Blog

Co-design the AI ​​usage charter for your organization

Illustration of a charter for secure AI

An AI usage charter is a policy document that establishes the rules, responsibilities, and boundaries for deploying artificial intelligence tools within an organization. It protects sensitive data, frames team practices, and reassures clients, partners, and regulators. When properly constructed, it draws on three essential references: the European AI Regulation, the GDPR, and DINUM's recommendations for public-sector employees.


In brief:

  • Implementing an AI usage charter must address human accountability, data protection, transparency, resource efficiency, and ongoing training.
  • Every tool deployment should be documented with its purpose, the data processed, the risk level, and mitigation measures to ensure compliance.
  • Regular governance through a dedicated committee tracks tool evolution and prevents the framework from becoming outdated, while verifying team buy-in.
  • Operational pseudonymization of sensitive data upstream of AI queries limits the risk of personal information leakage while enabling productive use.
  • Integrating pseudonymization into workflows can be an effective technical measure that strengthens GDPR compliance without impeding productivity.

Table of Contents

Why Launch an AI Usage Charter Now

A charter is not drafted as an administrative formality. It serves three concrete objectives: staying compliant with regulations that have been accumulating since 2024, maintaining control over the risks generative AI poses to enterprise data, and building internal and external trust-trust that evaporates the moment an employee pastes a confidential contract into a public chatbot.

Certain signals should trigger action immediately:

  • Deployment of generative AI tools within teams, even informally.
  • Regular handling of personal data or confidential documents.
  • Use of service providers or subcontractors who themselves employ third-party AI systems.

Involving legal, IT, HR, and business representatives from the outset prevents drafting a theoretical document that no one will follow.

Core Principles the Charter Must Address

The interministerial guide published by DINUM structures its recommendations around five principles, and this framework applies equally well in the private sector.

1. Human accountability. A decision affecting a person or contract must never rely solely on unverified AI output.

2. Data protection. No personally identifiable data should flow through a public AI system not controlled by the organization.

3. Transparency. The use of AI in producing content or analysis must be disclosed, both internally and to clients.

4. Resource efficiency. Every query has an energy cost; the charter should encourage judicious rather than automatic use.

5. Ongoing training. Teams must know how to recognize hallucinations, biases, or potential data leaks.

Pro tip: Frame each principle as a verifiable rule, not an abstract value. "Never paste a social security number into a prompt" is enforceable; "respect confidentiality" is not.

What the AI Act and GDPR Concretely Require of Your Charter

The European AI Regulation, which entered into application in 2024, establishes a harmonized framework for the European Union. It imposes technical documentation and transparency obligations that primarily affect three categories:

  • High-risk AI systems, governed by Articles 11 and 13 on technical documentation and transparency.
  • General-purpose AI models, addressed by Article 53.
  • Organizations deploying these systems internally, even without developing them in-house.

The AI Act does not replace the GDPR; the two texts work in tandem. CNIL emphasizes that the data protection impact assessment remains applicable and complementary, and recommends combining the DPIA and the fundamental rights impact assessment into a single document rather than duplicating them.

Your charter must therefore specify what will be documented for each tool deployment: the purpose, the nature of data processed, the risk level, and the mitigation measures adopted. Without this written record, demonstrating compliance during an audit is impossible. This topic is explored in depth in our guide on contract confidentiality and artificial intelligence.

How to Design an AI Usage Charter Step by Step

Co-design and use-case mapping strengthen ownership of the final text far more effectively than a charter imposed from the top down.

1. Assemble a cross-functional team. Legal, IT, HR, one or two representative business units, and ideally an employee who already uses AI daily.

2. Map actual usage, not just official usage. Ask teams which tools they already use, even without formal authorization.

3. Classify the sensitivity of data handled in each use case: public, internal, confidential, personal.

4. Define three authorization levels for each tool: prohibited, subject to approval, authorized without restriction.

5. Draft, validate, train, audit. Set a realistic timeline with an identified owner for each stage.

In practice, this classification produces outcomes like these:

  • Prohibited: pasting client contracts or HR files into a public chatbot without prior processing.
  • Subject to approval: using a code assistant on an internal repository, with peer review.
  • Authorized without restriction: rephrasing generic text without sensitive data.

Training and auditing are not optional add-ons. Without them, the charter remains a PDF no one revisits after signing.

Annexes That Make the Charter Truly Actionable

A static charter becomes obsolete within months, given how rapidly tools evolve. The solution adopted by several organizations is to separate stable principles from revisable annexes:

  • A map of authorized tools, classified by the sensitivity level of data they may process.
  • A simplified DPIA template covering both GDPR requirements and the documentation expected by the AI Act for internal deployers.
  • A standard audit form and a role-based sheet describing authorized uses by department.

Never embed the list of tools in the charter body itself. As Café IA notes, managing this list as a dynamic annex avoids republishing the entire document every time a new tool enters the market.

Existing Templates to Avoid Starting from Scratch

Several public documents offer directly reusable language, provided you adapt them to the private-sector context.

For a company, adaptation mainly involves replacing references to public service with internal approval workflows and specifying sanctions for non-compliance, which are absent from administrative charters.

Managing the Charter Over Time: Governance and Audits

A charter without associated governance quickly becomes stale. Assign oversight to a small committee-ethics board, IT-legal group, or existing governance body-meeting at least quarterly to review newly requested tools and reported incidents.

A few simple metrics suffice to measure actual adherence:

  • Number of tools validated and added to the map during the period.
  • Number of incidents or reports related to non-compliant use.
  • Number of audits conducted and their compliance rate.

Pro tip: A centralized registry of AI tool access requests, coupled with an approval workflow, transforms governance into a traceable process rather than an informal meeting. This is often what's missing in charters that fail after six months.

Plan for an explicit review clause every six to twelve months to integrate technological and regulatory developments. The AI Act itself provides for phased implementation through 2027 depending on system categories; a charter frozen at its initial version will mechanically fall behind.

Why Pseudonymization Changes the Game Against Shadow AI

Why pseudonymization changes the game against Shadow AI - overview diagram

Most charters fail on one specific point: they prohibit pasting personal data into public AI but give teams no practical means to verify compliance. The result is Shadow AI continuing in parallel, in the shadow of the official policy.

A pseudonymization layer applied before sending a document to an assistant like ChatGPT or Claude fills this operational gap: it removes identifying information without preventing the team from working normally. This does not replace training or access controls-these three components complement each other. And pseudonymization does not protect against deliberately misused prompts or decisions made without human review; it addresses the risk of leakage, not the risk of poor judgment.

- Jacques

Secure Your AI Queries Without Changing Your Workflow

Other approaches exist to address this risk: filtering network access, blocking certain domains, or intensively training teams to spot sensitive data before each query. These methods take time and never cover every use case.

Safe-doc

A pseudonymization solution can integrate directly into existing workflows, detecting and pseudonymizing many types of sensitive data in real time before a document reaches an external AI-without storing the processed content. For a legal department or IT organization that must demonstrate GDPR compliance while allowing teams to use familiar tools, this means concrete auditability with supporting reports, rather than a rule on paper that's difficult to verify. This type of safeguard can be designated in your charter as a reference technical measure. Consult the page dedicated to pseudonymization, compliance, and audit functions to see how to integrate it into your own framework.

Sources

Recommendations