Information Technology Services

Making Informed Decisions: University Data & AI 

Artificial intelligence (AI) tools such as Microsoft 365 (M365) Copilot and PatriotAI can significantly improve productivity, research, analysis, and content creation. However, using AI effectively requires thoughtful consideration of the type of data being shared and the specific AI service being used.  

Understanding University Data Classifications 

University policy groups information into three primary categories: 

  • Public Use Data: Information approved for public release, such as public websites, policies, and published materials.  
  • Restricted Data: Nonpublic information requiring safeguards against inappropriate disclosure. Examples include internal records, some information that may be subject to specific data use and sharing agreements, draft announcements and news releases.   
  • Highly Sensitive Data: Information requiring the strongest protections, such as Social Security numbers, payment card information, authentication secrets, certain health information, and controlled research data.  

Not All AI Tools are Created Equal 

AI tools and services vary significantly in how they operate and manage data. When deciding whether to use an AI service or tool, it is important to consider several factors, including: 

  • Whether the university has a direct contract, agreement, or approved relationship with the vendor. For example, PatriotAI and M365 Copilot are offered as part of existing contractual agreements with CloudForce and Microsoft. 
  • How the service is provided and supported. 
  • Where the uploaded files and data may be stored.   
  • How prompts, uploaded content, and other information may be used, including whether they are used to train the underlying large language model (LLM). 
  • Specific privacy, security, and compliance requirements associated with the service, often embedded in terms and conditions, or privacy statements.  

Carefully evaluating these considerations can help ensure that the selected AI tool aligns with institutional policies, data protection requirements, and the intended use case. 

Follow the “Minimum Necessary” Rule 

When Protected Data must be used, the guidance recommends providing only the minimum amount of information necessary to accomplish the task. Users should remove unnecessary identifiers, credentials, sensitive fields, and other data elements whenever feasible. AI-generated outputs should always be reviewed by a human before being relied upon for decisions or official activities.  

Special Considerations for File Uploads 

Users should be aware that uploading files to AI tools may result in copies being created and stored in associated systems. For example, when a file is attached to M365 Copilot chat, a copy of that file is saved to the user’s OneDrive account. As a result, storage location, sharing permissions, retention requirements, and access controls should be carefully considered when using AI services. Users are responsible for managing the sharing permissions associated with any files they upload. 

When in Doubt, Ask Before You Act 

Use AI tools thoughtfully, understand the data you are handling, use the least amount of data necessary, and ensure appropriate human oversight. When working with Protected Data, research datasets, regulated information, or unfamiliar AI services, users should seek guidance through established university governance and review processes through the ITS Support Center before proceeding.  

By taking a risk-based approach, the George Mason community can benefit from AI innovation while continuing to safeguard university data, protect privacy, and comply with legal, contractual, and regulatory obligations.