Artificial Intelligence (AI) Use Policy
Effective: 8/1/26
Contact: Teaching and Learning Technologies
This policy establishes the requirements for the secure, ethical and responsible use of Artificial Intelligence at William Jewell College. It is a risk management instrument designed to protect institutional data and systems, maintain compliance with legal and regulatory obligations, preserve cyber insurance coverage and financial stability, and enable innovation aligned with the College’s mission.
1. Purpose
William Jewell College (“the College”) recognizes the transformative potential of Artificial Intelligence (AI) in education, research, and operations. This policy establishes requirements for the secure, ethical, and responsible use of AI to protect institutional data and systems, maintain compliance with legal and regulatory obligations, preserve cyber insurance coverage and financial stability, and enable innovation aligned with the College’s mission. This policy is a risk management instrument, not a restriction on innovation.
2. Scope
This policy applies to all faculty, staff, students, contractors, and third parties, and to all College-owned and personally owned devices used for College business. It governs all AI systems, including Generative AI (e.g., large language models and copilots), Embedded and Vendor AI within software platforms, and Autonomous or Agentic Systems. The College explicitly recognizes shadow AI — the unauthorized use of AI tools — as a material institutional risk and governs accordingly.
3. Guiding Principles
All AI use at William Jewell College must adhere to the following principles. Security First: institutional data must be protected above convenience. Human Accountability: AI informs decisions, but humans make them. Transparency: AI use must be identifiable and auditable. Least Privilege: access is limited to what is necessary for the task at hand. Institution First: decisions must prioritize institutional risk over individual gain.
4. Acceptable Use of AI
AI may be used for academic support such as tutoring, drafting, and research assistance; administrative efficiency such as summarization and automation; cybersecurity and IT operations using approved tools only; and curriculum delivery and innovation. All use must comply with the data classification rules in Section 5, the approved tools list described in Section 6, and any course-specific faculty guidance applicable to students.
5. Data Protection and Classification Requirements
The following categories of data must not be entered into any AI system unless explicitly approved and properly secured: FERPA-protected student data, Personally Identifiable Information (PII), Human Resources data, financial data, research-restricted or proprietary data, health-related data (including HSA, wellness, and disability accommodation information), donor and advancement records, attorney-client privileged material and litigation-related records, pre-decisional personnel material (such as search committee notes and in-process performance documents), and confidential strategic documents (such as board materials and confidential memos). Before using AI, data must be anonymized or de-identified, users must verify that prompts do not expose sensitive information, and users are accountable for all data submitted. AI prompt submission is treated as data disclosure under this policy.
6. Approved AI Tools and Vendor Governance
The College will maintain a central registry of approved AI tools. All approved tools must undergo a security review covering data handling, retention, and training usage; a vendor risk assessment; and contractual protections addressing data ownership, breach notification timelines, and the use of institutional data for model training. The use of unapproved AI tools is prohibited unless explicitly authorized by the appropriate institutional authority.
When an existing vendor adds AI features to a platform already in use by the College (e.g., Microsoft Copilot, Google Workspace AI features, Zoom AI Companion, Canvas AI, or Element 451 Bolt Agents), those features must be reviewed under the same standards as a new AI tool before being enabled. The AI Governance Committee, in coordination with the Director of IT, is responsible for identifying when existing vendors introduce AI capabilities mid-contract, determining whether those features are enabled by default, or require opt-in, and conducting the appropriate security and data-handling review before institutional use is permitted.
7. Identity and Access Controls
All institutional AI systems must require Single Sign-On (SSO) and Multi-Factor Authentication (MFA), enforce role-based access control (RBAC), and prohibit shared credentials and credential delegation to AI agents. All access and identity events must be logged and monitored. Identity governance for AI platforms must be maintained at the same level of rigor as any other enterprise system.
8. Logging, Monitoring, and Audit
The College will maintain full auditability of AI use, including user interactions with AI systems, administrative actions and configuration changes, AI outputs used in institutional processes, and integrations with enterprise systems. Logs must be retained in accordance with legal and incident response requirements and must be integrated into existing SOC and SIEM capabilities. If it is not logged, it is not defensible.
9. Shadow AI Detection and Enforcement
The College reserves the right to detect unauthorized AI usage, block or restrict access to unapproved tools, and monitor network and endpoint activity. Technical enforcement measures may include Cloud Access Security Brokers (CASB), Data Loss Prevention (DLP) tools, and Secure Web Gateways. Violation of this policy may result in disciplinary action as described in Section 13.
10. Human Oversight and Decision-Making
AI must not be used as the sole decision-maker for hiring, firing, or employee discipline; financial approvals; academic evaluation without faculty oversight; or security response actions. Human review is required at each of these decision points and must be documented where applicable. This requirement reflects both a legal risk management imperative and a direct signal of institutional maturity.
11. AI Incident Response
AI-related incidents are incorporated into the College’s incident response program. Examples of AI-specific incidents include prompt data leakage, model manipulation or poisoning, and unauthorized data use or exposure. Response requirements include immediate reporting to IT and Security, activation of AI-specific response procedures, and timely notification aligned with legal and insurance obligations. Late or incomplete notification is one of the most common reasons cyber insurance claims are denied, and AI incidents require the same urgency as traditional cyber events.
12. Governance and Oversight
AI governance at William Jewell College is led by the Director of IT (IT) with guidance from the virtual Chief Information Security Officer (vCISO) as Executive Owner. An AI Governance Committee comprised of representatives from IT, Legal, Academic Affairs, and Finance is responsible for maintaining AI policy and standards, reviewing new AI tools and use cases, and tracking AI risk in the enterprise risk register. Policy review occurs at least annually or as required by emerging risk, ensuring that AI governance at William Jewell College remains intentional and current.
13. Compliance and Enforcement
Failure to comply with this policy may result in loss of system access, academic or disciplinary action, or contract termination for third parties. Violations that expose institutional risk may be escalated to executive leadership. The College takes compliance with this policy seriously as a matter of financial, legal, and reputational protection.
14. Alignment to Standards
This policy aligns with the NIST Cybersecurity Framework (CSF 2.0), the NIST AI Risk Management Framework (AI RMF), and applicable regulatory requirements including FERPA and GLBA. Alignment to these nationally recognized standards provides a defensible standard of care for regulators, insurers, and the courts and demonstrates that William Jewell College manages AI risk with rigor and intentionality.


