Using an AI tool? Make sure your information is protected
06 Oct 2026
As colleagues continue to explore and experiment with AI, you may use a variety of tools. In every activity you undertake, it is your responsibility to appropriately protect the information that you both own and share.
Information at the Restricted, Highly Restricted and Very Sensitive level (as classified by the Information Security Classification Scheme), requires additional care when being shared or processed and must only be used in approved tools. This includes personal, confidential and security-sensitive information such as student records, colleague records, health information, bank details, passport copies, unpublished research and security-sensitive research.
If this information is compromised the consequences could be serious. If you’re ever unsure or worried about the information you’re sharing, make sure to check the Information Security Classification Scheme in the first instance
What are the concerns?
Colleagues must not enter confidential information into unreviewed and unassessed tools, as they may process, store or handle information in ways that do not support the University’s data protection, contractual or information security obligations.
Before using an AI tool, ask yourself:
- Is this a University-approved AI tool?
- Is any of your information categorised as Restricted or above, based on the University Information Security Classification Scheme (ISCS)?
These checks will support your decision on whether information can be used safely with a particular tool, each time you use it.
