Kean University – AI & Emerging Technology Data Usage (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University data may be used with artificial intelligence (AI) systems and other emerging technologies in a secure, ethical, and compliant manner.
This SOP enforces University requirements that restrict the use of Confidential or Restricted data in public AI tools and ensure strong privacy, security, and governance controls for approved platforms.
Scope
- All University employees, contractors, student workers, and vendors
- All AI and emerging technology platforms (e.g., generative AI, machine learning, analytics automation)
- Any use of Public, Internal, Confidential, or Restricted University data
- Cloud, on‑premises, and hybrid environments
This SOP covers platform approval, data classification validation, prohibited uses, monitoring, and exception handling.
Definitions
- Artificial Intelligence (AI) – Systems performing tasks that normally require human intelligence.
- Public AI System – Third‑party AI platforms where the University does not control training, retention, or privacy.
- Approved AI Platform – University‑sanctioned AI systems vetted by Data Governance, IT Security, and Supplier Risk Management.
- Confidential Data – Sensitive information requiring encryption and MFA.
- Restricted Data – Legally regulated data requiring the highest level of protection.
Roles & Responsibilities
Data Governance Lead
- Maintains the Approved AI Platform List
- Documents classification rules and prohibited data types
Data Owners
- Approve use of data within AI systems
- Validate data classification and risk thresholds
IT Security
- Perform security reviews of AI platforms
- Monitor AI usage logs and enforce security controls
Supplier Risk Management
- Assess vendor security and contractual data protections
Users
- Use only approved AI platforms
- Follow classification and prohibited‑use rules
- Report suspected misuse immediately
Procedure
Step 1 — Determine Data Classification
Identify whether data is Public, Internal, Confidential, or Restricted before using any AI system. Confidential or Restricted data may only be used with approved AI platforms.
Step 2 — Confirm AI Platform Approval
Verify the platform is on the Approved AI Platform List. Unapproved platforms require formal review and approval before use.
Step 3 — Prepare Data for AI Use
Mask or anonymize sensitive fields when possible and ensure data is stored and transmitted only through approved University systems.
Step 4 — Use Approved AI Systems
Authenticate using required controls (including MFA where applicable), use only authorized datasets, and ensure logging is enabled.
Step 5 — Prohibited Uses
Users must not enter Confidential or Restricted data into public AI tools, use personal AI accounts for University work, or bypass privacy and retention controls.
Step 6 — Output Handling
Validate AI‑generated outputs for accuracy and privacy risk. Store outputs only on approved University systems.
Step 7 — Monitoring & Exceptions
IT Security monitors AI usage logs. Any exception to this SOP requires documented risk analysis and formal approval.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU DG SOP 10 – Privacy Protection, Masking & Anonymization
- KU DG SOP 11 – Logging, Monitoring & Alerting
- KU DG SOP 12 – Data Incident Response
- KU SEC 05 – Exception Management
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Identify | ID.IM – Information Management | ID.IM01, ID.IM03 |
| Protect | PR.DS – Data Security | PR.DS01, PR.DS02, PR.DS05, PR.DS06 |
| Detect | DE.CM – Monitoring | DE.CM01 |
Metrics & KPIs
- Percentage of AI usage on approved platforms
- Number of AI usage violations detected
- Time to investigate and remediate AI misuse
- Percentage of datasets masked or anonymized prior to AI use
Required Records & Storage
- Approved AI Platform List
- AI usage and access logs
- Data Owner approvals
- Exception approvals and risk analyses
- Incident reports related to AI misuse
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Data Governance Lead | Chief Information Security Officer |
``