Policies & Guidelines
UMS applies a layered compliance framework where existing system-wide policies are supplemented by AI-specific guidance. Every section is labeled to distinguish System Policy from System Guidance.
Before Entering University Data into AI:
Do not enter Protected or Personal Information into an AI tool unless that specific tool, workspace, and data classification have been approved by UMS.
- The UMS-managed ChatGPT Edu workspace has contractual data protections that permit use of FERPA-protected Student Records, except Social Security numbers and driver’s license/state identification numbers.
- This authorization applies only to the UMS-managed ChatGPT Edu workspace. It does not apply to the separate business-user workspace, personal ChatGPT accounts, or other ChatGPT environments.
- Other Restricted data remains prohibited unless expressly approved by UMS.
Acceptable Use
AI tool usage on UMS networks is governed by the system-wide Acceptable Use policy (APL VI-H), which applies to all students, employees, contractors, vendors, and guests using university IT resources.
|
Policy |
Reference |
AI Relevance |
|---|---|---|
|
Acceptable Use of Information Systems |
APL VI-H |
Governs all AI tool usage on UMS networks; prohibits harassment, malware creation, unauthorized access via AI |
|
Data Classification |
APL VI-I |
Defines Restricted, Confidential, and Internal tiers that determine what data can enter AI tools |
|
Employee Protection of Data |
APL VI-C |
Appendix C maintains the Permitted and Restricted Systems list governing which platforms can process which data tiers |
|
Information Security |
Board §901 |
Mandatory compliance; annual review; CISO-led governance council |
|
ICT Accessibility |
Board §902 |
All AI interfaces and outputs must provide equal access for persons with disabilities |
|
Academic Integrity |
Board §314 |
System-wide policy governing cheating and plagiarism; AI violations processed under this framework |
|
FERPA Compliance |
APL X-F |
Cloud-based AI resources in courses must protect student information; opt-out alternatives required |
|
Incident Response |
APL VI-B |
Security incident reporting for AI-related breaches |
Key AI Guidance Provisions
Academic Integrity
The UMS Academic Integrity Policy (Board Section 314) applies to all courses on all campuses. The UMaine Generative AI Teaching and Learning Guidelines define six levels of AI use that instructors can adopt for their courses.
The Six Levels of AI Use in Courses
Forbidden
No AI tools may be used for any aspect of the course.
Restricted
AI may only be used for specific, instructor-defined tasks.
With Disclosure
AI may be used but all use must be disclosed and cited.
Encouraged
AI use is encouraged as a learning tool with proper attribution.
Integrated
AI is embedded into course design and assignments.
Required
Students are required to use AI tools as part of coursework.
Campus-Specific Implementations
UMaine
CITL provides syllabus statements for each of the six AI-use levels. Faculty can request one-on-one instructional design consultations.
USM
Three-tier syllabus templates (Permitted, Restricted Unless Permitted, Fully Restricted). Student AI Guide advises: “if you wouldn’t post it on Reddit anonymously, don’t put it in an AI tool.”
UMA
Faculty and student ethical AI use checklists available through library guides.
UMFK
Requires transparency about how, why, and when AI technologies are used in coursework.
Citation Requirements
Students must acknowledge AI use in all assignments. Two citation approaches are accepted: footnote citation (“Service used, version, date. Text of prompt. Link to service”) or blanket acknowledgment (“Portions of the text and ideas in this document were created or edited using [Service]”). Failure to properly cite AI-generated material constitutes plagiarism under Board Section 314.
Research & Compliance
AI use in research contexts requires careful attention to data sovereignty, human subjects protections, grant compliance, and export controls.
IRB & Human Subjects
Standard IRB review processes apply to AI-related research involving human subjects. The UMaine AI Steering Committee published “Research with AI Guidelines” (May 2024) covering benefits, challenges, and responsible practices.
Grant Compliance
Researchers should review NIH Notice NOT-OD-25-132 (July 2025) on fairness in research applications and NSF guidance on generative AI use. Funding agency requirements may impose additional restrictions.
Data Sovereignty & Export Controls
UMS data classification policy covers regulatory research information, ITAR/EAR/CUI, and export-control data as Restricted. These data types must never be entered into AI tools.
Course Environments
Fee-based AI solutions require Information Security Office review. Students must be informed at course start that AI will be used or that AI is prohibited.
Data Security & Privacy
UMS’s Data Classification Policy (APL VI-I) determines what University information may be processed using artificial intelligence tools. Permitted data depends on both the data classification and the specific AI environment being used. A product’s approval for one data type or workspace does not constitute approval for other data types, accounts, or workspaces.
