Acceptable Generative AI Tool Use (Policy IT-17)
Policy:
Background
Artificial intelligence and machine learning (“AI/ML”) tools are being increasingly used for business, research, and administrative purposes at Clarkson College (“College”). While these tools increase productivity, it is essential that they are evaluated by the Information Technology department to ensure there are no data privacy and security risks or operational impacts. Many AI/ML platforms collect the information submitted to train their models, which could allow other users or vendors to access the data after it has been processed. Therefore, if College information is submitted into an unapproved AI/ML tool, it could put that information at risk and expose it to unauthorized individuals.
Purpose
This policy outlines the AI/ML tools that may be used with College data and provides guidance for how users should use these technologies responsibly. It also outlines the process for evaluating new AI/ML tools before they are used with College information, so the College can realize the benefits of AI/ML while maintaining security standards and fulfilling our obligation to protect sensitive data. Given the rapidly evolving nature of AI/ML technologies, this policy will be reviewed annually and updated as needed to address emerging risks and capabilities.
Scope
This policy covers anyone working for or with Clarkson College, including faculty, staff, student workers, and contractors. It covers all uses of AI/ML tools in the following situations:
- When accessed through College computing resources or networks
- When College data is involved, no matter the classification level, it falls under or the device being used
- For College teaching, research, administrative, or operational purposes. Examples include, but are not limited to:
- Development of software code
- Written documentation (i.e., policy, legislation, or regulations) and correspondence (such as memorandums, letters, text messages, and emails)
- Summarizing and proofreading documents
- Making business decisions that impact short-term or long-term activities or policies and procedures
- When the usage represents or affects Clarkson Colleg
This means that any AI/ML tools used for College-related work are covered by this policy, even if they are used on a personal device or a consumer AI service. Student use of AI for academic work is governed separately by academic policies and course-specific rules set by instructors.
Procedure:
Definitions
Generative Artificial Intelligence (GenAI) Tools: Software interfaces that generate outputs (such as text, images, videos) by drawing on information from various sources. Examples include Microsoft Copilot and OpenAI ChatGPT. GenAI tools can operate as standalone apps or integrate with other software and services (for example, Copilot in Microsoft 365 can be used from the Windows desktop or within Office apps). This capability is not limited to Microsoft products. Public GenAI Tools are those available to the general market, whether free or paid.
College AI/ML Tools: Tools that have been officially approved for use with College data. These tools are permitted for handling private or restricted College information and work with private College large language models (“LLMs”) that do not share data with external parties or the public.
Users: Individuals who are authorized to access and use College computing resources, including students, faculty, staff, contractors, guests, and others granted permission.
Machine Learning: A type of artificial intelligence that enables systems to learn from data and improve their performance or predictions without being explicitly programmed.
AI Agent: A software system that uses artificial intelligence to perform tasks, make decisions, or provide recommendations on behalf of a user or organization.
Acceptable Use by Data Classification (IT-10)
The type of data users may use with an AI/ML tool depends on what the tool has been approved to process, store, or transmit. Each approved AI/ML tool is assigned a maximum data classification level, as listed in the Approved software Listing.
- Public Data (Low Risk): May be used with any approved AI/ML tool.
- Private Data (Moderate Risk): May be used only with tools approved for private data or higher.
- Restricted Data (High Risk): May be used only with tools specifically approved to handle restricted data.
If data spans multiple classifications, use the highest-risk classification. Consult the Risk Classification Guide (IT-10) for details and examples.
Before using any AI/ML tool with College data, verify that it is authorized for the required classification in the Approved Software Listing. Never input College data into an unapproved AI/ML tool, regardless of classification. If the tool isn’t listed, initiate the technology approval process described later in this policy.
User Responsibilities
Anyone using AI/ML tools for College business, whether approved by Clarkson College or not, must follow these requirements:
- Accountability and Accuracy
Users are responsible for any AI/ML output that is used for official College work. All AI-generated content must be checked for accuracy before use or distribution and should never be used verbatim. These tools make mistakes, invent citations, and present false information confidently, so verifying against reliable sources is required.
- Legitimate Use Only
AI/ML tools are for authorized College business only. Users must not use AI to impersonate people without their permission, fabricate or alter research data, or misrepresent information.
- Avoiding Harmful Activities
Do not use AI/ML tools for malicious purposes, such as spreading disinformation, deceiving others, or harassing anyone.
- Avoiding High-Risk Decision Making
AI/ML tools must not be used for highly consequential automated decision-making without prior consultation and approval from the appropriate department director and Information Technology. Examples include:
- Policy creation
- Legal analysis or advice
- Recruitment, hiring, or personnel decisions
- Disciplinary decision-making
- Work that replaces duties of represented employees
- Security tools using facial recognition or biometric data
- Grading or assessment of student work
If uncertain about whether a planned use is considered high-risk decision-making, consult your department director and the Director of Technology Services before proceeding.
