Responsible AI Kit

Free resource · Word + Excel kit

Responsible AI toolkit: bias, transparency, explainability, and human oversight

What the person commissioning an AI project must decide, require, and verify to ensure the system does not discriminate, that those involved are aware they are dealing with AI, that every result can be explained, and that a human truly retains control. Updated to the AI ​​omnibus regulation that came into effect on July 27, 2026, with seven ready-to-use tools.

📄 Word, 18 pages📊 Excel Workbook, 7 tools⚖️ Updated as of October 2026🆓 Free
WBiasTransparencyExplainabilitySupervisionMonitoring1Standardbasic reflexes2Reinforcedtests and explanations3High riskimpact sheet

The responsible AI kit, in short

What it is
A decision kit for the sponsor of an AI project, who needs to be able to answer "is this system fair, understandable and under human control?": the ten reflexes of the sponsor, the rule applicable in October 2026, the qualification of the use case, the detection and reduction of biases, transparency, explainability, human supervision, monitoring over time, the case of generative AI assistants, the purchase requirements and a model impact sheet.
For who
Business units that commission or deploy an AI system, IT departments, data teams, compliance, CSR and HR teams, in large private and public organizations. No statistical skills required: equity metrics are explained simply.
Format
18-page Word document in 13 chapters and Excel workbook in 7 tools: automatic qualification of the use case, self-assessment on the 7 requirements of a trustworthy AI, ethical risk register, bias calculator, matched prompt tests, monthly monitoring of human supervision, supplier checklist.
What it contains
Why this kit and the ten reflexes of the sponsor; what the rule says in October 2026 (AI Act amended by the omnibus AI, article 22 of the GDPR, SCHUFA and Dun & Bradstreet judgments of the CJEU, Code of relations between the public and the administration); the qualification of the use case in four questions and three levels of vigilance; the sources of bias and the metrics of fairness; transparency and informing people; the global, local and counterfactual explanation; human supervision and the bias of automation; governance and the repositories; the case of Copilot, ChatGPT, Claude and Gemini; the purchasing requirements; the impact sheet template in six sections; the resources.
What is it based on?
Regulation (EU) 2024/1689 on artificial intelligence as amended by Regulation (EU) 2026/1744 known as omnibus AI, the GDPR, the case law of the Court of Justice of the European Union, the Code of Relations between the Public and the Administration, the work of the Defender of Rights, the ISO/IEC 42001, 42005 and TR 24027 standards, the NIST AI RMF and its generative AI profile AI 600-1, the European Commission's ALTAI assessment list and the Positive AI and Labelia labels.
Price
Free, in exchange for a professional email address. No unsolicited emails.
Update
October 2026, version 1.0. Review scheduled before December 2, 2027, application date postponed for the obligations of high-risk systems in Annex III of the AI Act.
What it doesn't replace
A legal opinion on your situation, a data protection impact assessment conducted with your DPO, or a statistical audit of your system by a specialized team. The kit empowers you to qualify, demand, and verify.
Go Further
AI Act kit from the sponsor, sponsor's GDPR kit, AI and Social Dialogue Kit, frugal AI kit, AI Systems Governance Kit, AI charter template.

Responsible AI isn't decreed in a charter; it's built through sponsoring decisions. Bias, transparency, explainability, and human oversight are the four areas where an AI project can cause real harm to people, and those on which a regulator, a judge, or a rejected candidate will hold you accountable. In October 2024, researchers at the University of Washington subjected more than 3 million CV comparisons to three language models: first names associated with white people were preferred in 85% of cases, while female first names were preferred in only 11%. Amazon had already abandoned a CV-sorting tool biased against women in 2018.

This toolkit translates responsible AI into concrete steps for anyone commissioning, purchasing, or deploying an AI system within a large organization: defining the use case and level of vigilance, measuring bias with understandable metrics, ensuring transparency with stakeholders, guaranteeing explainable results, organizing human oversight that goes beyond mere signatures, and incorporating these requirements into contracts. It is based on the law applicable in October 2026 and recognized frameworks, without jargon or promises of automatic compliance.

