AI Hub
Artificial Intelligence

Policies & Guidelines

Governance

Policies & Guidelines

UMS applies a layered compliance framework where existing system-wide policies are supplemented by AI-specific guidance. Every section is labeled to distinguish System Policy from System Guidance.

Before Entering University Data into AI:

  • The UMS-managed ChatGPT Edu workspace has contractual data protections that permit use of FERPA-protected Student Records, except Social Security numbers and driver’s license/state identification numbers.
  • This authorization applies only to the UMS-managed ChatGPT Edu workspace. It does not apply to the separate business-user workspace, personal ChatGPT accounts, or other ChatGPT environments.
  • Other Restricted data remains prohibited unless expressly approved by UMS.
System Policy — Acceptable Use

Acceptable Use

AI tool usage on UMS networks is governed by the system-wide Acceptable Use policy (APL VI-H), which applies to all students, employees, contractors, vendors, and guests using university IT resources.

Policy

Reference

AI Relevance

Acceptable Use of Information Systems

APL VI-H

Governs all AI tool usage on UMS networks; prohibits harassment, malware creation, unauthorized access via AI

Data Classification

APL VI-I

Defines Restricted, Confidential, and Internal tiers that determine what data can enter AI tools

Employee Protection of Data

APL VI-C

Appendix C maintains the Permitted and Restricted Systems list governing which platforms can process which data tiers

Information Security

Board §901

Mandatory compliance; annual review; CISO-led governance council

ICT Accessibility

Board §902

All AI interfaces and outputs must provide equal access for persons with disabilities

Academic Integrity

Board §314

System-wide policy governing cheating and plagiarism; AI violations processed under this framework

FERPA Compliance

APL X-F

Cloud-based AI resources in courses must protect student information; opt-out alternatives required

Incident Response

APL VI-B

Security incident reporting for AI-related breaches

Key AI Guidance Provisions

  • Faculty, staff, and students must NOT enter Protected or Personal Information into a generative AI tool unless that specific tool, workspace, and data classification have been approved by UMS
  • Participant awareness and consent required before AI add-ins are used in video meetings
  • Copyright and intellectual property protections apply to all AI inputs and outputs
  • Bias review and disclosure are required for AI-generated content
  • Accessibility rules apply to all AI output used in official contexts
  • Required classroom AI use must follow local university requirements
System Policy — Academic Integrity

Academic Integrity

The UMS Academic Integrity Policy (Board Section 314) applies to all courses on all campuses. The UMaine Generative AI Teaching and Learning Guidelines define six levels of AI use that instructors can adopt for their courses.

The Six Levels of AI Use in Courses

1

Forbidden

2

Restricted

3

With Disclosure

4

Encouraged

5

Integrated

6

Required

Campus-Specific Implementations

Campus Practice

UMaine

Campus Practice

USM

Campus Practice

UMA

Campus Practice

UMFK

Citation Requirements

System Guidance — Research & Compliance

Research & Compliance

AI use in research contexts requires careful attention to data sovereignty, human subjects protections, grant compliance, and export controls.

IRB & Human Subjects

Grant Compliance

Data Sovereignty & Export Controls

Course Environments

System Policy — Data Security & Privacy

Data Security & Privacy

UMS’s Data Classification Policy (APL VI-I) determines what University information may be processed using artificial intelligence tools. Permitted data depends on both the data classification and the specific AI environment being used. A product’s approval for one data type or workspace does not constitute approval for other data types, accounts, or workspaces.

Data Classifications at a Glance

Restricted

Confidential

Internal

Public

What Data Is Permitted Where

Because different enterprise environments carry different contractual protections, authorization depends on the combination of data classification and workspace — not on the classification alone.

Public

Supported
Supported
Supported
Supported

Internal

Supported

Per existing approval

No / avoid

Supported

Confidential

Supported

Subject to applicable requirements

Per existing approval

Not supported
Supported

Subject to applicable requirements

FERPA Student Records

Supported
Not supported
Not supported
Supported

SSN / Driver’s License #

Not supported
Not supported
Not supported
Not supported

Other Restricted data

Not supported

Unless specifically approved

Not supported
Not supported
Not supported

Unless specifically approved

* Gemini chats on UMS Google Workspace accounts are retained for 18 months and cannot be individually deleted — see the retention notice below. FERPA use in Gemini is subject to the same conditions as ChatGPT Edu: the user must be authorized to access the records for a legitimate University purpose, and data minimization applies.

