Data Use and Protection
The following guidance outlines how to use data safely with AI tools at KU. It covers appropriate data use with public (consumer) AI tools and the role of Microsoft Copilot as the University’s primary AI assistant and productivity tool.
| Public (Consumer) AI | University-Approved AI |
| Operates outside KU’s enterprise environment and does not include institutional privacy or security protections. Treat any information entered into these tools as public. | Provided or authorized by the University and includes additional contractual, privacy, and security safeguards designed to protect university data. |
⚠️ Do Not Share Sensitive, Confidential, or Restricted Data in Public (Consumer) AI Tools
University data entered into public AI tools (including tools you sign up for on your own) is not protected by the University. Sharing information in these tools should be treated as comparable to sharing it publicly.
Many public generative AI tools store user inputs and may use them to improve their systems. As a result, information you share may be retained, reviewed, or incorporated into future model training, including sensitive, confidential, or restricted data.
For guidance on data types and appropriate use, see the University’s Data Classification Policy.
| Data Type | Public AI | Examples |
| Public / Non-Sensitive | ✅ | Published research findings, public websites |
| Internal / Business Sensitive | ❌ | Student or applicant data, internal operations data |
| Confidential / Highly Sensitive | ❌ | Research data, budgets, business plans |
| Restricted / Regulated | ❌ | Patient data, credit card data, student financial data |
*Public data is generally safe to use with public AI tools. However, using large datasets, combining multiple sources, or adding extra context can introduce new privacy, security, or ethical risks. Before sharing data, review the tool's terms of use and think carefully about how the data might be stored or reused. When in doubt, treat the data cautiously and use approved and trusted tools.
University-Approved AI
Microsoft Copilot is approved for use with university data classified as public, sensitive, and confidential when:
- the user is signed in with a @ku.edu account, and
- Enterprise Data Protection is active (indicated by the shield icon).
Use of Copilot with restricted data requires prior consultation with departmental Technology Support Staff and may be subject to additional review or approval to ensure compliance with university data classification, security, and regulatory requirements.
See the Approved AI tools page for additional options at KU.
Microsoft Copilot is approved for use with university data classified as public, sensitive, and confidential when:
- the user is signed in with a @kumc.edu account, and
- Enterprise Data Protection is active (indicated by the shield icon).
KUMC Copilot operates within a HIPAA-aligned Microsoft 365 environment and benefits from enhanced technical, legal, and security protections provided through shared Microsoft 365 services with The University of Kansas Health System. When Enterprise Data Protection is active, KUMC users may use Copilot with restricted data. Users remain responsible for complying with applicable privacy, security, confidentiality, and data governance requirements.
For research and operational use cases involving regulated data, larger data volumes, or more advanced analytics, automation, and model development needs, KUMC users may have access to HIPAA-compliant AI tools through the KUMC Office of Research Informatics, including approved Databricks and Azure environments.
Microsoft Copilot is approved for use with university data classified as public, sensitive, and confidential when:
- the user is signed in with a @ku.edu account, and
- Enterprise Data Protection is active (indicated by the shield icon).
Use of Copilot with restricted data requires prior consultation with departmental Technology Support Staff and may be subject to additional review or approval to ensure compliance with university data classification, security, and regulatory requirements.
See the Approved AI tools page for additional options at KU.
Microsoft Copilot is approved for use with university data classified as public, sensitive, and confidential when:
- the user is signed in with a @kumc.edu account, and
- Enterprise Data Protection is active (indicated by the shield icon).
KUMC Copilot operates within a HIPAA-aligned Microsoft 365 environment and benefits from enhanced technical, legal, and security protections provided through shared Microsoft 365 services with The University of Kansas Health System. When Enterprise Data Protection is active, KUMC users may use Copilot with restricted data. Users remain responsible for complying with applicable privacy, security, confidentiality, and data governance requirements.
For research and operational use cases involving regulated data, larger data volumes, or more advanced analytics, automation, and model development needs, KUMC users may have access to HIPAA-compliant AI tools through the KUMC Office of Research Informatics, including approved Databricks and Azure environments.
⚠️ Advanced Use and High-Risk Data
Some AI use cases involving regulated data, large-scale data processing, custom model development, or advanced analytics may be better supported through approved research and cloud computing environments. Users should consult the appropriate University information security and research support offices when evaluating these use cases.
Do not enter Controlled Unclassified Information (CUI) into Microsoft Copilot or other AI tools unless an explicitly approved, compliant secure environment has been authorized.
For questions or unclear situations, contact ai_taskforce@ku.edu before proceeding.