- Obtaining Approval for New Use Cases
Before implementing any new application of AI/ML tools in their work, users must evaluate the ethics and risks involved and obtain approval from their department director. This is in addition to the technology approval and review process managed by the Information Technology department.
- Additional Responsibilities for Public AI/ML Tools
When using public AI/ML tools, users must:
- Protect Privacy: Users must not input personal information about students, faculty, staff, community members, or research participants into public AI systems
- Respect Intellectual Property: Users must ensure they have the right to use any copyrighted materials with AI tools. Fair use principles must be followed, especially when creating derivative works.
- Compliance: Users must follow all applicable laws, regulations, and College policies. See the Related Documentation section for more information.
Procurement Process
If users wish to utilize an AI/ML tool not listed on the Approved Software Listing, it must undergo a security risk assessment and operational review to determine its suitability for use with the College data and compatibility with existing College infrastructure and systems. The procurement process for a new AI/ML tool has been outlined below.
- Submitting a Request:
To begin, submit a ticket with the Help Desk that includes the name of the AI/ML tool and the vendor, a description of how the user intends to use the tool, the type of data that will be processed (public, private, or restricted), any existing account or subscription information, and the requester’s department and contact information.
- Risk Assessment Process:
The Information Technology department at Clarkson College will conduct a security risk assessment after the request is received. This assessment involves reviewing the vendor’s security practices and data handling procedures, privacy policies, compliance with relevant regulations, how the tool stores data, whether inputs are used for training, encryption levels, and protection against unauthorized access.
- Operational Review Process:
Information Technology evaluates the tool's operational fit within the College infrastructure. This includes reviewing platform architecture, system requirements, third-party dependencies, licensing model, ease of deployment and maintenance, and vendor support capabilities.
- Approval Workflow:
After the risk assessment and operational review are complete, the request goes to the appropriate approval authority based on the data classification involved. Tools handling restricted data require higher-level approval than those used with public information. The requester will be notified of the decision and any conditions that apply to using the tool. Once the tool is approved for use, it will be added to the Approved Software Listing, so other users are aware that it is approved for use.
- Required Training:
Prior to using an approved AI/ML tool, users are required to complete the most recent AI, data privacy, and security awareness training.
Data Privacy and Security
All AI/ML tools used with Clarkson College data must meet defined security requirements to protect against unauthorized access and data breaches. Data privacy and security requirements for AI/ML tools and their respective vendors at Clarkson College are outlined below.
- Training and Restrictions
AI/ML tools approved for handling private or restricted College data must not use that data to train their models or make it available to other users. The tool’s configuration should prevent College data from being incorporated into the vendor’s general training datasets or shared beyond Clarkson College. Before approving a tool, Information Technology verifies that appropriate data isolation controls are in place to enforce these protections.
- Encryption Requirements
Any AI/ML tool that processes or stores College data must encrypt that information both at rest and in transit. Encryption should adhere to current industry best practices to prevent unauthorized access in the event that data is intercepted or storage is compromised.
- Minimum Security Standards
All AI/ML tools must comply with the data security standards of Clarkson College and relevant legal regulations. These standards cover access controls, authentication, audit logging, and other vendor security requirements. The Information Technology department maintains detailed technical requirements that vendors must meet based on the data classification levels they will handle.
- Contractual Requirements
AI/ML tools and vendors handling the restricted and private data at Clarkson College must be bound by the Information Security Addendum (ISA) or an approved equivalent. The ISA specifies required security controls, data handling practices, breach notification, incident response, audit rights, sub-processor restrictions, and data retention/destruction provisions governing the relationship with the College. The ISA must be in place before processing data, with evidence of execution in procurement records. Where applicable, the College may require additional security audit documentation (SOC 2 Type II, ISO 27001, HECVAT). If a vendor cannot include an ISA or equivalent contractual language, the tool will not be approved for private and restricted data. The ISA remains in effect for the duration of the contract and includes data return or destruction obligations upon termination. Clarkson also administers a Service Provider Security Questionnaire (SPSQ) for vendor risk assessment; vendors may be required to complete the SPSQ to document security controls, privacy practices, regulatory compliance, and overall risk posture.
Reporting Violations
If you suspect a potential policy violation, please report it to the Information Technology department through the Help Desk, to a supervisor, or to the Director of Technology Services. Reports will be investigated confidentially, and no one will face retaliation for reporting concerns in good faith.
Enforcement
Violating this policy may result in disciplinary action, including but not limited to revocation of access to AI tools, academic penalties, or employment sanctions, in accordance with the policies and procedures of Clarkson College (see HR-7 Corrective Action, internal only). Contractors who violate this policy may face contract termination.
