Policy and Guidance

CMU’s use of AI is grounded in institutional policies and the recommendations of the cross-divisional workgroups of the Embracing AI at CMU Go Grant. Draft policy principles emphasize academic integrity, data privacy and security, compliance with applicable laws, role specific guidance, and university community education. 

Core principles

  • Student-centered learning and career readiness: AI should enhance learning and prepare graduates for an AI-rich workplace. 
  • Equity and accountability: Provide equitable access to AI education and tools, with clear expectations for use. 
  • Privacy and data security: Institutional data stewardship and regulatory compliance are nonnegotiable. 
  • Transparency and academic integrity: Be explicit about when and how AI is used; model proper attribution. 
  • Sustainability and assessment: Support with governance, staffing, and evaluation to ensure continuous improvement. 

Campus expectations

  • Use institutionally approved tools when working with university data; consumer tools are typically for public data only unless covered by an enterprise agreement.  
  • Do not input regulated data (e.g., HIPAA, CUI, PCI) into generative AI tools unless the tool is explicitly approved for that classification.  
  • Follow all applicable laws/policies (e.g., accessibility, copyright, research integrity, data security) and consult the appropriate office when in doubt. 
  • Provide clear guidance on acceptable use including syllabus statements and assignment directions.  Visit the Office of Curriculum and Instructional Support website for more information.  

Related policies and guidance

The following CMU policies provide the foundation for responsible, secure, and ethical use of artificial intelligence technologies. Community members are expected to follow these policies whenever using AI tools in teaching, learning, research, or administrative work.

Data Stewardship (Policy 3-30)

The Data Stewardship Policy establishes responsibilities for protecting university information and classifies institutional data as Public, Protected, or Restricted. The policy emphasizes safeguarding sensitive information and prohibits entering institutional data into generative AI systems without proper prior written approval.

Responsible Use of Computing (Policy 3-31)

The Responsible Use of Computing Policy governs the use of CMU computing, networking, and telecommunications resources. It establishes expectations for appropriate and lawful use of university technology, protection of privacy, security of user credentials, and responsible management of university data. Users may not upload CMU data to generative AI systems without prior written approval.

Information Security Policy (Policy 3-42)

The Information Security Policy protects the confidentiality, integrity, and availability of institutional data and information systems. It establishes university-wide expectations for safeguarding information across all formats and reinforces requirements for protecting institutional data when using AI technologies.

Future policy development

CMU continues to evaluate policies and practices to address emerging AI-related opportunities and risks. Current reviews focus on areas such as research integrity, data stewardship, information security, intellectual property, copyright, and responsible technology use to help ensure that AI is implemented safely, ethically, and in alignment with university values.