215 - Enterprise Artificial Intelligence Policy and Employee Use Standard
| Title: |
Enterprise Artificial Intelligence Policy and Employee Use Standard |
| Owner: |
Artificial Intelligence Governance Committee |
| Last Updated/Revised: |
07/30/2026 |
Policy objective
Ensure every employee understands the shared rules for responsible AI use, what constitutes acceptable and prohibited use, and the required protocol for introducing AI into an individual, departmental, institutional, or enterprise workflow.
How Employees Should Use This Policy
This consolidated policy translates the shared requirements of the three entity-specific artificial intelligence policies into one employee-facing standard. It is designed for foundational training and day-to-day reference. Employees remain responsible for following any additional requirements applicable to their role, department, institution, course, system, or professional discipline.
The three-question test
Before using AI for institutional work, ask: (1) Is the tool approved? (2) Is the information permitted for that tool? (3) Is the proposed use low risk, or does it require review and approval? If any answer is uncertain, stop and seek guidance before proceeding.
Employee Learning Outcomes
- Explain the organization’s position on responsible AI and the continuing importance of human judgment.
- Distinguish acceptable low-risk use from uses requiring review or formal approval.
- Protect student, employee, company, financial, health, legal, security, and other sensitive information.
- Recognize prohibited uses and high-impact decisions that may not be delegated to AI.
- Apply the required protocol for proposing, piloting, implementing, monitoring, and retiring AI-enabled work.
- Identify how to report an AI incident, error, privacy concern, biased result, or suspected misuse.
1. Policy Statement
United States University (USU) collectively referred to in this policy as the organization, support the responsible use of artificial intelligence to advance student success, academic quality, affordability, access, workforce readiness, compliance, operational effectiveness, and institutional sustainability.
AI is a capability that may assist people with analysis, drafting, communication, research, workflow support, and decision support. It is not a substitute for employee accountability, faculty authority, professional judgment, or the human relationships central to education and student care. Employees remain accountable for the work they produce and the decisions they make with AI assistance.
2. Purpose and Scope
This policy establishes a common standard for AI use across USU. It applies to all employees and to contractors, temporary workers, consultants, vendors, and other workforce members when they perform work for or on behalf of the organization.
The policy applies to generative AI, predictive analytics, machine learning, AI-enabled automation, agents, chatbots, embedded AI features, recommendation systems, AI detection tools, image or media generation, and any system that performs tasks commonly associated with human intelligence or judgment.
The policy applies whether the tool is free or paid, public or private, stand-alone or embedded in another platform, accessed through a personal or institutional account, or obtained directly from a vendor.
3. Core Principles
Mission and student success: AI use must serve a defined educational, operational, compliance, or service purpose. The organization will not adopt AI merely for novelty, optics, or vendor enthusiasm.
Human accountability: A person remains responsible for reviewing AI-assisted work and for decisions, communications, and actions taken as a result.
Privacy and security: Only authorized information may be used, and data must be minimized, protected, and handled according to institutional requirements.
Fairness and accessibility: AI must not be used in ways that unlawfully discriminate, create avoidable barriers, or bypass accessibility obligations.
Transparency and reviewability: Material AI involvement should be disclosed when required, and significant uses must be documented sufficiently to permit review.
Evidence and continuous improvement: AI uses should be tested, measured, monitored, corrected, and retired when they do not perform safely or effectively.
Academic integrity and faculty authority: Faculty and academic leadership retain authority over teaching, assessment, grading, course expectations, and academic integrity.
Public accountability: Public claims about AI capabilities, savings, student outcomes, or institutional performance must be accurate, supportable, and approved.
4. Roles and Responsibilities
4.1 Artificial Intelligence Governance Committee
The Artificial Intelligence Governance Committee (AIGC) is the enterprise executive body responsible for AI strategy, policy, risk classification, tool and use-case approval, training expectations, monitoring, incident oversight, and public AI claims across USU. The AIGC may approve, conditionally approve, defer, reject, pause, limit, or retire an AI use case.
