Key questions to consider when writing your association's AI charter

“Hold on, I’ll ask ChatGPT,” “Bruno’s Notetaker has joined the meeting”… Generative AI has become a part of our daily professional lives, and with so many tools and features, it’s hard to keep track: often, it’s all over the place.

Which tools can be used, and for what purpose? What information can be shared without risking harm to my beneficiaries or partners? If, like us, you find yourself grappling with these questions, it's probably time to develop a common framework for using these tools within your organization. But where to start?

To help answer these questions, we've put together a short guide to assist you in developing an AI charter tailored to your activities, drawing on the experience of Paul, Data Protection Officer (DPO) at pass Culture.

☀️Check out the end of the article to discover pass Culture's AI charter and Paul's insights! 😉

Why establish guidelines for internal AI use?

The question is worth asking as soon as one or more members of your organization use AI tools, even occasionally. These technologies are still new, can be divisive, and carry risks (legal, social, environmental, etc.).

Developing a charter allows you to:

- Share a common vision and language : it's an opportunity to discuss and raise awareness among your teams to agree on your stance and a clear framework to follow.

- Identify key areas of concern (data, automated decisions, generated content), especially if you deal with sensitive topics.

- Define best practices tailored to your context.

- Reassure your beneficiaries and partners by showing them that you have considered your practices and are implementing measures to reduce AI-related risks.

Key principles for an effective charter

Nothing is worse than vague rules, disconnected from practical realities, and imposed unilaterally! To get teams on board:

- One guiding principle: co-create. For teams to buy into and respect your charter, they must have been involved in its drafting.

- Create rules tailored to your activity : no copy-pasting a generic charter (or one generated by AI 🤭); start from questions and concrete cases you've encountered. Use examples that resonate with you and fit your context. Avoid overly generic phrases (e.g., "everyone is responsible for their actions"), which don't sufficiently clarify the course of action.

- Develop clear and accessible rules for all : avoid technical jargon. Your charter must be understood by all stakeholders in the association, including occasional volunteers. It can refer to educational resources for further learning.

- Plan for awareness and training sessions : drafting a charter can be an opportunity to raise awareness among teams (especially thanks to the AI Battle, we'll tell you more about it shortly).

- Keep the charter alive! Once drafted, don't let your charter fall by the wayside: present it to the teams, communicate it to your beneficiaries and partners, and schedule time for it to evolve. ☀️ Paul's tip: plan for a "flexible" implementation phase for the charter, to benefit from feedback from your collaborators, to strengthen or relax it.

So, where do we start?

1-Designate a point person who will be responsible for coordinating the project, and identify people who can be consulted ****: ideally employees, volunteers, and beneficiaries to reflect the different viewpoints of your association.

2-Map the existing situation : list everyone's current practices (content creation, administrative management, data analysis, beneficiary relations, fundraising…), as well as their fears and desires.

3-Identify the values of your associative project (solidarity, transparency, respect for dignity, inclusion...) that should be reflected in your use of AI. Example: the Culture Pass aims to keep humans at the heart of the organization, ensuring users that decisions affecting them would never be fully automated.

4-Organize thematic workshops (we've prepared a list for you below 👇) For each theme, collectively answer the suggested questions to develop rules, best practices, and safeguards.

A (non-exhaustive) list of key themes to address

1. Governance, decision-making framework

Issue : Who decides what, and how to ensure the charter is applied?

Key questions:

- Who approves the introduction of a new AI tool? Based on what criteria (cost, ethics, regulatory compliance, security)?

- Is the charter binding or merely recommended? Are there consequences for non-compliance? (e.g., the Culture Pass charter refers to its internal regulations)

- What uses are prohibited within your association? (e.g., automation of HR decisions, automatic evaluation of beneficiaries)

- Who should be contacted in case of doubt or error?

Example: At the Culture Pass, if an employee wishes to use a new tool, they must submit a request to the DPO and the IT security department, who will approve or reject it based on pre-determined criteria (security, sovereignty, environmental impact, etc.). It is forbidden to use AI in certain privileged contexts (e.g., individual interviews), and forbidden to impose an AI tool when an alternative exists.

2. Content Reliability and Responsibility

Issue: AI can produce errors (the famous "hallucinations") or amplify biases. Who verifies the quality of the content produced? Who assumes responsibility for it?

Questions to address:

- Should all AI-generated content be reviewed by a human before publication?

- Who is responsible for the reliability of AI-generated content: the person who generated it, the person in charge of the relevant scope within the association, or someone else?

- For which uses is AI too risky? (e.g., legal advice, medical information, decisions affecting beneficiaries)

- How can teams be trained to identify errors and biases in generated content?

Practical example: The Culture Pass requires a systematic critical review of all AI-generated documents by the person who generated them or who is responsible for that part of the activity before publication or transmission.

3. Data Protection and Confidentiality (GDPR)

The challenge: AI tools often store the data entrusted to them. How can you protect the sensitive information of your beneficiaries, employees, and partners?

