Guidelines for Acceptable Use of Artificial Intelligence

Purpose

Our University recognizes the growing use and importance of artificial intelligence (AI) across higher education. Moreover, the University acknowledges its obligation stated in Arkansas legislative Act 848 of 2025 to address the authorized use of AI and facilitate the training of University students and employees in this area. The University affirms that accountability for all final decisions -- including their rationale and formulation -- resides with human employees, in compliance with Arkansas Act 848 of 2025, regardless of any AI recommendation.

This document provides AI use guidelines for the university community. As a Carnegie Classification Research 1: Very High Research Spending and Doctorate Production (R1) research institution, the University of Arkansas encourages innovation and the use of AI to enhance teaching, learning, research, and administrative functions. However, AI use must be conducted in a manner that safeguards sensitive university data, protects individual privacy, and upholds ethical standards. This guidance supplements existing University of Arkansas policies (Code of Computing Practices | University of Arkansas) by addressing specific considerations for AI technologies, encouraging that their use aligns with the university's mission and complies with applicable laws and regulations.

Since AI is transforming rapidly, all guidelines below are subject to modifications. Updated guidelines will be posted at ai.uark.edu.

The potential for gains from AI in higher education is evident. However, along with these gains, we must ensure that this technology is used ethically. The ethical principles governing appropriate use of AI include fairness, transparency, privacy, non-maleficence, accountability, critical engagement, and accessibility. Those who rely on AI should be aware that it could produce biased outputs relating to, among other aspects, race, gender, ethnicity, age, disability status, and many other characteristics including geographic location, socioeconomic status, language, culture, and religion. Results that are indicative of harmful biases should be recognized and ethically addressed in the context of the scenario from which the results are generated. Moreover, there is the potential for AI systems to generate malicious, deceptive, misleading, or simply false content. For these reasons, users should not passively accept its outputs without critical engagement. Students and University employees are ultimately responsible for the content that they produce, share, and submit. University students and employees are expected to refrain from utilizing AI to in any way threaten University systems or security.

The introduction of AI does not change the fundamental obligations of academic and professional integrity; rather, it adds new considerations for accountability and fairness. The following principles guide the ethical use of AI at the university:

AI must not be used to engage in any activity that is illegal, violates university policies, or breaks contractual obligations. University General Counsel should be contacted with any questions regarding contractual obligations. As with any computing resource, all use of AI should be legal and ethical, reflect academic honesty and show respect for intellectual property, data ownership, security, privacy, and the rights of others (Code of Computing Practices | University of Arkansas). University members must not use AI tools to willfully generate or disseminate fraudulent, defamatory, harassing, or obscene content, or any material that would violate laws or university standards if produced by a human. All existing IT conduct rules apply fully to AI usage.

  • In particular, consistent with Act 848 of 2025, AI must not be used to: (1) Express a personal political opinion to an elected official unless the opinion is: (A) Within the scope of the employee's regular job duties; or (B) Requested by an elected official or public entity; (2) Engage in lobbying an elected official on a personal opinion if the employee is not a registered lobbyist for the public entity; (3) Engage in illegal activities or activities otherwise prohibited by federal law or state law; or (4) Intentionally override or avoid the security and system integrity procedures of the public entity.

The use of AI must be consistent with the principles of academic integrity and research ethics. Specifics regarding the use of AI in these areas are provided in separate sections of this guidance. Misrepresenting AI-generated work as one's own is prohibited. Members of the university community should be transparent about the role of AI tools. Plagiarism rules apply to AI outputs: if any user incorporates text, code, images, or data produced by an AI, they must ensure that doing so does not violate any copyrights or intellectual property rights, and they should cite or credit sources as required (LibGuide on AI citations). Fabrication or falsification of research data or citations using AI is considered research misconduct; all AI-generated content (e.g. text, data, and references) must be verified for accuracy. The existence of AI-generated references should be confirmed and the content associated with these references should be verified to represent the original sources and their claims. The University's Research and Scholarly Misconduct Policy applies to work involving AI just as it does to any other work.

Users of AI should strive for transparency in how AI is utilized, especially when it affects others or informs decision-making. When an AI system is used to assist in making a decision that has a material impact on institutional operations (examples include admissions screening, hiring recommendations, or financial aid analysis), the university will ensure that the use of AI is disclosed to appropriate stakeholders and that outcomes can be explained in understandable terms. Accountability is crucial: consistent with Act 848 of 2025, authorized humans make any final decision arising in the course of employment, regardless of what is recommended by an AI or automated decision tool. AI must not be used as the sole decision-maker for any critical or sensitive decisions without a human review process.

