Northern protects student records, personnel files, and sensitive research by setting clear rules for what can and can't go into an AI tool. Because every AI tool handles information differently, Northern classifies its data and matches each classification to the tools approved to handle it.
This page explains Northern's data classification rules, the Board-approved guarded environment, and which AI tools are currently approved for which types of data.
Frequently Asked Questions
What happens to my data when I use an AI tool?
When you use an AI tool, you should assume that anything you type, upload, or generate may be copied, stored, reviewed, or retained by the vendor. In some cases, that information may also be used to train or improve the vendor’s AI models. What the vendor does with the information you input is spelled out in the vendor’s Terms of Service, privacy policies, and/or contractual agreements. In the absence of a data protection agreement, you should assume the vendor has broader rights to use and retain all information you provide.
This is why BOR Policy 7.9 requires that restricted data utilize the Board-approved guarded environment or university-approved AI tools. The guarded environment is designed to protect sensitive information and provide security and oversight of university data. If information is sensitive, private, or protected by law or policy, it should never be entered into an unapproved AI tool. If you are uncertain if an AI tool is approved, please reach out to Technology Services before using the tool.
What is the BOR-approved 'guarded environment’, and how will it change what I can do?
The South Dakota Board of Regents (SDBOR) is implementing Amazon Bedrock, a secure, Board-approved AI environment that can be used with restricted data while providing appropriate security, privacy, identity management, auditing, and governance controls. BOR Policy 7.9 refers to this as the "guarded environment." It is designed to protect institutional, student, employee, research, and other sensitive data when using AI technologies.
For many users, the biggest change is that not all AI tools can be used with all types of data. Under BOR Policy 7.9, restricted data must be used only within the Board-approved guarded environment or university-approved AI tools. Currently, the university-approved AI tool is NSU’s Microsoft Copilot.
Public information can generally be used more broadly, and institutions may authorize additional AI tools for certain internal uses, subject to applicable policies and procedures.
The goal is not to limit innovation or prevent the use of AI. Rather, it is to provide a trusted environment where students, faculty, and staff can use AI capabilities while helping protect university data and meet legal, regulatory, and security requirements.
What data classification rules apply to AI use at Northern?
Put simply, BOR Policy 7.9 states that only certain types of data can be used with certain AI tools.
- The most sensitive data with the highest level of protection, called restricted data, can only be used by AI tools in the guarded environment approved by the BOR or by the university-approved AI tool. Restricted data includes education records, health information, financial records, payment card data, identification information like birthdate and Social Security number, and more.
- The next class of data is internal data; this is information that is sensitive due to proprietary, ethical or privacy considerations, such as internal reports, unpublished research, or technical documentation. The Board-approved guarded environment and university-approved AI tool is always appropriate for using AI with internal data. Additionally, AI tools outside a guarded environment may be approved for internal data, but only after following the software review process.
- Finally, public data is the third class of data and can be used freely within AI tools both inside and outside the guarded environment.
To learn more about these three classes of data, including specific examples, see BOR Policy 7.8. To read more details about the guarded environment and institutional expectations for governing AI use outside of that environment, see BOR Policy 7.9.
Can Northern use its own AI tools outside the BOR's guarded environment?
Yes, faculty, staff, and students can utilize AI tools outside of the BOR’s guarded environment for data that is not regulated or restricted. For restricted data, NSU has approved the use of Microsoft Copilot. If a new AI tool utilizes internal university data, a full software and security review must be conducted prior to use.
How does a new AI tool get reviewed and approved for use with university data?
If you would like to use a new AI tool for university work, complete a Software Review ticket. Technology Services will review the request and help determine what type of university data may be used with the tool.
If the tool is used with Regulated or Restricted data, the request must go through the Regents Information System (RIS) review process after NSU Technology Services has conducted their review. Under BOR Policy 7.9, RIS reviews requests for new AI tools, models, services, data integrations, and third-party solutions for possible inclusion in the Board-approved system software solution.
For tools that will only be used with Internal or Public data, NSU may approve them through our already-defined software review process.
What AI uses are flatly prohibited?
BOR Policy 7.9 states that AI should be used ethically and in alignment with the goals and mission of Northern and the BOR. It also lists ways that AI tools cannot be used. The prohibited uses are:
- Creating, uploading, or carrying out malware, spam, phishing campaigns, or other cyber scams, or to violate state, federal, or local laws.
- Weakening information security controls, bypassing access controls, exposing credentials or secrets, violating licensing restrictions, or conflicting with the approved system solution or data governance requirements.
- Impersonating another person, concealing the use of automated content where disclosure is required, circumventing academic or employment responsibilities, misrepresenting authorship, or engaging in unlawful, discriminatory, harassing, deceptive, or unethical conduct.
- Infringing copyright or other intellectual property rights
Are there exceptions to these rules?
Yes, there are three exceptions.
- First, the general rule is that internal data should only be used in the BOR-approved guarded environment. But, if an AI tool is approved for internal data via Northern’s authorization process, that tool can be used with such data outside the guarded environment.
- Second, when academic programming and research needs require AI use outside the guarded environment, say for learning purposes in a cyber security program, Northern can authorize this limited use. Again, the authorization must follow the process documented in Northern’s policies and procedures.
- Third, Northern may allow particular users to impersonate others when the need for such testing arises.
Is my AI activity monitored, and how long are records kept?
Like other university technology services, AI systems may maintain logs and records that can be reviewed for security, compliance, records management, and legal purposes. BOR Policy 7.9 requires the Board and institutions to have the ability to review, monitor, and audit AI-related activity when necessary.
AI-related records are subject to applicable records-retention requirements and public-records laws.
Who do I contact with data governance or security questions about AI?
See “Who are Northern’s AI Contacts?” under AI Definitions, Policies & Contacts