Artificial Intelligence Policy

1. Policy Statement

United States University (USU) supports responsible artificial intelligence that advances its mission to provide affordable, relevant, accessible, and student-centered education and serve students whose access may be limited by geography, life responsibilities, or traditional educational pathways. AI should expand access, strengthen learning and student support, improve institutional effectiveness, and prepare students for an AI-enabled workforce while preserving academic quality, human relationships, privacy, security, fairness, accessibility, and trust.

AI is not a replacement for faculty, advisors, staff, academic leaders, or student effort. People remain accountable for teaching, mentoring, assessment, advising, support, and consequential decisions. AI may assist, but it may not serve as the sole basis for a decision that materially affects a student, applicant, employee, academic outcome, financial status, access to services, disability accommodation, conduct outcome, clinical placement, or other significant interest.

Academic core

Course and assignment expectations control student AI use. Faculty retain authority to define appropriate use within institutional policy and program requirements. Students remain responsible for the originality, accuracy, attribution, evidence, and integrity of all submitted work.

2. Purpose and Objectives

This policy establishes institution-specific rules for AI use at USU while aligning with the enterprise AI governance framework. It is intended to support WSCUC expectations, federal distance-education requirements where applicable, and continuous improvement in student learning and success.

  • Provide clear expectations for students, faculty, staff, applicants, researchers, contractors, and vendors.
  • Preserve the validity of learning outcomes, assessment, academic integrity, faculty judgment, and required instructor interaction.
  • Protect education records, financial-aid information, health or clinical information, employee records, research data, and other institutional information.
  • Require human oversight, notice, correction, complaint, and appeal protections for high-impact student-facing AI.
  • Establish risk-based approval, testing, vendor review, monitoring, recordkeeping, incident response, and retirement requirements.
  • Promote responsible AI literacy, critical evaluation, ethical use, and workforce readiness.

3. Scope, Authority, and Policy Hierarchy

This policy applies to USU students, applicants, faculty, staff, administrators, researchers, contractors, agents, and vendors when they use AI for university education, employment, research, clinical or field activity, administration, communication, or services; use university systems or data; or represent the use as a USU activity.

It applies to stand-alone and embedded AI, free and paid tools, personal accounts used for university work, open-source models, generative AI, predictive analytics, AI-enabled automation, chatbots, tutoring systems, learning analytics, academic-integrity tools, proctoring or identity systems, synthetic media, and agentic AI.

  • The AIGC governs enterprise standards, risk classification, approved tools, high-impact use cases, vendor controls, public claims, and cross-entity systems.
  • USU academic leadership and appropriate faculty governance retain authority over academic policy, curriculum, program outcomes, faculty expectations, assessment, grading, academic integrity, student academic rights, and accreditation evidence.
  • Faculty may set course and assignment AI expectations within this policy and applicable program or academic requirements.
  • Applicable law, regulation, accreditation requirements, clinical or field-partner rules, contracts, accommodations, research requirements, records obligations, and stricter university policies control where they impose additional requirements.
  • Approval of a tool does not authorize every use; approval of a use case does not grant access to data, content, or systems otherwise restricted.

This policy applies to USU and to programs, personnel, records, systems, or operations integrated into USU through an approved transaction, merger, teach-out, or transfer, to the extent authorized by regulators and accreditors. Until a transition is legally and operationally effective, the adopted policy of the originating institution remains in force unless a documented transition standard is approved by the AIGC and the appropriate academic authority.