4.2 Employees and Other Workforce Members
- Complete the required AI training and periodic refreshers.
- Use only approved AI tools, accounts, features, integrations, and configurations for institutional work.
- Use only data authorized for the tool and purpose.
- Verify AI outputs before relying on, sharing, submitting, publishing, or acting upon them.
- Maintain required human review and never treat an AI output as automatically correct.
- Follow approval, documentation, disclosure, records, copyright, accessibility, and security requirements.
- Report suspected misuse, harmful output, privacy or security incidents, or material errors promptly.
4.3 Managers and Business Owners
Managers and business owners must ensure that AI use within their areas is authorized, appropriately classified, documented, staffed, monitored, and consistent with this policy. They may not direct employees to use an unapproved AI tool or bypass required review.
4.4 Faculty and Academic Leadership
Faculty and academic leaders retain responsibility for curriculum, teaching, academic standards, grading, student learning, academic integrity, and appropriate faculty-student interaction. AI may support these functions but may not displace required faculty judgment or institutional academic authority.
5. Acceptable Use
Acceptable use generally consists of low-risk work performed in an approved tool without confidential, regulated, restricted, or personally identifiable information. Acceptable use still requires employee review and accountability.
5.1 Examples of Generally Acceptable Low-Risk Use
- Brainstorming ideas, questions, outlines, or alternative approaches using public or non-sensitive information.
- Drafting or revising generic text that does not contain protected or confidential information.
- Summarizing public documents or information already approved for public release.
- Creating generic templates, checklists, agendas, training examples, or sample scenarios.
- Improving grammar, clarity, organization, tone, or readability of non-sensitive material.
- Generating formulas, code examples, or process ideas that are independently reviewed and tested before use.
- Using an approved enterprise AI feature in the manner and data environment for which it was approved.
Acceptable does not mean automatic
Even a low-risk use requires the employee to check accuracy, remove unsupported statements, respect intellectual property, avoid misleading attribution, and ensure the final product is appropriate for its audience.
6. Data and Information Rules
Employees may enter, upload, paste, connect, transmit, or expose information to an AI system only when both the tool and the specific data use are authorized. An enterprise license does not automatically authorize every kind of data or every use case.
6.1 Information That Requires Special Protection
- Student education records and personally identifiable student information, including grades, attendance, advising notes, academic progress, learning-management-system activity, and financial-aid information.
- Employee, applicant, payroll, benefits, performance, investigation, accommodation, and personnel information.
- Health, clinical, practicum, field-placement, disability, or accommodation information.
- Nonpublic financial, accounting, investor, legal, board, strategic, contractual, procurement, or acquisition information.
- Credentials, passwords, API keys, source code, system configurations, vulnerability details, security logs, or other cybersecurity information.
- Confidential research, proprietary materials, copyrighted content, trade secrets, or information subject to a nondisclosure agreement.
6.2 Minimum Data Practices
- Use the least amount of data necessary.
- Remove direct and indirect identifiers whenever possible.
- Do not assume that deleting a chat deletes the provider’s copies or logs.
- Do not enable plugins, connectors, browsing, file access, memory, agents, or external actions unless approved.
- Store authoritative records in the designated system of record, not solely in an AI chat or workspace.
- Follow retention, legal-hold, records, privacy, security, and contractual requirements.
7. Required Human Review
Employees must critically review AI outputs for factual accuracy, completeness, logic, bias, tone, confidentiality, accessibility, citation quality, copyright concerns, and consistency with law and institutional policy. The depth of review must increase with the consequence of error.
AI may not independently make or communicate final decisions that materially affect a student, employee, applicant, faculty member, vendor, or other stakeholder.
7.1 Decisions That Require Meaningful Human Judgment
- Admissions, enrollment status, academic standing, progression, grading, academic integrity, student conduct, or clinical and field placement eligibility.
- Financial-aid eligibility, satisfactory academic progress, disbursement, return of funds, or other regulated student-finance determinations.
- Disability accommodations or access to institutional services.
- Hiring, promotion, compensation, performance management, discipline, termination, or other employment decisions.
