Acceptable Generative AI Tool Use (Policy IT-17)

Policy: 

Background

Artificial intelligence and machine learning (“AI/ML”) tools are being increasingly used for business, research, and administrative purposes at Clarkson College (“College”). While these tools increase productivity, it is essential that they are evaluated by the Information Technology department to ensure there are no data privacy and security risks or operational impacts. Many AI/ML platforms collect the information submitted to train their models, which could allow other users or vendors to access the data after it has been processed. Therefore, if College information is submitted into an unapproved AI/ML tool, it could put that information at risk and expose it to unauthorized individuals.

Purpose

This policy outlines the AI/ML tools that may be used with College data and provides guidance for how users should use these technologies responsibly. It also outlines the process for evaluating new AI/ML tools before they are used with College information, so the College can realize the benefits of AI/ML while maintaining security standards and fulfilling our obligation to protect sensitive data. Given the rapidly evolving nature of AI/ML technologies, this policy will be reviewed annually and updated as needed to address emerging risks and capabilities.

Scope

This policy covers anyone working for or with Clarkson College, including faculty, staff, student workers, and contractors. It covers all uses of AI/ML tools in the following situations:

  • When accessed through College computing resources or networks
  • When College data is involved, no matter the classification level, it falls under or the device being used
  • For College teaching, research, administrative, or operational purposes. Examples include, but are not limited to:
    • Development of software code
    • Written documentation (i.e., policy, legislation, or regulations) and correspondence (such as memorandums, letters, text messages, and emails)
    • Summarizing and proofreading documents
    • Making business decisions that impact short-term or long-term activities or policies and procedures
    • When the usage represents or affects Clarkson Colleg

This means that any AI/ML tools used for College-related work are covered by this policy, even if they are used on a personal device or a consumer AI service. Student use of AI for academic work is governed separately by academic policies and course-specific rules set by instructors.

Procedure:

Definitions

Generative Artificial Intelligence (GenAI) Tools: Software interfaces that generate outputs (such as text, images, videos) by drawing on information from various sources. Examples include Microsoft Copilot and OpenAI ChatGPT. GenAI tools can operate as standalone apps or integrate with other software and services (for example, Copilot in Microsoft 365 can be used from the Windows desktop or within Office apps). This capability is not limited to Microsoft products. Public GenAI Tools are those available to the general market, whether free or paid.

College AI/ML Tools: Tools that have been officially approved for use with College data. These tools are permitted for handling private or restricted College information and work with private College large language models (“LLMs”) that do not share data with external parties or the public.

Users: Individuals who are authorized to access and use College computing resources, including students, faculty, staff, contractors, guests, and others granted permission.

Machine Learning: A type of artificial intelligence that enables systems to learn from data and improve their performance or predictions without being explicitly programmed.

AI Agent: A software system that uses artificial intelligence to perform tasks, make decisions, or provide recommendations on behalf of a user or organization.

Acceptable Use by Data Classification (IT-10)

The type of data users may use with an AI/ML tool depends on what the tool has been approved to process, store, or transmit. Each approved AI/ML tool is assigned a maximum data classification level, as listed in the Approved software Listing.

  • Public Data (Low Risk): May be used with any approved AI/ML tool.
  • Private Data (Moderate Risk): May be used only with tools approved for private data or higher.
  • Restricted Data (High Risk): May be used only with tools specifically approved to handle restricted data.

If data spans multiple classifications, use the highest-risk classification. Consult the Risk Classification Guide (IT-10) for details and examples.

Before using any AI/ML tool with College data, verify that it is authorized for the required classification in the Approved Software Listing. Never input College data into an unapproved AI/ML tool, regardless of classification. If the tool isn’t listed, initiate the technology approval process described later in this policy.

User Responsibilities

Anyone using AI/ML tools for College business, whether approved by Clarkson College or not, must follow these requirements:  

  • Accountability and Accuracy

Users are responsible for any AI/ML output that is used for official College work. All AI-generated content must be checked for accuracy before use or distribution and should never be used verbatim. These tools make mistakes, invent citations, and present false information confidently, so verifying against reliable sources is required.

  • Legitimate Use Only

AI/ML tools are for authorized College business only. Users must not use AI to impersonate people without their permission, fabricate or alter research data, or misrepresent information.

  • Avoiding Harmful Activities

Do not use AI/ML tools for malicious purposes, such as spreading disinformation, deceiving others, or harassing anyone.

  • Avoiding High-Risk Decision Making

AI/ML tools must not be used for highly consequential automated decision-making without prior consultation and approval from the appropriate department director and Information Technology. Examples include:

  • Policy creation
  • Legal analysis or advice
  • Recruitment, hiring, or personnel decisions
  • Disciplinary decision-making
  • Work that replaces duties of represented employees
  • Security tools using facial recognition or biometric data
  • Grading or assessment of student work

If uncertain about whether a planned use is considered high-risk decision-making, consult your department director and the Director of Technology Services before proceeding.

