Skip to main content

AI Decalogue

The CSIC has developed guidelines for the responsible use of generative artificial intelligence, drawing on a broad conception of this technology.

The CSIC has developed guidelines for the responsible use of generative artificial intelligence (hereinafter, Generative AI), drawing on a broad conception of this technology.

Generative AI is a type of artificial intelligence capable of producing new content — text, images, audio, video, code, or synthetic data — by learning patterns from large datasets. Rather than merely classifying or predicting, it generates original outputs that imitate or extrapolate what it has learned.

The training process uses data to build a model, which subsequently employs the learned patterns to generate new outputs (text, images, etc.).

Imagen
Image
imagen IA

These outputs may be difficult to distinguish from the products of human activity. It is important to underline the difference between computational processes and activities carried out by human beings. Generative AI learns patterns from large databases. It is humans who attribute cognitive capacities to its responses.

 

While generative AI encompasses computational instruments that can facilitate the production and management of knowledge, it also raises questions about its future development and how it can be used responsibly, appropriately, and effectively in scientific research. There are already clear signs of its limitations. Its deployment and implementation require, for instance, constant human intervention in prompt engineering, in successive processes of rubric design, annotation, and iteration, as well as in fine-tuning engineering and benchmarking. Metrics and, in particular, the difficulty of replicating results obtained through Generative AI, represent additional challenges that research must address.

 

The Association for Computing Machinery  (hereinafter, ACM) extended its professional guidelines for the responsible use of algorithmic systems to cover Generative AI, emphasising the need for human intervention and oversight through  four specific principles: (i) Limits and guidance on deployment and use establishing boundaries and guidelines for system deployment (human-in-the-loop); (ii) control over intellectual property rights; (iii) personal data control; and (iv) correctability (the ability to correct systems). It also adapted four further principles: transparency, auditability and contestability, limiting environmental impact, and enhanced security and privacy. Accordingly, it advocates that algorithmic systems — and Generative AI systems in particular — should allow individuals to prevent their data from being used to train the system or to facilitate its generation (opt-out principle), and that providers of such systems — in a broad sense, including designers and developers — should create and maintain public repositories where system errors can be noted and corrected.  


We recommend awareness and adoption of these principles in order to safeguard the legitimacy of scientific endeavour and to guide regulatory compliance. The European Commission's  Living guidelines on the responsible use of generative AI in research likewise insist on prudence, responsibility, and transparency in the use of generative AI, given its evolving and, to a certain degree, unpredictable nature.

 

Knowledge is generated by human beings, and the challenge lies in the learning that individuals must undertake in a new hybrid environment in which they must coordinate their actions with intelligent information-processing systems. It is particularly important to recognise that this new environment — the human-machine ecosystem — has social, ethical, legal, political, and ecological implications, all of which call for an open debate on justice and sustainability that must not be neglected in research.


The consensus definition of AI proposed by the Organisation for Economic Co-operation and Development (hereinafter, OECD) specifies that different systems vary in their levels of autonomy and adaptability following deployment. Generative AI thus represents a set of technologies applicable to diverse situations and scenarios across a plurality of social contexts. This is reflected in the structure of the ten Guidelines proposed here. They begin with the general scientific purpose that must be upheld; they then establish the professional, ethical, and legal conditions for the development and deployment of systems in scientific research; and they conclude with the specific requirements of justice and sustainability that their use must respect.

 

This document is divided into four sections:

  • The present Introduction.
  • A Decalogue for the use of Generative AI.
  • The Guidelines of the Decalogue.
  • A checklist at the end — also comprising ten points — designed to make the content of the Guidelines accessible and actionable.
     

 

 

LEGITIMATE SCIENTIFIC PURPOSE

Use generative AI exclusively for valid scientific objectives, always upholding integrity and avoiding data fabrication, falsification, and plagiarism.

REGULATORY COMPLIANCE

Be informed of and comply with applicable regulations, ethical codes, and institutional policies, respecting human rights and accepting responsibility for any breach.

HUMAN OVERSIGHT AND RESPONSIBILITY

Maintain constant human oversight and control over generated content, assuming full responsibility for its use and outcomes.

