The text you are reading
Common core
Principles, legal framework, data classification, authorisation levels, use statement, approved tools, governance. It applies to everyone, whatever their status or campus.
Reference text
The text that applies to everyone at ISC Paris, on every campus. This page gives the full reading of it, section by section, with the anchors you need to point someone at one precise paragraph.
What you are reading here
A reading for the screen, faithful to the text and rewritten to be findable. The official French PDF of version 3.0.1 remains the document that prevails. Where this page and the PDF differ, the PDF wins.
The text you are reading
Principles, legal framework, data classification, authorisation levels, use statement, approved tools, governance. It applies to everyone, whatever their status or campus.
Three role guides
Five annexes
Internal working documents, available from the AI Transformation Office and on the ISC Paris intranet.
The more protective provision prevails
Where the common core and a role guide diverge, the more protective provision applies. The rule cuts both ways: a guide may tighten the core, it may never loosen it.
You do not send other people’s personal data to an AI tool that ISC Paris has not approved. That covers data on students, staff, applicants and partners. The rule admits no convenience exception: an urgent need does not create an authorisation.
Adopted in June 2024, it applies in stages. Three dates matter for a school, and education is among the uses the regulation classifies as high risk.
The timeline
Every member of staff who uses AI at work must have received training suited to their role. ISC Paris is putting that training in place.
Admissions, assessment scoring and examinations fall into a regulated category. They follow a reinforced procedure: AITO approval, impact assessment, human oversight, traceability.
What the school actually says
ISC Paris undertakes to comply with the AI Act and to adjust its charter as European and national guidance appears. The school does not declare itself compliant for all that. The distinction is not rhetorical: compliance is built, it is not proclaimed.
The technical detail of the compliance work sits in a dedicated internal document, the ISC Paris AI Act Compliance Framework (annex A1). It is maintained by the AITO with HR, legal affairs and the Data Protection Officer.
| Signal | Category | Examples | Permitted AI use |
|---|---|---|---|
| Allowed | Public | Website, brochures, external communications, freely available information. | Any tool |
| Conditional | Internal | Course material, meeting notes, working documents, ongoing projects. | AITO-approved tools only |
| Conditional | Confidential | Budgets, examinations, strategy, contracts, sensitive correspondence. | Approved tools and prior authorisation, both together |
| Prohibited | Personal | HR data, student files, health, identity. | Prohibited in any tool not approved by ISC Paris |
Effective pseudonymisation, within the meaning of Article 4(5) GDPR, does not remove personal data status: it is not enough to authorise the use of an unapproved tool. Anonymisation within the meaning of Recital 26 is rarely achievable on rich text data, and validating it falls to the Data Protection Officer. A student file with the name deleted is still a student file.
| Level | Name | Description | Permitted AI intensity |
|---|---|---|---|
| N0 | No AI | No AI assistance. Controlled environment. | 0 / 4 |
| N1 | Preparation | AI for brainstorming and research. Final output produced without AI. | 1 / 4 |
| N2 | Assistance | AI for specific tasks, rewording or structure. Statement mandatory. | 2 / 4 |
| N3 | Collaboration | AI embedded in the process. Critical thinking and validation required. | 3 / 4 |
| N4 | Exploration | Creative use of AI. Command of the tool is assessed. | 4 / 4 |
By default
Submitted work at N2. Invigilated exams at N0 or N1. Where the brief says nothing, the default level applies. In case of doubt, the student asks the teacher before starting.
Four mandatory items
AI USE STATEMENT Tool(s): [Claude 3.5, ChatGPT-4, Mistral Large] Parts concerned: [outline, rewording of the introduction, data analysis] Nature of the assistance: [structuring, translation, checking] Checks: [sources verified on Google Scholar, figures confirmed against INSEE]
The ready-to-paste template (annex A3) is available on the ISC Paris intranet.
