Governance

Policy & compliance

Havas Lynx's compliance training — the rules for using AI day-to-day, handling data safely, the EU AI Act, and AI-generated imagery.

General usage

Approved Tools Only

All AI use for client work must go through LynxAI. Free consumer tiers (ChatGPT free, Claude.ai free) are not approved. Personal AI subscriptions are for personal use only.

Human in the Loop

All AI outputs used in client work must be reviewed, edited, and validated by a qualified human. AI generates — humans are responsible. No exceptions for client-facing content.

Client Disclosure

Follow client-specific disclosure requirements (see Client Guidelines). When in doubt, disclose. Building trust on AI transparency is a competitive advantage, not a risk.

Data Handling

LynxAI is zero-retention — inputs aren't stored or used to train models. Don't input client PII or confidential data without checking the client's specific AI position first.

GDPR & Data Privacy

Processing personal data through AI requires a legal basis under GDPR. If you're unsure whether your use case involves personal data, assume it does and escalate to the Data Privacy team.

Factual Accuracy

Verify all factual claims, statistics, citations, and medical information against primary sources. AI can hallucinate confidently and incorrectly — always check.

Medical & Regulatory Content

AI-assisted medical, clinical, and regulatory content must go through formal MLR review regardless of AI involvement. AI does not replace or accelerate the medical review process.

Copyright

AI-generated content may reproduce copyrighted material. Treat all AI text and imagery as requiring the same copyright review as externally sourced content. Get legal guidance before using AI image generation for clients.

PII & data

If the AI comes to the data (automated), names stay. If you take the data to the AI (manual upload), scrub the names. This rule applies to everyone, regardless of which AI tools or licences you have.

EU AI Act

Mandatory transparency training for synthetic media on EU-distributed healthcare assets — 12 chapters, from why it matters to real-world scenarios.

AI images

Level 1 — Safest

Established & AI-Ready

In-platform tools with commercial licensing built in: Adobe Firefly, Getty AI (iStock), Microsoft Designer. No additional legal sign-off required.

Level 2 — Use with governance

Established, Needs Checks

General-purpose generators (Midjourney, DALL·E, Stable Diffusion). Requires: licensing check, disclosure label, and human creative direction to establish authorship.

Level 3 — Legal sign-off required

Emerging Territory

Patient likeness, real people's faces, clinical imagery, deepfakes. Requires legal sign-off before use — without exception.