University members must be alert to the risk of discriminatory bias in AI systems. An AI tool trained on inappropriate or unrepresentative data could produce biased or unfair outcomes. AI may not be used in ways that constitute discrimination or harassment as define under University policy, especially in contexts like employment, admissions, student evaluations, or resource allocation. The university is subject to equal opportunity and anti-discrimination laws (such as Title VI, Title VII, ADA, etc.), and these extend to decisions or actions influenced by AI.

The use of AI to enhance student learning has great potential and is supported by the University. Moreover, the University acknowledges that existence of AI continues to be integrated into software and services that we already use each day (e.g. web browser, text editor, learning management system). Guidelines that address every AI tool are impractical. The guidelines in what follows provide more specific direction on the appropriate and responsible use of AI by faculty and students in the areas of teaching and learning. The principles provide reasonable boundaries for AI use in these areas. However, the intent is to not excessively limit the use of AI as a tool for both students and faculty. The guiding principle is that students may use AI in a manner that enhances learning without violating rules set forth by a course instructor and the University's Academic Integrity Policy.

  • Subject to applicable University policies and institutional determinations regarding such matter as curriculum and learning methods, faculty members are responsible for determining the appropriate uses of AI in their courses.
  • Student use of AI to satisfy course requirements or assessments is prohibited without the explicit permission of the course instructor. It is the responsibility of the student to seek permission from the instructor if there is any doubt as to how AI may be used to generate an academic submission (e.g. homework, project, quiz, exam).
    • An example of prohibited use would be the utilization of an AI tool to generate the solution to an assigned homework problem without instructor permission.
  • AI tools and services utilized as learning tools without gaining unauthorized academic advantage are permissible.
    • Examples of such acceptable use include the utilization of AI resources available as part of the University's library services or the use of an AI tool to create practice problems as part of a student's preparations for an upcoming exam. Similarly, the review of summative AI services commonly found in web browsers is acceptable.
  • Student general use of AI must adhere to the University's Academic Integrity Policy. Use of AI in a manner not approved by the course instructor is subject to this policy.
  • Faculty are encouraged to clearly communicate their policies regarding AI in their syllabi, outlining permitted and prohibited uses and attribution standards. Syllabus statement guidelines can be found at the Academic Integrity Resources website. Faculty should be aware that without a clear syllabus statement on how students can use AI, it may be hard to resolve violations.
  • To promote transparency and consistency with the ethical use of AI, faculty are encouraged to disclose substantive use of AI in creating course content, grading, or providing feedback.
  • The acceptable use of AI towards completing graduate academic milestones administered at the program level (e.g. comprehensive exams or qualifying exams) should be defined by that program.
  • Faculty and students must follow Fair Use laws and policies with respect to use of copyrighted course materials or proprietary instructional resources in any AI tool.
  • Uncited use of the work of others, whether a person or AI, is a violation of the University's Academic Integrity Policy.

As an R1 institution, the University recognizes the importance of advancing AI research and innovation. University researchers and units making use of AI must follow ethical guidelines and, where applicable, research protocols. The following guidelines are not intended to stifle AI use in research but to ensure it is done responsibly.

  • All research outputs must be attributable to faculty and/or student researchers, with transparent documentation of any AI-assisted contributions.
  • Any content resulting from the summative use of AI in research documents should be verified by researchers.
  • The acceptable use of AI for students conducting research towards an academic milestone (e.g. honors thesis, master's thesis, dissertation) is at the discretion of the student's graduate advisory committee. The use of AI without permission from the committee is a violation of the University's Academic Integrity Policy.
  • Research activities rely heavily on interactions with parties external to the University, including grant agencies, academic publications, and industry partners. External organizations may have specific limitations or guidance on the use of AI for material created for that organization. This includes, but is not limited to, the creation of journal articles, development of research methodologies and tools, reviews of proposals, data management, and research accounting and reporting. In addition to internal University requirements on the use of AI, it is the responsibility of the University researcher to ensure that AI requirements from external organizations are adhered to in all aspects of conducting research.

Data and network security considerations are essential in the use of any AI tools. The University's approved data classification categories are published in Fayetteville Policies and Procedures 921.0. The list of University licensed tools and the process to seek vetting and approval of additional tools is maintained at ai.uark.edu/tools. University licensed tools must be accessed through the University's enterprise implementation when used in restricted data scenarios. Any AI tool (free, University licensed, not University licensed) used on a University system or for University business must be vetted and approved by UITS.  The list of licensed and otherwise approved tools will be updated as additional approvals are given.  In cases where tools not licensed by the University are approved, these tools may be used as long as they do not pose a security or operational threat to University computing assets and network.   AI applications developed internally for campus use (for example, developing a campus chatbot or an AI system for student services) should go through appropriate approval channels to assess risk (security, privacy, compliance) before being deployed broadly.

