Body
Policy Version
Version Number: 2.0
Date of Change: 5/29/2026
Summary of Changes: Updated policy language in response to University System of Georgia (USG) policy review
Author/Editor Name: Brad Fowler<
Approval Status/Date: Draft/NA
1. Purpose and Scope
Artificial Intelligence (AI) technologies offer a host of opportunities for furthering intellectual endeavors and human understanding. However, as an emerging field, AI also offers potential ethical and practical pitfalls. Therefore, this policy establishes core requirements for the appropriate use of such technologies at Georgia College & State University (GCSU).
1.1 Definitions and scope of AI within the institution’s context
For the purpose of this policy, Artificial Intelligence (AI) refers to a broad range of technologies that enable computer systems to perform tasks that typically require human intelligence. As defined by the University System of Georgia (USG), these tasks include, but are not limited to:
- Learning: Acquiring and retaining knowledge or skills through experience, data, or instruction.
- Reasoning: Using logic and inference to draw conclusions, solve problems, and make predictions.
- Problem-solving: Identifying and implementing solutions to defined challenges.
- Perception: Processing and interpreting sensory input such as images, audio, and text to understand the surrounding environment.
- Natural Language Processing: Understanding, interpreting, and generating human language.
- Decision-making: Selecting a course of action based on available information and predefined goals.
This definition encompasses various AI approaches, including machine learning (encompassing deep learning), natural language processing, computer vision, and rule-based systems. AI systems can operate with varying degrees of autonomy and complexity, ranging from narrowly focused applications to more general-purpose capabilities.
This policy applies to the development, deployment, and use of all AI systems within Georgia College & State University, regardless of their specific architecture or application. The overarching principle is to ensure that the use of these technologies is conducted in an ethical manner.
2. AI Systems Inventory
AI systems and tools will be inventoried each semester by the GCSU IT department and reported to University Senate through the annual inventory review outlined in section 2.4. The AI Systems Inventory is maintained at: https://ai.gcsu.edu.
2.1 Scope of the AI Systems Inventory
This policy and its inventory requirements apply to all AI systems and AI-enabled tools used for any purpose related to university operations, including but not limited to academic instruction, research, administrative functions, student services, and institutional communications. The inventory encompasses:
- All AI systems regardless of whether they are commercially purchased, freely available, open-source, or developed in-house;
- All AI systems regardless of whether they are used on or off the university's network or technology infrastructure;
- All AI systems used in both academic and non-academic contexts.
For purposes of this policy, the inventory shall distinguish between:
- Purpose-built AI systems: Software or platforms designed primarily to deliver AI functionality (e.g., generative AI tools, AI tutoring platforms, AI-assisted grading systems); and
- AI-embedded software: Mainstream software applications that incorporate AI features as a component of broader functionality (e.g., word processors with AI writing assistants, learning management systems with AI-powered analytics). AI-embedded software shall be inventoried separately and subject to a streamlined review process as defined by the Department of Information Technology.
2.2 AI Tool Inventory Requirements
The Department of Information Technology will maintain a comprehensive inventory of all AI systems and AI-enabled tools as defined in Section 2.1. The inventory shall include, at minimum, the following elements for each tool:
- Tool name and vendor or developer
- Tool type and primary AI model type or architecture
- Description of data interactions, including types of data processed, stored, or transmitted
- Intended purpose and applicable university context (academic, administrative, research, etc.)
- Classification of the tool as purpose-built AI or AI-embedded software
- Procurement status (purchased, free, open-source, or in-house developed)
- Network access requirements (on-campus network, off-campus, or cloud-based)
- Date of most recent cybersecurity review
- Approval status and any conditions of use
2.3 AI Usage Reporting
The Department of Information Technology shall develop and maintain a digital AI software usage reporting form. Completion of the form is required for all faculty and administrative staff and is not optional.
- Faculty and administrative staff are required to submit an AI usage form each semester, identifying all AI-based software used by them or their students within each course. College deans and Department Chairs will receive a completion update.
- The Department of Information Technology shall distribute the form no later than the second week of each semester and establish a submission deadline no later than the fourth week of each semester.
- Compliance of AI software reporting will follow established standards for annual IT reporting and training.