PRIVACY AND CONFIDENTIALITY

Do not enter sensitive information, non-anonymised personal data, or confidential material into publicly accessible Generative AI tools, and monitor the configuration of the technology in use.

AUTHORSHIP, SUBSTANTIVE CONTRIBUTION, AND INTELLECTUAL PROPERTY

Respect copyright and related intellectual property rights, verify and validate all AI-generated information, and do not claim AI-generated content as one's own.

TRANSPARENCY, TRACEABILITY, REPRODUCIBILITY, AND REPLICABILITY

Always disclose the use of Generative AI, specifying which tools were used in the research, at which stages, and with which parameters.

CYBERSECURITY

Protect systems by refraining from connecting Generative AI to repositories that lack adequate security guarantees, so as to minimise risks and avoid the adverse consequences of imprudent use.

CONTESTATION AND REDRESS

Be familiar with the procedures for challenging or rectifying results obtained through Generative AI in the event of error or dispute.

PROFESSIONAL COMPETENCE AND APPROPRIATENESS OF USE

Develop the skills needed to assess the appropriate use of these tools and employ them in a critical, reflective, and efficient manner.

SOCIAL JUSTICE AND SUSTAINABILITY

Use Generative AI responsibly, taking into account its social, economic, and environmental impact on the scientific community and on society at large.

1. Legitimate scientific purpose

A commitment to excellence and quality in science demands integrity of conduct and responsible behaviour, ensuring quality and rigour at every stage of research, compliance with applicable regulations, and due consideration of ethical aspects. Research staff must set lawful and legitimate objectives and, as stipulated in the National Declaration on Scientific Integrity, pursue knowledge grounded in corroborated and validated results that guarantee their credibility and soundness.

 

At present, the majority of Generative AI systems are founded on probability theory and stochastic models. These systems use models built from data through machine learning (ML) methods — in particular, artificial neural networks (deep learning, DL). They are now capable of producing far more complex structures than was previously possible, for two reasons: (I) increased computational power (Graphics Processing Units, GPUs) and (ii) the introduction of self-supervised learning, or automatic data annotation, into the learning process. The system learns without using explicitly provided labels as input. 

 

These technologies have transformed natural language processing and the processes of data analysis and treatment, and are increasingly used in both basic and applied research. However, there is sufficient evidence to assert that, in the creation of knowledge, various generative AI systems may be affected by bias, misrepresentation, or plagiarism. Impact and risk assessments are therefore indispensable for harm prevention. Under no circumstances may the use of AI systems and tools excuse scientific misconduct such as data fabrication or falsification, plagiarism, or any other unacceptable conduct. The chosen generative AI system should not have an adverse effect on the fundamental values set out in this Decalogue.

 

As UNESCO states in its Recommendation on the Ethics of Artificial Intelligence,  the use of AI systems must not go beyond what is necessary to achieve a legitimate objective. Proportionality and the prevention of harm are identified as basic principles. We endorse and recommend adherence to the nine guidelines of the ACM's Statement on Principles for Responsible Algorithmic Systems, its extension to generative AI as mentioned above, as well as the recommendations for researchers contained in the European Commission's Living guidelines on the responsible use of generative AI in research.

 

2. Regulatory Compliance

Regulatory compliance means, in the first instance, that actions and conduct must conform to regional, national, European, and international regulation. Compliance also extends to alignment of conduct with the public policies of official agencies (for example, data protection authorities or national consumer and competition authorities), and with the standards, technical protocols, and best practice guides applicable to research. It is essential to underscore the inescapable duty to respect the Human Rights enshrined in the  United Nations Universal Declaration of Human Rights and in the Charter of Fundamental Rights of the European Union. The development of national projects is likewise bounded by the constitutional limits of each State.

 

Conduct may be individual — relating to persons — or collective — relating to administrations, associations, organisations, companies, and corporations. It is important to note that, in cases of criminal law violations and those of property and contractual law where intent or manifest breach is demonstrated, liability is individual. Research staff are responsible for fulfilling their legal, ethical, and social obligations, and must be aware that the consequences may extend to both the institution and the researchers responsible for the research.