1. What the rule says in October 2026

The European regulation on artificial intelligence was amended by Regulation (EU) 2026/1744, known as the AI ​​Omnibus Regulation, which entered into force on July 27, 2026. While the timeline has shifted, the core principles already apply: prohibited practices, transparency obligations, and, for much longer, the rights of individuals regarding automated decisions. Penalties under the AI Act can reach up to €35 million or 7% of global annual turnover. This guide distinguishes between current obligations, upcoming regulations, and best practices.

textsThis appliesFrom or by
AI Act, Article 5Prohibition of certain AI practices: to be verified for each use case before any deployment.2th February 2025
AI Act, Article 50Transparency obligations: informing people that they are interacting with an AI system, marking and labeling certain generated content.August 2, 2026
AI Act, Schedule IIIObligations of high-risk systems (employment, access to essential services, education and other listed areas), deferred by the AI ​​omnibus.2th December 2027
GDPR, Article 22Right not to be subject to a decision based solely on automated processing producing legal or significant effects.In force
CJEU, SCHUFA (2023)A score calculated by a third party falls under Article 22 when it plays a decisive role in the decision.Decision of December 7, 2023
CJEU, Dun & Bradstreet (2025)The person concerned has the right to an explanation of the procedure and the principles actually applied to achieve the result.Judgment of February 27, 2025
Code of relations between the public and the administrationFor the public sector: information on algorithmic processing used to make an individual decision and communication of their rules to the person who requests it.In force

2. Qualify the use case: three levels of vigilance

Not all AI projects require the same level of effort. The toolkit suggests assessing each use case by asking four questions, including the "directly applicable output" test developed by the French Ombudsman: does the system's output apply to a person without a human review? The answers place the use case into one of three vigilance levels described below. In the Excel workbook, the automated assessment tool asks eight questions and calculates the level.

LevelTypical situationWhat the kit requires
StandardInternal use without effect on an identified person, for example summarizing documents or assisting with writing.Basic reflexes: informing users, rules of use, verifying results.
ReinforcedThe system influences a decision that concerns people, with real human review.Bias testing, explanatory power, and sustained human supervision over time.
High riskScope of Annex III of the AI Act or automated decision within the meaning of Article 22 of the GDPR.Impact assessment, complete supplier documentation, formalized supervision, information for individuals.

3. Detect and reduce biases

AI bias almost never stems from intention: it arises from historical data that reproduces past inequalities, from a sample that underrepresents certain groups, from variables that substitute for others, or from the way the system is used. The toolkit describes these sources of bias and explains in simple terms the fairness metrics that can be used to identify them. These metrics are not contradictory, but they do not measure the same thing: the choice of metric is a sponsor's decision and must be documented.

Metric or testThe question askedIn the binder
Selection parityAre the different groups retained in the same proportions?Bias calculator: selection rate per group and ratio between groups.
Equal opportunitiesAmong those who actually meet the criteria, does each group have the same chance of being selected?Bias calculator: true positive rate per group.
Equality of errorsDoes the system make mistakes more often for one group than for another?Bias calculator: false alarms by group.
4/5 RuleIs the selection rate of a group less than 80% of that of the most favoured group? This is a warning sign, not a legal threshold in France.Bias calculator: ratio compared to the 80% benchmark.
Paired prompt testsDoes a generative AI assistant respond differently when only a first name, gender, or age changes in the request?Paired prompt testing tool.

4. Transparency and explainability

Transparency is aimed at two audiences. First, the teams using the system: for a high-risk system, the notice that the provider must submit under Section 13 of the AI Act describes its capabilities, limitations, and the conditions for its oversight. Second, the individuals concerned: they need to know that AI is involved and, for certain generated content, that this content is indeed AI-generated. The toolkit provides a template for the information notice and the rules for labeling content.

Explainability addresses another question: why this result? Since the Dun & Bradstreet ruling, a person affected by an automated decision can demand an understandable explanation. The toolkit distinguishes three levels of explanation and offers a five-point model response to give to someone who asks why they were excluded, rated, or directed.

Type of explanationThe question she answersFor who
GlobalHow does the system generally work, and what factors have the greatest impact?Sponsor, compliance, steering committee.
LocalWhy this particular result, for this particular person?Person concerned, user who supervises.
CounterfactualWhat would have needed to be changed to obtain a different result?The person concerned who disputes or wants to take action.

5. Human supervision that is not a signature

Simply involving a human isn't enough if they approve everything. Automation bias—the tendency to follow a system's recommendation rather than one's own judgment—quickly transforms oversight into a mere formality. The toolkit offers five monthly indicators to verify that oversight is genuine, including the acceptance rate without modifications: above 95%, the workbook monitoring tool triggers an alert. It also describes the organizational structure that enables this oversight.

6. The case of generative AI assistants

Most large organizations deploy generalist assistants such as Copilot, ChatGPT, Claude, or Gemini. These assistants pose three specific questions: Confabulation (the assistant can confidently deliver a false answer), bias (a University of Washington study shows that biases are present in language patterns), and liability (in the case of Moffatt v. Air Canada, 2024, the airline was held responsible for erroneous information provided by its chatbot to a customer). The toolkit derives clear usage guidelines from this, including a prohibition against assigning resume screening to a generalist assistant.