4. Definitions

Term  Definition
Accountable human A person with appropriate authority and subject-matter knowledge who reviews AI-supported work, exercises independent judgment, and remains responsible for the resulting decision, action, communication, or record.
Agentic AI An AI system that can plan or carry out multi-step tasks, call tools, access systems, send communications, change records, initiate transactions, or take other actions with limited human intervention.
AI incident An event or near miss involving unauthorized disclosure, security compromise, harmful or discriminatory output, significant error, improper automation, intellectual-property concern, policy violation, unsupported public claim, or other material adverse effect involving AI.
AI system A machine-based system that infers from inputs to generate predictions, recommendations, classifications, content, or actions. The term includes generative AI, machine learning, predictive analytics, AI-enabled automation, and embedded AI features.
AI AI tool An AI system authorized for a defined entity, purpose, user group, data classification, and risk level through the AIGC-approved process. Approval of a tool does not approve every possible use of that tool.
Generative AI AI that produces or transforms text, code, images, audio, video, data, or other content in response to prompts or other inputs.
High-impact AI AI that informs, recommends, automates, or materially influences a decision or service affecting a student, applicant, employee, financial interest, academic outcome, legal or compliance obligation, public statement, or other significant interest.
Institutional data Data created, received, maintained, licensed, or controlled by or for the entity, including student, employee, financial, operational, academic, research, security, legal, contractual, and strategic information.
Material AI use Use of AI that meaningfully contributes to the substance, analysis, expression, coding, evidence, recommendation, decision, or final form of work, rather than merely correcting spelling, formatting, or other routine mechanics.
Restricted data Information requiring the highest level of protection, including education records and student PII, financial-aid information, nonpublic financial or investor information, employee records, health or clinical information, credentials and security data, privileged legal information, and other information designated restricted by policy or law.
AI-assisted academic work Student or faculty work in which AI contributes to ideas, language, analysis, code, images, translation, feedback, research, or another substantive element.
Course AI expectations The faculty-established rules for AI use in a course or assignment, consistent with this policy, program requirements, academic governance, accreditation, and learning outcomes.
Student-facing AI An AI system that communicates with a student or applicant, provides guidance or support, analyzes student data, or influences a service, opportunity, assessment, status, or decision affecting the individual.

5. Responsible AI Principles

5.1 Student success and mission

AI initiatives must address a defined educational or institutional need and improve, or reasonably be expected to improve, learning, support, access, affordability, workforce relevance, service quality, compliance, or institutional effectiveness.

5.2 Human-centered education

AI should strengthen the work of faculty and staff and create more time for meaningful teaching, advising, mentoring, feedback, and student care. It must not erode faculty responsibility or reduce students to automated scores or labels.

5.3 Academic integrity and AI literacy

The University will address both misuse and responsible use. Students should learn to question AI, verify evidence, identify bias and limitations, protect data, disclose material use, and apply AI ethically in academic and professional settings.

5.4 Privacy, security, fairness, and accessibility

AI use must minimize data, protect confidentiality, resist security threats, provide accessible alternatives, and be evaluated for bias, differential impact, and barriers affecting protected or vulnerable groups.

5.5 Transparency, review, and accountability

Students and other affected people should know when they are interacting with AI or when AI materially supports a high-impact process, understand limitations appropriate to the context, and have access to human assistance and established review channels.

5.6 Evidence and continuous improvement

AI must be piloted and measured where appropriate, with evidence tied to student learning, student success, service quality, accuracy, fairness, accessibility, and institutional effectiveness. Evaluation should support evidence-based improvement, student learning, student success, educational effectiveness, institutional integrity, and reliable accreditation evidence.

5.7 Distance education and instructor responsibility

Because USU provides distance education, AI may supplement but may not replace qualified instructor responsibility or the regular and substantive interaction required by applicable federal requirements and University academic standards.

6. Governance and Responsibilities

6.1 Artificial Intelligence Governance Committee

  • Approve institution-wide and high-impact AI use cases, tools, integrations, vendors, risk classifications, conditions, exceptions, and retirements.
  • Maintain the AI inventory, approved-tool registry, risk register, decision records, incident records, and monitoring expectations.
  • Require privacy, security, compliance, legal, accessibility, academic, financial-aid, HR, research, clinical, accreditation, or vendor review as appropriate.
  • Govern public statements and claims about AI capability, student outcomes, learning, service, savings, personalization, compliance, or competitive advantage.

6.2 Academic leadership and faculty governance

Academic leaders and applicable faculty governance establish program and institutional academic requirements, ensure alignment with learning outcomes and accreditation, resolve conflicts among course practices, and review AI uses that affect curriculum, assessment, grading, academic integrity, or faculty responsibility.