 

With regard to the institution, and in accordance with the Artificial Intelligence Regulation (the so-called EU AI Act), the design, development, implementation, and use of AI systems, in addition to being subject to scientific and technical standards, must meet strict safety and privacy requirements. They must comply with administrative powers and, in the case of high-risk systems, require explicit authorisation before they can be built and deployed. It is advisable for research staff to be aware of and to use the risk-level classification pyramid established by the Artificial Intelligence Regulation, both before and during the use of Generative AI techniques, in order to fulfil their obligations. The Regulation requires reasonable, verifiable, and documented actions, including regulatory review and risk assessment as well as the requirement of traceability (model, version, parameters, and human oversight). Attention should also be paid to the amendments to the  Proposal for a Digital Omnibus Regulation on AI that will be implemented in 2026 and 2027.

 

On the part of research staff, the use of Generative AI programmes must comply with contractual terms, adhere to applicable regulations, and — of particular relevance — observe the standards, protocols, and practices of each specific research field as well as the ethical principles of the Código de Buenas Prácticas Científicas del CSIC (Code of Good Scientific Practice). This Code promotes honesty, integrity, independence, and the absence of bias in research. In the event of conflict or induced harm, the legal and ethical characterisation of the research staff's actions must be considered in the allocation of responsibility. This underscores the requirement for due diligence and awareness of obligations on the part of the research team and its members.

 

Finally, an important aspect of European regulation must be highlighted. The transfer of data — both knowledge and personal data — outside the European area has significant legal and data sovereignty implications. Research staff must be attentive to the applicable requirements and restrictions in force with regard to third countries.

 

3. Human oversight and responsibility

The inclusion of incorrect results that appear credible must be prevented, avoiding potential errors, the fabrication of bibliographic references, facts, data, links, illustrations, or any other false content.


The adoption of generative AI in research always requires human oversight, since scientific, moral, and legal responsibility rests with individuals. In any use and for the creation of any content, it is a primary duty to maintain an informed critical spirit. When content created by AI tools is used in research activities, the generated responses must be verified with the utmost care.


The production of content through generative AI in scientific research contexts requires basic training both on the functioning of generative AI and on research ethics, in order to enable co-regulation of its use under the researcher's responsibility. Co-regulation entails properly distinguishing between human agency and the agency of artificial systems, as well as understanding how both interact within a specific scientific activity context, linked to the different processes of the research task (methodological design, data collection and analysis, scientific writing, peer review). Research staff are responsible for their work and must make informed and critical decisions at every stage of research. This principle is particularly relevant in matters relating to authorship, knowledge traceability, and the acknowledgement of one's own and others' contributions.

 

Prior training, preparation, and supervision of outputs are therefore crucial both when using generative AI tools and when these are themselves the object of research and development. According to the Commission's Living Guidelines, bias may arise in training data, prompts, citations (which may be fabricated), and interpretation (the opacity produced by the difficulty of identifying traceability and explaining inferences).

 

The ACM´s Statement on Principles for Responsible Algorithmic Systems  underscores that algorithms can be fed and trained through machine learning techniques that prove opaque and produce errors. In the use of Generative AI, research staff must clearly document how datasets, variables, and specific models have been selected for development, training, validation, and testing, as well as the specific measures used to ensure data quality and the reliability of results. It is likewise advisable to have independent verification and validation processes that are amenable to public scrutiny. Accordingly, research staff should facilitate testing by third parties. The Oxford Internet Institute has cautioned about problems of replicability and the reliability of metrics used hitherto to validate Generative AI systems through quality benchmarking.

 

Furthermore, human oversight is not only required in the design of AI systems, but in the management of all phases of the lifecycle of AI systems used in research: detecting problems, correcting them, and, if necessary, orderly withdrawing services or products previously made available to third parties. It is advisable to establish protocols governing how to report incidents (serious errors, detected biases, privacy violations, etc.) and how to respond, including, if appropriate, the suspension or dismantling of a service or product (a model, for instance).

 

4. Privacy and confidentiality

Research staff may inadvertently incur privacy and confidentiality violations that can give rise to sanctions by Data Protection Authorities or litigation before the courts. Moreover, Generative AI platforms typically retain and repurpose these data. With the exception of Pro versions, those with enterprise licences, or when the incognito mode is activated, the use of generative AI tools should be avoided.


