Privacy Guidance for use of Artificial Intelligence

Artificial intelligence (AI) is a set of technologies that are based primarily on machine learning and deep learning and are used for data analytics, predictions and forecasting, natural language processing, intelligent data retrieval, and more. Artificial Intelligence can also assist with making recommendations or decisions, and solving complex problems. AI that can produce new content and ideas, including conversations, stories, images, videos, and music is called Generative AI or GenAI. For the purpose of this guidance, Artificial Intelligence Technology will be referred as “AI Tools”.

Artificial Intelligence (AI), including Generative AI (GenAI), can help us work more efficiently by assisting with writing, analysis, research, automation, and decision support. However, AI tools can also introduce privacy, security, compliance, and ethical risks if they are used improperly.

Key Privacy Risks Associated with AI Use

Potential Disclosure of personal data
Any data used as input into a GenAI tool may be stored by the tool and used to improve the model.
Entering personal data, student records or health information into a GenAI Tool could result in the unauthorized disclosure of the respective data. Some models may expose sensitive information that was used as input.

Data Retention and Secondary use
AI providers may retain prompts, uploaded files, conversations, and outputs for operational, security, auditing, or service-improvement purposes. 
Before using an AI tool, understand: 
•    What data is retained.
•    How long it is retained.
•    Whether personal data is used to train AI models. 
•    Whether retention and AI nodel training settings can be disabled.

Re-identification
Even when obvious identifiers are removed, AI technologies may increase the risk that individuals can be re-identified, especially when data is combined with other information sources. For example: a 2025 study on healthcare AI found that features extracted from medical imaging foundation models could be used to re-identify patients across data sets. A 2026 study demonstrated that generative AI models can reconstruct realistic human faces from partially masked images.

Lack of transparency
GenAI Tools often operate with limited transparency, making it difficult for users to understand how data is collected, processed, stored, and reused. Many providers do not fully disclose what happens to user inputs, whether prompts are retained or used for model training, or how outputs are generated.

Bias and Ethical Use
AI systems can produce incorrect, misleading, incomplete, or biased outputs. AI-generated content should always be reviewed by a qualified person before it is relied upon for university business. (“Humans are biased. GenAI is even worse” – Bloomberg, June 2023)
They can also infer sensitive traits (health status, political orientation, etc.), from minimal input data like text, images, or behavioral patterns. This raises ethical concerns around privacy violations, amplifying existing bias, or discrimination. (“Generative AI ethics: 11 biggest concerns and risks” – TechTarget, 2025)

Protecting privacy is a shared responsibility. Users should work only with approved AI tools, restrict access to authorized individuals, minimize the amount of personal information provided, enable available privacy safeguards, and ensure their activities comply with university privacy, security, and data protection requirements. 
The following guidance is intended to govern the use of AI Tools with university data.
Reviews and Approvals

Before using an AI tool that processes university data (including, but not limited to personal information):

  1. Verify that the tool has been approved for university use.
    A list of AI tools approved for use within the GW community can be found on this page: Artificial Intelligence (AI) Evaluation & Status. Additionally, you can also Explore tools and resources with AI capabilities, available at GW to enhance teaching, learning, research, and administrative tasks.
  2. If you plan to use an AI tool that has not been approved by GW, you must complete all applicable security, privacy, procurement, and legal review processes before using the tool for university purposes.
    o    Follow the Procurement Contract Review and Approval Process when purchasing information technology that includes AI capabilities. When necessary to leverage the use of AI Tools that will process PII, the AI Tool must be reviewed and approved, by the GW Privacy Office and the Office of General Counsel.
    o    Before an AI tool may be used with university data, it must undergo a cybersecurity risk assessment in accordance with GW requirements. AI tools that collect, access, store, transmit, or process university data, particularly regulated or restricted data or data integrated with GW systems, must successfully complete the required security review and obtain all necessary approvals before use.

The use of un-approved AI Tools for university operations and purposes will be considered a violation of university policies related to privacy and data protection.

Privacy Requirements

The use of AI must comply with the following privacy requirements and applicable university policies.

