AI Appropriate Use Procedure

Document Type: Procedure / Appropriate Use Guidance
Audience: All USU Faculty, Staff & Researchers
Last Reviewed: April 2026
Category: IT / Emerging Technology

Why This Matters

This page documents USU's procedure for appropriate AI use as required by Policy 5200, Section 2.8.

Artificial Intelligence is reshaping how we teach, research, and work. Tools that can draft, analyze, summarize, code, and reason are now widely accessible, and faculty, staff, and researchers across USU are already finding creative and productive ways to use them. That's a good thing.

This document is here to help you navigate that landscape: make informed decisions about the tools you use, and get the most out of AI while protecting yourself, your colleagues, and the university.

USU is forward-looking when it comes to AI, and this is by design. This document is an extension of that commitment, asking not "how do we restrict this?" but "how do we enable our people to use these tools effectively, confidently, responsibly, and in alignment with this procedure?"

AI tools abound, and many faculty, staff, and researchers are already using them productively. The guiding principles in this document apply to any tool you choose to use. Adhering to them is the standard USU expects, regardless of which tool you reach for. USU IT is continuously evaluating and adding support for new AI tools and services as the landscape evolves; for those who want a structured option with institutional support and baseline protections, see the What Tools Can I Use at USU? section.

Have questions or want to share how you're using AI? Join the conversation in the #ai_usu Slack channel or reach out to your IT support professional .

Guiding Principles

The following principles constitute USU's procedural expectations for AI use. They apply to any AI tool, any workflow, and any role at USU, and are a foundation for making good decisions as the technology continues to evolve.

You are accountable for your work product, whether AI helped create it or not.

  • Verify before you trust. AI tools can produce content that sounds authoritative but is inaccurate, biased, or incomplete. Review AI-generated work for accuracy, bias, and copyright compliance before using it in any official, academic, or administrative context.
  • Know your data. Before putting any university information into an AI tool, consider its risk classification. This includes student records, health information, personal data, and proprietary or confidential institutional information. Not all tools provide the same protections, and some data should never leave the institution. See the Data Classification section below, and when in doubt, treat data at the highest applicable tier.
  • AI supports your judgment; it does not replace it. These tools are powerful aids, but critical thinking, academic rigor, and professional judgment remain yours.
  • Be transparent. Disclose AI use where it is expected or required: in academic work, publications, grant applications, and official communications. Follow your department's, journal's, or funding agency's disclosure guidance.
  • Respect intellectual property. Be thoughtful about copyright and licensing when using AI to generate, remix, or repurpose content. Where attribution is expected, provide it, regardless of whether AI assisted in the creation.
  • Do not let AI become a source of research misconduct. Fabrication, falsification, or plagiarism, whether produced by you or by an AI tool you used, can constitute research misconduct under federal definitions, and a number of federal agencies now explicitly treat AI-induced FFP as misconduct. You are responsible for the integrity of anything you propose, perform, review, submit, publish, or attribute to yourself.
  • Do your research on the tools you use. Not all AI services are the same. Some have unclear data retention or training practices. Before committing to a tool for university work, understand how it handles your data.
  • Follow USU's official guidance. ai.usu.edu and this AI Appropriate Use Procedure are the authoritative sources for USU procedures, approved tools, and best practices around AI use. Refer to them when making decisions about AI in your work, and check back as guidance evolves alongside the technology.
  • Be aware of AI services already available through USU. Before acquiring an AI tool with USU funds or your @usu.edu account, check what is already available centrally. Do not acquire a service that USU already provides. Using centrally managed services eliminates duplicative purchasing, takes advantage of baseline security configurations, and gives you the benefit of institutional protections such as Single Sign-On (SSO), which lets you log in with your USU credentials rather than managing a separate account and password.

Understanding Data Classification

One of the most important decisions when using any AI tool is understanding what data you are putting into it. USU's Data Classification Policy defines three tiers:

Low-Risk Data
Generally available to the public. Exercise standard judgment when using with AI tools.
Moderate-Risk Data
Subject to legal restrictions, contractual limitations, or data whose unauthorized use could have an adverse impact on USU or an individual. Use only with AI tools that have appropriate institutional or contractual protections in place. USU-provisioned tenants are the appropriate starting point.
High-Risk Data
Data subject to breach reporting requirements or whose unauthorized use could have a significant adverse impact on USU or an individual (e.g., FERPA, HIPAA, export-controlled data). Do not use with consumer AI tools. Contact the appropriate office for guidance: the Chief Data Privacy Officer for general privacy and PII concerns, the Registrar for FERPA/student records, the HIPAA Privacy Officer for health data, and the Office of Research for export-controlled data or research data relating to a sponsored project.