Privacy may be simply defined as the protection of a private sphere from any intrusion into the public domain. Confidentiality means that certain data are subject to restrictions on access and disclosure, such that authorisation is required to access, manage, handle, or make this information public. In short, confidential information is shared only with those with whom one strictly wishes and is entitled to share it. Confidentiality also entails the protection of sensitive information and the obligation not to disclose information obtained in relationships of trust. Both dimensions are relevant to research.


There is a risk that privacy and confidentiality may not be adequately protected. Unless the relevant option is deactivated in each application's settings, the most widely used Generative AI tools retain conversations by default for the purpose of further training their models, including human review to improve the service. The utmost care must therefore be exercised regarding the information provided, avoiding the sharing of personal data, sensitive or protected information, as well as results that are legally protected or commercially valuable. It is likewise advisable to verify whether tools are in beta version and whether they store interactions for the purpose of training the model. In a research environment, it is prudent to use closed tools, open-source tools deployed in closed environments, or tools with a different level of protection.

 

Recent developments in the General-Purpose AI Code of Practice of the Artificial Intelligence Regulation, which entered into force on 2 August 2025, and the European Data Protection Board's Guidelines 3/2025 on the Interplay between the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR), effective from 12 September of the same year, underscore that respect for privacy rights — both by design and by default — must be an integral part of the development of Generative AI.

 

This requires technical measures such as differential privacy, data filtering, and model unlearning capabilities. Implementation challenges arise when personal data become embedded in the parameters of a trained model. It is therefore difficult for users to verify that these requirements are being effectively met, and uncritical acceptance of the outputs of such systems may lead to violations of privacy and intellectual property.


This constitutes a particularly sensitive issue. The configuration of privacy protection across the body of legal systems that safeguard data protection is founded on the consent of the data subject for the sharing of personal data. However, most individuals give their consent without a real understanding of the data they are sharing or the purposes and scope of that sharing. Consent is frequently obtained through mere adhesion to general terms of use or through forms that are difficult for the average citizen to understand. An ethical approach to the creation of databases for use in generative intelligence must take these circumstances into account and apply prior filtering of irrelevant personal data and anonymisation mechanisms.

 

The National Institute of Standards and Technology of the United States Department of Commerce (hereinafter, NIST) has defined with precision the various meanings of confidentiality. Confidentiality in AI regulation extends beyond traditional data protection to encompass the entire AI value chain, requiring research teams developing AI systems — particularly in collaboration with companies — to implement comprehensive security architectures that protect sensitive information from unauthorised access during the training, processing, and inference phases. Technical confidentiality measures include the implementation of filtering mechanisms to prevent the leakage of personal data in AI outputs, the use of encryption for data in transit and at rest, the application of differential privacy techniques during training, and the establishment of secure processing environments with network isolation and access restrictions.

 

5. Authorship, substantive contribution and intellectual property

The attribution of authorship in a literary, artistic, or scientific work requires a contribution in which the intellectual input is substantive. The criteria for authorship demand, in addition to a substantial contribution to the intellectual creation in question, approval of its final version and acceptance of responsibility for the contribution made and the knowledge produced.

 

In Spain, a distinction is drawn between intellectual property (hereinafter, IP) and industrial property. IP protects creativity and innovation (in art, science, and technology, including software), and it is important to note that protection operates from the outset — from the moment the original creation is generated — and does not require prior registration. Industrial property, by contrast, refers to patents, designs, registered trademarks, and designations of origin that hold commercial value. For the characteristics of IP, reference may be made to  Real Decreto Legislativo 1/1996, de 12 de abril (Royal Legislative Decree 1/1996 of 12 April).

 

The personal rights comprising IP vest in the author full disposition and the exclusive right to exploit the work, such that its disclosure and publication requires the author's consent. It is for the author to decide the licence or assignment of exploitation rights to be granted. However, where research has been publicly funded, the publication and dissemination of results must be carried out under international open licences (such as Creative Commons). It should be noted here that, as a public body, the CSIC is committed to and promotes an open science consistent with the European open science policy for innovationn. The CSIC Library and Archives Network is the cross-cutting system responsible for ensuring access to scientific information resources for CSIC researchers in support of the research process.