List as at 1 September 2026. Reviewed quarterly: March, June, September, December. Precise versions and configurations are consolidated in the internal register. Any tool not listed counts as unapproved for internal or confidential data.
| Tool | Data accepted | Hosting | Energy profile | Status |
|---|---|---|---|---|
| Conversational assistants and productivity | ||||
| Claude (Anthropic), professional version with training opt-out | Public, internal | United States, transfer covered by DPF and SCC | Standard to heavy | Approved |
| ChatGPT (OpenAI), professional or Edu version with training opt-out | Public, internal | United States, transfer covered by DPF and SCC | Standard to heavy | Approved |
| Microsoft Copilot 365, ISC tenant | Public, internal | European Union, ISC tenant | Standard | Approved |
| Gemini (Google), Workspace version with confidentiality guarantees | Public, internal | United States, transfer covered by DPF and SCC | Standard to heavy | Approved |
| Perplexity, professional version | Public, internal | United States, transfer covered by DPF and SCC | Standard | Approved |
| Audiovisual content creation | ||||
| HeyGen, AI avatars and video | Public, internal. Written consent of the people filmed is mandatory | United States, transfer covered by DPF and SCC | Heavy | Approved with conditions |
| ElevenLabs, speech synthesis and voice cloning | Public, internal. Written consent of the people recorded is mandatory | United States, transfer covered by DPF and SCC | Standard to heavy | Approved with conditions |
| Code and development | ||||
| Claude Code (Anthropic CLI) | Public, internal. No confidential proprietary code without approval | United States, transfer covered by DPF and SCC | Standard to heavy | Approved |
| OpenAI Codex (CLI or IDE) | Public, internal. No confidential proprietary code without approval | United States, transfer covered by DPF and SCC | Standard to heavy | Approved |
| Under evaluation | ||||
| Claude Cowork (Anthropic), collaborative workspace | To be determined | United States | To be assessed | IT and DPO opinion awaited before deployment |
Personal accounts
You may not use a personal AI account to process ISC Paris data other than public data. Approval covers a configuration, not a product name.
Write to aito@iscparis.com with the name of the tool and a link to its vendor, the intended use case in one or two sentences, the type of data involved, and the department or programme concerned. The assessment then takes one of three routes.
Four possible decisions: approved, approved with conditions, refused, or redirected to an equivalent tool already approved. An approved tool joins the list at the next quarterly update.
The charter creates no disciplinary regime of its own
It sits within pre-existing legal frameworks. Any disciplinary measure flows from the reference texts and the procedures that organise them.
Support comes before sanction. Dialogue stays the priority. An isolated breach, declared and corrected, will always be treated more favourably than one hidden and persistent.
Human analysis prevails over any AI detector
No detection score amounts to proof. What decides is the human examination of the work, the context and the person’s explanations, and that alone.
The AI Transformation Office coordinates ISC Paris AI policy. It approves tools, supports projects, organises training, and monitors regulatory and ethical developments.
For editorial arbitration and contested cases, the AITO widens to two permanent guests: a designated faculty member appointed by the academic departments, and an elected student appointed by the representative bodies. The Data Protection Officer, IT and HR are consulted whenever a subject falls within their remit.
The revision cycle
The charter must be dynamic without being unstable.
Common core, version 3.0
Every year, at the September start of term, ISC Paris publishes an AI usage indicator: request volumes, model types, main purposes, change over the past year. The first indicator is published in September 2027. Transparency binds the institution as much as individuals.
Presentation to the works council for information and consultation in May 2026, participatory consultation of students, staff and faculty in June 2026, presentation to the executive committee, HR, the academic registry and the Data Protection Officer for approval in July 2026, then a second passage before the works council for its opinion on the final text prior to publication. The text states that these steps are prospective and that the effective dates and opinions given will be updated in the published version.
A system able to produce text, images, code or other content from an instruction.
An instruction given to an AI tool to obtain a response.
Content invented by the AI and presented as factual.
Switching off the use of your data to train the model.
Irreversible removal of the elements that allow a person to be identified.
Fundamental Rights Impact Assessment, required by the AI Act before any high-risk deployment.
AI Transformation Office, the ISC Paris team in charge of AI policy.
Internal working documents, available from the AI Transformation Office and on the ISC Paris intranet. They are not published on this site.
This page settles only what the charter settles. For a case it does not cover, write to the AITO before you act, not afterwards.
aito@iscparis.comIt was drafted with the assistance of artificial intelligence tools, in line with the principles it sets out.
What AI did: help with structure and consistency, monitoring of sector practice, and first drafts of certain sections, all reworked by people.
What AI did not do: define the values and strategic direction of ISC Paris, settle policy trade-offs, validate content without human supervision, or decide in place of those accountable.