UTD AI Policies

Karl Ho

Roadmap

  • Three governing documents, and which one applies to you
  • UTDSP5017 — the student-facing policy
  • Permitted, partial, prohibited: what each looks like in practice
  • Citation, verification, and where students get into trouble
  • Data rules that apply to everyone
  • A four-question checklist

Three documents, three audiences

Document Issued by Governs Applies to students?
UTDSP5017 Policy Office (Mar 2025) Generative AI in academic work Yes — primary
Initial Guidelines for Gen AI OIT Everyday best practice Yes, as good practice
AI Usage Guidelines Info Security Office + OIT Faculty/staff official duties Not academic conduct

Students: UTDSP5017 is your policy. The ISO guidelines explicitly do not govern academic conduct or plagiarism — they govern employment duties and data handling.

Anchoring policies

Generative AI does not sit in a policy vacuum. It inherits from:

Policy What it covers
UTDSP5003 Student Code of Conduct
UTDBP3096 Information Security and Acceptable Use
UTDSP5010 FERPA
TRAIGA Texas Responsible AI Governance Act (signed June 22, 2025)

Plus HIPAA, copyright, and tool licensing terms.

UTDSP5017

Generative AI Use in Academic Work

Scope: coursework, independent research, dissertations, theses.

  • Grounded in the Student Code of Conduct (UTDSP5003)
  • Preserves academic and personal integrity while encouraging creativity and innovation
  • Faculty have the freedom and responsibility to decide how generative AI may be used in their courses.
  • Faculty may permit, prohibit, or partially allow AI
  • Expectations must be communicated before the semester’s work begins — in the syllabus and in assignment descriptions
  • When permitting, faculty should specify the citation style

Three regimes

Regime What you may do What you owe
Permitted Use AI ethically and responsibly across the work Document and attribute in APA/MLA/Chicago or the style named; validate all output
Partial Use AI only where the assignment prompt says so Follow the written guidelines exactly; attribution still required
Prohibited Nothing — present your own work Ideating, outlining, writing, studying, generating text, tables, code, analysis, video, images are all covered

Unauthorized use is a violation of UTDSP5003.

Examples: what falls where

Scenario Likely status
Instructor’s syllabus permits AI; you use ChatGPT to brainstorm a thesis and cite it Permitted
Prompt says “AI allowed for debugging, not for writing the analysis”; you use it to fix a loop Partial — allowed
Same prompt; you also have it draft your interpretation section Partial — violation
Syllabus prohibits AI; you use Grammarly’s generative rewrite on your essay Prohibited — ask first
Syllabus prohibits AI; you use it to make a study guide for the exam Prohibited — “studying” is named
Take-home exam, no AI statement anywhere Ask. Do not assume.

The embedded-AI problem

AI is now inside tools you already use — Word, Google Docs, Grammarly, Excel, your IDE, your search engine.

  • The policy anticipates this: students should receive written guidance on which specific applications are not permitted
  • If the syllabus is silent on a tool you are already using, ask in writing and keep the reply.
  • “I didn’t know autocomplete counted” is not a defense the policy contemplates

Citation and attribution

When AI use is permitted or partially permitted, you must document and attribute it.

Style Typical treatment
APA Cite the model as software; include the prompt in an appendix
MLA Cite the prompt as the “title”; name the tool and version
Chicago Note the tool, version, date, and prompt

Follow the written guideline from your instructor — a professional style may be specified instead. Undisclosed use of a permitted tool is still an integrity problem.

Verification is your job

The policy: students must validate or verify the output from generative AI. AI-generated work does not replace your understanding and interpretation of the course material.

Why it matters in practice:

  • Fabricated citations — a plausible author, journal, year, and DOI that does not exist
  • Confidently wrong numbers in a statistical or financial answer
  • Code that runs but implements the wrong method
  • Summaries of readings that invert the author’s argument

You submit it, you own it. “The AI said so” transfers no responsibility.

The other side of the policy

The policy is not prohibitionist. It states plainly:

Workforce-ready students may need generative AI skills and must learn appropriate workplace and academic uses appropriate to their discipline.

  • Learning to use AI well is treated as a legitimate educational goal
  • The constraint is disclosure, verification, and the instructor’s rule — not the tool itself
  • Discipline-appropriate use is expected to differ across programs

Academic integrity clause

Applies to students, faculty, and staff alike:

  • No use for activity that is illegal or fraudulent, or that violates state or federal law, or UT Dallas / UT System policy
  • Compliance with Information Security and Acceptable Use (UTDBP3096) and FERPA
  • Misuse producing academic dishonesty — or jeopardizing protected university or student data — is subject to discipline under the Student Code of Conduct

Data and Tools

Rules that apply to everyone

Condensed from the OIT and ISO guidance:

Rule In practice
Protect confidential data Default settings are not private. No FERPA or HIPAA data in generative AI tools.
Review before publishing Output can be inaccurate, misleading, fabricated, or carry copyrighted material
Follow existing policy Catalog policies, graduate policies, Acceptable Use Policy still apply
Watch for phishing AI makes convincing phishing and deepfakes cheap — keep reporting
Ask OIT before procuring UTD already licenses vetted tools

Which tool, and with what data

Provided by OIT: CometAI · Microsoft Copilot · Amazon Bedrock

Data type Public tool (personal account) UTD-provided tool
Public data OK OK
Course notes, your own drafts OK (subject to syllabus) OK
Confidential / Controlled data No With OIT guidance
FERPA records (grades, rosters) Never Only as approved
HIPAA data Never Only as approved

Faculty and staff on official duties: use UTD-provided tools and check which account you are logged into. Personally subscribed tools may not be used for job duties.

Ethics, briefly

  • Bias — models trained on incomplete or biased data output the same; avoid perpetuating bias by race, gender, age, or other protected characteristics

  • Transparency — be open about AI-generated content; you are responsible for anything you present as your own original work

  • Harm — no discriminatory, harassing, or defamatory content; no harm to individuals, groups, or the university

  • Accountability for agents — users own the actions AI agents take on their behalf

  • Questions or consultation: infosecurity@utdallas.edu

Four questions before you prompt

Question Rule
1. Is this academic work? UTDSP5017 governs — the instructor’s written rule controls
2. Which regime applies? Permitted / partial / prohibited. If unstated, ask in writing
3. What data am I entering? Public only in public tools. Never FERPA or HIPAA
4. Have I verified the output? Every citation, number, and claim. You submit it, you own it

Themes across all three documents: accountability is non-transferable · data classification, not tool preference, is the operative distinction · disclosure is the default · verification is mandatory · the rules will keep changing.

Sources