6.3 Faculty

Faculty must communicate course and assignment expectations, design valid assessments, review AI-supported teaching or grading materials, protect student data, provide substantive academic judgment and interaction, use approved tools, and follow academic-integrity and due-process requirements.

6.4 Students

Students must follow course and assignment rules, use only authorized data and tools, disclose material AI use, verify output and sources, protect information belonging to other people, preserve evidence of process when required, and submit work that truthfully demonstrates their own competence.

6.5 Administrative and control functions

Role  Minimum responsibility
Business or academic owner Purpose, risk, resources, approval, human oversight, training, records, metrics, monitoring, incidents, and retirement.
Technology and cybersecurity Architecture, access, secure integration, logging, testing, continuity, and incident response.
Privacy, compliance, and legal FERPA and privacy, financial-aid and consumer requirements, civil rights, contracts, records, notices, complaints, and exceptions.
Accessibility and disability services Accessible evaluation, accommodations, alternatives, and prevention of AI-created barriers.
Registrar, financial aid, advising, and student services Qualified human decisions, accurate records, student notice, correction, escalation, and appeal.
Research or clinical leadership IRB, sponsor, publication, clinical-partner, patient or participant, and professional requirements.
Procurement and vendors Due diligence, protective terms, vendor monitoring, and exit.

7. AI Risk Classification and Approval

Risk is based on use, data, affected people, scale, automation, integration, reversibility, and consequences. The same product may have different risk levels in different courses, departments, or workflows.

Risk level  Typical characteristics and examples Approval standard
Prohibited unless explicitly approved Unapproved restricted data; autonomous high-impact decisions; impersonation or deceptive synthetic media; unsupported public claims; unlawful, discriminatory, malicious, or contractually prohibited uses. Not permitted unless the AIGC grants a written, narrowly scoped exception after all required reviews.
Low risk General productivity using public or non-sensitive information, such as brainstorming, formatting, or summarizing public material in an approved tool. Permitted after required training and subject to general use rules. No separate use-case approval is ordinarily required.
Moderate risk Internal workflows, drafts, de-identified analysis, approved coding assistance, or limited-impact automation that does not make or materially influence a high-impact decision.  Documented owner, approved tool, data review, validation, and approval under an AIGC-designated process.
High impact Student-facing tools; predictive analytics using student data; advising alerts; academic, financial-aid, HR, marketing, compliance, or other consequential decision support. Full AIGC review plus relevant privacy, security, legal, compliance, accessibility, HR, finance, and academic review. Human final authority is required.
Enterprise-critical Cross-entity or high-volume systems; agentic AI with external actions; significant financial, accreditation, public-company, cybersecurity, or operational risk. Documented AIGC decision, accountable executive, controlled pilot, monitoring plan, incident and continuity controls, and periodic reauthorization.
  • Low-risk academic or productivity use is permitted only in an approved tool and within the rules of this policy, the course, and the assignment.
  • Any use involving identifiable student data, grading, advising alerts, financial aid, admissions, academic standing, conduct, accommodations, clinical placement, employee decisions, or public claims is at least high impact unless the AIGC documents otherwise.
  • Agentic AI that can change records, send messages, submit forms, make transactions, or act in external systems is high impact or enterprise-critical and requires explicit approval for each action scope.
  • Material changes in tools, models, data, integration, scale, automation, or purpose require reassessment and may require renewed approval.

8. Student Academic Use of AI

8.1 Course and assignment expectations

Faculty must state the permitted level of AI use in the syllabus, assignment instructions, or another clear course communication. Requirements may vary by assignment. Program or accreditation requirements may impose stricter rules. Course expectations should identify approved or prohibited tools, required disclosure, permitted stages of work, evidence of process, and consequences of misuse.

When course or assignment instructions are silent, students may use approved AI for low-risk learning support such as brainstorming, study questions, concept explanation, or routine spelling and grammar assistance, but may not submit AI-generated or materially AI-rewritten content as their own work. Any material use must be disclosed.

