Responsible use
AI can help you produce work, but it cannot be accountable for it. A named person remains responsible for every output that leaves your hands.
Confirm current tool approvals on the
Penn Generative AI Tools & Resources
page before requesting or purchasing.
Institutional accounts only
Penn’s protections come from the contract behind the account, not the brand name. Personal or free-tier ChatGPT, Claude, or Microsoft accounts are not approved for Penn data.
- Sign in with
pennkey@upenn.edu via PennKey SSO (Two-Step Verification applies).
- Confirm your Penn identity (and Penn shield where shown) before entering work content.
- Licenses are named individuals — no shared or generic logins for interactive tools.
- API keys and service accounts go through the LLM Gateway (or the relevant platform), with a named owner; never paste keys into a prompt.
Hard limits (every tool)
- Never enter credentials or payment data: passwords, API keys, tokens, connection strings, SSNs, or credit/payment cards.
- No PHI/HIPAA unless the specific tool is contractually approved for it (Claude Enterprise, ChatGPT Edu, and Gemini are not).
- Student records are Moderate (FERPA) — use only tools approved for Moderate, for a legitimate educational purpose, with minimum identifiable detail.
- Minimize before you paste: redact names and identifiers you do not need; prefer summaries or synthetic examples.
- Outputs inherit the classification of their inputs — store and share accordingly.
- New tools or integrations with Moderate/High data require Privacy + OIS review (SPIA / VSTAR via Procurement).
Acceptable use
AI-assisted work remains subject to Penn’s existing computing policies. See the
Acceptable Use Policy on Electronic Resources
and the
University guidance on generative AI.
Code & agents (interim)
- Use only approved coding assistants; treat internal source as at least Moderate risk.
- AI-generated code needs human review before merge; normal testing and change management still apply.
- Verify every suggested dependency — models commonly hallucinate package names.
- Scope agent permissions narrowly; keep a human approving consequential actions.
- Detailed AI Coding Tools guidance is forthcoming; Copilot Studio is licensed separately from Copilot Chat / M365 Copilot.
References:
Penn Data Risk Classification ·
OIS Generative AI guidance ·
Penn Generative AI Tools ·
Acceptable Use Policy ·
CETLI course policies