- Legal, compliance, accreditation, audit, financial reporting, investor, cybersecurity, or public-disclosure decisions.
- Any decision for which an individual has a right to notice, correction, review, complaint, appeal, or human assistance.
8. Prohibited Use
The following activities are prohibited unless specifically authorized through the AIGC and all other required institutional approval processes:
- Using an unapproved AI tool, personal account, browser extension, plugin, connector, agent, or integration for institutional work involving protected or nonpublic information.
- Uploading protected, confidential, restricted, or personally identifiable information to a public or unauthorized AI service.
- Allowing AI to make a final high-impact decision without meaningful human review and accountability.
- Using AI to impersonate another person, fabricate records, create deceptive communications, or conceal the origin of material content when disclosure is required.
- Producing or distributing false, misleading, discriminatory, harassing, threatening, defamatory, or unlawful content.
- Relying on fabricated citations, invented facts, or unverified AI output in official work.
- Using AI to bypass security controls, monitoring, access restrictions, procurement, records requirements, or required approvals.
- Using AI to conduct unauthorized surveillance, infer sensitive traits, or profile individuals in a manner inconsistent with law or policy.
- Submitting AI-generated work as one’s own professional or academic work when doing so violates instructions, disclosure requirements, or standards of integrity.
- Making public claims that AI improved student outcomes, efficiency, costs, revenue, compliance, or other results without validation and approval.
9. Risk Classification and Approval
Approval is based on the proposed use, not merely the name of the tool. A tool may be approved for one purpose and prohibited for another. Employees must not expand an approved use beyond its documented scope.
| Risk level |
Typical characteristics |
Employee action |
Approval standard |
| Low risk |
Approved tool; public or non-sensitive information; limited consequences if wrong
|
Proceed after training; review output |
Permitted under established standards |
| Moderate risk |
Internal workflow, de-identified analysis, draft communication, or limited stakeholder impact |
Document the use and follow the designated review process |
Manager or AIGC designated approval |
| High impact |
Student-facing, employee-facing, predictive, regulated, sensitive-data, academic, financial-aid, HR, compliance, or enterprise-system use |
Do not pilot or deploy before formal review |
Full AIGC and required control-function review |
| Enterprise-critical |
Cross-entity, high-volume, material financial, accreditation, public-company, or significant operational risk |
Submit a complete business case and control plan |
Documented AIGC decision and continuing oversight |
| Prohibited unless explicitly approved |
Autonomous high-impact decisions, unauthorized sensitive data, impersonation, unsupported public claims, or unlawful use |
Stop; do not proceed |
Not permitted absent specific written approval |
10. Protocol for Integrating AI into the Work Environment
The following protocol applies when an employee or department wants to introduce AI into a recurring workflow, connect AI to an institutional system, use institutional data, automate an action, create a student- or employee-facing experience, or expand beyond routine low-risk productivity use.
- Define the problem. Describe the business, academic, compliance, service, or student-success problem. Identify the current process, pain points, affected users, and why AI may be appropriate. Do not begin with a tool and search for a problem.
- Check the approved-tool registry. Confirm whether the tool, feature, model, account type, integration, and intended use are approved. An approved product may contain newly introduced AI features that have not yet been reviewed.
- Identify the data. List the information the AI would receive, generate, retain, or expose. Classify the data and remove or minimize identifiers. Determine whether FERPA, employment, financial, health, security, contractual, or other restrictions apply.
- Classify the risk. Use the risk table in this policy. Consider the consequence of an incorrect, biased, inaccessible, delayed, or unauthorized output; the number of people affected; and whether the AI can take actions.
- Obtain required review. For anything above low risk, submit the use through the designated intake process. Required reviewers may include AI governance, technology, cybersecurity, privacy, compliance, legal, accessibility, HR, finance, financial aid, academic leadership, institutional research, procurement, or communications.
- Design human oversight and safeguards. Name the accountable owner and reviewer. Define what AI may do, what it may not do, how outputs will be validated, when a human must intervene, how users obtain human assistance, and how the process stops safely.
