Foundations & alignment

Built on Group standards, not invented from scratch.

The AI Design Authority does not set its own rules in isolation. It operationalises Capgemini's Group guidelines, cybersecurity policy, and risk architecture for Invent's AI product teams — and aligns to the Group Industrialization Design Authority and its asset lifecycle. This page is the map back to source.

Where we sit

The AI-specialist complement to the Group's authority.

Group Industrialization already runs a Design Authority (IDA) that owns standards and manages the Asset & Service lifecycle. We are its AI counterpart — same custodial role, applied to the specific risks of building AI products.

We apply, not invent

Our standards restate and make actionable the Group Gen AI Guidelines, Cyber AI Policy, and Risk Reference Architecture — we do not compete with them.

We align to ASLM

Our review gates map to the Group asset lifecycle (Initialize → Plan & Design → Incubation → Industrialization → Run) and its Ready-to-Plan / Industrialize / Run checkpoints.

We defer to Cyber & Ethics

Cybersecurity sign-off sits with the CISO; ethics and data protection with the Ethics-for-AI framework and the DPO. We coordinate, we do not overrule them.

Where this lands for Invent. We operationalise the Group material inside Beacon, our single AI portal. The Authority's review of internal Claude skills entering the AI Library, and its technology approval of client-ready assets listing on the Asset Exchange, are how the Cyber Approval Process and the ASLM gates are made concrete for AI product teams.

Source of truth

The Group material we align to.

Every standard and gate on this site traces to one or more of these. Where they update, we update.

DocumentWhat it governsOwner
Generative AI Group GuidelinesResponsible use, approved-technology access, the Code of Ethics for AI, and the Group risk taxonomy.Group
Group Cybersecurity AI Policy v1.0Mandatory AI cybersecurity controls, aligned to ISO/IEC 42001. Twelve AI principles and the Exception Management process.Group Cybersecurity
GCS Gen AI Risk Reference Architecture v3.1The sixteen technology-agnostic Gen AI risks and their mitigations, by user type.Group Cybersecurity
Cyber Approval ProcessThe five-step security approval flow from scoping to deployment, and the CISO decision.Cybersecurity
Technology-specific Gen AI GuidelinesApproved-model and platform rules — Azure OpenAI, Azure AI Studio, GCP Vertex, Gemini Code Assist.Group
Vibe Coding GuidanceSafe use of AI coding assistants: approved tools, untrusted output, human accountability, secure CI.Group Cybersecurity
Group Industrialization Blueprint 2026 & ASLMThe Industrialization Design Authority construct and the Asset & Service lifecycle and gates.Group Industrialization

Source documents are held in the Group repositories referenced on the Talent and SharePoint pages; this site summarises, it does not replace them.

Risk Reference Architecture

The sixteen Gen AI risks we design against.

From the GCS Gen AI Risk Reference Architecture. Every AI product is risk-assessed against these using the Group AI solution risk assessment questionnaire. Applicability varies by whether we act as end user, deployer, or provider.

01

Input Data Leakage

Sensitive data exposed through prompts.

02

Output Data Leakage

Confidential data surfaced in responses.

03

Overreliance

Users trusting output beyond its warrant.

04

Biased or Harmful Output

Discriminatory or unsafe generation.

05

Hallucination

Confident but inaccurate output.

06

Prompt Injection

Jailbreaking and instruction hijacking.

07

Denial of Service

Resource exhaustion and abuse.

08

Excessive Permission

Over-broad access granted to the system.

09

Unauthorized Retrieval

Access to data it should not reach.

10

Supply Chain — Application

Compromised libraries and components.

11

Data Leakage

Leak across the data layer.

12

Supply Chain — Model

Compromised or untrusted models.

13

Model Drift

Degrading behaviour over time.

14

Model Theft

Extraction or exfiltration of the model.

15

Data Poisoning

Corrupted training or grounding data.

16

Training Data Leakage

Memorised data leaking from the model.

Primary mitigations, per the architecture. Grounding with retrieval (RAG) for hallucination; guardrails against prompt injection; layer isolation and least privilege; data classification and masking; red-teaming before production; and monitoring for drift and abuse in service.

ISO/IEC 42001 aligned

The twelve AI cybersecurity principles.

From the Group Cybersecurity AI Policy. Compliance is mandatory; any exception runs through Exception Management with CISO sign-off. Our standards and gates make these principles checkable.

01

Governance & Control

AI runs under Capgemini's governance, privacy, IP and cyber policies.

02

Roles & Responsibilities

Defined, allocated, with escalation and segregation of duties.

03

Human Resources

Competent people at each lifecycle stage.

04

Reporting

Risks, issues and incidents reported to management.

05

Documentation

Data, tooling and system resources documented and current.

06

Asset Management

Data classified to the Capgemini scheme.

07

Risk Assessment

Full-lifecycle assessment incl. EU AI Act categories.

08

System Lifecycle

Security & privacy across the whole lifecycle.

09

Deployment

Controlled, monitored, access-restricted release.

10

Development & Data

Data masking, provenance, representative datasets.

11

Third Parties

Contracts, obligations and incident reporting.

12

Responsible Use

Human oversight and output monitoring in use.

Group rules we enforce without exception

The lines the Group has already drawn.

  • Only Group-approved Gen AI technologies and models — approved via the Talent page. All others are forbidden.
  • Never through private accounts; never for prohibited use cases (e.g. most creative image generation, on IP grounds).
  • Prompts on approved tools are not used to train provider or third-party models.
  • Sensitive personal data or live data requires a DPO and CISO assessment before use.
  • On a client's environment, the client's guidelines apply first.

External standards we build to. OWASP Top 10, OWASP ASVS, and the NIST Secure Software Development Framework (SSDF) — the industry references cited across the Group guidance.

Questions on cyber risk?

The GCS AI team is the Group point of contact for the Risk Reference Architecture and approval process: gcs-ai.fr@capgemini.com.