7. Buy and track over time

Most systems are purchased: your contract will bind your supplier. The kit lists the requirements to be included in the purchase and provides a 14-item supplier checklist with a calculated completion rate. Once the system is deployed, it proposes proportionate governance: monitoring of performance drift and bias, clear allocation of responsibilities, a lean committee, and a six-section impact assessment template inspired by Section 27 of the AI Act. Finally, it identifies relevant frameworks: ISO/IEC 42001 for the management system, ISO/IEC 42005 for impact analysis, ISO/IEC TR 24027 for bias, the NIST AI RMF and its generative AI profile AI 600-1, the ALTAI list, and the Positive AI and Labelia certifications.

8. What the kit contains

The Word document has 18 pages in 13 chapters: why this kit; the 10 reflexes of the sponsor; what the rule says in October 2026; qualify the use case; detect and reduce biases; be transparent; be able to explain; human supervision; monitoring over time and governance; the case of generative AI assistants; requirements to be included in purchases; the impact sheet template; resources.

The Excel workbook "Responsible AI Kit Tools" covers the approach in seven tools: automatic qualification of the use case (8 questions, calculated level); self-assessment on the 7 requirements of a trustworthy AI (28 questions inspired by the ALTAI list); the register of ethical risks with calculated criticality; the bias calculator (selection rate, ratio, true positive rate, false alerts per group); the paired prompt tests; the monthly monitoring of human supervision, with alert beyond 95% acceptance without modification; the 14-piece supplier checklist with completeness rate.

The kit, chapter by chapter: what each chapter contains and what its purpose is. The templates to fill in are in the Word document and the Excel workbook.

Chapter 1. Why this kit

What responsible AI means for a client, and why bias, transparency, explainability, and human oversight are decided at the scoping and purchasing stage.

Chapter 2. The 10 reflexes of the client

The ten key reflexes of the client, which summarize the approach of the kit.

Chapter 3. What the rule says in October 2026

The AI Act as amended by the AI ​​omnibus (section 5 prohibitions, section 50 transparency, Annex III high risk postponed to 2 December 2027), Article 22 of the GDPR, the SCHUFA and Dun & Bradstreet judgments, and the Code of Relations between the Public and the Administration for the public sector.

Chapter 4. Defining the Use Case

Four questions, including the "directly applicable output" test, and three levels of vigilance: standard, reinforced, high risk.

Chapter 5. Detecting and Reducing Biases

Sources of bias, fairness metrics explained simply (parity of selection, equality of opportunity, equality of errors), the 4/5 rule and its limitations, paired prompt tests for generative AI.

Chapter 6. Being transparent

The notice required by Article 13, information for the persons concerned, a model information notice and the labeling of generated content.

Chapter 7. Being able to explain

A global, local, and counterfactual explanation, and a five-point model for responding to someone who asks why.

Chapter 8. Human Supervision

The automation bias, five monthly indicators, and the organization that makes supervision real.

Chapter 9. Long-term monitoring and governance

The drift, who does what, a light committee, and the ISO/IEC 42001, 42005, TR 24027, NIST AI RMF and AI 600-1, ALTAI, Positive AI and Labelia standards.

Chapter 10. The case of generative AI assistants

Copilot, ChatGPT, Claude and Gemini: confabulation, bias, prohibition of CV screening by a generalist assistant, and the lessons of the Moffatt v. Air Canada case.

Chapter 11. Requirements to be included in purchases

What you should ask the supplier before signing, and what you should write in the contract.

Chapter 12. The Impact Assessment Form

A six-section form inspired by Article 27 of the AI Act, to be completed for each case of enhanced or high-risk use.

Chapter 13. Resources

The texts, standards, guides and tools cited, for further reading.

Download the responsible AI kit (Word + Excel, free)

18 pages in 13 chapters, plus a binder of 7 tools. Written by NextStart.AI based on the AI Act as amended by the AI ​​omnibus, the GDPR and the case law of the Court of Justice of the European Union, ISO/IEC standards, the NIST AI RMF and the ALTAI list, and the AI ​​adoption programs that we support in large organizations.

  • The rule applicable in October 2026 and the three levels of vigilance
  • Fairness metrics explained simply and the bias calculator
  • The information notice model, the three types of explanation, and the five-point response
  • Human supervision monitored monthly, the supplier checklist and the impact assessment form

    9. Frequently Asked Questions

    What exactly is responsible AI?

    This is an AI system that can be demonstrated to be non-discriminatory, where those involved are aware of its intervention, where its results can be explained, and where a human retains genuine control. For a client, this translates into specific decisions: defining the use case, selecting and measuring bias metrics, informing stakeholders, requesting documentation from the vendor, and monitoring over time. The toolkit transforms each of these points into a practical tool.

