Part-IS does not prohibit artificial intelligence in aeronautical tenders. An AI falls within the Part-IS analysis when the systems, data, services, or interfaces it uses are exposed to information security risks that may have an impact on aviation safety. The confidential nature of a document or the use of an AI is therefore not sufficient, on its own, to trigger Part-IS. For a bidder or a buyer, the challenge is to define the actual scope of the processing, its interfaces, and its potential impact on aviation safety.
What does Part-IS cover in aviation?
Part-IS governs information security risks that may have an impact on aviation safety; it does not regulate AI as a distinct technology. The framework is based in particular on Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022, applicable since 16 October 2025, and on Implementing Regulation (EU) 2023/203 of 27 October 2022, whose consolidated version is applicable as of 22 February 2026.
These texts cover different categories of civil aviation organisations. Regulation 2022/1645 applies in particular to certain design and production organisations under Part-21, as well as certain aerodrome operators. Regulation 2023/203 applies to other organisations, notably those involved in continuing airworthiness, air operations, personnel, air traffic management and U-space. The scope must therefore be checked organisation by organisation: belonging to the aeronautical sector does not mean that every activity or every piece of data automatically falls under Part-IS.
When does an AI for tenders fall within the Part-IS analysis?
An AI used for tenders falls within the Part-IS analysis when its use involves elements or interfaces exposed to an information security risk that may have an impact on aviation safety. Point IS.I.OR.205 of Regulation (EU) 2023/203 requires the organization to identify its activities, facilities, resources, and services, as well as the equipment, systems, data, and information that contribute to their operation. It also requires identifying interfaces with other organizations that may create mutual exposure to risks.
For an AI used during an aeronautical tender process, five questions help define the scope:
- What data is processed? You must identify the information from the tender dossier that is actually imported or used.
- What activity do they contribute to? The link with an activity likely to have an impact on aviation safety is decisive.
- Where is the processing carried out? The architecture determines, in particular, the interfaces and flows to be analyzed.
- Which third parties or systems are connected? The publisher, service providers, and internal systems may create additional interfaces.
- What risk could result from this? Part-IS targets information security risks that could have an impact on aviation safety.
A business requirements document with no link to aviation safety therefore does not become Part-IS data simply because it comes from an aeronautics stakeholder. Conversely, a call for tenders may involve information, systems, or interfaces that fall within the assessment provided for by IS.I.OR.205.
Does Part-IS require on-premises or air-gapped AI?
No. Part-IS does not require an on-premise or air-gapped architecture for all artificial intelligence tools. The regulation requires risk management covering systems, data, services, and interfaces; it does not designate an AI architecture as compliant in principle. However, the chosen architecture concretely changes the flows and interfaces that the organization must analyze.
| Architecture | Flows to review | Part-IS point of attention |
|---|---|---|
| External AI service | Documents or data transmitted outside the internal system | Interfaces with the supplier and services received |
| On-premise | Processing within the organization’s infrastructure | Integration into the IS, access and data processed |
| Air-gapped | Processing in an isolated network | Local access, updates and transfers |
A local installation can reduce certain external interfaces, but it does not, on its own, make the tool “Part-IS compliant”. For a CISO, an offering manager, or a buyer, the useful question is therefore: what systems, data, services, and interfaces does this AI add to our risk analysis?
Can ChatGPT or a cloud AI be used for an aerospace call for tenders?
Part-IS does not prohibit cloud AI services. However, their use must be assessed based on the data transmitted, the processing carried out outside the information system, and the interfaces created with the provider. So the question is not “cloud or not cloud,” but which data, which flows, and which risks for aviation safety?
What should be checked before using an AI in an aeronautical tender?
The actual processing of information must be documented before concluding on the integration of AI into the Part-IS framework. The analysis must cover the main processing as well as the accompanying services, interfaces, and access rights.
- Nature of the information. Distinguish between business documents, technical specifications, program data, and information related to activities likely to affect aviation safety.
- Model execution location. Local processing and a call to an external service do not create the same interfaces.
- Outbound flows. Identify whether documents, extracts, logs, or other data leave the organization’s environment.
- Service providers involved. List the services received and the interfaces created with other organizations.
- Access rights. Check that AI does not lead to expanding, without analysis, access to information reserved for certain functions or programs.
- Potential impact on aviation safety. It is this link that makes Part-IS relevant, not the presence of the term “AI”.
Is an AI provider automatically subject to Part-IS?
No. An external supplier does not automatically fall within the scope of Part-IS. However, the organisation concerned must analyse the risks created by the interface with this supplier. Where the supplier directly performs information security management activities covered by Part-IS, additional requirements may apply.
How does Specgen handle aeronautics tenders?
Specgen is a French artificial intelligence platform for complex technical tenders, with one solution for bidders and another for buyers. It analyses the tender dossier, extracts and structures requirements, searches internal knowledge that the user is authorised to access, assists drafting in existing documents, and checks the response for compliance. It can be deployed on-premise or air-gapped, with no external AI API and no outbound data flows, so that dossiers and internal knowledge are processed within the organisation’s infrastructure.
In aviation, this architecture makes it possible to process the tender documents and selected knowledge within the organization’s infrastructure. It does not make the tool or the organization “Part-IS compliant”: qualification still depends on the scope, the data, the interfaces, and the risks identified by the organization.The Specgen page dedicated to aerospace calls for tenders presents the uses of the platform for this sector.
To review the architecture suited to your aeronautics tenders, a demonstration can be arranged with the relevant teams.
FAQ: Part-IS, AI and aeronautical tenders
Does Part-IS prohibit artificial intelligence?
No. Part-IS governs information security risks that may affect aviation safety; it does not prohibit a particular technology. An organisation must determine whether the use of AI involves systems, data, services or interfaces that fall within its risk assessment, and then apply appropriate measures.
Can ChatGPT be used for an aeronautics tender?
Part-IS does not mention ChatGPT and does not prohibit it in principle. However, the organization must analyze the data sent, the flows created to the external service, and the risks associated with that interface when these may have an impact on aviation safety. The use case and the data processed are therefore decisive.
Is an on-premise AI compliant with Part-IS?
No, not by nature. An on-premise architecture reduces certain external interfaces but does not constitute regulatory compliance in itself. The organization must still identify the relevant systems, data, services, and interfaces, assess risks likely to affect aviation safety, and implement appropriate risk treatment measures.
Is an AI provider automatically subject to IS.I.OR.235?
No. According to EASA, IS.I.OR.235 targets providers or subcontractors that perform tasks falling under information security management activities. Other providers may nevertheless be concerned by the interface and risk analysis required by IS.I.OR.205.
Key takeaways
Part-IS does not prohibit artificial intelligence in aeronautics tenders. Its application depends on the data, systems, services, and interfaces involved, and above all on their potential impact on aviation safety. A cloud, on-premise, or air-gapped AI is therefore not inherently “Part-IS compliant.” The right architecture is the one that enables the organization to control its data, flows, interfaces, and the associated risks.
Sources
Commission Delegated Regulation (EU) 2022/1645 of 14 July 2022 (EUR-Lex)
Commission Implementing Regulation (EU) 2023/203 of 27 October 2022 (EUR-Lex)
EASA, Part-IS Implementation Task Force: FAQ and AMC/GM, in particular IS.I.OR.205 and IS.I.OR.235

