AI: AI Tools & Data Classification Quick-Reference Guide

Overview

AI tools are approved based on what kind of data you're putting into them, not just which tool it is. If your data is just public information, most tools are fine. If it involves student records, personal identifiers, health info, or sensitive UT business data, you should only use UT-managed tools like Microsoft Copilot, UT Verse, or the UT AI Hub — and even then, some data types need special review first. 

The information below is presented from the UT Guidance Chart for Using AI Tools to assist users in determining which AI tools they can use with their data. 

Step 1: What kind of data are you working with?

Pick the option that best describes the data you want to type into (or upload to) an AI tool.

If your data is... Call it...
Already published publicly, or meant for anyone to see (press releases, public course catalogs, marketing copy) Public
Everyday UT business info not meant for the public, but not sensitive (internal memos, draft schedules, non-sensitive meeting notes) Internal Use Only
Sensitive UT business data not covered by a specific law below (contracts, financials, HR data, unpublished research) Private
Student records — grades, schedules, advising notes, disciplinary records FERPA
Social Security numbers, driver's license numbers, financial account numbers, passport numbers Restricted PII
Health/medical records, patient info HIPAA
Government-controlled unclassified research/contract data CUI

Step 2: What AI tool do you want to use?

Tool type Examples
A. Free or paid public AI tool NOT managed by UT ChatGPT (Free, Plus, Pro), Claude Pro/Max, Google Gemini, Copilot Free, any AI app where you log in with non-UT credentials
B. AI feature built into UT-purchased software AI features inside a vendor tool UT already has a contract for (e.g., AI in an already-licensed platform)
C. Sovereign AI system A UT-owned/managed AI environment that isn't public-facing and has been specially configured
D. UT-managed AI platform Microsoft Copilot (UT M365 version), UT Verse, UT AI Hub, Anthropic for Education

Step 3: Look up the answer

A. Free/Paid Public AI Tools (ChatGPT, Claude, Gemini, etc. — NOT UT-managed)

✅ Public data only. Nothing else. Do not paste Internal, Private, FERPA, PII, HIPAA, or CUI data into these tools — even the paid versions — unless it's specifically Microsoft Copilot for M365, UT Verse, or UT AI Hub (see section D below).

B. AI Features Inside UT-Purchased Software

  • ✅ Public, Internal
  • ⚠️ Review required for Private, FERPA, Restricted PII, HIPAA — must be cleared with the Governance, Risk & Compliance (GRC) team before use
  • ❌ Not for CUI

C. Sovereign AI Systems (UT-owned, not public-facing)

  • ✅ Public, Internal, Private, FERPA
  • ⚠️ Limited use for Restricted PII and HIPAA — only if specific security lockdowns are documented and verified (e.g., no Internet access, no external data transmission)
  • ❌ Not for CUI
  • Requires GRC review before deployment

D. UT-Managed Platforms: Microsoft Copilot (M365), UT Verse, UT AI Hub

  • ✅ Public, Internal, Private, FERPA
  • ⚠️ Limited use for Restricted PII — only with documented security configuration
  • ❌ Not for HIPAA or CUI