Data Classifications at a Glance
Restricted
FERPA student records, HIPAA/ePHI, SSNs, financial account numbers, GLBA, PCI, ITAR/EAR/CUI, human subject data
Prohibited except where a specific environment is expressly approved for a specific Restricted category (see below).
Confidential
Internal budgets, personnel records, draft policies, non-public research data, vendor contracts
Approved, licensed AI tools only
Internal
Internal communications, meeting notes, operational procedures, non-sensitive institutional data
Approved, licensed AI tools only
Public
Published research, public web content, press releases, course catalogs
May be used with any AI tool
What Data Is Permitted Where
Because different enterprise environments carry different contractual protections, authorization depends on the combination of data classification and workspace — not on the classification alone.
|
Data |
UMS ChatGPT Edu |
ChatGPT Business-user workspace |
Personal / free AI (any vendor) |
UMS Gemini Chats* |
|---|---|---|---|---|
|
Public |
||||
|
Internal |
Per existing approval |
No / avoid |
||
|
Confidential |
Subject to applicable requirements |
Per existing approval |
Subject to applicable requirements |
|
|
FERPA Student Records |
||||
|
SSN / Driver’s License # |
||||
|
Other Restricted data |
Unless specifically approved |
Unless specifically approved |
* Gemini chats on UMS Google Workspace accounts are retained for 18 months and cannot be individually deleted — see the retention notice below. FERPA use in Gemini is subject to the same conditions as ChatGPT Edu: the user must be authorized to access the records for a legitimate University purpose, and data minimization applies.
UMS ChatGPT Edu Workspace
The UMS-managed ChatGPT Edu workspace is covered by the University’s contractual data protection requirements, including the Safeguarding Data Protection Agreement incorporated into the University’s agreement with OpenAI.
Within the UMS-managed ChatGPT Edu workspace, users may process:
- Public information
- Internal information, when otherwise appropriate for the intended use
- Confidential information, when otherwise appropriate for the intended use
- FERPA-protected Student Records, subject to the limitations below
FERPA / Student Records
FERPA-protected Student Records may be processed only within the UMS-managed ChatGPT Edu workspace and only when the user is authorized to access and use those records for a legitimate University purpose.
Never enter these — even within a Student Record
- Social Security numbers (SSNs)
- Driver’s license or state identification numbers
Authorization for Student Records does not constitute authorization for other categories of Restricted information. Unless separately reviewed and expressly approved by UMS Information Security and applicable data owners, other Restricted data remains prohibited, including HIPAA/ePHI, payment card information, financial account credentials, GLBA-regulated information, ITAR/EAR/CUI, and other specially regulated or high-risk data.
Users should apply data minimization principles and provide only the Student Record information reasonably necessary to accomplish the intended University purpose.
Other ChatGPT Workspaces and Accounts
The authorization above applies only to the UMS-managed ChatGPT Edu workspace covered by the University’s contractual data protections.
- The separate business-user ChatGPT workspace is not covered by the same UMS ChatGPT Edu data protection agreement and is not approved for FERPA-protected Student Records.
- Personal ChatGPT accounts, individually purchased accounts, business workspaces, or other ChatGPT environments must not be assumed to have the same authorization as the UMS-managed ChatGPT Edu workspace.
- Users are responsible for verifying that they are working within the UMS-managed ChatGPT Edu workspace before entering any FERPA-protected Student Record information.
Other AI Tools
Authorization is specific to each AI service and its applicable University agreement. Users must consult the UMS Approved AI Tools guidance before entering Protected Information into any AI system.
Approval of one AI service or workspace for a particular data classification does not imply approval of another service or workspace for that classification.
Gemini Data Retention Notice
Gemini chats on UMS Google Workspace accounts are retained for 18 months and cannot be deleted individually. Users should be aware of this when using Gemini for any work-related conversations. Gemini’s approval for FERPA data is separate from the ChatGPT Edu authorization above and is governed by its own University agreement.
Accessibility & Equity
Board of Trustees policy (Section 902) and the OCR Resolution require WCAG 2.1 AA compliance for all digital content, including AI systems.
WCAG 2.1 AA Compliance
All AI interfaces and outputs must meet Web Content Accessibility Guidelines 2.1 AA standards, as required by the OCR Resolution.
Bias Mitigation
AI outputs must be reviewed for disparate impact on protected classifications. Bias review is a mandatory step before relying on AI-generated content for decisions.