When data spans multiple categories, always classify and treat it at the highest applicable tier. See the full USU Data Classification Policy for definitions and examples.

Role-Specific Guidance

Guidance tailored to faculty, researchers, and administrative staff (including expectations around syllabi, research workflows, and administrative use) is maintained at AI Help, Guidance & Resources , where it can be kept current as practices evolve.

What Tools Can I Use at USU?

The current list of AI tools available at USU, including which data classifications each tool is approved for and any conditions that apply, is maintained on the AI Tools page at ai.usu.edu. That page is the source of truth for tool availability and approval status. Approvals depend on contracts and configurations remaining in force and can change, so this procedure intentionally does not list individual tools or statuses.

Keep in mind that an approved tool is not the whole answer: whether a use of AI is appropriate also depends on the data you put in, what the AI is being used to do or decide, and any law, regulation, or contract that applies to your work. The Tools page walks through these factors alongside the tool list.

Most of the tools on that list are available because USU has contracted centrally with some of the top tier AI service providers, through which faculty, staff, and researchers can obtain provisioned access. Some of these are not site licenses; access is provisioned individually and requires a department index number to obtain a license through the appropriate USU tenant. Individual licenses can be requested at software.usu.edu. Where a service is available through USU's central contracts, that is the approved method of acquisition.

Accounts provisioned through USU's central contracts include a set of baseline protections that personally or departmentally purchased accounts do not provide by default. These protections apply specifically to centrally acquired services and are not guaranteed for accounts obtained outside of USU's central procurement:

Content does not train the model
USU tenant accounts are configured to opt out of contributing your inputs and outputs to AI model training by default.
Single Sign-On (SSO)
Access is tied to your USU credential, making account management and offboarding consistent with university identity governance.
Baseline security configuration
Default settings are applied at the tenant level to align with USU's security posture.

Note that the level of data governance varies by tool; not all services in the USU tenant carry the same agreements. For example, a Business Associate Agreement (BAA) is in place for some tools but not others. As outlined in the guiding principles and data classification information above, always verify that the specific tool you are using is appropriate for your data.

Ready to get started?

Visit ai.usu.edu/tools for the current catalog of available USU AI services and to request provisioning through the USU tenant. For help getting set up, reach out to your IT support professional or contact the IT Service Desk at servicedesk@usu.edu | 435-797-HELP (4357).

* If USU funds are currently paying for a personally acquired AI subscription, we can work with you to transition to the appropriate central service at a time that makes sense. Reach out to your IT support professional to start that conversation.

Prohibited Uses

The following uses of AI are prohibited regardless of which tool is used, including USU-licensed services. They are grounded in federal and state law and in institutional policy. The AI Tools page summarizes this list where tool decisions are made; this procedure contains the complete, authoritative list.

Illegal Content

Generating content that is illegal under federal or state law, including child sexual abuse material (CSAM), credible threats, or any other content prohibited by law or USU policy.

Synthetic Media to Deceive or Harm

Creating AI-generated images, audio, or video (deepfakes) that realistically impersonate a real person without their consent, or that are designed to deceive, harass, defame, or cause harm.

Unauthorized commercial use of a simulated personal identity is also actionable under Utah SB 271 (2025), the Unauthorized Artificial Intelligence Impersonation Amendments, effective May 7, 2025.

Controlled or Restricted Research Data

Entering data subject to export control regulations (EAR, ITAR), Controlled Unclassified Information (CUI) handling requirements, or sponsor-imposed restrictions (NIST SP 800-171, DoD CMMC) into any AI tool not specifically reviewed and approved for that data.

Grant Peer Review Content

Uploading or submitting grant proposals or reviewer materials to any AI tool for analysis, summary, or drafting peer-review critiques. NIH and NSF prohibit generative AI in peer review; this applies to USU-licensed services as well.