 

Since generative AI tools and systems are trained on large volumes of data that may contain texts, images, designs, and other content protected by copyright and industrial property rights, their use and outputs may constitute IP and industrial property infringements. Models trained on authorised content should be preferred, and the terms of use and licences of the tools should be reviewed.

 

Although there are differences between United States and european regulation of IP as it relates to Generative AI, a prompt cannot be considered an intellectual creation generating copyright. Nor is having ideas sufficient to obtain a patent. The European Patent Convention requires inventions to be novel, to involve an inventive step, and to be susceptible of industrial application. In the United States, IP encompasses creative works or ideas expressed in a form that enables them to be shared or recreated, emulated, or manufactured by others. Patents, trademarks, copyright, and trade secrets are regarded as distinct forms of IP.

 

Content generated by AI cannot be assumed per se to constitute an original creation. It is necessary to validate and verify the information, to interpret it appropriately, and to declare the degree of Generative AI contribution, both in the drafting of project proposals and in the resulting publications.

 

There is another factor that must be considered in the introduction of Generative AI: The impact on consumer and user rights, and the influence of AI algorithmic formulas on commercial relationships, with potential practices contrary to competition law or the principle of fair trading. Such harms, even if produced inadvertently, may give rise to sanctions by regulatory authorities.

 

6. Transparency, Traceability, Reproducibility and Replicability.

The growing adoption of Generative AI tools is accompanied by the ethical obligation to declare the degree of contribution of the generative AI tool to each creation. Many journals, publishing consortia, conferences, dissemination outlets, and funding bodies have issued guidelines that must be consulted to ensure the transparent use of generative AI. The duty to disclose also applies to works deposited in digital repositories, whether as preprints or as final non-peer-reviewed publications.


When data are obtained, shared, or processed in a data space (institutional, sectoral, or European), this must be declared, and the team must comply with the relevant governance instruments (participation agreements, access/use policies, and exchange conditions), without prejudice to compliance with the standard of reasonable diligence applicable to research staff.


There is an evolving ethical debate as to what is mandatory, optional, or unnecessary to disclose with regard to the use of generative AI across all processes. These requirements may vary between disciplines, publishing consortia, and other research environments. There is therefore no single policy that fits all content and fields of knowledge. For instance, disclosure of its use to improve the readability and correctness of texts is mandatory in many journals, while in others it has become optional. Declaration of the scientific, technical, and legal typology of the tools used is also commonly required.


Reference must be made here to the reproducibility and replicability of scientific results. Reproducibility relates to transparency and technical rigour; replicability relates to scientific robustness. Reproducibility means that, given the same data, the same code, and the same protocol, a researcher can obtain the same results as those produced in the original research. Replicability means that applying the same method to new data generates results consistent with those of the original research. Both properties are required. In research, if AI-generated results are not reproducible and replicable, they lose scientific value and impede both internal and external audit. AI (opaque models, dynamic data, cloud services, etc.) makes reproducibility and replicability particularly challenging. It is therefore necessary to document datasets adequately, record the models used, the prompts, and the data processing pipelines.

 

In the field of scientific publication, some publishing consortia have created a specific section before the reference list for disclosure statements. Other journals propose inclusion in the 'Methods' section, while others ask for details to be included in appendices or supplementary materials. The American Psychological Association (APA) has also updated its guidelines for the in-text citation of Generative AI and for including it as a software tool in reference lists. CEUR-Working Proceedings, one of the most widely used open-access journals, offers a policy on AI assistance tools detailing which practices it regards as acceptable and which it does not in publications: Generative AI may assist in drafting an article, but may never replace the writing process, and must be used responsibly. Since 1997, the  Committee on Publication Ethics (COPE), a not-for-profit organisation encompassing many scientific journals, has also taken a position against AI tools being accorded the status of author.

 

In more general contexts (developments, patents, etc.), research staff must identify the correct procedure for making the required disclosure. Where potential intellectual property violations arise, questions of proof (evidence) arise. In civil proceedings, the burden of proof lies with the party making the allegation — that is, with providing evidence of the harm suffered — and an individual whose rights have been violated faces considerable difficulty in demonstrating the traceability of the decision-making process in a generative AI system. In industrial property law, the principle of reversal of the burden of proof applies, such that it would be for the defendant to demonstrate that their product is original. In any event, with a view to safeguarding economic and authorship rights, it is advisable for research staff, to the extent possible, to maintain a traceability record.