Equitable Access
The September 2025 Board minutes show the AI Task Force recommending system-wide Gemini deployment centered on equitable access, privacy, training, and governance.
Guidelines for Using AI in Zoom Meetings
As Artificial Intelligence tools become more integrated into our daily workflows, it is important to use them responsibly, securely, and respectfully during virtual meetings. Below is the official etiquette and policy guidance for utilizing AI note-takers within the University of Maine System (UMS).
Use the Approved Tool: Zoom AI Companion
Please use the built-in Zoom AI Assistant (Zoom AI Companion) for meeting summaries and notes. Other third-party AI note-takers and transcription bots (such as Otter.ai, Fireflies.ai, etc.) have not been vetted by UMS for privacy, security, and data compliance, and therefore should not be used.
The Host Makes the Decision
The meeting host has the sole authority to decide whether AI note-taking will be enabled for a specific meeting.
Guest Etiquette: Rely on the Host
If you are attending a meeting as a guest, do not activate or invite your own AI note-taker into the meeting. Instead, ask the host prior to or at the start of the meeting if they are using the Zoom AI Assistant, and request that they share the official summary with attendees afterward.
Protect Sensitive Information
Hosts must exercise extreme caution and turn off AI note-takers when discussing protected or sensitive data. This includes, but is not limited to:
- Student educational records protected by FERPA.
- Protected health information covered by HIPAA.
- Confidential or sensitive matters discussed in Executive Sessions (not meant for public record).
Additional Best Practices for AI Note-Taking
Maintain Transparency
Even though Zoom displays a notification when the AI Companion is active, it is a professional courtesy to verbally announce at the start of the meeting that AI will be summarizing the conversation.
Review for Accuracy
AI tools are helpful but not perfect. They can occasionally misattribute quotes, miss subtle nuances, or hallucinate information. The host should always review and edit the AI-generated summary for accuracy before taking action on the notes or publishing them.
Be Mindful of Inclusivity
Ensure all participants feel comfortable with the AI recording their input. If a participant expresses hesitation or needs to share something off-the-record, be prepared to pause or turn off the AI tool.
Configuring Zoom AI Settings (Instructions for Hosts)
Hosts should familiarize themselves with the options available in their UMS Zoom profile to manage the type of note summary they receive and how those notes are distributed.
How to adjust your AI Companion settings:
- Log in to the Zoom Web Portal using your UMS credentials.
- In the left-hand navigation menu, click on Settings.
- Click the AI Companion tab at the top of the page.
- Scroll to Meeting Summary with AI Companion to adjust your preferences:
- Share options: Look for the setting to “Automatically share summary with meeting invitees.” Enabling this will automatically distribute the final notes to your guests so you don’t have to forward them manually.
- Summary formats: Depending on the current Zoom version, you can configure how summaries are formatted (e.g., Next Steps, Quick Recap) and whether the summary automatically starts when the meeting begins.
- (Optional) If you are also recording the meeting, review the Smart Recording section to enable AI features like chapter generation and key takeaway highlights.
Using Plaud Responsibly
These practices mirror the etiquette UMS already expects for AI note-taking in meetings. They keep your use of Plaud secure, respectful, and aligned with policy.
Disclose before you record
Tell everyone present that you’re using an AI note-taker before you start, even in a one-party-consent state. A spoken heads-up is a professional courtesy and gives anyone uncomfortable the chance to speak up. (See the suggested wording above.)
In a meeting, defer to the host
If you’re a guest in someone else’s meeting, don’t record on your own initiative. Ask the host whether note-taking is okay and whether they’ll share an official summary afterward. The person running the meeting decides what gets recorded.
Protect sensitive information — turn it off
Stop recording the moment a conversation turns to protected or sensitive matters. That includes:
- Student education records (FERPA)
- Protected health information (HIPAA)
- HR and personnel matters
- Confidential financial or research data
- Anything that belongs in a closed or executive session
When in doubt, don’t record.
Review AI summaries for accuracy
AI note-takers are helpful but imperfect — they can misattribute quotes, miss nuance, or invent details. Read and correct any Plaud summary before you act on it or pass it along. The accuracy of the notes is your responsibility, not Plaud’s.
Be mindful of inclusivity
Make sure everyone is comfortable being recorded. If someone hesitates or needs to say something off the record, be ready to pause or shut off the device. Comfort in the room comes before a tidy transcript.
Keep notes in their place
Plaud summaries are your personal working notes, not an official record (APL VII-A). Decisions, commitments, and action items still need to land in email, a ticket, or the appropriate UMS system of record.
