8.2 Student responsibilities

  1. Follow the most specific applicable rule: law or clinical requirement, University policy, program requirement, course syllabus, assignment instruction, and faculty direction.
  2. Remain the author and decision maker. Understand, verify, and be able to explain every submitted idea, statement, calculation, citation, code segment, image, or conclusion.
  3. Check facts, sources, quotations, citations, data, calculations, and professional or clinical claims. AI-generated sources may be false or misrepresented.
  4. Disclose material AI use in the form required by the instructor. Disclosure does not make otherwise prohibited use acceptable.
  5. Do not enter education records, patient or client information, classmate work, confidential employer or clinical-partner information, exam materials, answer keys, licensed course content, or other restricted information into an unapproved AI tool.
  6. Retain drafts, prompts, outputs, notes, version history, or reflection sufficient to demonstrate the work process when required by the course or a good-faith academic-integrity review.
  7. Use AI in a manner consistent with professional ethics, program competencies, licensure expectations, and the need to demonstrate personal mastery.

8.3 Prohibited academic conduct

  • Using AI during an examination, quiz, competency check, proctored activity, clinical evaluation, or other restricted assessment without express authorization.
  • Submitting AI output, translation, code, analysis, images, or media as original unaided work when independent work is required.
  • Fabricating or altering sources, quotations, data, interviews, research participants, clinical experiences, clinical hours, patient records, lab results, reflections, or evidence.
  • Using AI to impersonate another person, complete work for another student, defeat identity verification, evade academic-integrity controls, or conceal prohibited use.
  • Uploading work created by another person, unpublished research, instructor materials, examinations, publisher content, or confidential information without authority.
  • Relying on AI to perform professional, clinical, legal, or safety-critical judgment that the student is required to demonstrate personally.

Responsibility for submitted work

A student may not defend inaccurate, fabricated, biased, infringing, or prohibited work by stating that an AI tool produced it. The student remains responsible for the submission and for compliance with course expectations.

9. Faculty and Academic Use of AI

9.1 Course design and instructional materials

Faculty may use approved AI to assist with brainstorming, examples, outlines, question banks, rubrics, simulations, accessibility drafts, and content review when the use supports course and program outcomes. Faculty must independently evaluate accuracy, currency, level, inclusivity, accessibility, source integrity, copyright, and alignment before student use.

  • Material AI-generated course content must be reviewed and revised by qualified faculty. It must not be presented as authoritative merely because it is fluent or polished.
  • Faculty may not upload restricted student information, identifiable student work, unpublished scholarship, publisher materials, answer keys, or confidential institutional content into an unapproved tool.
  • Required AI tools must be approved, reasonably accessible, compatible with accommodations, and accompanied by an alternative when a student cannot lawfully or accessibly use the tool.
  • Faculty should teach students how AI may fail, how to verify it, how to disclose it, and how responsible use connects to the discipline and profession.

9.2 Feedback and grading

AI may assist with drafting feedback, organizing rubric evidence, or identifying patterns only in an approved environment and under active faculty supervision. Faculty must review the underlying work and make the final evaluative judgment. AI may not independently assign a final grade, make a pass/fail decision, determine competency, or issue substantive feedback without faculty review.

9.3 Faculty-student interaction

AI-generated announcements, reminders, tutoring, or responses may supplement but not replace required and meaningful faculty interaction. Faculty must remain identifiable, available, responsible for the course, and substantively engaged in teaching, feedback, discussion, and student support. Automated activity alone does not establish instructor interaction.

9.4 Faculty scholarship and professional work listing USU

Faculty are responsible for originality, accuracy, authorship, disclosure, research integrity, professional standards, and publisher or sponsor requirements. AI may not be listed as an author, and generated citations, analyses, data, and images must be verified and disclosed as required.

10. Assessment, Academic Integrity, and AI Detection

10.1 Assessment validity

Assessments must provide credible evidence of the stated learning outcomes and the competence personally demonstrated by the student. Programs and faculty should redesign or supplement assessments when unrestricted AI would defeat the outcome. Appropriate methods may include staged drafts, process notes, source checks, oral explanation, live demonstration, individualized application, supervised practice, reflection, or comparison and critique of AI output.

