Use this guide to choose an approved University AI environment and determine what information may be used in it. The Artificial Intelligence Use Policy governs all AI use; these guidelines provide product-specific approvals, restrictions, and procedures. “Must” and “must not” identify requirements. 

1.0 Product and Data Selection 

Data or activity 

Copilot Chat 

Microsoft 365 Copilot 

ChatGPT Business 

Gemini for Education 

Public information 

Permitted 

Permitted 

Permitted 

Permitted 

Internal nonpublic information 

Permitted 

Permitted 

Permitted 

Permitted 

FERPA education records 

Permitted 

Permitted 

Permitted 

Conditional 

HIPAA protected health information 

Conditional 

Conditional 

Prohibited 

Conditional 

GLBA regulated information 

Conditional 

Conditional 

Prohibited 

Not approved 

Credentials and restricted identifiers 

Conditional 

Conditional 

See Section 5 

Conditional 



Permitted does not mean unrestricted. Users must have an authorized University purpose and appropriate access, use only the information necessary for the task, and comply with the applicable product restrictions. Mixed files must satisfy the restrictions for every data type they contain. 

Conditional means the information may be used only in an ITS-approved configuration or workflow and subject to any additional requirements stated in the applicable product section. 

2.0 Common Scenarios 

Scenario 

Required treatment 

Draft a general campus announcement 

Use an approved product and verify accuracy before release. 

Summarize one student’s authorized advising record 

Use an environment permitted for all included data, minimize the information provided, and verify the factual summary. No separate decision-use approval is required when the AI is not evaluating the person or recommending an outcome. 

Score applicants or recommend employee ratings 

Obtain prior University approval appropriate to the use and data involved. Meaningful human review is required. 

Explain an already approved financial-aid decision 

Use an environment approved for the actual data involved. GLBA information is prohibited in ChatGPT Business and is not approved for Gemini under this guide. 

Connect an AI assistant to the student information system 

Separate ITS integration review is required. Approved data boundaries, least privilege, and permitted functions must be technically enforced before access is enabled. 

Share a project containing student records 

Every recipient must be authorized for the underlying records. Use restricted sharing and do not create public links. 

Automatically deny an accommodation or post a final grade based on AI judgment 

Prohibited. AI may not autonomously make, approve, deny, or implement a consequential decision. 

3.0 Requirements for Every Approved Product 

3.1 Before entering information 

  • Confirm that the task and data type are permitted for the selected product. 
  • Sign in through the ITS-provided entry point and verify that the active account and workspace are University-managed. A University email address alone does not establish that the session is covered by a University agreement. 
  • Review the complete input, including files, hidden spreadsheet sheets, comments, revisions, images, attachments, metadata, browser or screen context, and automatically retrieved information. 
  • Provide only the records and fields necessary for the task. Use synthetic or appropriately de-identified information when practical. Do not submit prohibited information merely to ask the AI to remove or de-identify it. 

3.2 During and after the task 

  • Use only approved uploads, search features, apps, connectors, external actions, screen or browser context, and other tools. If the processing boundary cannot be confirmed, stop and use an approved alternative. 
  • Do not change settings to contribute University information to model training or optional data-sharing programs unless ITS has approved the disclosure. 
  • Keep protected information out of broadly shared or persistent instructions, assistants, projects, memories, and knowledge sources when a limited conversation will accomplish the task. 
  • Check results against authoritative records and sources before relying on or distributing them. Validate calculations and executable code. 
  • Review recipients, sharing permissions, attachments, and proposed actions before sending, exporting, or sharing AI-generated content. 
  • Store required University records in the designated University system. AI conversation history is not an official system of record. 

3.3 If something goes wrong 

Stop the affected activity and immediately report accidental disclosure, unexpected retrieval, exposed credentials, suspicious tool instructions, unauthorized actions, or other suspected AI-related security or privacy incidents to ITS through established reporting channels. Preserve relevant information and follow ITS directions for containment, credential changes, and other corrective actions. 

4.0 Microsoft Copilot 

4.1 Copilot Chat 

Approved environment: the University-managed Microsoft work or school Copilot Chat experience with enterprise data protection. Consumer Microsoft accounts, personal subscriptions, GitHub Copilot, and other products using the Copilot name are outside this approval. 

The University authorizes approved Copilot configurations and workflows for FERPA, HIPAA, and GLBA information as specifically identified by ITS. Use only the ITS-approved configuration appropriate to the data. The enterprise data protection indicator confirms the account context but does not establish that every feature, search path, agent, or connected service is approved. 