Academic Policies and Procedures
- Academic Honors (Policy AA-16)
- Academic Integrity (Policy SW-25)
- Academic Probation (Policy AA-20)
- Academic Related Activities and Travel Release (Policy SW-40)
- Academic Travel Abroad Release (Policy SW-11)
- Academic Year
- Acceptable Generative AI Tool Use (Policy IT-17)
- Acceptable Use-Personal Device
- Access to Campus Facilities (Policy SW-28)
- Admissions (Policy AD-1, AD-2, and AD-11)
- Advanced Standing Credit (Policy AA-47)
- Application and Enrollment Fee Waivers (Policy AD-4)
- Articulation Agreements
- Assessment of Student Success Skills (Policy OG-23)
- Auditing a Course (Policy AA-35)
- Background Checks and Drug Screening for Students (Policy SW-23)
- Student in Crisis (Policy SW-24)
- Bookstore Voucher (Policy SA-2)
- Business Ethics (Policy EC-21)
- Cancellation of Course (Policy AA-36)
- Change of Personal Information
- Code of Conduct (Policy SW-18)
- Collection of Delinquent Student Accounts (Policy SA-9)
- Computing (Policy IT-2)
- Conditional Acceptance and Recitation Requirements (Policy AD-11)
- Copyright (Policy IT-4)
- Course Load Requirements (Policy FA-6)
- Coursework Categories for Undergraduate Degrees
- Credit Hour Definition (Policy AA-55)
- Crime Awareness & Campus Security (Policy SW-5)
- Crime Reporting and Disclosures
- Undergraduate Deans List (Policy AA-27)
- Degree Progress Audit (Policy AA-5)
- Disbursement of Financial Aid (Policy FA-2)
- Discontinuance of an Academic Program (EC-24)
- Dismissal (Policy AA-24)
- Drug and Alcohol (Policy SW-15)
- Computing Policy (Policy IT-2)
- Email (Policy IT-1)
- Emergency Notification, Response and Evacuation (Policy SW-30)
- Emotional Support Animal (Policy SW-38)
- Equal Opportunity and Non- Discrimination (Policy SW-1)
- Family Education Rights & Privacy Act (Policy SS-9)
- FERPA Identify Verification
- Financial Aid Award (Policy FA-19)
- Financial Aid Eligibility Requirements (Policy FA-20)
- Forms Submission
- Freedom of Expression (Policy EC-22)
- Grade Change (Policy AA-37)
- Grade Point Average (Policy AA-29)
- Grade Reports
- Graduation Eligibility (Policy AA-8)
- Health and Safety Requirements (Policy SW-7)
- Help Desk (Policy IT-7)
- Identification Badge (Policy SS-10)
- Incident Reporting (Policy OG-6)
- Incomplete Grades (Policy AA-10)
- Independent Study (Policy AA-41)
- Information Security (Policy IT-11)
- Institutional Repository (Policy OG-30)
- Institutional Review of Research Involving Human Subjects (Policy OG-8)
- International Admissions & Transcripts (Policy AD-2)
- Interprofessional Education, Intercultural Development Inventory (IDI), and Service (AA-54)
- Issuing Timely Warnings (Policy SW-32)
- Last Date of Attendance (Policy AA-63)
- Law Enforcement on Campus (Policy SW-33)
- Leave of Absence (Policy AA-30)
- Letter Grades and Quality Points (Policy AA-6)
- Liability Insurance (Policy SW-12)
- Library Collection Development (Policy OG-29)
- Media (Policy OG-12)
- Missing Student (Policy SW-34)
- Non-Smoking (Policy SW-16)
- Online Education
- Organizational Governance-Policy Guidelines (OG-15)
- Petition for a Course Offering
- Student Petition for Reconsideration (Policy SW-22)
- Privacy (Policy IT-3)
- Professional Judgment (Policy FA-17)
- Program Completion (Policy AA-17)
- Progression (Policy AA-2)
- Public Address System (Policy OG-3)
- Public Complaint (Policy EC-20)
- Readmission (Policy AD-10)
- Registration/Add a Course (Policy AA-32)
- Reporting Criminal Offenses (Policy SW-36)
- Credit Hour Residency Requirement (Policy AA-28)
- Records Retention (Policy EC-2)
- Satisfactory Academic Progress for Financial Aid Eligibility (FA-21)
- Security Awareness Programs (Policy SW-37)
- Service Animal (Policy SW-39)
- Sexual Misconduct (Policy SW-27)
- Social Media (Policy OG-28)
- State Authorization
- Statement of Financial Responsibility (Policy SA-12)
- Student Accommodations (Policy SW-2)
- Student Classifications & Status
- Student Emergency Fund
- Student Grievance (Policy SW-14)
- Student Location & Disclosures for Professional Licensure or Certification Disclosure (Policy OG-33)
- Student Parking (Policy SS-1)
- Teach-Out (Policy AA-64)
- Transcripts
- Transfer Credit (Policy AA-52)
- Tuition and Fees Payment Plan (Policy SA-10)
- Tuition Refund (Policy SA-6)
- Undergraduate Class Standing (Policy AA-38)
- Weather-Related School Closing (Policy OG-4)
- Withdrawal From Course Grade (Policy AA-3)