10.2 Academic-integrity review

A concern about AI misuse must be handled under applicable academic-integrity procedures and due process. Evidence should consider assignment rules, the work process documented by the student, drafts, sources, explanations, metadata where lawfully available, and the substance of the work.

10.3 AI-detection tools

  • An AI-detection score or automated authorship estimate may not be the sole evidence of misconduct or the sole basis for an adverse academic decision.
  • Detection tools must be institutionally approved before use, including review of privacy, data retention, vendor training, accuracy, bias, accessibility, and contractual treatment of student work.
  • Faculty must not upload student work to an unapproved detector or external service.
  • A student must have a fair opportunity to understand the concern, provide context or process evidence, and use the established review or appeal process.

10.4 Identity verification and proctoring

AI-enabled identity verification, biometric matching, behavior analysis, or remote proctoring requires high-impact approval, notice, data minimization, security, accessibility, a nonpunitive resolution path for technical failures, and qualified human review before an allegation or adverse decision. Automated suspicion, gaze, motion, emotion, or anomaly signals are not conclusive evidence.

11. Student-Facing and Administrative AI

11.1 General protections

A student-facing AI system must identify itself as automated when a reasonable person might believe it is a human, state relevant limitations, avoid implying that it can make decisions it cannot make, and provide a clear path to qualified human assistance. Student support must remain available when the system is unavailable, inaccessible, inaccurate, or inappropriate.

11.2 High-impact decisions

AI may inform but may not independently make final decisions concerning admissions, financial-aid eligibility or satisfactory academic progress, academic standing, grading, competency, transfer credit, clinical or field placement, disability accommodations, student conduct, enrollment status, withdrawal, graduation, or access to a university service or opportunity.

  • The person responsible must review relevant source information, consider context not available to the model, and have authority to override the recommendation.
  • The University must provide an established means to correct inaccurate data and seek human review or appeal of an adverse decision.
  • Records must identify the AI contribution, responsible reviewer, final action, material override, and notice provided.
  • A predictive score, risk flag, or engagement indicator may be used to offer support, not to stigmatize, punish, or create an unapproved eligibility barrier.

11.3 Advising, outreach, and early alerts

AI-supported advising and early alerts must use validated data, proportionate outreach, respectful language, and human context. Risk indicators must not be treated as diagnoses or facts. Owners must monitor false positives and negatives, differential outreach, student response, intervention completion, and whether the system improves support rather than simply increasing contact volume.

11.4 Financial aid

AI may assist with workflow, document organization, reminders, quality checks, or decision support only in approved systems. Qualified financial-aid personnel retain responsibility for eligibility, satisfactory academic progress, verification, professional judgment, packaging, disbursement, return-of-funds, and adverse communications. Student financial information may not be entered into unapproved AI.

11.5 Marketing, enrollment, and communications

AI-generated or personalized communications must be accurate, accessible, nondeceptive, approved for the data used, and reviewed before publication or high-volume delivery. Bots must not misrepresent themselves as people, pressure applicants through fabricated urgency, claim guaranteed outcomes, or use sensitive traits for unapproved targeting.

12. Research, Clinical, and Professional Uses

12.1 Research and scholarship

  • Researchers must follow IRB, sponsor, data-use agreement, grant, publication, professional, and research-integrity requirements. Approval of an AI tool does not replace research approval.
  • Human-subject data, identifiable education records, confidential sponsor information, unpublished participant data, or restricted datasets may be used only in a specifically approved environment and protocol.
  • AI may not be named as an author. Researchers remain accountable for methods, analysis, code, data, citations, images, interpretation, disclosure, and reproducibility.
  • Synthetic data or AI-generated material must be clearly identified and evaluated for whether it preserves or distorts the characteristics needed for the research.
  • AI-assisted literature review must include source verification; generated citations may not be relied on without checking the underlying work.

