Body
Overview
AI tools are approved based on what kind of data you're putting into them, not just which tool it is. If your data is just public information, most tools are fine. If it involves student records, personal identifiers, health info, or sensitive UT business data, you should only use UT-managed tools like Microsoft Copilot, UT Verse, or the UT AI Hub — and even then, some data types need special review first.
The information below is presented from the UT Guidance Chart for Using AI Tools to assist users in determining which AI tools they can use with their data.
Step 1: What kind of data are you working with?
Pick the option that best describes the data you want to type into (or upload to) an AI tool.
| If your data is... |
Call it... |
| Already published publicly, or meant for anyone to see (press releases, public course catalogs, marketing copy) |
Public |
| Everyday UT business info not meant for the public, but not sensitive (internal memos, draft schedules, non-sensitive meeting notes) |
Internal Use Only |
| Sensitive UT business data not covered by a specific law below (contracts, financials, HR data, unpublished research) |
Private |
| Student records — grades, schedules, advising notes, disciplinary records |
FERPA |
| Social Security numbers, driver's license numbers, financial account numbers, passport numbers |
Restricted PII |
| Health/medical records, patient info |
HIPAA |
| Government-controlled unclassified research/contract data |
CUI |
Step 2: What AI tool do you want to use?
| Tool type |
Examples |
| A. Free or paid public AI tool NOT managed by UT |
ChatGPT (Free, Plus, Pro), Claude Pro/Max, Google Gemini, Copilot Free, any AI app where you log in with non-UT credentials |
| B. AI feature built into UT-purchased software |
AI features inside a vendor tool UT already has a contract for (e.g., AI in an already-licensed platform) |
| C. Sovereign AI system |
A UT-owned/managed AI environment that isn't public-facing and has been specially configured |
| D. UT-managed AI platform |
Microsoft Copilot (UT M365 version), UT Verse, UT AI Hub, Anthropic for Education |
Step 3: Look up the answer
A. Free/Paid Public AI Tools (ChatGPT, Claude, Gemini, etc. — NOT UT-managed)
✅ Public data only. Nothing else. Do not paste Internal, Private, FERPA, PII, HIPAA, or CUI data into these tools — even the paid versions — unless it's specifically Microsoft Copilot for M365, UT Verse, or UT AI Hub (see section D below).
B. AI Features Inside UT-Purchased Software
- ✅ Public, Internal
- ⚠️ Review required for Private, FERPA, Restricted PII, HIPAA — must be cleared with the Governance, Risk & Compliance (GRC) team before use
- ❌ Not for CUI
C. Sovereign AI Systems (UT-owned, not public-facing)
- ✅ Public, Internal, Private, FERPA
- ⚠️ Limited use for Restricted PII and HIPAA — only if specific security lockdowns are documented and verified (e.g., no Internet access, no external data transmission)
- ❌ Not for CUI
- Requires GRC review before deployment
D. UT-Managed Platforms: Microsoft Copilot (M365), UT Verse, UT AI Hub
- ✅ Public, Internal, Private, FERPA
- ⚠️ Limited use for Restricted PII — only with documented security configuration
- ❌ Not for HIPAA or CUI