Read together with the other Legal Centre documents and the signed order. For relationships governed by Italian law, the Italian version prevails over the bilingual version unless otherwise agreed.
1. Scope and principles
ISOPILOT uses AI to support information gathering, classification, analysis and document drafting. Governance is based on lawfulness, transparency, human control, minimisation, security, source quality, traceability and organisational accountability.
This policy applies to UESE, administrators, users and consultants configuring or using AI features. The Customer must integrate it with its own rules, assessments and training.
2. Roles and responsibilities
- UESE: governs the platform, selects providers, protects keys, defines controls and monitors incidents.
- Superadmin: configures model, prompts, limits and access without exposing secrets.
- Customer: determines purposes, data, authorised users and review level.
- User/consultant: submits appropriate requests, checks sources and corrects Outputs.
- Approver: assumes responsibility for publishing the controlled version.
3. Use-case assessment
Before using an Output in a material process, the Customer assesses purpose, recipients, data, potential effects, necessity of AI, required accuracy, oversight, vulnerable persons and consequences of error. Use for ISO documentation is normally assistive; it may become high-impact if linked to decisions about individuals, health, safety, employment, credit or access to services.
4. Prohibited or unsupported uses
ISOPILOT must not be used for practices prohibited by AI law, harmful manipulation, social scoring, unlawful inference of sensitive categories, unauthorised surveillance, deceptive content or fraudulent impersonation of professionals. Solely automated decisions with legal or similarly significant effects are not supported.
5. Data, sources and minimisation
Users must prefer reliable, current and relevant sources, distinguish official data from marketing statements and minimise unnecessary personal data. Company records and websites may be combined, but conflicting information must be confirmed. Scanned documents or images may require manual verification.
6. Transparency and communication
Where appropriate, documents should state that they were prepared with AI assistance and subsequently reviewed. A virtual consultant’s name must not imply human review that did not occur. Synthetic public-facing content must be identified where required by law.
7. Human oversight and approval
Every Output intended for operational use must be checked by a competent person with genuine ability to understand, challenge, correct or reject it. Health and safety, environment, privacy, cybersecurity, contracts and regulated requirements require specialist review proportionate to risk.
The draft → review → approval → publication workflow must not be bypassed. Synchronised cross-document changes require impact analysis.
8. Accuracy, hallucinations and references
Models may fabricate facts, references or citations. Users must verify laws, standard editions, clauses, names, dates, calculations and obligations against authoritative sources. ISOPILOT should flag uncertainty and missing data, but such flagging cannot be guaranteed in every case.
9. Traceability, versioning and monitoring
The platform may record configuration, model, prompt version, relevant Inputs, Outputs, author, revisions, approvals and hashes. Logs support reconstruction, security and improvement; access is restricted. The Customer must retain evidence consistent with its management system.
10. Competence and AI literacy
Users must receive role-appropriate instruction on model limitations, data protection, prompt injection, verification, confidentiality and incident reporting. The Customer retains training evidence where required by its governance or law.
11. Incidents and improvement
Unsafe outputs, disclosure, bias, unauthorised access or abnormal behaviour must be reported. UESE may suspend models or features, correct prompts, add filters and notify affected customers. Lessons learned feed into assessments, controls and documentation.
12. Regulatory framework
Governance considers Regulation (EU) 2024/1689 (AI Act), as amended and applicable over time, GDPR, cybersecurity, intellectual property, consumer protection and sector-specific rules. Actual applicability depends on role, use and risk; the Customer must conduct its own assessment.