AI Services from Countries of Concern

Using AI tools operated by entities subject to the laws of foreign adversary countries (China, Cuba, Iran, North Korea, Russia, Venezuela) for university work. (DOJ Data Security Program, 28 CFR Part 202, in effect since April 2025.)

Consequential Decisions Without Meaningful Human Review

Using AI as the sole basis for consequential decisions about individuals, including admissions, financial aid, grades, hiring, performance evaluation, accommodations, or discipline. A reviewer who rubber-stamps the model is not oversight; review must be meaningful and capable of changing the outcome.

Discriminatory Use Against Protected Classes

Any use of AI that would discriminate against individuals on bases protected by Title VI, Title IX, Section 504, the ADA, FCRA, ECOA, or federal employment-discrimination law. AI involvement does not change civil-rights obligations.

Emotion Recognition & Sensitive-Trait Inference

Using AI to infer emotional state, affect, or sensitive traits (race, national origin, sex, disability, sexual orientation, religion, political opinion) of students, employees, or applicants. (Grounded in USU's civil-rights obligations under Title VI, Title IX, and the ADA/Section 504; these uses also carry accuracy and bias risks that cannot be adequately mitigated.)

Impersonation

Using AI to generate content that impersonates another individual in ways intended to deceive, or that the individual has not authorized.

Circumventing Security Controls

Using AI tools to probe, exploit, or bypass university security measures, access controls, or authentication systems.

Training External Models on USU Data

Permitting USU institutional data to be used to train or fine-tune external (vendor or third-party) AI models, regardless of a tool's default settings. Institutional data is for institutional purposes.

Processing Institutional Data Outside Approved Tools

Processing any USU institutional data, regardless of classification, in AI tools that USU has not procured, evaluated, or approved. Personal accounts and free-tier tools are not approved paths for institutional data.

How USU Governs AI Risk

USU's approach to AI risk is informed by the NIST AI Risk Management Framework (AI RMF 1.0) and its companion Playbook. In plain terms:

What USU does Where it lives NIST AI RMF alignment
Maintains an inventory of approved AI services The Tool Capability table on the AI Tools page is USU's maintained inventory of centrally evaluated AI services. GOVERN 1.6 (AI system inventory)
Documents legal & regulatory requirements Factor 3 on the AI Tools page and the Prohibited Uses list in this procedure. GOVERN 1.1 (legal and regulatory requirements understood, managed, documented)
Matches oversight to the risk of the use The Factor 2 use levels on the AI Tools page and the PIA gate for consequential decisions. GOVERN 1.3 (risk-based prioritization); MAP 1.1 (intended purpose and context); MAP 3.5 (human oversight)
Assigns accountability for AI decisions The USU AI Committee provides executive oversight of AI adoption and this guidance; InfoSec, the CDPO, and the Office of Research own the review paths named in this procedure and on the AI Tools page. GOVERN 2.1, 2.3 (roles, responsibilities, executive accountability)
Reviews this guidance on a defined cadence The AI Tools page and this procedure are reviewed at least annually, and when contracts change or new services are evaluated. GOVERN 1.5 (periodic review); MANAGE 4.1 (post-deployment monitoring)
Can revoke approvals Tool approvals are contingent on contracts and configurations remaining in force. USU may change a tool's status or delist it if protections lapse. MANAGE 2.4 (mechanisms to disengage or deactivate); GOVERN 6.1 (third-party risk)
Collects feedback and provides a path to raise concerns The resource recommendation form and #ai_usu on Slack for general feedback. Individuals affected by an AI-supported decision may raise concerns with the responsible office or the CDPO. GOVERN 5.1 (external feedback); MEASURE 3.3 (feedback and appeal processes)

Formal evaluation obligations under the RMF's MEASURE function (testing, bias evaluation, monitoring) attach to high-risk deployments through the PIA process rather than to routine productivity use.

Frequently Asked Questions

What should I know about AI services based in foreign countries?

Some AI services (such as DeepSeek) are developed and operated in foreign jurisdictions where data privacy laws, government access rights, and data retention practices differ significantly from U.S. standards. USU discourages the use of such services for university work. If you believe a specific service is necessary for your work, you are expected to work with the relevant governing unit to evaluate it before use (e.g., the Office of Research and, where applicable, the project sponsor for research-related use cases).

Can I use AI to help with peer review of grant proposals?