12.2 Clinical, practicum, and field education

  • Patient, client, student, site, or partner information may not be entered into an unapproved AI system. De-identification must satisfy the applicable context and partner requirements.
  • AI may not independently diagnose, prescribe, create patient-care orders, determine clinical eligibility, make placement decisions, or replace supervision by qualified professionals.
  • Students and faculty must not fabricate clinical documentation, hours, encounters, reflections, assessments, or site records with AI.
  • Clinical and field partners may impose stricter rules. The stricter rule applies, and partner systems may be used only for approved purposes.
  • Approved simulations or AI-supported practice must be labeled as simulated, pedagogically validated, accessible, and followed by qualified feedback where required.

13. Data Privacy, Security, and Vendor Governance

13.1 Data rules

The University will protect education records, student PII, grades, attendance, learning-management activity, advising notes, financial-aid information, employee records, applicant information, health or clinical information, research data, credentials, legal information, and other restricted data. Only the minimum data needed for an approved purpose may be used.

  • Public or nonsensitive information may be used in an approved tool subject to copyright, licensing, accuracy, and course rules.
  • Confidential or restricted information may be used only in an environment approved for the specific data and use case, with documented authority, access, retention, deletion, and vendor protections.
  • Prompts, outputs, embeddings, logs, transcripts, fine-tuning data, model feedback, and generated profiles are institutional data when created for University work.
  • Personal accounts and consumer tools may not be used for restricted University data even when a user has enabled a privacy setting.
  • Users must not place passwords, access tokens, answer keys, security details, privileged information, or clinical secrets in a general AI prompt.

13.2 Security and agentic controls

Systems must use controls appropriate to risk, including least privilege, multifactor authentication, encryption, logging, secure integration, testing for prompt injection and data leakage, monitoring, backups, incident response, and shutdown or rollback. Agentic AI requires narrow permissions, rate and transaction limits, human confirmation for consequential actions, audit logs, and a kill switch.

13.3 Vendors and embedded AI

AI vendors and embedded platform features require review of data ownership, training and reuse, retention and deletion, subprocessors, security, breach notification, accessibility, performance, bias, human oversight, auditability, intellectual property, service changes, public claims, and exit. A vendor update that introduces AI or changes data use may not be enabled until reviewed.

14. Accessibility, Fairness, and Civil Rights

  • AI systems used for instruction, assessment, communication, application, employment, or student services must be evaluated for accessibility and compatibility with assistive technology. An accessible alternative and human assistance must be available when needed.
  • Approved disability accommodations and assistive technology are governed through established accessibility processes. Faculty should not prohibit accommodation-related AI function without consulting the appropriate office.
  • Models, data, thresholds, and workflows must be evaluated for differential impact across relevant groups and for proxies that may reproduce protected characteristics or socioeconomic disadvantage.
  • The University may not use AI to discriminate, retaliate, harass, or deny equal access. A system that produces inequitable outcomes must be corrected, limited, paused, or retired even if average accuracy appears acceptable.
  • Automated translation, captioning, or accessibility content must be reviewed when an error could materially affect rights, safety, academic requirements, or understanding.

Owners of high-impact AI must document the populations assessed, known limitations, complaint patterns, overrides, false positives and negatives, and remedial action. Fairness review is ongoing, not a one-time procurement check.

15. Transparency, Intellectual Property, Records, and Accreditation

15.1 Transparency and disclosure

  • Student-facing bots and automated communications must be identified as AI when the recipient could reasonably believe a person is responding.
  • Material AI use in academic work, research, course content, institutional reports, and public communications must be disclosed as required by the course, profession, publisher, sponsor, contract, or University process.
  • Notices should explain purpose, limitations, relevant data use, human assistance, and review options in language appropriate to the audience and risk.

15.2 Intellectual property and likeness

Users must respect copyright, license, trademark, confidentiality, publicity, and contractual rights. They may not upload work created by another person, proprietary course content, unpublished research, licensed publisher material, or voice or likeness without authority. AI output must be checked for copied expression, false attribution, fabricated sources, and rights concerns before use.

15.3 Records

Official decisions and records must be maintained in authorized systems. High-impact use must retain enough information to reconstruct the approved system and version, data sources, material output, human reviewer, final decision, notices, overrides, complaints, and monitoring. Records must follow retention schedules and legal holds.