 

7.  Cibersecurity

Generative AI is not exempt from security risks, and the challenges it presents are highly diverse. In relation to platforms and their interconnection, NIST defines cybersecurity as the prevention of damage, protection, and restoration of computer systems, electronic communications systems, electronic communications services, wired and electronic communications — including the information they contain — with a view to ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. This last principle guarantees that a party cannot deny its participation in a digital communication or transaction. It provides verifiable evidence of the origin and integrity of data, making it impossible for a sender to deny having sent a message or for a recipient to deny having received it. This is generally achieved through cryptographic methods such as digital signatures, which use a private key to sign a message and a public key to verify the signature. With regard to the configuration possibilities of platforms and computing systems, the correct protection of positioning, navigation, and timing (PNT) data — encompassing information on location (such as longitude, latitude, and altitude), orientation, and time — must be ensured.


Adversarial attacks can manipulate generative AI models to produce false, incorrect, or harmful responses. Generative AI can likewise be used for highly personalised phishing emails, tailored to each recipient to increase the probability of achieving malicious objectives. Other malicious uses include data hijacking, the theft of ideas and trade secrets, the discovery of vulnerabilities, the creation of malware, and the automation of large-scale attacks. The utmost caution is advised; the security configurations of the tools used — whether open-source, proprietary, or institutional — should be monitored and controlled. Institutional recommendations should be known and implemented in order to be protected against adverse uses, and researchers should be aware of the possibilities of hacking.


Furthermore, confidentiality in the regulation of generative AI extends beyond traditional data protection to encompass the entire AI value chain, requiring research teams developing generative AI systems — particularly in collaboration with companies — to implement comprehensive security architectures that protect sensitive information from unauthorised access during the training, processing, and inference phases. In view of the functions performed, some AI systems should be accompanied by mechanisms to ensure civil liability coverage.


Technical confidentiality measures include the implementation of filtering mechanisms to prevent the leakage of personal data in outputs, the use of encryption for data in transit and at rest, the application of differential privacy techniques during training, and the establishment of secure processing environments with network isolation and access restrictions. Where generative AI systems are being developed, research staff must ensure the stability and reliability of the systems. Their robustness must be demonstrated through the recording of documentation relating to tests and changes throughout their lifecycles.


There is a further aspect that merits emphasis. When AI is not merely a tool for research but the very object of research — for example, in the development of AI through the design of models — additional responsibilities are assumed: technological resources may be created whose capabilities, if misused, may have adverse consequences. In this regard, dual-use risks — intentional or unintended misuse — should be assessed and security measures designed from the outset.

 

Reference is recommended to the Instrucción del CSIC de 8 de Mayo de 2024 (Information Security Regulations)), the Esquema Nacional de Seguridad (2022) (National Security Framework), and, with regard to European regulation, the Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022.

 

8. Contestation and redress

The outputs of generative AI may give rise to conflicts of interest. It is therefore not only necessary to know in advance the publication policy regarding its use, but also advisable to be aware of what types of controversy may arise, what type of response is to be expected, and what mechanisms are in place in cases of error of judgement or conflict. The principle of contestation relates to these situations. When a generative AI system significantly affects a person, community, group, or environment, there is typically a process that allows the use or outputs of the system to be challenged. It is the responsibility of researchers to know these processes and, where appropriate, to seek guidance from their institution, since the latter may also be affected.


The research team, in accordance with the standard of reasonable diligence applicable to researchers, must anticipate, detect, and manage controversies or harms arising from the use of Generative AI, activating contestation and redress protocols (notification, preservation of evidence, correction, and communication to editors and funding sources).


Awareness of the context and the relevant parties is also important. Collaboration with technology providers and private funding is very common in AI. This may influence the choice of tools, the interpretation of results, and the public communication of research. Many interests are at stake, and the pressure from technology companies is considerable. Particular rigour is therefore required regarding what is received from or contracted with third parties and on what terms (disclosure of funding sources and relationships with AI service providers; collaboration agreements, such as those granting early, preferential, or free access to AI services and products; publication of results where there is a commercial interest; etc.).