No. Federal funders including the National Institutes of Health (NIH) and the National Science Foundation (NSF) prohibit the use of generative AI tools when reviewing grant proposals, and uploading proposal content to any external AI platform violates the confidentiality and data integrity agreements peer reviewers sign. This prohibition applies to USU-licensed tools as well; institutional contracts do not override funder policy. Questions about a specific agency's rules should go to the Office of Research .

How do AI chatbots for department websites work?

Many departments are interested in adding an AI chatbot to their website: one that can answer questions about their programs, services, or resources using curated, department-specific content. This is a great use of AI, and USU IT is actively working on it. In collaboration with the web programming team, we are developing solutions designed to be straightforward for departments and content managers to deploy and maintain, without requiring deep technical expertise.

If your department is interested in an AI chatbot for your website, stay tuned. Solutions are in development. In the meantime, reach out to your IT support professional or join the #ai_usu Slack channel to share your interest and follow along as options become available.

What about agents like OpenClaw and Hermes?

AI-powered bots and agents can be valuable for automating workflows and providing quick assistance. Popular examples include OpenClaw (previously known as ClawdBot and MoltBot), Hermes Agent, and the many variants they have inspired, such as IronClaw, NanoClaw, and ZeroClaw. However, bots that are poorly scoped or improperly configured can introduce real risks: data exposure, unintended actions, or outputs that carry institutional weight without appropriate review. As the person deploying an AI agent, you are accountable for its actions. Approach deployment thoughtfully, ensure agents are properly sandboxed and clearly scoped in what data they can access and what actions they can take, and seek guidance before going live. The guiding principles in this document apply fully to AI agents.

Do your homework before you deploy, and protect yourself.

Third-party AI bots and agents have a mixed track record when it comes to data handling and security. Before connecting any bot to university systems, research it thoroughly. Known vulnerabilities, data leakage issues, and unexpected data sharing behaviors have been documented across many popular tools. "Free" or "easy to set up" does not mean safe.

Any bot you use for university purposes should be sandboxed, meaning it should operate with the minimum access needed and have no connection to USU data systems unless that access has been explicitly reviewed and approved.

Your personal data is at stake too.

Be extremely cautious about what you give any AI bot access to. Granting unfettered access to your email, your file system, or (worst of all) your password manager is a recipe for personal disaster. If you are not absolutely certain a tool is trustworthy and properly scoped, do not give it access to anything sensitive. When in doubt, give it access to nothing.

As a starting point: search for known security and data leakage concerns before deploying any bot. Then talk to your IT support professional or post in #ai_usu on Slack before you go live.

What additional scrutiny applies when procuring software or services that include AI components, or when an existing vendor adds an AI feature?

AI is increasingly embedded in software that is not marketed as an "AI tool": think HR platforms, student information system add-ons, research tools, document management systems, and more. When a vendor adds AI features to a product USU uses or is evaluating, that changes the procurement picture.

Any service that includes AI components should receive additional scrutiny during procurement, over and above the standard process. At a minimum, expect a Privacy Impact Assessment (PIA) and a security review of how the AI feature handles data: what data it accesses, whether it is used to train external models, where it is processed and stored, and what contractual protections exist. Depending on the data involved, additional review by the Chief Data Privacy Officer, Office of Research, or other relevant offices may be required.

If you are evaluating a new service, renewing a contract for an existing one, or implementing an add-on to existing software, and AI features are involved, loop in your IT support professional early. Do not assume that existing contractual protections automatically extend to AI features added after the original agreement was signed. When in doubt, verify with the vendor and confirm with IT before enabling or using AI-powered features.

What about local and self-hosted AI models?

Local and self-hosted AI models can be a good option for sensitive workflows where sending data to an external service is not appropriate. The guiding principles apply here as with any AI use: verify outputs, be transparent, and ensure the model and its outputs are fit for the purpose you have in mind.

USU IT is actively exploring on-premise and locally hosted AI model options and looks forward to offering supported solutions for workflows where keeping data within the institution is a priority. Watch ai.usu.edu and the #ai_usu Slack channel for updates as those options become available.

Support & Community

  • Find your IT support professional: mytech.usu.edu
  • IT Service Desk: servicedesk@usu.edu | 435-797-HELP (4357)
  • Join the conversation: #ai_usu on Slack. Share what you're working on, ask questions, and learn from colleagues across campus.
  • Information Security: infosec.usu.edu