Questions to address:

- What data can be shared with AI? Which are prohibited? (personal data, sensitive data as defined by GDPR, internal confidential information)

- Should we opt for paid licenses and configure certain AI tools for enhanced security, especially if there's a need to work with personal or sensitive data?

- Are free tools allowed? Under what conditions?

- How can data be anonymized before being used with AI?

- What is the procedure in case of a data breach or suspected data breach?

Example: Pass Culture strictly prohibits the injection of sensitive data, regardless of an tool's confidentiality guarantees. If an employee makes a mistake, they are required to report it immediately to the IT security department.

☀️ Paul's Tip: To err is human! Initially, it's better to encourage users to report an "accidental" confidential data share rather than immediately imposing sanctions.

4. Equity and Anti-Discrimination

The Challenge: AI algorithms can reproduce and amplify discriminatory biases (gender, origin, age, etc.).

Key Questions:

- For each intended use, what are the risks of discrimination?

- How to test and monitor biases in the tools you use?

- Is AI acceptable for decisions impacting individuals? (candidate selection, aid allocation, beneficiary evaluation)

- How can you ensure that your use of AI respects your values of inclusion and equality?

Example: At Pass Culture, it is forbidden to automate recruitment decisions, which are particularly sensitive. AI is also prohibited for any decisions concerning an employee in the context of their manager's evaluation. In short, recruitment and annual evaluations are "human" moments that Pass Culture has decided to safeguard.

5. Transparency

The Challenge: Strengthen the relationship of trust with your beneficiaries and partners by being transparent about the content they interact with.

Questions to be addressed:

- In which situations should you explicitly mention the use of AI? (emails, published content, chatbots, analyses...)

- What wording should be used? (e.g., "content partially generated by AI")

- Can individuals receiving support refuse to interact with AI?

- How to internally document AI uses to ensure traceability?

E.g.: the Culture Pass systematically adds a dedicated mention to all content, entirely or predominantly created by AI, that is disseminated externally. The case of IT development is also strictly regulated (mention of the AI tool, prohibition of its use for certain critical systems).

6. Digital sobriety and environmental impact

The challenge: AI is extremely energy-intensive, and certain uses (image and video generation) have a particularly high environmental cost.

Questions to be addressed:

- Does the time or efficiency gain of a use case justify the energy expenditure?

- Is there a less energy-intensive alternative to achieve the same goal? (classic search engine, simple human writing...)

- How to limit unnecessary uses?

- How to raise your teams' awareness of the ecological impact of their uses?

Example : the Culture Pass AI charter recommends using AI only within the strict framework of its missions (i.e., avoiding generating an image of a galette for the next snack), and only if the time saving is sufficiently significant.

Alright, time to write!

We suggest this structure:

- Preamble: Why did you create this charter?

- Scope: To whom and what does it apply (your employees, your beneficiaries, etc.)?

- Commitments: The values you identified during your reflection process, which guided the rules you established

- Rules: List the rules that emerged from your discussions on key themes (governance, energy efficiency, etc.). You can also group them by use case (communication, beneficiary relations, etc.) if that makes sense for you.

- Monitoring and Evolution (who to contact if in doubt about procedures, charter revision frequency, etc.)

- In the appendix, educational resources to help you grasp the subject

After drafting: bringing your AI charter to life

Or how to prevent your charter from gathering dust in a drawer

- Have the charter validated by your decision-making bodies to give it legitimacy, then communicate its adoption to your audiences.

- Present the charter to your teams, and incorporate it into the onboarding process for new arrivals.

- Create regular forums for discussion, gather feedback, adjust unclear or unsuitable rules, and document changes to account for new tools and uses.

- Share your experience with other associations!

Need help getting started?

Participate in an AI Battle workshop - ESS version!

**Created by Latitudes, The AI Battle** ESS version is a fun and collaborative 2-hour workshop specifically designed to support impact stakeholders.

Objectives:

- Demystify AI and its main challenges: creativity, bias reproduction, lack of reliability, and impacts on citizenship and the environment.

- Discover and foster discussions on use cases in the ESS (content creation, tools for beneficiaries, data analysis, decision-making support, decision to refuse any use of AI…)

- Identify best practices practical for your organization, which can serve as a basis for your AI charter.

To run the workshop, 2 options:

👉 Train to facilitate the game, via a free online training, to master the workshop and facilitate it independently

👉 Engage Latitudes, who will request a workshop facilitator (subject to availability)

Testimonial from Paul, DPO of Pass Culture

"As Pass Culture is a state operator tasked with a public service mission to democratize and diversify cultural practices among young people, creating a charter on AI use was both a challenge and a necessity. Its development provided an opportunity to establish a common set of values around this growing topic and to initiate a collective reflection on the role we wish to assign to this technology within our organization."

The starting point for this work was a study conducted with employees to better understand their uses, expectations, and concerns regarding this technology. An anonymous consultation form is a good starting point for initiating this work. A first version of this charter was then drafted, and subsequently enhanced/modified by various stakeholders (experts, Works Council, CSR committee, Management Committee, and GDPR Committee). To ensure its dissemination, a dedicated poster is currently being prepared!

We hope this little guide has been helpful!