- Pilot within the approved scope. Use a limited population, data set, duration, and feature set. Train authorized users. Test accuracy, bias, accessibility, security, user experience, workload, and failure modes. Do not expand the pilot without approval.
- Measure and document results. Compare results to baseline. Record errors, overrides, complaints, incidents, costs, time savings, student or employee effects, and any unintended consequences. Do not claim success without evidence.
- Seek authorization to scale. The AIGC or designated authority determines whether the use may continue, expand, be modified, paused, or retired. Material changes in model, vendor, data, integration, purpose, or affected population require reassessment.
- Monitor throughout the lifecycle. Maintain ownership, records, access controls, training, periodic testing, vendor oversight, and incident response. Retire the use when it is no longer safe, effective, supported, necessary, or compliant.
Stop-and-escalate rule
Employees must pause and seek guidance whenever the tool behaves unexpectedly, exposes information, produces discriminatory or harmful content, takes an unauthorized action, affects a high-impact decision, or appears to operate outside the approved scope.
11. Special Requirements for Student-Facing and Academic Uses
- AI-supported advising, early alerts, outreach, tutoring, academic support, assessment, proctoring, grading, integrity review, or student-service workflows require appropriate academic and institutional oversight.
- Students must have a practical way to reach a qualified human, question or correct information, and escalate concerns when AI is used in a material process.
- Faculty retain authority to define permitted student AI use consistent with course outcomes, assignment instructions, and university policy.
- AI detection alone is not sufficient evidence of academic misconduct. Any integrity determination must use a fair process and meaningful human review.
- AI may assist faculty but may not replace required faculty teaching, evaluation, feedback, or regular and substantive interaction.
- Student work may not be uploaded to an unapproved AI or detection service.
12. Communications, Intellectual Property, and Records
12.1 Communications and Disclosure
Employees must disclose material AI assistance when required by law, policy, professional standards, assignment or course instructions, a supervisor, or the nature of communication. AI-generated or AI-modified public communications require the same review and approval as other official communications.
12.2 Intellectual Property and Attribution
Employees must not assume that AI output is original, accurate, non-infringing, or owned by the organization. Review for copyrighted, trademarked, proprietary, confidential, or improperly attributed material before use. Do not upload third-party material when the organization lacks permission to do so.
12.3 Records
AI-generated content that documents institutional decisions, transactions, student or employee matters, approvals, or official communications may be an institutional record. Employees must place the final record and any required supporting documentation in the authorized system of record and follow retention and legal-hold requirements.
13. Vendors, Embedded AI, and Agents
No employee may independently purchase, subscribe to, activate, integrate, or accept material terms for an AI service on behalf of the organization unless authorized. Vendor review may address security, privacy, accessibility, data ownership, training or reuse of inputs and outputs, retention, subprocessors, breach notification, audit rights, intellectual property, service levels, model changes, exit rights, and deletion.
AI agents or systems capable of sending messages, changing records, initiating transactions, executing code, accessing files, or taking other external actions require explicit approval, least-privilege access, testing, logging, spending or action limits, human confirmation for consequential actions, and an immediate stop mechanism.
14. Incidents, Errors, and Reporting
An AI incident includes unauthorized data exposure, harmful or discriminatory output, an incorrect high-impact decision, security compromise, unauthorized action, impersonation, material misinformation, unexpected model behavior, recordkeeping failure, or use outside the approved scope.
Employees must promptly stop or contain the activity when safe to do so, preserve relevant information, notify their supervisor and the designated institutional reporting channel, and avoid deleting evidence. Privacy, security, compliance, academic, HR, legal, communications, or other response teams will be engaged as appropriate.
Good-faith reporting of an AI concern is encouraged. Employees should not attempt to conceal an error or independently manage a significant incident outside established response procedures.
15. Exceptions and Enforcement
Exceptions must be documented, time-limited, narrowly scoped, and approved by the AIGC or its formally designated authority together with any other required institutional reviewer. Operational urgency does not by itself authorize bypassing privacy, security, legal, academic, procurement, accessibility, or governance requirements.
