The AI Design Authority does not set its own rules in isolation. It operationalises Capgemini's Group guidelines, cybersecurity policy, and risk architecture for Invent's AI product teams — and aligns to the Group Industrialization Design Authority and its asset lifecycle. This page is the map back to source.
Group Industrialization already runs a Design Authority (IDA) that owns standards and manages the Asset & Service lifecycle. We are its AI counterpart — same custodial role, applied to the specific risks of building AI products.
Our standards restate and make actionable the Group Gen AI Guidelines, Cyber AI Policy, and Risk Reference Architecture — we do not compete with them.
Our review gates map to the Group asset lifecycle (Initialize → Plan & Design → Incubation → Industrialization → Run) and its Ready-to-Plan / Industrialize / Run checkpoints.
Cybersecurity sign-off sits with the CISO; ethics and data protection with the Ethics-for-AI framework and the DPO. We coordinate, we do not overrule them.
Where this lands for Invent. We operationalise the Group material inside Beacon, our single AI portal. The Authority's review of internal Claude skills entering the AI Library, and its technology approval of client-ready assets listing on the Asset Exchange, are how the Cyber Approval Process and the ASLM gates are made concrete for AI product teams.
Every standard and gate on this site traces to one or more of these. Where they update, we update.
| Document | What it governs | Owner |
|---|---|---|
| Generative AI Group Guidelines | Responsible use, approved-technology access, the Code of Ethics for AI, and the Group risk taxonomy. | Group |
| Group Cybersecurity AI Policy v1.0 | Mandatory AI cybersecurity controls, aligned to ISO/IEC 42001. Twelve AI principles and the Exception Management process. | Group Cybersecurity |
| GCS Gen AI Risk Reference Architecture v3.1 | The sixteen technology-agnostic Gen AI risks and their mitigations, by user type. | Group Cybersecurity |
| Cyber Approval Process | The five-step security approval flow from scoping to deployment, and the CISO decision. | Cybersecurity |
| Technology-specific Gen AI Guidelines | Approved-model and platform rules — Azure OpenAI, Azure AI Studio, GCP Vertex, Gemini Code Assist. | Group |
| Vibe Coding Guidance | Safe use of AI coding assistants: approved tools, untrusted output, human accountability, secure CI. | Group Cybersecurity |
| Group Industrialization Blueprint 2026 & ASLM | The Industrialization Design Authority construct and the Asset & Service lifecycle and gates. | Group Industrialization |
Source documents are held in the Group repositories referenced on the Talent and SharePoint pages; this site summarises, it does not replace them.
From the GCS Gen AI Risk Reference Architecture. Every AI product is risk-assessed against these using the Group AI solution risk assessment questionnaire. Applicability varies by whether we act as end user, deployer, or provider.
Sensitive data exposed through prompts.
Confidential data surfaced in responses.
Users trusting output beyond its warrant.
Discriminatory or unsafe generation.
Confident but inaccurate output.
Jailbreaking and instruction hijacking.
Resource exhaustion and abuse.
Over-broad access granted to the system.
Access to data it should not reach.
Compromised libraries and components.
Leak across the data layer.
Compromised or untrusted models.
Degrading behaviour over time.
Extraction or exfiltration of the model.
Corrupted training or grounding data.
Memorised data leaking from the model.
Primary mitigations, per the architecture. Grounding with retrieval (RAG) for hallucination; guardrails against prompt injection; layer isolation and least privilege; data classification and masking; red-teaming before production; and monitoring for drift and abuse in service.
From the Group Cybersecurity AI Policy. Compliance is mandatory; any exception runs through Exception Management with CISO sign-off. Our standards and gates make these principles checkable.
AI runs under Capgemini's governance, privacy, IP and cyber policies.
Defined, allocated, with escalation and segregation of duties.
Competent people at each lifecycle stage.
Risks, issues and incidents reported to management.
Data, tooling and system resources documented and current.
Data classified to the Capgemini scheme.
Full-lifecycle assessment incl. EU AI Act categories.
Security & privacy across the whole lifecycle.
Controlled, monitored, access-restricted release.
Data masking, provenance, representative datasets.
Contracts, obligations and incident reporting.
Human oversight and output monitoring in use.
External standards we build to. OWASP Top 10, OWASP ASVS, and the NIST Secure Software Development Framework (SSDF) — the industry references cited across the Group guidance.
The GCS AI team is the Group point of contact for the Risk Reference Architecture and approval process: gcs-ai.fr@capgemini.com.