UMS ChatGPT Edu Workspace

The UMS-managed ChatGPT Edu workspace is covered by the University’s contractual data protection requirements, including the Safeguarding Data Protection Agreement incorporated into the University’s agreement with OpenAI.

Within the UMS-managed ChatGPT Edu workspace, users may process:

  • Public information
  • Internal information, when otherwise appropriate for the intended use
  • Confidential information, when otherwise appropriate for the intended use
  • FERPA-protected Student Records, subject to the limitations below

FERPA / Student Records

FERPA-protected Student Records may be processed only within the UMS-managed ChatGPT Edu workspace and only when the user is authorized to access and use those records for a legitimate University purpose.

Never enter these — even within a Student Record

Authorization for Student Records does not constitute authorization for other categories of Restricted information. Unless separately reviewed and expressly approved by UMS Information Security and applicable data owners, other Restricted data remains prohibited, including HIPAA/ePHI, payment card information, financial account credentials, GLBA-regulated information, ITAR/EAR/CUI, and other specially regulated or high-risk data.

Users should apply data minimization principles and provide only the Student Record information reasonably necessary to accomplish the intended University purpose.

Other ChatGPT Workspaces and Accounts

The authorization above applies only to the UMS-managed ChatGPT Edu workspace covered by the University’s contractual data protections.

  • The separate business-user ChatGPT workspace is not covered by the same UMS ChatGPT Edu data protection agreement and is not approved for FERPA-protected Student Records.
  • Personal ChatGPT accounts, individually purchased accounts, business workspaces, or other ChatGPT environments must not be assumed to have the same authorization as the UMS-managed ChatGPT Edu workspace.
  • Users are responsible for verifying that they are working within the UMS-managed ChatGPT Edu workspace before entering any FERPA-protected Student Record information.

Other AI Tools

Authorization is specific to each AI service and its applicable University agreement. Users must consult the UMS Approved AI Tools guidance before entering Protected Information into any AI system.

Approval of one AI service or workspace for a particular data classification does not imply approval of another service or workspace for that classification.

Gemini Data Retention Notice

System Policy — Accessibility & Equity

Accessibility & Equity

Board of Trustees policy (Section 902) and the OCR Resolution require WCAG 2.1 AA compliance for all digital content, including AI systems.

WCAG 2.1 AA Compliance

All AI interfaces and outputs must meet Web Content Accessibility Guidelines 2.1 AA standards, as required by the OCR Resolution.

Bias Mitigation

AI outputs must be reviewed for disparate impact on protected classifications. Bias review is a mandatory step before relying on AI-generated content for decisions.

Equitable Access

The September 2025 Board minutes show the AI Task Force recommending system-wide Gemini deployment centered on equitable access, privacy, training, and governance.

System Guidance — Meetings & Note-Taking

Guidelines for Using AI in Zoom Meetings

As Artificial Intelligence tools become more integrated into our daily workflows, it is important to use them responsibly, securely, and respectfully during virtual meetings. Below is the official etiquette and policy guidance for utilizing AI note-takers within the University of Maine System (UMS).

1

Use the Approved Tool: Zoom AI Companion

2

The Host Makes the Decision

3

Guest Etiquette: Rely on the Host

4

Protect Sensitive Information

5

Additional Best Practices for AI Note-Taking

Maintain Transparency

Even though Zoom displays a notification when the AI Companion is active, it is a professional courtesy to verbally announce at the start of the meeting that AI will be summarizing the conversation.

Review for Accuracy

AI tools are helpful but not perfect. They can occasionally misattribute quotes, miss subtle nuances, or hallucinate information. The host should always review and edit the AI-generated summary for accuracy before taking action on the notes or publishing them.

Be Mindful of Inclusivity

Ensure all participants feel comfortable with the AI recording their input. If a participant expresses hesitation or needs to share something off-the-record, be prepared to pause or turn off the AI tool.

6

Configuring Zoom AI Settings (Instructions for Hosts)

Using Plaud Responsibly

1

Disclose before you record

2

In a meeting, defer to the host

3

Protect sensitive information — turn it off

4

Review AI summaries for accuracy

5

Be mindful of inclusivity

6

Keep notes in their place