process internal or confidential data. For public data you remain free to choose your tool, within the principles of the charter.

List as at 1 September 2026. Reviewed quarterly: March, June, September, December. Precise versions and configurations are consolidated in the internal register. Any tool not listed counts as unapproved for internal or confidential data.

ToolData acceptedHostingEnergy profileStatus
Conversational assistants and productivity
Claude (Anthropic), professional version with training opt-outPublic, internalUnited States, transfer covered by DPF and SCCStandard to heavyApproved
ChatGPT (OpenAI), professional or Edu version with training opt-outPublic, internalUnited States, transfer covered by DPF and SCCStandard to heavyApproved
Microsoft Copilot 365, ISC tenantPublic, internalEuropean Union, ISC tenantStandardApproved
Gemini (Google), Workspace version with confidentiality guaranteesPublic, internalUnited States, transfer covered by DPF and SCCStandard to heavyApproved
Perplexity, professional versionPublic, internalUnited States, transfer covered by DPF and SCCStandardApproved
Audiovisual content creation
HeyGen, AI avatars and videoPublic, internal. Written consent of the people filmed is mandatoryUnited States, transfer covered by DPF and SCCHeavyApproved with conditions
ElevenLabs, speech synthesis and voice cloningPublic, internal. Written consent of the people recorded is mandatoryUnited States, transfer covered by DPF and SCCStandard to heavyApproved with conditions
Code and development
Claude Code (Anthropic CLI)Public, internal. No confidential proprietary code without approvalUnited States, transfer covered by DPF and SCCStandard to heavyApproved
OpenAI Codex (CLI or IDE)Public, internal. No confidential proprietary code without approvalUnited States, transfer covered by DPF and SCCStandard to heavyApproved
Under evaluation
Claude Cowork (Anthropic), collaborative workspaceTo be determinedUnited StatesTo be assessedIT and DPO opinion awaited before deployment

Personal accounts

You may not use a personal AI account to process ISC Paris data other than public data. Approval covers a configuration, not a product name.

Conditions applying to every approved tool

  • Professional, Team, Enterprise or Edu version only, never the free version by default.
  • Training opt-out enabled by default in the ISC configuration: no incoming data feeds model training.
  • Transfers outside the European Union are covered contractually by the EU-US Data Privacy Framework and, in the alternative, by the European Commission Standard Contractual Clauses.
  • Personal data remains subject to the opinion of the Data Protection Officer. No processing of sensitive personal data (Article 9 GDPR) without a prior data protection impact assessment.
  • HeyGen and ElevenLabs: written, free, informed and revocable consent of the people concerned, image or voice, with a consent register kept.
  • Claude Code and OpenAI Codex: no processing of proprietary source code or secrets, API keys, credentials, client data, without prior approval.

Not approved to date

  • ChatGPT free version, without training opt-out by default.
  • Consumer AI tools without documented GDPR guarantees.
  • Tools whose vendor has published no clear retention policy.
  • Tools not entered in the AITO register.

Requesting approval for a tool

Write to aito@iscparis.com with the name of the tool and a link to its vendor, the intended use case in one or two sentences, the type of data involved, and the department or programme concerned. The assessment then takes one of three routes.

  1. Fast route72 working hoursTools already approved by MESR, Renater, SecNumCloud or European equivalents. Consistency check and acknowledgement of receipt.
  2. Standard route2 to 4 weeksTools that are not high risk, public or internal data. Simplified GDPR and security audit by the DPO and IT.
  3. High-risk route4 to 8 weeks, extendableHigh-risk uses within the meaning of Annex III of the AI Act. Full procedure: FRIA, data protection impact assessment where personal data is involved, IT audit, DPO signature, AITO and executive committee approval.

Four possible decisions: approved, approved with conditions, refused, or redirected to an equivalent tool already approved. An approved tool joins the list at the next quarterly update.

Check a piece of data in a tool

Sanctions and applicable law

Breaching the charter exposes you to consequences suited to the nature of the breach, its context and its author. They do not come out of nowhere: they flow from texts that existed before the charter.

The charter creates no disciplinary regime of its own

It sits within pre-existing legal frameworks. Any disciplinary measure flows from the reference texts and the procedures that organise them.

Three populations, three texts

  • StudentsThe ISC Paris academic regulations, adopted by the competent body. Breaching the charter may amount to a breach of academic obligations under those regulations, examined under the procedure they set out: adversarial procedure, disciplinary board, appeal.
  • StaffThe French Labour Code and the ISC Paris internal regulations. No disciplinary sanction is imposed outside the internal regulations in force. The charter sets the professional expectations; the internal regulations set the scale and terms of any sanction.
  • FacultyISC Paris statutes and specific procedures. The charter creates no new contractual or statutory obligations that have not been negotiated. The detailed framework sits in the faculty guide.

