West Virginia University (WVU) recognizes the potential of artificial intelligence (AI) tools to assist administrative, academic, and research work with tasks like drafting, brainstorming, summarizing, analysis, accessibility, coding, and creating text, images, audio or video. Some AI tools can also search information, connect to other systems, or take actions on a user's behalf.
These capabilities can create privacy, security, accuracy, bias, accessibility, copyright, intellectual property, and compliance risks when used with inappropriate information or without adequate review.
The Office of the Provost, Office of General Counsel and Information Technology Services provide the following guidance for faculty, staff and students using AI for University administrative, academic, and research activities.
These guidelines supplement existing WVU policies, standards and procedures and reflect WVU's commitment to the responsible integration of AI. As AI technologies and University services evolve, these guidelines will be updated accordingly.
Questions or suggestions regarding this guidance may be directed to Information Security Services at infosec@wvu.edu.
Core Principles
These core principles support the ethical and responsible use of technology at WVU, including AI, and reinforce the Acceptable Use of Data and Technology Resources Policy. It is important to always keep these core principles in mind when using any technology at WVU, including generative AI.
- Understand capabilities and limitations. Before using an AI tool, understand its intended use and limitations. AI-generated content may be inaccurate, incomplete, misleading, biased or fabricated. It may also contain incorrect citations or reproduce protected material. Do not assume an AI response is authoritative simply because it appears confident or detailed.
- Employ Trust and Transparency. Ensure clarity and openness when employing AI, particularly in areas affecting decision-making or policy development. Always ask yourself if a reasonable person would expect to know that you used generative AI to create the product and explain how you used AI.
- Use human judgment. AI may support drafting, summarizing, brainstorming, analysis and other appropriate tasks, but it does not replace human expertise, accountability, professional judgment or required approvals. The person using AI remains responsible for the resulting work.
- Be transparent. Let people know when AI played a meaningful role in creating work, supporting a decision or preparing a communication when University policy, law, professional standards or reasonable expectations call for disclosure.
- Check the result. Review AI-generated content for accuracy, completeness, bias, accessibility, tone, source reliability, copyright and other intellectual-property concerns before using or sharing it. Independently verify important facts, calculations, quotations, citations and references.
- Protect data privacy and security. Before providing information to AI, identify and classify the data you want to upload. Never enter student, employee, patient, donor, contract, budget, security issues, legal matters, unpublished research, or nonpublic WVU business processes into AI. For more information about data classification see the University Data section below.
- Confirm you have approval. Approval of an AI product does not automatically approve every use or feature of that product. Approval may be limited to specific business purposes, data, configurations, account types, features and users. Additional review may be required before expanding an approved use to new data, integrations, APIs, connectors, users, automated actions, agents or workflows. Approval of an existing product also does not automatically authorize new AI functionality later added by the vendor.
- Be adaptable. AI tools, models, capabilities and risks change quickly. These guidelines will evolve as WVU's technology environment and institutional needs change.
University Data
It is important to identify and classify the data you want to use with an AI tool prior to adding the data to it. The WVU Data Classification Policy classifies University Data in four categories: Public, Internal, Confidential or Sensitive. Never enter Internal, Confidential or Sensitive WVU information into an AI service unless the specific service, account or configuration, feature and use have been approved for that information. Provide only the minimum information needed for the task. If you are unsure how information is classified, treat it as nonpublic and ask for guidance. When in doubt, don't paste it.
Additionally, sometimes Public or Internal data could also include personally identifiable information of individuals who are connected to the University including students and employees. NEVER include identifiable student, employee, patient, or donor information into AI, regardless of WVU data classification, unless the AI service, configuration, and use have been approved for that information.
Use of AI Tools at WVU
AI tools may generate, summarize, analyze, retrieve or transform text, images, code, audio, video and other information. Some operate as standalone chat services, while others are embedded into applications or can connect to University information and systems.
AI can improve efficiency and support University work, but it should be used as an aid rather than a substitute for responsible professional judgment.
Before using AI, consider the tool and feature you are using, the account you are signed into, the information you plan to provide or expose, what other information or systems the AI can access, and what will happen with the resulting output or action.
WVU-supported AI currently includes basic Microsoft 365 Copilot Chat access and Blackboard AI features, where available. WVU-supported access does not mean that every feature is approved for every classification of WVU data or business purpose.
