Artificial Intelligence
Guidance Chart for Using AI Tools
Service navigation
This matrix clarifies where UT users may input university data using AI tools based on UT’s data classification.
Key
Yes
Review
Limited
No
Examples and Clarifications
- Review: indicates that use requires coordination with the campus IT department and the Governance, Risk, and Compliance (GRC) team to validate security, privacy, and policy compliance before the data set may be used.
- Limited: indicates that use is permitted only when specific security configurations have been implemented to ensure that university data remains within the controlled environment. Required configurations may include, but are not limited to:
- Disabling web search, internet-connected plugins, or browse functionality
- Disabling or restricting API access, agent capabilities, and third-party integrations
- Configuring the system for offline or air-gapped operation where applicable
- Ensuring all data processing occurs within UT-owned or UT-managed infrastructure
- Verifying that no data is transmitted to external services, model training pipelines, or third-party endpoints
- The requestor, or purchaser, must document the specific configurations applied and confirm that the environment meets the security requirements for the applicable data classification.
- Note: Each campus may determine its own risk tolerance and may impose additional restrictions or prohibit use in this category.
- Free Public-facing AI tools may ONLY be used with Public Data
Examples: ChatGPT Free, Gemini Free, MS Copilot Free, any mobile app - Paid Non-UT Contracted/Managed AI Platforms may only be used with Public Data
Examples: Claude Pro/Max, ChatGPT Go/Plus/Pro/Business, Gemini Plus/Pro/Ultra, etc.
These are any paid tier of a public AI tool that is not managed by Central IT. - AI Features native to Purchased Software Solutions
AI features or functionality that are built into, bundled with, or integrated as a core component of a commercially licensed software application. These AI capabilities are delivered as part of the software vendor’s platform and operate within the terms of the existing purchase or licensing agreement. - Sovereign AI Systems
AI systems deployed within UT-owned or UT-managed infrastructure that are not publicly accessible may support higher data classifications when appropriate technical, administrative, and contractual safeguards have been implemented. Deployment and use require review by the appropriate IT and Governance, Risk, and Compliance (GRC) teams to ensure compliance with University policies and applicable legal and regulatory requirements. - UT-Contracted/Managed AI Platforms
Examples: Anthropic for Education, Microsoft Copilot for M365, UT AI Hub, UT Verse.
These platforms must be covered by a formal UT agreement that includes UT-standard security, AI, privacy, and data-handling provisions. A contract addendum may be necessary for changes to existing agreements to add current standardized language. - Developmental Protocols
The development, customization, or integration of any AI application, including locally installed or internally developed large language models, is subject to the same University of Tennessee data classification requirements and institutional policies, and does not exempt the application or its users from compliance obligations based on deployment method or hosting location.

Explore
Write
Chat
Call