In all cases, AI tools (licensed and otherwise) must be vetted and approved before use on a University system or for University business.  Additional considerations should be made when considering what types of data can be uploaded into these tools.  The Data Classification Guide below shows the existing classifications of data for University of Arkansas system.

Data Classification

Classification Level

Definition

Examples

Restricted and Highly Sensitive Data

Data regulated by federal, state, or local laws, or data that could cause serious harm if compromised

•FERPA-protected student records

• HIPAA-protected health information

• Social Security numbers

• Employment files and HR data

• Research data with security protocols

Sensitive (Internal) Data

Data not intended for public sharing without permission

• Internal emails

• Technical system configurations

• Employee University ID numbers

• Unpublished research data

Public Data

Data with low risk if disclosed, available to general public

• Press releases

• Class schedules

• University newsletters

• Directory information

 

Data or information classified as either restricted or highly sensitive may only be uploaded to University licensed AI tools or tools approved by University Information Technology Services for explicit use with restricted data declared by the user. Among the most critical data classified as restricted or highly critical is personal data and information associated with FERPA/HIPAA laws.

Personal Data and FERPA/HIPAA: Student education records are protected by the Family Educational Rights and Privacy Act (FERPA) and university policy;  faculty or staff must not input students' coursework, grades, or other non-directory student information into non-approved AI services, as this may constitute an unauthorized disclosure. Similarly, any health or medical information subject to HIPAA or other medical privacy laws must not be shared with AI tools unless in compliance with those laws (which typically requires a business associate agreement or patient consent, if it is allowed at all). In general, treat AI queries the same as any external disclosure: persons with access to confidential or sensitive information shall disclose it only as authorized by FERPA, the Arkansas Freedom of Information Act, and other applicable laws, and only for official university business. If an AI tool is part of official university business (e.g. an institution-provided system with proper safeguards), its use should still be limited to the minimum necessary personal data.

Data or information classified as sensitive (internal) may only be uploaded to University licensed AI tools or tools approved by University Information Technology Services for specific use with this data classification.  If a non-licensed approved University tool is utilized, the user should seek permission from the group that is responsible for the data before uploading into the tool.

Data obtained from a publicly available source for use on a University System or for University business may be uploaded to any University licensed AI tool or tools approved by University Information Technology Services.

Research Data

The allowable use of research data in AI depends on a number of factors. For clarity, examples are provided below to distinguish when external tools are allowed or when data is restricted/highly sensitive and may only be used with a University-approved enterprise AI tool or a tool that has been separately been reviewed and approved by UITS for use with specified data only with acknowledgement of acceptable use restrictions agreed to by researcher.

Research Data Category

Examples

AI Tool Usage

Protected Sponsored Research Data

• Department of Defense funded research

• Department of Energy project data

• Industry-sponsored data with security requirements

• Export-controlled research data

• Classified or sensitive government contracts

University-approved tools that are also allowed by research sponsor ONLY - Required by sponsor security protocols

Sponsored Research Data for Public Dissemination

• NIH-funded research intended for publication

• NSF grant data for public dissemination

• Foundation-sponsored research for community benefit

• Open science initiative data

University-approved tools only

Publicly Available Research Data

• Published journal datasets

• Government open data portals

• Public repositories (e.g., GenBank, PubMed)

• Census and demographic data

University-approved tools only

Generated or Collected Research Data from Unsponsored Research

• Faculty pilot studies

• Unfunded laboratory experiments

• Survey data from academic

• Observational research datasets not covered in another category

University-approved tools only if used on a University System or for University Business

Copyrighted Data

• Published articles and books

• Proprietary software documentation

• Licensed datasets

• Commercial research reports

• Copyrighted multimedia content

University licensed tools only unless permission from copyright holder is obtained or AI tool is limited to Fair Use policy compliance

Data (generated or sponsor-provided) in which data security research protocols are required by the sponsor may only be used with either University licensed tools or University-approved tools that have been approved for explicit use with sponsored research data. It is the responsibility of the researcher to determine if their data falls in this category.

Some research sponsors allow or encourage the dissemination of generated research data to the public for use by the broader research community. Unless restricted by other stated guidelines (e.g. FERPA and HIPAA), research data in this category can be used with any University-approved tool.