Other AI services or features may be used for WVU administrative work only when they have been specifically authorized or reviewed through the IT Purchase Request process and any other required University review.
| Tool | Appropriate Use | Do Not Use |
|---|---|---|
| Basic Microsoft 365 Copilot Chat | General brainstorming, drafting, rewriting and summarizing using Public WVU information or other information specifically approved for Copilot Chat, when signed in with a WVU work or school account. | Do not enter FERPA, PHI including de-identified PHI, HR records, donor data, legal matters, security findings, credentials or other protected WVU information unless that specific use has been approved. Do not assume new Copilot features, agents or connectors are automatically approved. |
| Blackboard AI | Course and LMS support within WVU-enabled Blackboard features, such as helping develop learning modules, prompts or rubrics where appropriate. | Do not enter student-specific records, grades, accommodations, conduct matters, health information or other protected information unless the specific feature and use have been approved for that information. |
| Other AI Tools | Uses approved through the IT Purchase Request, vendor review, Information Security review or other required University review. Approval applies only to the reviewed tool, configuration, data, users and business purpose. | Do not expand an approved use to new data, integrations, APIs, connectors, automated actions, agents or materially different functionality without required additional review. |
| Unapproved free or personally purchased consumer AI tools | Personal learning or experimentation unrelated to WVU business and using information you are authorized to disclose. | Do not use for WVU administrative work unless specifically authorized. Do not enter University Data, upload WVU business records, or connect WVU accounts, files or systems to an unapproved service. |
Do not use AI browser extensions, plug-ins, desktop assistants, meeting bots or connected agents with WVU systems or nonpublic WVU information unless the specific integration has been reviewed and approved.
Do not connect AI tools or agents to WVU email, calendars, Teams, SharePoint, OneDrive, Google Drive, Blackboard, ticketing systems, financial systems, HR systems, source-code repositories, databases, APIs or other WVU systems unless the integration has been reviewed and approved.
AI tools create additional risk when they can access WVU files, messages, tickets, databases, code or other systems. AI agents that can retrieve files, send messages, change records, run code or take actions require additional review, limited and least-privilege access, appropriate logging and human approval for consequential actions.
Information retrieved by AI from websites, email, documents or other sources should be treated as untrusted input. Malicious or hidden instructions can attempt to manipulate an AI system into disclosing information or performing unintended actions.
Example Scenarios for Use of AI
AI may help rewrite public-facing drafts, brainstorm training ideas, create generic meeting agendas, summarize public information from WVU websites, or draft presentation outlines when the tool and information are appropriate for the use.
Do not use unapproved AI with student records, HR or personnel matters, nonpublic budget information, contracts, legal documents, security findings, logs, vulnerabilities, system information, credentials, donor or alumni information, sensitive meeting transcripts, unpublished research or other Internal, Confidential or Sensitive WVU information.
| Scenario | Appropriate Use | Do Not Use |
|---|---|---|
| Communications | AI may help draft or improve general communications, presentations or FAQs using information permitted for the service. Material AI-generated content should be reviewed before official distribution. | Do not use unapproved AI to personalize communications with nonpublic WVU information. Marketing, social media and branded communications may be subject to additional WVU requirements. |
| Documents, data and reporting | AI may help organize or summarize Public information or other information approved for the service. | Do not upload Internal, Confidential or Sensitive WVU information into an unapproved tool. AI-generated summaries remain subject to applicable data-protection requirements. |
| Audio, video and image creation | AI may support accessibility, translation, editing or content development when applicable rights and permissions are clear. | Do not create deceptive media, unauthorized impersonations or content that violates law, University policy, copyright or other intellectual-property rights. |
| Coding assistance | AI may help with boilerplate, examples, documentation, testing, debugging or learning when the code and related information are permitted for the service. | Do not submit nonpublic WVU source code, secrets, logs, internal system information, credentials or security findings to unapproved tools. AI-generated code must be reviewed for security, correctness and applicable licensing concerns. |
| Meeting transcription | Approved AI transcription and meeting assistants may support transcription, summarization or note-taking when participants have been informed and the information discussed is permitted for the tool. | Do not use the tool unless participants have been given notice and any required consent has been obtained. Do not use AI transcription in meetings involving sensitive, Confidential, legal, personnel, health, student, security or high-level strategic matters unless the specific use has been approved. |
Data Privacy and Security
Use of AI does not change WVU's obligations under the Information Privacy Policy or other requirements for protecting University information.
Do not assume that a consumer or otherwise unapproved AI service provides the privacy, security, retention, deletion or contractual protections required by WVU. Nonpublic WVU information may be processed only by AI services and uses approved for that information.
A provider's statement that prompts, files or other customer information are not used to train its general-purpose AI models does not by itself mean the service is approved for WVU information. Review may also consider how information is stored, how long it is retained, who can access it, deletion capabilities, authentication, logging, accessibility, incident response, intellectual-property terms and risks created by connecting the AI service to WVU systems.
Use the IT Purchase Request process for required review of AI tools, services and integrations, including free software and no-cost services where applicable.
Report any known or suspected AI-related security or privacy incident promptly through the WVU Incident Report Form.
Last Updated September 1, 2026