Skip to content Skip to main navigation Report an accessibility issue
Artificial Intelligence

Guidance Chart for Using AI Tools


Service navigation


This matrix clarifies where UT users may input university data using AI tools based on UT’s data classification.

Data Classification

Public

Internal
Use Only
Private

FERPA

Restricted PII

HIPAA

CUI

Free3 / Paid4 Non-UT
Managed AI Platforms
YesNoNoNoNoNoNo
AI Features native to
Purchased Software
Solutions with
UT Contracts5
YesYesQuestionable1Questionable1Questionable1Questionable1No
Sovereign
AI Systems 6
YesYesYesAllowedlimited2limited2No
UT-Contracted/Managed
AI Platforms:
Microsoft Copilot,
UT Verse, UT AI Hub7
YesYesYesAllowedlimited2NoNo

Key

Allowed Yes

Questionable Review

limited Limited

Not Allowed No


Examples and Clarifications

  1. Review: indicates that use requires coordination with the campus IT department and the Governance, Risk, and Compliance (GRC) team to validate security, privacy, and policy compliance before the data set may be used.
  2. Limited: indicates that use is permitted only when specific security configurations have been implemented to ensure that university data remains within the controlled environment. Required configurations may include, but are not limited to:
    • Disabling web search, internet-connected plugins, or browse functionality
    • Disabling or restricting API access, agent capabilities, and third-party integrations
    • Configuring the system for offline or air-gapped operation where applicable
    • Ensuring all data processing occurs within UT-owned or UT-managed infrastructure
    • Verifying that no data is transmitted to external services, model training pipelines, or third-party endpoints
    • The requestor, or purchaser, must document the specific configurations applied and confirm that the environment meets the security requirements for the applicable data classification.
    • Note: Each campus may determine its own risk tolerance and may impose additional restrictions or prohibit use in this category.
  3. Free Public-facing AI tools may ONLY be used with Public Data
    Examples: ChatGPT Free, Gemini Free, MS Copilot Free, any mobile app
  4. Paid Non-UT Contracted/Managed AI Platforms may only be used with Public Data
    Examples: Claude Pro/Max, ChatGPT Go/Plus/Pro/Business, Gemini Plus/Pro/Ultra, etc.
    These are any paid tier of a public AI tool that is not managed by Central IT.
  5. AI Features native to Purchased Software Solutions
    AI features or functionality that are built into, bundled with, or integrated as a core component of a commercially licensed software application. These AI capabilities are delivered as part of the software vendor’s platform and operate within the terms of the existing purchase or licensing agreement.  
  6. Sovereign AI Systems
    AI systems deployed within UT-owned or UT-managed infrastructure that are not publicly accessible may support higher data classifications when appropriate technical, administrative, and contractual safeguards have been implemented. Deployment and use require review by the appropriate IT and Governance, Risk, and Compliance (GRC) teams to ensure compliance with University policies and applicable legal and regulatory requirements.
  7. UT-Contracted/Managed AI Platforms
    Examples: Anthropic for Education, Microsoft Copilot for M365, UT AI Hub, UT Verse.
    These platforms must be covered by a formal UT agreement that includes UT-standard security, AI, privacy, and data-handling provisions. A contract addendum may be necessary for changes to existing agreements to add current standardized language.
  8. Developmental Protocols
    The development, customization, or integration of any AI application, including locally installed or internally developed large language models, is subject to the same University of Tennessee data classification requirements and institutional policies, and does not exempt the application or its users from compliance obligations based on deployment method or hosting location.