Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support
Leadership guide/Security, privacy & compliance
Start with the people, information and activity involved. Then determine the requirements, controls and accountable reviewers.
This US-focused map supports issue identification. It is not an exhaustive legal inventory or a determination that a particular use is compliant. Applicable requirements depend on the institution, jurisdiction, activity, people, information and agreements.
Determine which information is an education record, whether disclosure is authorized and what conditions apply to service providers, access and redisclosure.
Bring in: Privacy, registrar and counsel.
Determine institutional and activity-specific coverage, including relevant financial-aid arrangements. Connect AI processing to the applicable information-security program.
Bring in: Information security, financial aid and counsel.
Review access to the actual learning or service activity, applicable accommodations and the requirements for covered web and mobile services. Confirm current applicability and timelines.
Bring in: Accessibility, disability services and counsel.
Review potentially discriminatory effects in learning, access, services and institutional decisions. Determine the applicable Title VI, Title IX, Section 504 and other obligations with qualified review.
Bring in: Civil-rights office and counsel.
Review selection, evaluation and employee-facing AI with HR and counsel. Consider applicable federal and state rules, accommodations, agreements and employee participation.
Bring in: Human resources and counsel.
Determine whether the entity, activity and information are covered. Do not assume every campus health record falls under HIPAA; reconcile education-record and partner requirements.
Bring in: Clinical leadership, privacy and counsel.
Check rights to upload, reproduce, disclose or reuse student, faculty, library, research and partner material. Attribution alone does not establish permission.
Bring in: Library, research, procurement and counsel.
Determine whether the activity requires research review, informed consent or other protections. Keep AI assistance within the approved protocol and sponsor conditions.
Bring in: Research office, IRB and counsel.
Ask responsible offices to identify state and local privacy, breach-notification, recording, public-records, procurement and AI-specific rules; system and board requirements; accreditation and professional standards; grants, contracts and collective agreements; and partner or placement restrictions.
For dual-enrollment and younger learners, review age-related account conditions, consent, supervision and any applicable children’s privacy requirements. For specialized research or international activity, include the relevant sponsor, data-transfer, export-control and other jurisdictional requirements.
Keep the resulting record specific: the requirement, the affected use, the responsible reviewer, the control or process that satisfies it, and the date or event requiring review.
A more capable model may have the same interface while reaching more information or taking additional actions. Reassess the changed use.
Work through information safeguards→Set boundaries for actions→
Risk and approval, AI security, vendor evidence, release testing, monitoring and incident response.