Contestation in the regulation of generative AI encompasses both the technical capacity of individuals to challenge decisions driven by it and the procedural mechanisms enabling meaningful redress when Generative AI systems cause harm or produce undesired outcomes. Effective contestation requires more than post hoc explanations of algorithmic functioning: it demands the provision of factual grounds enabling individuals to identify whether the legal conditions for adverse decisions have been met, distinguishing between: (i) technical explanations of how the system works; (ii) legal justifications for specific outcomes; and (iii) the creation of records enabling audit and potential public oversight and analysis mechanisms with guarantees for both parties.

 

Contestation and redress mechanisms must be meaningful and readily accessible, including effective complaints procedures, impartial compliance bodies to facilitate review processes, and points of contact for users who believe their rights have been violated. The challenge lies in ensuring the balance between individuals and Generative AI systems. A preliminary step is to use the mechanisms provided in the CSIC Code of Good Scientific Practice and the CSIC Manual of Conflicts of Interest.

 

We reiterate that private individuals have few means, limited knowledge, and minimal facilitation for proving violations of their personal or economic rights. To redress this imbalance, it would be entirely necessary to establish traceability archives and a mechanism of access to evidence suited both to technical audit and to use in civil proceedings.

 

9. Professional competence and appropiateness of use

The efficient use of Generative AI requires specific learning, in varying degrees and in keeping with the characteristics of the research field, encompassing the different architectures, models, and prompt engineering techniques. The context of use and the capacity to validate results must also be taken into account. Awareness and critical understanding of its problems of opacity, bias, or limitations, as well as of the potential improvements it brings, must likewise be consciously applied. In short, the efficient and ethical use of generative AI requires a sufficient level of acquired skills and knowledge of expected outcomes. The complexity of the applications must be commensurate with the level of training and experience. Consistent with the standard of reasonable diligence applicable to research staff, the team shall demonstrate minimum technical competence, assess limitations and risks, and document the appropriateness of use, avoiding uncritical automation.


In current applications, prompt engineering seeks to contextualise each instruction to improve the utility and reliability of generative AI outputs. An example of inexperienced use may occur when the drafting of a text in English by a non-native speaker substantially alters the meaning and originality of a contribution. Another example may arise in the uncontrolled automation of processes in experimental design, algorithmics, software development, or data analytics, where instructions that fail to capture the specificities of the problems may yield highly standardised or erroneous information.

 

In Europe, the development of Generative AI capabilities is one of the fundamental pillars established by the  Competitiveness Compass and the AI Continent Action Plan. It must also be accompanied by strengthened knowledge of research ethics and integrity. Familiarity is recommended both with the particular uses of generative AI and with the policies governing its use, based on the national and European regulations that define its limits — in particular, the Artificial Intelligence Regulation (the EU AI Act, as cited above). The adoption of generative AI must not disregard the duty to mitigate its potential adverse effects, such as the erosion of skills (deskilling) or the undue increase in technological dependency.

 

10. Social justice and sustainability

These Guidelines have proposed a number of principles for the use of generative artificial intelligence in research, including: (i) transparency in the disclosure and attribution of results; (ii) verification of AI-generated content and analyses; (iii) documentation of data; (iv) an approach grounded in ethics, equity, fairness, respect for the law, and human rights; and (v) permanent public debate, oversight, and participation.


Generative AI has an economic, social, and political dimension that has already permeated and transformed the daily and working lives of many people, affects the generation, performance, and maintenance of employment, and has a highly significant impact on nature and ecological systems. This makes the creation of consensus within the scientific community for the development of responsible and sustainable generative AI all the more urgent.

 

Across all areas covered by the Common European Data Spaces ― from energy, industry, and finance to education, health, public administration, mobility, and tourism — the use of Generative AI has already had a transformative impact. However, innovation is not without its risks. Some have already been identified in these Guidelines, such as bias in training data, outputs, and interpretation, or the difficulty of tracing algorithms and information processes.

 

It is important to consider the current and future effects of Generative AI, both during the process of design and production and in the development and application of systems. The non-substantive, insufficiently transparent, or biased development and use of Generative AI, as well as an approach driven exclusively by commercial gain without regard to its impact, may cause harm to individuals, minority groups, social contexts, natural environments, businesses, and the business fabric as a whole. This position is aligned with the European Research Area Policy agenda (2025-2027),  ERA structural policies,  and the European Code of Conduct for Research Integrity, which promote a holistic approach in research and technological development integrating gender equality, equal opportunities, and inclusion, as well as sustainability and citizen participation.

