AI Usage Policy
We recognise that the use of Artificial Intelligence (AI) presents many strategic and operational opportunities. We are committed to embracing technology so that we can continue to innovate and improve, but we are also aware of the risks that come with new technologies. For this reason, there is a need for us to have rules around how we use AI in the workplace.
This policy applies to:
- All College staff, Fellows, contractors and affiliates using AI tools for academic, administrative, or operational purposes.
- AI tools including generative AI, automation systems, and embedded AI features in platforms such as Microsoft 365 Copilot.
This policy has been based on Collegiate and Inter-Collegiate policies as well as the. Failure to adhere to the following principles when using AI to handle College information may result in disciplinary action.
Human Oversight
You are permitted to use AI to assist you, however, you must be aware of the risks and requirements set out in this policy. AI is a support tool, not a substitute for human judgement, you remain entirely responsible for the quality and accuracy of your work.
Transparency
Users must disclose when AI has been used to generate content, make decisions, or interact with others. Outputs should be clearly marked (e.g., 'Generated using AI').
Data Protection & Privacy
- Categories of data listed in Appendix B may only be used with AI listed in Appendix A.
- Special Category Data (see Appendix C) must not be input into AI tools.
- In general (for AI not listed in Appendix A), AI learns from the information that is input, because of this it is possible for other users of that AI to extract the information input and cause a data breach.
Security & Compliance
- Only approved AI tools (see Appendix A) may be used for processing College information (see
Appendix B). The approval process for tools is listed below under Governance. - Non-approved AI can be used for processing of information not listed in Appendices B and C. e.g. ChatGPT may be used to summarise publicly available information from a website.
- AI inputs and outputs must be classified appropriately and stored securely.
- Users must not use AI for activities that could breach laws, infringe intellectual property, or cause reputational harm. Also see the College’s IT Regulations for details.
Fairness & Non-Discrimination
AI outputs must be reviewed for bias. Users must ensure fairness, especially in decision-making
contexts.
Prohibited Uses
AI must not be used:
- For automated decision-making with legal or significant effects without human review.
- To impersonate individuals or misrepresent College positions.
- To generate or disseminate harmful, discriminatory, or misleading content.
- The IT Manager is responsible for monitoring, but Heads of Departments and Senior Officers are responsible for monitoring their staff use and outputs are in line with this and other relevant policies.
- For an AI tool to be approved due diligence of the company will be carried out and a DPIA produced by the relevant staff (e.g. IT Manager and DPO), these will be presented for approval or rejection at the next IT Committee meeting.
- Breaches of this policy may result in disciplinary action and/or revocation of access.
- All users must complete AI literacy training before using AI tools.
- Specific training will be provided for new AI deployments.
- Questions or concerns should be directed to the IT Office or Data Protection Officer.
This policy will be reviewed annually or in response to significant changes in technology, regulation, or College strategy.
Last Updated: February 2026
Next Review Due: February 2027
Policy Owner: IT Manager, 91¶¶Òõ
Contact: help@murrayedwards.cam.ac.uk
The following AI services are approved for use in processing College information:
Microsoft CoPilot Enterprise under the following conditions:
- You must be logged in with your 91¶¶Òõ account, as it then operates within the
College’s Microsoft 365 tenant, ensuring data residency, compliance, and privacy as it does not train on user data or share prompts or outputs externally and supports productivity, summarisation, drafting, and data analysis tasks within secure boundaries. - Only share approved information types with the AI service (see Appendix B).
- Validate AI-generated content before publication or decision-making.
- Detailed data protection information is available .
The following information categories are approved for use with the AI tools listed in Appendix A providing they do not include any information from the prohibited categories listed in Appendix C:
- Work documents
- Emails and calendars
- Teams chats & transcripts
- Internal business information
- Non-sensitive personal data (names, job roles, etc.)
- People’s information that is not Special Category Data
Information types you must not share with any AI tools, including those listed in Appendix A, because they fall under UK GDPR Special Category Data or high‑risk categories. You may request consideration of using AI for this information by completing special DPIA and obtaining internal approval from the DPO:
- Health data
- Biometric data
- Genetic data
- Political opinions
- Religious or philosophical beliefs
- Trade‑union membership
- Sex life / sexual orientation data
- Criminal‑offence data