Artificial Intelligence (AI) Use Guidelines and Responsibilities

Summary

Guidelines for the responsible, ethical, and secure use of AI tools at SFA, including acceptable and prohibited uses, which data can be used with AI, and user responsibilities under university policy, TAC 202, TAC 219, and FERPA.

Body

Artificial Intelligence (AI) Use Guidelines and Responsibilities

Quick Overview
  • Artificial Intelligence (AI) tools may provide benefits for teaching, learning, research, and administrative operations when used responsibly.
  • AI systems must be used in accordance with university policies, applicable laws, and State of Texas requirements, including TAC 202, TAC 219, FERPA, and other applicable regulations.
  • Users are responsible for reviewing and validating AI-generated content for accuracy, bias, and appropriateness.
  • Confidential, sensitive, regulated, or non-public university data must not be entered into unapproved AI platforms.
  • Heightened Scrutiny Artificial Intelligence Systems (HSAIS) may require additional governance reviews and approvals prior to use.

Who This Applies To

  • Faculty
  • Staff
  • Student Employees
  • Researchers
  • Contractors and Third Parties acting on behalf of SFA

Purpose

Stephen F. Austin State University recognizes that Artificial Intelligence technologies, including Generative AI tools, can support innovation, productivity, teaching, research, and operational efficiency. This article provides guidance for the responsible, ethical, and secure use of AI technologies at SFA.

The use of AI technologies must align with university policies, academic integrity expectations, information security requirements, accessibility obligations, and applicable federal and state laws and regulations.

Acceptable Uses of AI

Examples of acceptable AI use cases may include:

  • Brainstorming and idea generation
  • Drafting or summarizing non-sensitive content
  • Research assistance and data analysis
  • Code development and troubleshooting
  • Administrative productivity enhancements
  • Teaching and learning support
  • Accessibility and communication assistance

All AI-generated outputs should be reviewed and validated by the user before being relied upon, published, submitted, or distributed.

Prohibited or Restricted Uses

The following activities are prohibited unless explicitly approved through the appropriate governance and review processes:

  • Submitting confidential, regulated, or restricted university data into unapproved AI systems
  • Using AI systems in a manner that violates FERPA, HIPAA, PCI DSS, TAC 202, TAC 219, copyright law, or other legal or regulatory requirements
  • Using AI-generated content without appropriate review, attribution, or validation
  • Automated decision-making involving students, employees, or members of the public without required governance review
  • Using AI to generate discriminatory, harmful, misleading, fraudulent, or inappropriate content
  • Circumventing academic integrity or authorship expectations through undisclosed AI usage
  • Uploading sensitive research, institutional data, credentials, or export-controlled information into public AI platforms

Data Classification and AI

University data classification requirements continue to apply when using Artificial Intelligence technologies. Users must understand the classification level of institutional data before entering information into any AI platform or service.

Data classified as confidential, regulated, or otherwise restricted must not be entered into public or unapproved AI systems.

Security Category Description AI Usage Guidance
Category III - Public Information intended for public disclosure that presents little to no risk to the university if disclosed. Generally permitted for use with approved AI platforms.
Category II - Sensitive Information that is not public and could result in operational, reputational, or administrative risk if improperly disclosed. Only use with university-approved AI systems and with appropriate safeguards.
Category I - Confidential / Regulated Highly sensitive or regulated information protected by law, regulation, contract, or university policy, including FERPA, HIPAA, PCI DSS, CJIS, or other regulated data types. Do not upload to public or unapproved AI systems. Formal review, contractual protections, and governance approval may be required.

Examples of data that should not be entered into unapproved AI platforms include:

  • Student education records protected under FERPA
  • Social Security numbers and government identifiers
  • Payment card or financial information
  • Protected health information (PHI)
  • Personnel records and confidential HR data
  • Credentials, passwords, API keys, or security-related information
  • Confidential research or export-controlled information

For additional information regarding university data classifications, refer to the SFA Data Classification guidance.

Academic and Research Considerations

Faculty members may establish course-specific expectations regarding the use of AI tools in coursework, assignments, examinations, and research activities. Students should not assume AI use is permitted unless explicitly stated by the instructor.

Researchers should evaluate whether proposed AI usage introduces concerns related to:

  • Data privacy and confidentiality
  • Intellectual property and copyright
  • Bias and fairness
  • Research integrity
  • Export controls
  • Sponsored research obligations

Heightened Scrutiny AI Systems (HSAIS)

Certain AI systems may fall under the definition of a Heightened Scrutiny Artificial Intelligence System (HSAIS) under Texas Administrative Code 219. These systems may require:

  • Formal risk assessments
  • AI governance review
  • Accessibility and bias evaluations
  • Security and privacy assessments
  • Approval prior to procurement or deployment

Examples may include AI systems that influence admissions, grading, disciplinary actions, employment decisions, financial aid determinations, or other high-impact institutional processes.

User Responsibilities

Individuals using AI technologies at SFA are responsible for:

  • Ensuring compliance with university policy and applicable laws
  • Protecting university and personal data
  • Reviewing AI-generated content for accuracy and bias
  • Properly attributing or disclosing AI-assisted content when required
  • Using AI tools ethically and responsibly
  • Reporting suspected misuse, security incidents, or policy violations

Additional Guidance and Resources

  • SFA Information Security Policies
  • Texas Administrative Code (TAC) 202
  • Texas Administrative Code (TAC) 219
  • FERPA Guidance
  • UT System Information Security Policies

References

This guidance was developed using industry and higher education best practices, including guidance published by peer institutions.

  • University of Texas at Austin AI Guidance
  • Texas A&M University AI Use Guidelines and Ethics

Details

Details

Article ID: 174953
Created
Sun 10/4/26 7:09 PM
Modified
Sun 10/4/26 7:09 PM