  • For protected information, use the ITS-approved workflow with web search disabled or otherwise technically prevented from receiving the protected information. A prompt instructing the AI not to search is not an access control. 
  • Upload only the information required for the task and review the entire file before upload. 
  • If browser or page context is enabled, confirm exactly what content is being shared. Do not summarize a protected system through browser context unless ITS has approved that data flow. 
  • Agents, connectors, third-party services, and automated actions require separate ITS approval. 

4.2 Microsoft 365 Copilot 

Approved environment: Microsoft 365 Copilot in University-managed and authorized Microsoft 365 applications and services. The University authorizes approved Microsoft 365 Copilot configurations and workflows for FERPA, HIPAA, and GLBA information as specifically identified by ITS. Existing access permissions and data restrictions continue to apply. 

  • Word and PowerPoint: select only authorized source documents, verify facts and citations, and inspect output before wider distribution. 
  • Excel: limit workbooks to necessary sheets and fields. Independently verify formulas, totals, assumptions, and whether aggregates can identify individuals. 
  • Outlook: review source messages, recipients, quoted text, and attachments before sending AI-assisted drafts. 
  • Teams: use transcription, meeting capture, and AI notes only where permitted by University procedures and applicable notice or consent requirements. 
  • Search and organizational content: inspect retrieved sources. If unexpected records appear, stop using the content and report the access issue. 
  • Third-party agents, connectors, and automated record changes require separate ITS review. 

5.0 ChatGPT Business 

Approved environment: the University of Findlay’s managed ChatGPT Business workspace only. Verify that the active workspace is the University workspace before using nonpublic information. Personal ChatGPT accounts, personally purchased plans, API services, and other OpenAI environments are outside this approval. 

5.1 Data authorization 

  • Public and internal University information: permitted for authorized University purposes unless otherwise restricted. 
  • FERPA education records: permitted when the user is authorized to access and use the information for the University purpose involved. Use only the information necessary for the task. 
  • HIPAA protected health information: prohibited. 
  • GLBA-regulated information: prohibited. 
  • Passwords, authentication codes, recovery codes, tokens, API secrets, and private keys: prohibited in prompts and files. 
  • Payment card information, Social Security numbers, highly sensitive government identifiers, and information otherwise restricted from third-party processing require explicit ITS approval for the specific workflow and remain subject to all other prohibitions. 

5.2 FERPA and sensitive student records 

Use only the student information necessary for the task. Remove identifiers when identity is unnecessary. Title IX, discipline, accommodation, counseling, immigration, legal, or detailed financial records require authorization from the responsible data owner and confirmation that the information is permitted in the selected product. A record's connection to a student does not override HIPAA, GLBA, or other restrictions. 

5.3 Projects, GPTs, and connected tools 

Keep protected records out of broadly shared Projects, GPTs, instructions, and knowledge sources. Verify that every participant is authorized for the underlying information and do not create public links containing nonpublic information. Apps, connectors, GPT actions, MCP servers, APIs, agents, web browsing, and other external processing require separate ITS approval for the information and actions involved. Availability in the workspace is not approval. No approval under this guide authorizes HIPAA or GLBA processing in ChatGPT Business. 

6.0 Gemini for Education 

Approved environment: Gemini in the University-managed Google Workspace for Education domain as a core service and through ITS-approved features. Personal Gemini accounts, consumer subscriptions, Google AI Studio, developer APIs, Additional Google Services, and unapproved connected applications are outside this approval. 

  • Public and internal University information: permitted in the approved managed core service. 
  • FERPA education records: conditional. The user must be authorized to access and use the information for the University purpose involved, and ITS must have approved the relevant Gemini core service and workflow for FERPA. 
  • HIPAA protected health information: conditional. PHI may be processed only through BAA-covered Gemini features in an ITS-approved configuration and for an authorized purpose. The responsible data owner must authorize the workflow. 
  • GLBA-regulated information: not approved under these guidelines. 
  • Gemini in Chrome, Additional Google Services, third-party applications, and other features outside the approved BAA-covered scope must not receive PHI. 
  • Gems, saved instructions, shared conversations, and knowledge files are persistent resources. Limit access to authorized users and do not use public sharing for nonpublic information. 
  • Use only ITS-approved connected applications and search features. 

7.0 Requesting Approval or Review 

Contact ITS before using AI for an activity requiring prior approval under the Artificial Intelligence Use Policy or these guidelines. Provide sufficient information for ITS to understand the proposed purpose, AI product or workspace, information involved, intended users, integrations or external destinations, and proposed actions. 

ITS will coordinate review with the responsible data owner and other University offices as appropriate. Additional information, testing, or safeguards may be required based on the risk and nature of the proposed use. Development and testing should use synthetic or appropriately de-identified information when practical until required approval is documented. 

Approval applies only to the reviewed use. Material changes to the purpose, data, product, integration, users, or automated actions may require additional review.