Artificial Intelligence (AI) technologies are rapidly becoming part of the university’s academic, research, and administrative operations. UCF IT supports the use of AI tools and recognizes their potential to enhance productivity and streamline university data management practices.
Equally important, however, is ensuring that information processed by these tools remains secure, compliant with state and federal requirements, and protective of sensitive third-party data such as copyrighted materials, patents, and research data entrusted to the university.
QUICK links
Applicable UCF Policies
While UCF does not currently maintain a standalone “AI Policy,” several existing university policies govern the appropriate and secure use of Artificial Intelligence.
UCF Policy 4.008 outlines minimum protections for information at varying levels of sensitivity. UCF Policy 4.014 requires a vendor risk assessment prior to use or purchase of cloud-based tools involving restricted or highly restricted data.
Accordingly, UCF IT’s official statement on AI is as follows:
Enterprise Agreements
The key component to safeguarding UCF data is the establishment of enterprise agreements with AI vendors. These agreements ensure that university data is protected and not used to train external large language models (LLMs).
With an appropriate contractual framework, AI tools may be approved for use with even highly restricted data.
Where enterprise agreements cannot yet be established, UCF IT is expanding its infrastructure to provide access to AI tools within UCF-sanctioned cloud environments.
These environments help ensure privacy, compliance, and ethical standards while enabling the university community to benefit from AI capabilities. To explore these options, departments and individuals are encouraged to request consultation with UCF IT.
AI Tools
The following table provides guidance on the maximum data classification that may be processed using common AI tools, either directly or integrated into another tool, based on the Information Security Office's review of security, privacy, compliance, and contractual considerations. Inclusion in this table does not, by itself, authorize the use or procurement of a particular AI service, nor does it supersede university procurement, contractual, regulatory, or departmental requirements. Users are responsible for ensuring that any use of AI tools aligns with applicable university policies, standards, contractual agreements, and approved business purposes. Before processing university data with an AI tool, users should verify that the proposed use is permitted under the applicable agreement and that the data classification does not exceed the level identified in this guidance.
| Product Name | Vendor Name | UNRESTRICTED | RESTRICTED* | HIGHLY RESTRICTED * | Status | |||
|---|---|---|---|---|---|---|---|---|
|
Protected University Data |
CUI / Export Controlled |
HIPAA | PCI | |||||
| ChatGPT | OpenAI | Pending Review | ||||||
| Claude | Anthropic | Under Review - 2/1/2026 | ||||||
| Claude Code | Anthropic | Conditional - 3/1/2026 | ||||||
| Copilot 365 | Microsoft | Reviewed - 1/1/2024 | ||||||
| Copilot Chat | Microsoft | Reviewed - 1/1/2024 | ||||||
| Gemini | Under Review - 3/1/2026 | |||||||
| GitHub Copilot | Microsoft | Reviewed - 1/1/2026 | ||||||
| DeepSeek | DeepSeek | Denied - 1/29/2026 | ||||||
| Meeting Insights | AudioCodes | Reviewed - 2/1/2026 | ||||||
| NotebookLM | Under Review - 3/1/2026 | |||||||
| OpenClaw | Open Source | Pending Review | ||||||
Restricted and Highly Restricted data must only be processed by UCF-managed or governed tools and technologies where there is a formal contract or agreement with appropriate data-protection terms and a completed UCF Risk Assessment.
An assessment for one Highly Restricted data type does not satisfy review requirements for all Highly Restricted data types. Refer to the applicable columns in the table for specific regulated data types such as CUI/Export Controlled Data, HIPAA, and PCI.
See KB article: Use of Claude AI at UCF for current availability, limitations, security requirements, and approved alternatives.
Copilot 365 can only be used with CUI / Export controlled data in Knight Shield.