15.4 Accreditation and public representations

AI may assist with drafting or organizing accreditation materials, institutional reports, catalogs, websites, or marketing, but authorized personnel must verify every factual representation and preserve the underlying evidence. Confidential accreditor materials and nonpublic institutional data may not be entered into unapproved AI. Claims about learning, student success, retention, completion, outcomes, personalization, efficiency, savings, compliance, or proprietary AI must be accurate, supportable, appropriately limited, and approved.

16. Training and AI Literacy

The University will provide foundational and role-based AI education. Access to certain systems may be conditioned on successful completion of training or demonstration of competence.

  • Students: course expectations, integrity, verification, disclosure, privacy, bias, source evaluation, intellectual property, professional ethics, and discipline-specific applications.
  • Faculty: assignment design, assessment validity, student communication, detection limitations, approved tools, privacy, accessibility, feedback and grading controls, research integrity, and required instructor interaction.
  • Advisors and student-service staff: limitations of predictive scores, respectful outreach, data correction, human review, documentation, escalation, and student-support metrics.
  • Financial aid, registrar, admissions, disability services, HR, research, clinical, marketing, technology, and leadership: role-specific legal, operational, data, security, fairness, and approval controls.
  • System owners and reviewers: validation, monitoring, model change, incident response, vendor oversight, records, and decommissioning.

AI literacy should be integrated into programs where it supports learning outcomes and workforce relevance. Integration must be purposeful and should teach students to evaluate and govern AI, not merely operate a tool.

17. Incidents, Complaints, Exceptions, and Enforcement

17.1 Incidents and correction

Suspected exposure of restricted data, security compromise, harmful or biased output, material error, inaccessible process, fabricated evidence, improper high-impact decision, unapproved automation, or public misstatement must be reported promptly through established University and AIGC channels. The owner must contain the issue, preserve records, support affected persons, and participate in investigation and remediation.

17.2 Student and employee questions or complaints

Students and employees may ask how an AI-enabled process works, seek human assistance, report inaccurate data or harmful output, and use established complaint, grievance, appeal, accessibility, academic-integrity, privacy, or employment processes. Good-faith questions and reports must not result in retaliation.

17.3 Exceptions

An exception must be written, time-limited, purpose-specific, and approved by the AIGC and appropriate academic or control authority. It must identify scope, data, users, controls, monitoring, expiration, and exit. An exception cannot waive law, accreditation, clinical-partner, or due-process requirements.

17.4 Enforcement

Violations may result in loss of access, removal of a tool, correction of records or work, academic-integrity action, employment or contract action, remediation, or referral under applicable policies. Decisions must follow established due process and must not rely solely on AI output or detection.

18. Review and Continuous Improvement

The AIGC and University academic leadership will review this policy at least annually and after a material incident, legal or accreditation change, major model or vendor change, new high-impact capability, or organizational transition. Review should consider evidence from students, faculty, staff, incidents, complaints, monitoring, audits, learning outcomes, student success, accessibility, and vendor performance.

The University may issue standards, procedures, templates, syllabus language, approved-tool lists, training, and implementation deadlines under this policy. Material amendments require documented approval through the appropriate governance process.

Appendix A. Course AI Use Designations

Faculty should select and communicate the designation that best preserves the learning outcomes for each course or assignment. A designation does not override approved accommodations, program rules, or a stricter legal, clinical, sponsor, or accreditation requirement.

Designation  Student rule
Appropriate use
Prohibited Students may not use generative AI for the identified course or assignment except an approved accommodation or expressly permitted assistive function. Use when independent performance is essential to the learning outcome and AI would invalidate the assessment.
Limited or permission-based AI may be used only for the activities, tools, stages, or purposes expressly listed by the instructor. Material use must be disclosed. Use when selected AI support is pedagogically useful but core work must remain independently produced.
Permitted with disclosure Students may use AI as a learning or production aid, but must follow attribution, verification, privacy, and process requirements and disclose material use. Use when critical evaluation and responsible AI use are part of the learning design.
Required or structured The assignment requires specified AI use, comparison, critique, documentation, or reflection. The instructor defines approved tools and evidence of process. Use when AI competence is an explicit learning objective.