  • Obtaining Approval for New Use Cases

Before implementing any new application of AI/ML tools in their work, users must evaluate the ethics and risks involved and obtain approval from their department director. This is in addition to the technology approval and review process managed by the Information Technology department.

  • Additional Responsibilities for Public AI/ML Tools

When using public AI/ML tools, users must:

  • Protect Privacy: Users must not input personal information about students, faculty, staff, community members, or research participants into public AI systems
  •  Respect Intellectual Property: Users must ensure they have the right to use any copyrighted materials with AI tools. Fair use principles must be followed, especially when creating derivative works.
  •  Compliance: Users must follow all applicable laws, regulations, and College policies. See the Related Documentation section for more information.

Procurement Process

If users wish to utilize an AI/ML tool not listed on the Approved Software Listing, it must undergo a security risk assessment and operational review to determine its suitability for use with the College data and compatibility with existing College infrastructure and systems. The procurement process for a new AI/ML tool has been outlined below.

  1. Submitting a Request:

To begin, submit a ticket with the Help Desk that includes the name of the AI/ML tool and the vendor, a description of how the user intends to use the tool, the type of data that will be processed (public, private, or restricted), any existing account or subscription information, and the requester’s department and contact information.

 

  1. Risk Assessment Process:

The Information Technology department at Clarkson College will conduct a security risk assessment after the request is received. This assessment involves reviewing the vendor’s security practices and data handling procedures, privacy policies, compliance with relevant regulations, how the tool stores data, whether inputs are used for training, encryption levels, and protection against unauthorized access.

 

  1. Operational Review Process:

Information Technology evaluates the tool's operational fit within the College infrastructure. This includes reviewing platform architecture, system requirements, third-party dependencies, licensing model, ease of deployment and maintenance, and vendor support capabilities.

 

  1. Approval Workflow:

After the risk assessment and operational review are complete, the request goes to the appropriate approval authority based on the data classification involved. Tools handling restricted data require higher-level approval than those used with public information. The requester will be notified of the decision and any conditions that apply to using the tool. Once the tool is approved for use, it will be added to the Approved Software Listing, so other users are aware that it is approved for use.

 

  1. Required Training:

Prior to using an approved AI/ML tool, users are required to complete the most recent AI, data privacy, and security awareness training.

Data Privacy and Security

All AI/ML tools used with Clarkson College data must meet defined security requirements to protect against unauthorized access and data breaches. Data privacy and security requirements for AI/ML tools and their respective vendors at Clarkson College are outlined below.

  • Training and Restrictions

AI/ML tools approved for handling private or restricted College data must not use that data to train their models or make it available to other users. The tool’s configuration should prevent College data from being incorporated into the vendor’s general training datasets or shared beyond Clarkson College. Before approving a tool, Information Technology verifies that appropriate data isolation controls are in place to enforce these protections.

  • Encryption Requirements

Any AI/ML tool that processes or stores College data must encrypt that information both at rest and in transit. Encryption should adhere to current industry best practices to prevent unauthorized access in the event that data is intercepted or storage is compromised.

 

  • Minimum Security Standards

All AI/ML tools must comply with the data security standards of Clarkson College and relevant legal regulations. These standards cover access controls, authentication, audit logging, and other vendor security requirements. The Information Technology department maintains detailed technical requirements that vendors must meet based on the data classification levels they will handle.

  • Contractual Requirements

AI/ML tools and vendors handling the restricted and private data at Clarkson College must be bound by the Information Security Addendum (ISA) or an approved equivalent. The ISA specifies required security controls, data handling practices, breach notification, incident response, audit rights, sub-processor restrictions, and data retention/destruction provisions governing the relationship with the College. The ISA must be in place before processing data, with evidence of execution in procurement records. Where applicable, the College may require additional security audit documentation (SOC 2 Type II, ISO 27001, HECVAT). If a vendor cannot include an ISA or equivalent contractual language, the tool will not be approved for private and restricted data. The ISA remains in effect for the duration of the contract and includes data return or destruction obligations upon termination. Clarkson also administers a Service Provider Security Questionnaire (SPSQ) for vendor risk assessment; vendors may be required to complete the SPSQ to document security controls, privacy practices, regulatory compliance, and overall risk posture.

Reporting Violations

If you suspect a potential policy violation, please report it to the Information Technology department through the Help Desk, to a supervisor, or to the Director of Technology Services. Reports will be investigated confidentially, and no one will face retaliation for reporting concerns in good faith.

Enforcement

Violating this policy may result in disciplinary action, including but not limited to revocation of access to AI tools, academic penalties, or employment sanctions, in accordance with the policies and procedures of Clarkson College (see HR-7 Corrective Action, internal only).  Contractors who violate this policy may face contract termination.