    Is our project already affected by the AI Act?

    Probably, at least in part. The prohibitions in Article 5 have applied since February 2, 2025, and the transparency obligations in Article 50 since August 2, 2026. The AI ​​omnibus bill postponed the obligations for high-risk systems listed in Annex III until December 2, 2027, which allows time to prepare, not to ignore. Article 22 of the GDPR already applies to any decision based solely on automated processing.

    How can we tell if our system is biased?

    By measuring it. The kit's bias calculator compares selection rates, true positive rates, and false positive rates between groups, and calculates the ratio between groups. The 4/5 rule serves as a warning signal, but it is not a legal threshold in France. For a generative AI assistant, paired prompt tests consist of asking the same question, changing only a first name, gender, or age, and then comparing the responses.

    Do we need to be able to explain every result produced by AI?

    As soon as a result has an effect on a person, yes. Since the CJEU's Dun & Bradstreet ruling (2025), individuals affected by an automated decision can obtain an explanation of the procedure and principles actually applied. In the public sector, the Code of Relations between the Public and the Administration already mandates information on algorithmic processing. The toolkit distinguishes between general, local, and counterfactual explanations and offers a five-point response template.

    Is it enough for a human to validate each result?

    Not necessarily. If the person accepts almost everything without making any changes, supervision becomes a formality: this is the automation bias. The kit offers five monthly indicators to verify that supervision is genuine; the monitoring tool triggers an alert when more than 95% of the results are accepted without modification.

    Can Copilot or ChatGPT be used to sort CVs?

    The toolkit recommends prohibiting it with a generalist assistant. A University of Washington study (October 2024) analyzing over 3 million resume comparisons showed that three language models preferred first names associated with white people in 85% of cases, and female first names in only 11%. Furthermore, recruitment is among the high-risk areas listed in Schedule III of the AI Act.

    What to start with ?

    By qualifying your use cases: the automated qualification tool asks eight questions and provides a level of vigilance for each. Then, for enhanced or high-risk use cases, the 28-question self-assessment, inspired by the ALTAI list, and the ethical risk register indicate where to focus your efforts. The supplier checklist is useful from the next purchase or renewal.

    10. Going further

    This kit complements the other kits from the sponsor: the AI Act kit covers what applies to a deployer and the AI ​​literacy program, the GDPR kit covers the qualification of projects and the file that the DPO expects, the AI and Social Dialogue Kit prepares the consultation of the CSE, the Security and data kit addresses the project's security risks, the frugal AI kit its environmental footprint and the AI Sovereignty Kit its dependencies. The AI Systems Governance Kit provides the register and qualification grid, the AI charter template sets the rules of use. Organizations that want to define their use cases and train their teams in the responsible use of AI do so within the framework of the AI training in companies and the mission Governing your agents.

    Read also : Sponsor's AI Act Kit: The 2026-2027 Roadmap, GDPR Kit for AI Project Sponsors, AI Project Sponsor Security and Data Kit, AI systems governance: the 2026 toolkit et AI Charter in Business: The 2026 Model (Downloadable).

    The entire series of free kits. To drive adoption: AI charter template, AI Ambassadors Kit, Manager's toolkit for dealing with AI, Adoption Roadmap Kit, AI maturity grid, AI Measurement and ROI Kit et AI Governance KitFor the AI ​​project sponsor: AI Act kit, GDPR kit, Security and data kit, AI and Social Dialogue Kit, frugal AI kit et AI Sovereignty KitBy profession: AI HR kit, AI marketing kit, AI finance kit, AI kit for lawyers, AI kit for salespeople, AI toolkit for project managers, AI innovator kit et communicator's AI kit.

    11. sources

    The rules and figures cited on this page and in the kit are based in particular on the following sources. The kit provides a complete list of these sources in its Resources chapter.

    Back to top
    The entire NextStart.AI catalogEight consulting missions, seven pillars, around twenty formats, fifteen professions, five tools
    Nine detailed customer case studiesLarge groups, public agencies and networks: from acculturation to production

    Insurance and social protection

    Health and life sciences

    Public sector and research

    The NextStart.AI collectiveConsultants, trainers and industry experts: more than 4,850 professionals trained since 2023
    All free resourcesDiagnostics, comparison tool, Finders, charter template, Word templates and industry-specific kits
    The NextStart.AI blogComparisons of tools, practices, agents, governance: analyses and feedback from the field
    Let's talk about your AI projectResponse within 24 business hours, written quote after initial discussion
    AI agents in businessUnderstanding, choosing the tool, training the teams, deploying
    Delegate entire tasksClaude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work