 

Researchers communicate their results and methods, including the use of automated services or tools and AI, in a manner consistent with the accepted standards of the discipline and, where appropriate, in such a way that they can be verified and reproduced
Researchers, research institutions, and organisations review and evaluate applications submitted for publication, funding, appointment, promotion, or reward in a transparent and justifiable manner, and disclose the use of AI and automated tools.
The Code establishes that concealing the use of AI or automated tools in the creation of content or the drafting of publications constitutes a breach of research integrity.
 

 

According to the United Nations Environment Programme it is necessary to consider the hardware and software cycles as a whole — from the extraction of raw materials, production, transport, and the construction of data centres, to the management of electronic waste, and the collection, preparation, and deployment of data. Throughout this cycle, the resource consumption of Generative AI — in particular water and energy — is immense and is expected to continue growing. On this matter, it is necessary to implement standardised methods and parameters for measuring the environmental impact of Generative AI and to prioritise research into green technologies (green computing), energy efficiency, and circular economy principles in cloud computing and data centres.

 

In summary, the use of Generative AI in research demands an express commitment to non-discrimination, the reduction of digital divides, and the minimisation of environmental footprint, ensuring the accessibility of tools and results (universal design, interoperable formats, perceptive alternatives) and algorithmic equity through the documented identification and mitigation of bias. To this end, and acting in accordance with the standard of reasonable diligence applicable to research staff, priority shall be given to efficient models and deployments, infrastructure powered by renewable energy, and decentralised solutions that reinforce technological sovereignty — including, where viable, on-premise/edge computing, federated learning, and participation in data spaces (institutional, sectoral, or European).


Clear governance rules must be established to foster the federation, efficiency, and cooperative use of data, without exceeding the applicable legal purposes and guarantees; procurement decisions must necessarily take into account ethical considerations (including efficiency, accessibility and the right to exit, and auditability). Where generative AI has contributed to the production of results with social impact, this involvement shall be declared, along with the measures adopted with regard to accessibility, equity, and sustainability.

1. Have you considered any alternatives before deciding to use Generative AI systems to create content or to support your research (large language models, foundation models, chatbots)?

Yes / No

2. Have you consulted the applicable regulations on Generative AI that are relevant to and applicable in your research?

Yes / No

3. Do you consider that you maintain control and can account for all stages of your research, and, in the event of the use of generative AI techniques, can you justify the transparency of the algorithms and the correctness of the training and fine-tuning methods of the system?

Yes / No

4. Have you carried out an impact assessment and verified that, where your research uses sensitive data, these are properly anonymised and comply with the requirements of privacy and data protection?

Yes / No

5. Do you consider that you have duly respected copyright and industrial property rights? Following the relevant assessment, do you consider that any of the results of your research are legally protectable, for example by means of a patent? Have you assessed the potential impact on the individual or economic rights of consumers?

Yes / No

6. Have you used Generative AI techniques for the dissemination of your research results? If so, are you familiar with the publisher's requirements regarding the form of disclosure and citation practices?

Yes / No

7. If you have introduced Generative AI techniques into your research, did you conduct a prior assessment of how to address vulnerabilities and biases, as well as cybersecurity risks, to prevent harm and unintended consequences?

Yes / No

8. Have you been able to anticipate the possibility of conflicts arising and have you familiarised yourself with the existing methods of contestation and redress? Following the relevant assessment, have you provided for possible conflict-resolution mechanisms? Have you clearly identified the applicable regulations and the competent authorities in the event of a potential conflict?

Yes / No

9. Do you consider that you have sufficient experience and knowledge to assess the appropriateness of using Generative AI techniques and to weigh their limitations? If so, have you addressed the metrics and the replicability of the scientific results obtained through them?

Yes / No

10. Do you consider that your use of generative AI in research complies with the Guidelines of this document, in the interest of consolidating an attitude and conduct of integrity and responsibility within the scientific community and institution to which you belong?

Yes / No