Violations may result in removal of access, corrective action, retraining, suspension or retirement of a use case, contract remedies, or disciplinary action consistent with applicable policy and law.
16. Training and Acknowledgment
All employees must complete foundational AI training before using institutional AI tools or AI for institutional work, except where expressly authorized for controlled training or testing. Role-specific training may be required for faculty, advisors, student services, financial aid, marketing, HR, technology, data and analytics, compliance, leadership, and AI use-case owners.
Training completion does not authorize every tool or use. Employees remain responsible for checking current approved-tool, data, and use-case requirements.
17. Policy Review and Relationship to Entity-Specific Requirements
This consolidated standard expresses the requirements shared across USU and is intended to support a common Tier 1 course. Entity-specific academic, accreditation, employment, regulatory, operational, or governance requirements continue to apply. When requirements differ, employees must follow the more specific or more protective requirement.
The AIGC will review this policy at least annually and when material changes occur in technology, law, regulation, accreditation expectations, organizational structure, vendor practices, or institutional risk.
Appendix A. Employee Quick Decision Guide
| Question |
If yes |
If no or unsure |
| Is the exact tool, feature, account, and integration approved for institutional work? |
Continue to the data question. |
Do not use it. Check the approved-tool registry or request review.
|
| Is every item of information permitted for this tool and purpose? |
Continue to the risk question. |
Remove or de-identify the information, use another approved environment, or seek approval.
|
| Is the use clearly low risk and within the approved scope? |
Proceed after applying human review and all other policy requirements.
|
Submit through the designated AI intake and approval process.
|
| Could the output materially affect a student, employee, applicant, institutional decision, or public claim? |
Treat as high impact and obtain formal approval with meaningful human oversight.
|
Continue to monitor the consequence of error.
|
| Did the system behave unexpectedly or create a concern? |
Stop, contain, preserve evidence, and report promptly.
|
Continue within the approved scope and monitoring plan.
|
Appendix B. Common Scenarios for Tier 1 Training
Allowed with normal review: An employee uses an approved enterprise AI tool to improve the clarity of a generic meeting agenda containing no confidential information.
Not allowed: An employee pastes a student’s name, grades, advising notes, and financial-aid status into a free public chatbot to draft an outreach message.
Requires approval: A department wants an AI agent to read CRM records, identify students at risk, draft messages, and automatically send outreach.
Requires human judgment: An AI tool flags a student submission as likely AI-generated. A faculty member must independently review the evidence and follow the academic-integrity process; the detector result cannot be the sole basis for a finding.
Public-claims control: A presentation states that AI increased retention by a specific percentage. The claim may not be used publicly unless the evidence and wording have been reviewed and approved.
Incident response: An approved chatbot displays another student’s information. The employee stops use, preserves the details, and reports the event immediately through the designated channel.
Appendix C. Minimum Information for an AI Use-Case Request
- Problem statement, desired outcome, current process, and why AI is being considered.
- Named executive sponsor, business owner, implementation owner, and affected entity or entities.
- Tool, vendor, model, features, integrations, connectors, and ability to take actions.
- Users and populations affected, including students, applicants, faculty, employees, or the public.
- Data inventory, classification, sources, retention, access, and deletion plan.
- Risk classification and consequence of error or bias.
- Human oversight, review, escalation, correction, complaint, appeal, and fallback processes.
- Privacy, security, accessibility, legal, compliance, academic, accreditation, procurement, financial, and communications considerations.
- Pilot plan, testing methods, success metrics, acceptance thresholds, monitoring, and stop criteria.
- Budget, staffing, vendor terms, records plan and exit or decommissioning plan.
Appendix D. Source Policy Documents
This working document consolidates shared requirements from the following internal drafts:
The entity-specific policies contain additional details for enterprise operations, academic governance, accreditation, student use, faculty responsibilities, and distance-education safeguards. This consolidated version is structured for common employee training and should be updated whenever the underlying policies change.