Data obtained from a publicly available source can be used with any University-approved tool.

Research data generated or collected without a sponsor agreement may be used with University-approved AI tools. Restrictions on the use of non-licensed University approved AI tools on this data are determined by whether the data or information has commercialization or intellectual property considerations that the University seeks to protect. If the researcher has any doubts as to whether their data can be considered for IP/commercialization consideration contact Technology Ventures before using non-licensed University approved AI tools with their data.

Copyrighted data or information may only be uploaded into a non-licensed University approved AI tool with permission of the copyright holder or in limited use that follows Fair Use laws and policies. Otherwise, a licensed University approved tool is required. 

 

Privacy

Respect for privacy is necessary when using AI. All use of AI tools must comply with privacy laws, regulations, and university privacy policies to ensure that personal information is handled lawfully and ethically. University members must not use AI in a way that violates an individual's expectation of privacy or confidentiality. The following guidelines apply:

University members should stay aware of and comply with any federal or state regulations governing AI use and data privacy. All federal and state laws that protect privacy or regulate data apply to the use of computing resources, including AI (Code of Computing Practices | University of Arkansas). This includes not only FERPA and HIPAA as noted, but also laws such as the Electronic Communications Privacy Act and state data protection laws. If AI tools are used to collect, generate, or analyze personal data (for example, using AI for a survey or to monitor individuals), the use must comply with consent requirements and any applicable human subjects research regulations. Researchers using AI in studies involving human subjects or personal data must follow Institutional Review Board (IRB) protocols and the Common Rule (45 CFR 46) where applicable. In summary, AI should never be used as a means to evade or "work around" privacy rules -- the same standards of confidentiality apply regardless of technology.

Use of AI must also align with the University's own privacy and information policies (General Data Protection Regulation Policy | University of Arkansas). For instance, employees must remember that university records (including data stored or generated via AI) may be subject to the Arkansas Freedom of Information Act (FOIA) and thus could be disclosed pursuant to a FOIA request. Caution should be exercised not to inadvertently expose personal or sensitive data to public disclosure through improper use of AI. If a user is unsure whether an AI use case might raise privacy concerns, they should consult with the University's chief information security officer or the Office of General Counsel before proceeding.

Anyone who has reason to believe that another person has violated these Guidelines shall report the matter promptly to the Office of the CISO (Chief Information Security Officer) and/or their supervisor or department head. Failure to report a suspected violation is a violation of these Guidelines. After a suspected violation has been reported or discovered, the issue will be handled as soon as possible to mitigate any harm to the university and its affiliates.

Violation of these Guidelines may result in loss of access and disciplinary action up to and including termination. For additional information, see the Code of Computing Practices. Code of Computing Practices | VCFA | University of Arkansas (uark.edu)

Exemptions from these Guidelines must be approved. Any questions about the contents of these Guidelines or their applicability to a particular situation should be referred to the Office of the CISO. Please see the Exemption policy.

 

University members should consult the following related policies, standards, and regulations in conjunction with this AI Acceptable Use Policy:

Code of Computing Practices (Fayetteville Policies and Procedures 900.0) -- Governs general use of computing resources and user responsibilities (Code of Computing Practices | University of Arkansas). All AI use must conform to this code.

Data Classification (FPP 921.0) and Data Management, Use and Protection (FPP 922.0) -- Define categories of sensitive data and requirements for handling such data (Data Classification | University of Arkansas) (Data Management, Use and Protection | University of Arkansas). These policies inform what information may or may not be used with AI tools.

University Privacy Policies -- Including compliance with FERPA for student records and any applicable data privacy guidelines issued by the University or UA System. (See, e.g., Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and Arkansas Freedom of Information Act) (General Data Protection Regulation Policy | University of Arkansas)

Academic Integrity and Research Misconduct Policies -- Ensure that use of AI does not violate standards of academic honesty or research integrity. Academic Policy on integrity and the Research and Scholarly Misconduct Policy outline expectations for originality, attribution, and truthfulness in academic work (Academic Integrity Policy | University of Arkansas).

Federal and State AI Guidance -- The university endeavors to align with evolving best practices and guidelines for ethical AI. For example, the White House's Blueprint for an AI Bill of Rights and NIST's AI Risk Management Framework emphasize principles like transparency, accountability, fairness, and privacy in AI systems (Trustworthy and Responsible AI | NIST). University AI use will be informed by such principles, as well as any future federal or Arkansas state regulations governing AI.

University of Arkansas AI Resources – Repository of guidance information, approved AI tools, and links to training resources (Artificial Intelligence Information | University of Arkansas).