Skip to main content

UTEP Standard 26: Acceptable Use of AI Tools

This AI Use Standard lays out best practices for using AI while protecting sensitive data, whether institutional, personal, or proprietary. As things continue to evolve, expect further updates.

Allowable Use

 

When publicly available tools like ChatGPT or Google Gemini are used, any data entered can be used to train the corresponding large language model as if it were published. The university provides access to AI tools that contractually safeguard your information and ensure it remains protected from public disclosure. The University’s Microsoft Campus Agreement includes the necessary data protections, to include not using customer data to train their models. As a result, you can use university data in the university instance of Microsoft Co-Pilot and protect that data from public disclosure.

The following guidance outlines the types of data that may be used with AI tools in accordance with the UTEP Information Security Standard 9 - Data Classification Standard and relevant university polices.

Public or Published Data

Data that is publicly available or classified as Published university information, as defined by the UTEP Information Security Standard 9 - Data Classification Standard (DCS), may be used freely with all AI tools.

Acceptable Use

In all cases, use should be consistent with the Acceptable Use Policy.

Controlled or Confidential Data

Data classified as Controlled or Confidential university information, as defined by the UTEP information Security Standard 9 – Data Classification Standard, can be used with AI tools that are managed by the university and covered by contracts explicitly protecting university data. These contracts should ensure that the data is NOT used to train the corporation’s models. It should also ensure data is isolated in a separate instance inaccessible to external parties.

Prohibited Use

 

Unauthorized AI Tools

AI tools that lack a university contract and appropriate data-sharing controls are not approved for use with Controlled or Confidential university data, as defined by the UTEP information Security Standard 9 – Data Classification Standard. This includes free or non-UT-managed versions of AI tools like ChatGPT and Copilot.

Sensitive Information

Student records subject to FERPA, proprietary information, and any other data classified as Confidential or Controlled must not be used with AI tools that are not contracted with the university and protected.

Non-Public Output

Unauthorized AI tools should not be used to generate non-public outputs, such as proprietary or unpublished research, legal analysis or advice, recruitment or personnel decisions, academic work when prohibited by instructors, creation of non-public instructional materials, or grading.

Additional Guidance

 

Personal Liability

Accepting click-through agreements without delegated signature authority may result in personal responsibility for compliance with the terms and conditions of the AI tool.

Vendor and Third-Party Compliance

When engaging with AI tools provided by external vendors, ensure compliance with UTEP Information Security Standard 22, which outlines requirements for vendor and third-party controls and compliance.

Standardized Notice

University is required by state rules to ensure that any AI system deployed or used, if it interacts directly with the public or is a controlling factor in a consequential decision, includes a standardized notice. More information on that notice will be forthcoming.

 

For more information on the use of AI Tools for teaching and learning, please see the following guidance from the Office of the Provost.

 

For more information on the use of AI tools for Research, please see the following for guidance from Research & Innovation.

FAQs

Public or Published Data: You may use data that is publicly available or classified as Published University information with AI tools.
Controlled or Confidential Data: You may use these data types only with university-managed AI tools covered by contracts that protect university data and prevent its use for model training. The data must be processed in isolated environments inaccessible to external parties.
Microsoft Copilot and related tools are authorized, as the university’s contract with Microsoft includes necessary safeguards. All use must comply with the university’s Acceptable Use Policy.
Public AI tools do not offer data or intellectual property protection. In contrast, Copilot Chat and 365 Copilot provide a secure environment where users can explore, create and innovate within protected boundaries.
Yes. AI tools not covered by a university-approved contract (such as free or non-university licensed versions of Copilot, ChatGPT, Gemini, or Grok) are not approved for use with Controlled or Confidential data.
No. Student records protected under FERPA, proprietary information, and any other Confidential or Controlled data must not be entered into unauthorized AI tools.
Non-public content such as proprietary or unpublished research, legal analysis, recruitment or personnel decisions, academic work not permitted by instructors, instructional material not intended for public release, or grading must not be processed or generated by unauthorized AI tools.
Yes. AI tools must not be used for illegal, fraudulent, or policy-violating activities. Accepting click-through agreements without delegated signature authority may result in personal liability for compliance with the tool’s terms.
Ensure compliance with UTEP Information Security Standard 22, which outlines requirements for vendor and third-party controls and compliance.
FERPA is covered under the Data Protection Addendum established with the UT System. Microsoft’s approach to FERPA compliance can be found here: Microsoft and FERPA
Risks include data leakage, loss of ownership of intellectual property, and copyright issues. Non-public materials include unpublished research, internal curriculum, or proprietary training modules.
Microsoft has pledged to be carbon negative by 2030 and to remove all historical carbon emissions by 2050. Many Azure data centers run on 100% renewable energy, with ongoing efforts to expand this globally.
Microsoft’s most recent Environmental Sustainability Report includes comprehensive details on its global initiatives, including Azure’s platform-level efforts.

Guidance on Appropriate Use

For questions regarding the appropriate use of AI Tools, please contact the UTEP Information Security Office at security@utep.edu.