2.4 Annual Inventory Review — Scope, Outcomes, and Documentation
The Resources, Planning and Institutional Policy Committee, in collaboration with the Institutional AI Policy Lead, shall conduct an annual review of the AI Systems Inventory. The review shall encompass the following:
- Assessment of all tools added, modified, or removed from the inventory during the prior year;
- Evaluation of whether inventoried tools continue to align with the ethical principles established in Section 3 of this policy;
- Review of any reported AI-related incidents, breaches, or compliance issues and their resolution for annual reporting;
- Consideration of emerging AI technologies, risks, and regulatory developments that may require policy updates.
The annual review shall produce the following documentation:
- A written Annual AI Inventory Report summarizing findings, flagged tools, and recommended actions;
- A prioritized list of recommended policy or procedural updates, if any, submitted to the University Senate through the Resources, Planning and Institutional Policy standing committee;
- A record of any tools approved, conditionally approved, or prohibited.
The Annual AI Inventory Report shall be published to the campus community in a manner consistent with university transparency practices.
3. Ethical principles and guidelines concerning the use of AI
3.1 Accountability and responsible use of AI-generated content
Any faculty or staff member seeking to incorporate the use of AI technologies in official university activities must:
- Abide by established institutional policy and standard operating procedures
- Follow established standards and practices for attribution based on discipline
- Ensure that any information or data generated is accurate and appropriate
- Ensure that all confidential and personal information or data is used in accordance with Section 3.3 below
- Ensure that any use of AI technologies in the classroom promotes student learning, facilitates a more personalized learning environment, and/or increases human and intellectual connection.
All students must abide by the guidelines for AI usage found in the Bobcat Code and in the Student Academic Dishonesty Policy.
3.1a Ethical Standards for AI Tools Used in Institutional Contexts
All AI tools used in institutional contexts at GCSU must be in compliance with the following ethical principles. AI tools shall be evaluated against these criteria:
- The tool must incorporate mechanisms to identify, reduce, and monitor algorithmic bias. Vendors must provide documentation of bias testing and mitigation practices.
- The tool must provide clear attribution for AI-generated outputs and support institutional oversight of how the tool is used.
- The tool must incorporate safeguards to minimize the generation of false, fabricated, or misleading content. Vendor documentation of accuracy benchmarks and hallucination mitigation strategies is required.
- The tool's capabilities, limitations, and data practices must be clearly disclosed by the vendor and communicated to end users.
- The tool must support, rather than replace, human judgment and decision-making, particularly in high-stakes academic or administrative contexts.
- The tool must comply with applicable accessibility standards (e.g., WCAG 2.1 AA) to ensure equitable access for all students and staff, including those with disabilities.
- The tool must incorporate defenses against prompt injection attacks and other adversarial inputs that could compromise data integrity, system security, or user privacy.
3.1b AI Tool Procurement and Legal Review Requirements
The procurement of any AI tool or AI-enabled software by the university, regardless of cost, must follow the process below before the tool is authorized for use at GCSU:
- All AI tool acquisitions purchased by the university must be reviewed and approved by the Department of Information Technology with guidance from the Office of Legal Affairs when needed, and any relevant procurement authority as specified in USG Business Procedures Manual (BPM) Section 3.4.4 'Supplier Contracts.'
- Any AI tool that processes, stores, or transmits sensitive, confidential, or protected data — including but not limited to student records, research data, personnel data, or personally identifiable information — requires formal approval from IT, Legal Affairs, and procurement prior to use, regardless of cost or whether the tool is free.
- Vendor and third-party contracts for AI tools must contain explicit provisions addressing: ethical use commitments; bias and hallucination mitigation; prompt injection safeguards; data privacy protections consistent with BPM Section 12.6; breach notification requirements; and data retention and deletion obligations.
- All approved AI tools are subject to an annual cybersecurity review conducted by the Department of Information Technology. Results of the review shall be incorporated into the Annual AI Inventory Report.
- All AI tools procured by faculty using their personal funds must follow the requirements laid out in Section 3 of this policy. The Department of Information Technology will provide a service to verify the compliance of third-party AI tools through their standard IT Service Desk.
- The use of AI systems that handle institutional data must go through standard university procurement procedures
3.2 Professional Development, Training, and Awareness
3.2a Training Requirements for Faculty, Staff, and Students
All members of the GCSU community who use AI tools in the course of their academic or professional activities are required to complete AI ethics and responsible use training as described below.
- All faculty are required to complete AI ethics, responsible use, and compliance training upon initial hire and annually thereafter. Training must be completed prior to the use of AI tools in any instructional or research context. The Division of Academic Affairs, in consultation with the Center for Teaching and Learning, is responsible for developing, delivering, and updating the faculty training program.