A graduated principle

Support comes before sanction. Dialogue stays the priority. An isolated breach, declared and corrected, will always be treated more favourably than one hidden and persistent.

Rights of the person concerned

  • They may explain themselves.
  • The adversarial procedure is respected.
  • They have the rights of appeal set out in the applicable regulations.

Human analysis prevails over any AI detector

No detection score amounts to proof. What decides is the human examination of the work, the context and the person’s explanations, and that alone.

Governance and annual cycle

The charter is a living document. It has a team that carries it, a calendar that revises it, and an indicator that puts the school itself under transparency.

AITO

The AI Transformation Office coordinates ISC Paris AI policy. It approves tools, supports projects, organises training, and monitors regulatory and ethical developments.

Extended AITO

For editorial arbitration and contested cases, the AITO widens to two permanent guests: a designated faculty member appointed by the academic departments, and an elected student appointed by the representative bodies. The Data Protection Officer, IT and HR are consulted whenever a subject falls within their remit.

The revision cycle

  1. JuneAI use survey of students, staff and faculty.
  2. June and JulyStudent focus group, faculty workshop, staff workshop.
  3. Summer and start of termExtended AITO review, amendments integrated.
  4. SeptemberPublication of the minor version: corrections, adjustments, new examples.
  5. Every two yearsMajor revision, structural overhaul where needed.

The charter must be dynamic without being unstable.

Common core, version 3.0

Annual public indicator

Every year, at the September start of term, ISC Paris publishes an AI usage indicator: request volumes, model types, main purposes, change over the past year. The first indicator is published in September 2027. Transparency binds the institution as much as individuals.

How version 3.0 was validated

Presentation to the works council for information and consultation in May 2026, participatory consultation of students, staff and faculty in June 2026, presentation to the executive committee, HR, the academic registry and the Data Protection Officer for approval in July 2026, then a second passage before the works council for its opinion on the final text prior to publication. The text states that these steps are prospective and that the effective dates and opinions given will be updated in the published version.

AI Act, governance and commitments

Glossary

Seven terms, as the charter defines them. Open the one you need.
Generative AI

A system able to produce text, images, code or other content from an instruction.

Prompt

An instruction given to an AI tool to obtain a response.

Hallucination

Content invented by the AI and presented as factual.

Opt-out

Switching off the use of your data to train the model.

Anonymisation

Irreversible removal of the elements that allow a person to be identified.

FRIA

Fundamental Rights Impact Assessment, required by the AI Act before any high-risk deployment.

AITO

AI Transformation Office, the ISC Paris team in charge of AI policy.

Documents to download

The official text is downloaded here. The role guides have their own pages on this site. The annexes are internal working documents.
AI use charter, common core, version 3.0.1PDF, 1.5 MB, FrenchThe official text, in French. This is the document that prevails.

The three role guides

The annexes

  • A1AI Act compliance framework
  • A2Syllabus template, levels N0 to N4
  • A3AI use statement template
  • A4AI incident kit
  • A5List of AITO-approved tools

Internal working documents, available from the AI Transformation Office and on the ISC Paris intranet. They are not published on this site.

A doubt about a specific case

This page settles only what the charter settles. For a case it does not cover, write to the AITO before you act, not afterwards.

aito@iscparis.com

Sources and transparency

What version 3.0 draws on, and what AI did in the drafting.
  • ISC Paris charter v2.1, January 2026.
  • MESR DemoES, Charte d’usages et bonnes pratiques de l’IA, September 2025.
  • ESCP Summit, AI in Higher Education, March 2026.
  • AI Assessment Scale, Perkins, Furze, Roe and MacVaugh, revised version 2, 2024.
  • UNESCO, AI Competency Framework for Students and Teachers, September 2024.
  • Russell Group Principles on Use of Generative AI Tools in Education, 2023, revised 2024.
  • AI Index Report 2026, Stanford HAI.
  • See the Future Study 2026, CarringtonCrisp et al., n = 1,863, 40 countries.
  • HEPI Student Generative AI Survey 2025.
  • Full text of Regulation (EU) 2024/1689, the AI Act.

This charter declares its own use of AI

It was drafted with the assistance of artificial intelligence tools, in line with the principles it sets out.

What AI did: help with structure and consistency, monitoring of sector practice, and first drafts of certain sections, all reworked by people.

What AI did not do: define the values and strategic direction of ISC Paris, settle policy trade-offs, validate content without human supervision, or decide in place of those accountable.