Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support
Leadership guide/Decisions/Tools, use cases & vendors
An approved product still needs a defined purpose, appropriate data and clear operating boundaries.
HumanSkills recommendation · September 2026
In this guideRecommended positionYour local choicesA campus situationWho is responsibleLanguage to useEvidence of implementationSupporting sourcesDownload PDF→
Read, share and use with your team.
HumanSkills recommendationMake approval specific enough to be usable: tool, use case, information, users, permissions and conditions. Offer a simple route for routine, low-risk uses and specialist review for consequential uses, protected information and connected actions.
A campus subscription does not answer whether a particular feature may access personnel records, evaluate students or send messages. Permission can become ambiguous when a vendor introduces new features inside an existing product.
What the evidence supportsPurdue requires both tool and use-case approval for sensitive or restricted data. RPCC maintains an approval and governance process. These are concrete precedents for treating the intended use as part of the approval decision.
The right arrangement depends on the purpose, consequences, applicable requirements and capacity of your institution. Use these options to make the choice explicit.
Pre-authorized routine uses
Consider this when: The use stays within defined low-risk boundaries and permitted information.
The tradeoff: Reduces delay, but requires understandable boundaries, examples and a way to ask about exceptions.
Bounded pilots
Consider this when: The institution needs evidence before broader adoption.
The tradeoff: Set owners, limited access, success measures, review dates and a way to stop or exit.
Individual review
Consider this when: The use affects rights, sensitive information, important decisions or external actions.
The tradeoff: Needs specialist capacity and an escalation route so review does not stall indefinitely.
An employee sees a new assistant inside a college-licensed platform. It can summarize files across connected folders. The employee assumes the existing subscription approves the feature.
The question is whether the new feature changes access, processing or vendor data use.
What the team produces: An approved-use entry that staff can understand and specialists can verify.
Board & trustees
Request assurance that consequential deployments enter an accountable review process.
Institutional leaders
Assign approval authority, review capacity and a route for timely escalation.
AI task force
Make the review process coherent across procurement, IT, privacy, accessibility and the affected service.
Apply these roles within your institution’s actual governance and delegated authority.
Illustrative model clause
Approval of an AI product does not authorize every use of that product. The approving authority must specify permitted purposes, information, users and capabilities, together with review conditions. Material changes to those conditions require reassessment before expanded use.
Copy the clause
Review this clause with the full policy and local requirements. It is an implementation starting point, not a statement of measured consensus.
Model policy §4→Model policy §5→Model policy §9→Model policy §12→
When to reconsiderReview new integrations, vendor changes, expanded data access, new populations and features that can initiate actions.
Selected precedents and guidance supporting this chapter. These sources do not imply institutional endorsement of HumanSkills or agreement with every recommendation.
Source review: 24 September 2026. Read the editorial approach.
Continue the workProtect the information people entrust to you.
→
Read the research comparisons and explore the annotated library across US colleges, universities and international institutions. Use the model language as a starting point for your own decision.
Shared ground and local choices→Make the policy yours→