- All GCSU employees, affiliates, and vendors/contractors who are granted access to institutional data, resources, and services are required to complete mandatory cybersecurity awareness training, which includes AI awareness, per USG IT Handbook Section 05.09.02 Cybersecurity Awareness and Training Plan Requirements
- The Division of Student Life shall provide training on AI ethics, responsible use, and potential risks as part of new student orientation and through ongoing educational programming.
All training programs must cover, at minimum: an overview of this policy and all related USG policies; ethical principles governing AI use, including bias, transparency, and accountability; responsible use and attribution practices; data privacy and security obligations; and emerging risks including hallucinations, prompt injection attacks, and academic integrity concerns.
3.2b Tracking and Accountability for Training Completion
- The Division of Academic Affairs is responsible for tracking faculty training completion and reporting to department chairs and Deans each semester.
- The Office of Human Resources is responsible for tracking staff training completion and incorporating it into the annual performance review process as applicable.
- The Division of Student Life is responsible for tracking student training completion.
- Training completion records for all groups shall be reported annually to the Institutional AI Policy Lead and included in the Annual AI Inventory Report.
3.2c Policy Awareness
To ensure campus-wide familiarity with this policy, the following awareness measures are required:
- This policy shall be published in the institutional policy library and referenced in the GCSU Faculty Handbook, Employee Handbook, Student Handbook, and Academic Catalog.
- The Center for Teaching and Learning shall publish and maintain accessible guidance materials summarizing this policy and related procedures for faculty and students.
- Deans and department chairs are responsible for ensuring that faculty in their units are aware of this policy and understand their obligations under it.
- The Division of Student Life shall ensure this policy is communicated to students through orientation programs, the student portal, and other appropriate channels each academic year.
- The Office of Human Resources is responsible for ensuring the policy reference is maintained, current, and accessible to all staff and that any updates to this policy are communicated to staff through appropriate HR communication channels.
3.3 Privacy and security of Information
All AI usage must follow established laws, policies, and regulations as it pertains to using and handling confidential data information.
All AI usage must follow privacy guidelines set in Section 12.6 of the USG BPM, the USG Handbook, and all established USG data privacy policies.
All divisions of the university must use University-licensed AI systems only as intended and ensure all confidential information is properly protected. Personally identifiable information must be encrypted and/or anonymized.
Any AI-related breaches must follow the appropriate measures based on the University’s Incident Response Plan.
4. Governance and Oversight
4.1 Regulatory
All regulatory aspects of AI use in higher education will be monitored through the Office of Legal Affairs.
4.1a Data Protection Impact Assessments
When an AI tool is determined to process or store personally identifiable information (PII), the Department of Information Technology, in coordination with the Office of Legal Affairs, shall require the completion of a Data Protection Impact Assessment (DPIA) prior to the tool's approval for use.
- A DPIA shall document the nature of the PII being processed, the purpose and legal basis for processing, risks identified, and mitigation measures implemented.
- Vendor compliance documentation, including evidence of data protection practices and any applicable certifications (e.g., SOC 2, ISO 27001), shall be obtained and retained as part of the DPIA process.
- DPIAs and associated vendor compliance documentation shall be retained by the Department of Information Technology and made available for audit purposes upon request.
- The DPIA process shall adhere to the requirements of USG BPM Section 12.6 'Data Privacy.'
4.1b Record Retention for AI-Related Compliance
The Department of Information Technology, in coordination with the Office of Legal Affairs, is responsible for maintaining records necessary to support AI-related compliance audits and investigations. Such records shall include:
- The AI Systems Inventory and all prior versions thereof
- AI tool procurement and legal review documentation
- DPIAs and vendor compliance documentation
- Annual cybersecurity review reports
- AI-related incident and breach reports
- Training completion records
Records shall be retained in accordance with the university's records retention schedule and applicable state and federal law. The Office of Legal Affairs shall determine the applicable retention periods for each record category.
4.2 Compliance
All aspects of compliance as it pertains to the acquisition and use of AI-based systems will be the responsibility of the Department of Information Technology.
4.3 Scholarly Research
Any AI use in human subjects research must be clearly defined and ethical, having all procedures approved by the Institutional Review Board.
Faculty and students using AI technologies in academic research must comply with publication guidelines, professional association standards, USG policy, and all applicable state and federal laws.
4.4 Intellectual Property
AI systems may not be given access to intellectual property without the express consent of the original author/creator, where the intellectual property falls under legal protection.
