Skip to content

Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support

Leadership guide/Security, privacy & compliance

Security, privacy & compliance

Make the safeguards
specific to the use.

Start with the people, information and activity involved. Then determine the requirements, controls and accountable reviewers.

This US-focused map supports issue identification. It is not an exhaustive legal inventory or a determination that a particular use is compliant. Applicable requirements depend on the institution, jurisdiction, activity, people, information and agreements.

Education recordsFERPA

Determine which information is an education record, whether disclosure is authorized and what conditions apply to service providers, access and redisclosure.

Bring in: Privacy, registrar and counsel.

Read the official source ↗Information security

GLBA and the Safeguards Rule

Determine institutional and activity-specific coverage, including relevant financial-aid arrangements. Connect AI processing to the applicable information-security program.

Bring in: Information security, financial aid and counsel.

Read the official source ↗Accessibility

ADA and Section 504

Review access to the actual learning or service activity, applicable accommodations and the requirements for covered web and mobile services. Confirm current applicability and timelines.

Bring in: Accessibility, disability services and counsel.

Read the official source ↗Equal treatment

Education civil-rights requirements

Review potentially discriminatory effects in learning, access, services and institutional decisions. Determine the applicable Title VI, Title IX, Section 504 and other obligations with qualified review.

Bring in: Civil-rights office and counsel.

Read the official source ↗Employment

Employment discrimination and workplace obligations

Review selection, evaluation and employee-facing AI with HR and counsel. Consider applicable federal and state rules, accommodations, agreements and employee participation.

Bring in: Human resources and counsel.

Read the official source ↗Health and clinical activity

HIPAA where applicable

Determine whether the entity, activity and information are covered. Do not assume every campus health record falls under HIPAA; reconcile education-record and partner requirements.

Bring in: Clinical leadership, privacy and counsel.

Read the official source ↗Rights in content

Copyright and contractual permissions

Check rights to upload, reproduce, disclose or reuse student, faculty, library, research and partner material. Attribution alone does not establish permission.

Bring in: Library, research, procurement and counsel.

Read the official source ↗Research participation

Human-subjects research requirements

Determine whether the activity requires research review, informed consent or other protections. Keep AI assistance within the approved protocol and sponsor conditions.

Bring in: Research office, IRB and counsel.

Read the official source ↗

Complete the local requirements map.

Ask responsible offices to identify state and local privacy, breach-notification, recording, public-records, procurement and AI-specific rules; system and board requirements; accreditation and professional standards; grants, contracts and collective agreements; and partner or placement restrictions.

For dual-enrollment and younger learners, review age-related account conditions, consent, supervision and any applicable children’s privacy requirements. For specialized research or international activity, include the relevant sponsor, data-transfer, export-control and other jurisdictional requirements.

Keep the resulting record specific: the requirement, the affected use, the responsible reviewer, the control or process that satisfies it, and the date or event requiring review.

As AI becomes more capableReview the new authority
the system receives.

A more capable model may have the same interface while reaching more information or taking additional actions. Reassess the changed use.

Work through information safeguards→Set boundaries for actions→

Put the arrangements into practice.

Risk and approval, AI security, vendor evidence, release testing, monitoring and incident response.

Open operations and assurance→Download the guide→