Model syllabus statement

Course AI expectations

The use of artificial intelligence in this course is governed by the AI designation and assignment instructions provided by the instructor. Students must use only permitted tools and purposes, protect confidential information, verify all output and sources, disclose material AI use, and remain able to explain and defend the submitted work. When instructions are silent, AI may support brainstorming or study but may not generate or materially rewrite work submitted for credit.

Appendix B. AI Use Disclosure

When disclosure is required, the instructor may prescribe a format. A complete disclosure ordinarily includes:

  • Tool and, when known, model or version.
  • Date or period of use.
  • Purpose of use, such as brainstorming, outlining, coding support, translation, feedback, data analysis, or image generation.
  • How the output was checked, changed, rejected, cited, or incorporated.
  • Any instructor-required prompt or output record, provided that the record does not disclose restricted or third-party confidential information.

Sample disclosure

Example: I used an approved generative AI tool to brainstorm possible structures for the literature review. I independently located and read the cited sources, rejected unsupported suggestions, and wrote the final analysis in my own words. I retained the prompt and output as required and the submitted work reflects my own understanding.

Appendix C. High-Impact AI Approval Packet

The following information is required for high-impact and enterprise-critical use cases and may be required for moderate-risk use:

  1. Executive summary and clear problem statement.
  2. Named accountable executive, business owner, system owner, and implementation owner.
  3. Affected entity or entities, users, and stakeholders.
  4. Expected value, mission alignment, alternatives considered, and why AI is appropriate.
  5. AI tool, model, version, deployment method, integrations, plugins, connectors, and agentic capabilities.
  6. Data inventory, classification, source, quality, minimization, retention, access, and deletion plan.
  7. Privacy, FERPA, financial-aid, employee, health or clinical, and confidentiality analysis as applicable.
  8. Cybersecurity architecture, threat assessment, testing, logging, access control, business continuity, and incident response.
  9. Vendor due diligence and contractual protections, including training or reuse of inputs and outputs.
  10. Legal, regulatory, accreditation, academic, accessibility, civil-rights, and intellectual-property review as applicable.
  11. Human oversight model, nondelegable decisions, escalation path, and human fallback.
  12. Notice, disclosure, consent, correction, complaint, and appeal mechanisms where applicable.
  13. Testing and validation plan, including accuracy, reliability, hallucination, bias, subgroup effects, accessibility, and security.
  14. Success metrics, baseline, acceptance thresholds, limitations, and evidence plan.
  15. Pilot scope, duration, authorized users, training, and change-management plan.
  16. Monitoring plan for performance, drift, differential impact, user experience, incidents, model changes, and vendor changes.
  17. Recordkeeping requirements, system-of-record treatment, retention schedule, and audit trail.
  18. Budget, total cost of ownership, staffing, dependency, and value-realization analysis.
  19. Communications plan, including controls for public, student-facing, accreditor, and investor-related claims.
  20. Exit, suspension, rollback, data return or deletion, and decommissioning plan.

Appendix D. Student-Facing Minimum Controls

Control  Minimum requirement
Purpose and owner  Defined student need, named accountable owner, approved scope, and documented alternatives.
Notice Clear identification of AI when appropriate, purpose and limitation notice, data-use information, and human contact path.
Human authority Qualified person makes final high-impact decision, can override, and reviews context outside the model.
Data Minimum necessary data, documented authority, accurate source, correction process, access control, retention, and deletion.
Validation Accuracy, false positives and negatives, bias and subgroup effects, accessibility, security, usability, and representative testing.
Support and appeal Human assistance, correction, complaint, grievance, or appeal through established processes; no retaliation.
Monitoring Performance, drift, outcomes, differential effects, overrides, complaints, incidents, model changes, and user feedback.
Records and exit Decision traceability, system-of-record treatment, required retention, rollback, continuity, data deletion, and retirement.