4.5 Points of Contact
4.5a Institutional AI Policy Lead — Duties and Responsibilities
The President shall create the Institutional AI Policy Lead role and appoint a member of the university faculty or staff to the role for a term of three years. The Institutional AI Policy Lead shall have the following defined responsibilities:
- Serving as the university's primary point of accountability for the development, implementation, and oversight of this AI policy;
- Coordinating the annual policy review process in collaboration with the Resources, Planning and Institutional Policy Committee;
- Overseeing the annual AI training compliance process and reviewing training completion reports from the relevant divisions;
- Maintaining awareness of emerging developments in AI technology, ethics, and regulation and advising the President and relevant governing bodies on required policy updates;
- Receiving, reviewing, and routing formal AI-related complaints and issues in accordance with Section 4.5b below;
- Submitting an annual AI Policy Implementation Report to the President and University Senate summarizing the status of policy compliance, training completion, inventory findings, and any recommended changes.
4.5b AI Questions, Guidance, and Complaints
- All questions or concerns related to this policy should follow the established chains of command.
- Queries on guidance on the use of AI in academic instruction should be forwarded to the Center for Teaching and Learning.
- Queries on guidance on the general use of AI should be forwarded to the Department of Information Technology.
- Complaints related to AI tool usage should be directed to the Institutional AI Policy Lead through the universities’ online AI resource webpage. The Institutional AI Policy Lead will handle complaints in coordination with the President, Division of Academic Affairs, Division of Student Life, Department of Information Technology, and the Office of Legal Affairs.
5. User Guidance and Documentation
5.1 University Guidance on Course AI Expectations
The Center for Teaching and Learning shall develop and publish model AI Use Statement language, along with accompanying best practices guidance, to assist faculty in meeting this requirement. Faculty are encouraged to consult the Center for Teaching and Learning for support in developing course-level AI policies.
University-wide course AI expectations are provided in the university’s required syllabus statements under Student Academic Dishonesty, maintained by the Office of the Registrar at https://www.gcsu.edu/registrar/required-syllabus-statements.
5.2 Administrative Staff Guidance on AI Use
Administrative staff who use AI tools in the course of their university responsibilities are expected to do so in a manner consistent with this policy, applicable USG guidelines, and the data privacy and security requirements established in Section 3.3.
Administrative staff using AI tools in the creation or editing of official university communications, reports, records, or other institutional materials remain personally accountable for the accuracy, appropriateness, and integrity of that content consistent with Section 5.3. AI tools may not be used to process, transmit, or store sensitive institutional data, personally identifiable information, or confidential records unless the tool has been reviewed and approved for that purpose through the processes outlined in Sections 3.1b and 4.1a
The Department of Information Technology serves as the primary resource for administrative staff on matters related to AI tool selection, approval, and appropriate use. Staff should consult the IT Service Desk before adopting any AI tool not already listed in the university's approved AI inventory, consistent with the procurement and review requirements established in Section 3.1b. The Department of Information Technology maintains a list of approved AI tools and provides guidance on their appropriate use through the university's AI resource webpage.
The Department of Information Technology, shall develop and maintain accessible guidance materials for administrative staff on the responsible use of AI tools in administrative functions. This guidance shall be published on the university's AI resource webpage and updated as needed to reflect changes in approved tools, policy requirements, or emerging risks. Administrative staff are encouraged to consult their department head or the Department of Information Technology with questions about whether a specific AI use case is appropriate or requires additional review
5.3 Accountability for AI-Generated Content
All members of the GCSU community who use AI tools in official university activities remain personally accountable for the accuracy, integrity, and appropriateness of any AI-generated content they submit, publish, or use in an official capacity. The use of an AI tool does not transfer or diminish the user's professional, academic, or ethical responsibilities.
The GCSU Library maintains citation guidance and best practices for AI-generated content, including examples across major citation styles. This resource is available at: https://libguides.gcsu.edu/c.php?g=21259&p=10598639.
6. Policy Review and Updates
6.1 Review Schedule
This policy will be reviewed annually by the Resources, Planning and Institutional Policy committee in collaboration with the AI Policy Lead and the Office of Legal Affairs to ensure continued relevance, effectiveness, and compliance with current regulations and best practices.
6.2 Update Process
Policy updates may be initiated by:
- Scheduled annual review
- Changes in applicable laws and regulations
- Significant incidents or compliance issues
- Technical developments affecting policy scope
- Recommendations from the GCSU community
6.3 Version Control
Each policy revision will be documented with:
- Version number
- Date of change
- Summary of changes
- Author/Editor name
- Approval date/Status