Transparency and disclosure of AI Use

Individuals should be informed when they are interacting with, or receiving content generated by, an AI system, unless the use of AI is already clear from the context. Providing appropriate notice promotes transparency, supports informed engagement, and helps maintain trust in university processes.
Examples may include: AI-powered chatbots, AI meeting assistants and transcription tools, AI-assisted customer service and support tools.
When implementing AI technologies, departments should consider how and when users will be notified of AI involvement and ensure such notifications are consistent with university policies and applicable legal and regulatory requirements. 

Data Minimization

When using AI tools, apply the principle of data minimization by providing only the information necessary to accomplish the intended purpose. Before entering personal information into an AI system, consider whether the objective can be achieved using less data or without personal information altogether. Whenever possible:
•    Remove names and other direct identifiers.
•    Use anonymized, de-identified, or pseudonymized data.
•    Use aggregated information instead of individual-level data.
•    Limit data shared with the AI tool to only the specific information needed for the task.
•    Avoid uploading complete records, documents, or datasets when a subset of the information will suffice.
Do Not Enter Sensitive Information AI Tools. Unless explicitly authorized and approved, do not enter:
•    Social Security numbers
•    Government-issued ID numbers
•    Financial account information
•    Protected health information (PHI)
•    Student education records protected by FERPA
•    Identifiable Research participant data
•    Confidential personnel information
The use of personal information within AI tools should be carefully evaluated and limited to what is necessary, particularly when the data is protected under university policies and applicable privacy and data protection laws. For example, in social media, when analyzing user behavior for targeted advertising, anonymized demographic data and aggregated interaction patterns should be used, rather than individual user profiles. Another example would be when, in research, an AI Tool is analyzing patient data to verify diagnosis, it should only use anonymized medical records, focusing on relevant health indicators instead of storing full patient histories.

Data Security Requirements for AI Tools

AI tools can introduce security and privacy risks, particularly when they process university data. Before an AI tool is used for university purposes, it must undergo a cybersecurity risk assessment and complete applicable security, privacy, and compliance reviews. Only AI tools that have received the necessary university approvals may be used to collect, access, store, transmit, or process university data.

Configure Privacy settings

Many approved AI tools include privacy and data protection settings that can help reduce risk to personal data. Before using an AI tool, take time to review and enable available privacy features that are appropriate for your use case.
For example, when using AI-powered meeting assistants (e.g. the Zoom AI Companion), consider disabling automatic activation features so participants can be notified and, when required, provide consent before AI features are enabled.
If you are unsure which privacy settings to use, consult GW Information Technology (GWIT) for guidance on the privacy and security features available in university approved AI tools.

Human Oversight and Accountability

AI tools can assist with analysis, recommendations, and decision support, but they should not be the sole basis for decisions that significantly affect individuals. Appropriate human oversight should be maintained throughout the decision-making process, particularly when decisions may impact a person's rights, opportunities, access to services, academic standing, employment, health, or well-being. Examples include: 
•    Employment and hiring decisions 
•    Student admissions, academic, and support services 
•    Healthcare-related activities
•    Research involving human participants
•    Disciplinary or conduct matters
•    Eligibility for services, benefits, or resources 
Individuals with appropriate authority and expertise remain responsible for reviewing AI-generated outputs, exercising independent judgment, and making final decisions. AI should be used to inform, not replace, human decision-making. 

Surveillance, Monitoring, and High-Risk Uses of AI

The use of AI for surveillance, monitoring, or behavioral analysis is considered a high-risk activity due to its potential impact on privacy, fairness, and trust. As a result, these higher-risk applications require heightened scrutiny, comprehensive review, and approval at the highest institutional level before use. Contact the Privacy Office for further guidance.

Related Policies and Guidance

Generative AI at GW

GWIT - AI Guidance and Best Practices

GW - Artificial Intelligence (AI) Evaluation & Status

GW Privacy of Personal Information Policy

Contract Review and Approval Process

Data Sharing - Privacy Requirements

Privacy Considerations when using Virtual Meeting and Collaboration platforms 

Cybersecurity Risk Assessments