Artificial Intelligence General Policy

1. Policy

Issued: January 9, 2026
Last Revised: September 1, 2026
Last Reviewed: September 1, 2026

2. Policy Purpose

​​This Policy sets requirements for the USC community related to the approved use of AI Tools. It sets out the benefits and risks that will be considered when determining whether to approve a new AI Tool or use case as well as the process for seeking that consideration and approval. Of the many risks associated with the use of AI Tools, among the most significant is ensuring appropriate use of USC data. This Policy, therefore, goes into more detail on the types of data usage with AI Tools that are most likely to be approved.  

3. Scope

This policy applies to all USC “Covered Individuals” who are, for the purposes of this policy, all: 

  • ​University faculty members (including part-time and visiting faculty or those on sabbatical or leave)  
  • ​Staff and other employees (such as postdoctoral scholars, postdoctoral fellows, and student workers) and graduate assistants 
  • ​iVIP users (guests with electronic access), as well as any other users of the network infrastructure, including independent contractors or others (e.g., temporary agency employees) who may be given access on a temporary basis to University systems 
  • ​Third parties, including vendors, affiliates, consultants, contractors, sub-contractors, and other authorized representatives acting on behalf of the University 
  • ​Students​​ 

4. Definitions

Term Definition  
Artificial Intelligence Artificial Intelligence (AI) refers to machine-based systems that can perform tasks that would typically require human intelligence. It often involves algorithms or models capable of learning, reasoning, and making decisions. AI can be found in a wide range of applications and technologies, from voice agents that engage in natural language processing to image recognition tools and from autonomous vehicles to virtual assistants. 
AI Tools A general term identifying applications, services, features, and add-ins that leverage AI to create content or otherwise support or enhance the creation of content, whether as a stand-alone application or service or as functionality embedded within another tool, platform, or service. 
USC Enterprise AI Tools AI Tools procured, licensed, integrated, and authorized by the University for institutional use, as specified on the ITS website (https://itservices.usc.edu/ai/). These tools have been assessed by USC’s Office of Cybersecurity and have undergone review for contractual protections, security requirements, and applicable privacy and data use terms intended to protect USC data and other information used with the tools. 
Generative Artificial Intelligence  Generative Artificial Intelligence (Generative AI or GAI) is a subset of AI techniques that learns patterns contained in input data to generate new content that emulates the structure and characteristics of the input data but is novel content, including text, computer code, synthetic data, workflows, and models of physical objects. Generative AI also can be used to create novel art, literature, or material design.  
Covered Individuals  People or entities specified by the Scope of this Policy, in Section 3 above.  
System Owners  The individuals responsible for the procurement, development, integration, modification, operation, maintenance, or retirement of an information system. System Owners are key contributors in developing system design specifications to ensure the security and user operational needs are documented, tested, and implemented.  
Locally Hosted AI Tool AI tool hosted within applications, servers, and databases directly controlled by USC, allowing USC to manage security, access controls, maintenance, and operations. 
Public Data (See Data Protection Policy) Data that is not regulated and is generally made available through public interfaces and requires no protection mechanisms 
Internal Use Only Data (See Data Protection Policy) Data that includes all information used to conduct USC business, unless categorized as “Confidential” or “Public”. Examples include: Non-regulated Personally Identifiable Information; In-process contracts and agreements; Employee performance evaluation information; Audit reports; Network diagrams; Non-public USC policies; Information involving USC strategy and implementation plans; Internal USC memos and emails; USC and employee ID numbers 
Confidential Data (see Data Protection Policy) Regulated or sensitive data that could cause legal, financial, reputational, or operational harm to USC and/or its community members if disclosed or could require compliance efforts if exposed to unauthorized parties.  
Confidential – Controlled Data (see Data Protection Policy) A sub-category of Confidential Data that includes Confidential-Controlled Data, as defined in the USC Data Protection Policy, and any data subject to U.S. export control laws. This includes, but is not limited to, Covered Defense Information, Controlled Technical Information (CTI), Controlled Unclassified Information (CUI), and other information with military, space, or national security applications for which the data provider (e.g., a research sponsor) has imposed safeguarding, access, or dissemination controls or where USC is otherwise legally or contractually required to restrict or prevent disclosure to third parties. 
Agentic Artificial Intelligence (Agentic AI) Agentic Artificial Intelligence (Agentic AI) refers to AI systems capable of independently planning, initiating, and executing actions to achieve specified objectives with limited or no real-time human intervention. Agentic AI systems may use tools, access external systems or data sources, invoke other AI models, make decisions, and perform multi-step workflows autonomously or semi-autonomously. Examples include autonomous research agents, AI assistants capable of taking actions on behalf of users, and systems that interact with enterprise applications or external services. 
Machine Learning Machine Learning (ML) refers to a subset of Artificial Intelligence that uses statistical models and algorithms to identify patterns in data and improve performance on a task through experience rather than explicit programming. Machine Learning includes supervised, unsupervised, reinforcement, and deep learning techniques and may be used for prediction, classification, recommendations, anomaly detection, or other automated decision-making functions. 

5. Policy Details

Benefits & Risks Associated with Use of AI Tools 

​The use of AI Tools creates new opportunities for the USC community. That same usage can present substantial legal, regulatory, and reputational risks that USC must balance. 

​Benefits from the use of AI Tools may include: 

  • ​Facilitating expedited progress towards University or individual objectives and goals; 
  • ​Allowing for new forms of analysis not realistically possible absent the use of AI; 
  • ​Cost savings and process efficiencies; and 
  • ​Improved substantive outcomes for one or more segments of the USC community. 

​Examples of significant risks that can accompany the use of AI Tools include: 

  • ​Data Privacy: Sensitive information belonging to USC and/or members of its community is improperly exposed to third parties; 
  • ​Cybersecurity: The confidentiality, integrity, or availability of USC’s systems are compromised; 
  • ​Transparency: An AI Tool does not provide sufficient explainability or interpretability, such that users of the tool cannot understand why the AI Tool provided particular outputs based on the inputs; 
  • ​Performance: The AI Tool provides outputs that are inaccurate or simply false, especially in ways that are challenging for users to identify; 
  • ​Intellectual Property: Use of the AI Tool puts intellectual property protections for USC and/or the members of the community using the tool at risk (e.g., by allowing the tool to leverage protected data without permission or through contractual provisions governing use of the tool); 
  • ​Improper Bias: The AI Tool leverages training data or other functionality that causes it to provide outputs that are unfair or improperly biased; 
  • ​Legal: Ensuring the AI Tool complies with the patchwork of state and federal AI-related regulation. 

Enterprise AI Tools 

​The Offices of Cybersecurity, Ethics and Compliance, and General Counsel may collectively designate an AI Tool as an Enterprise AI Tool. Tools with that designation have been reviewed for contractual protections, security requirements, and applicable privacy and data use terms intended to protect USC data and other information used with the tools. As such, use of Enterprise AI Tools is encouraged over non-Enterprise AI Tools. A list of USC Enterprise AI Tools can be found on the ITS website (https://itservices.usc.edu/ai/). 

Pre-authorized Uses of AI Tools 

​The following use cases for AI Tools are pre-authorized and do not require review, absent any deviations from the requirements defined in this Policy: 

  • ​The use of Public data with any AI Tool; 
  • ​The use of (1) Internal-Use Only or (2) Confidential data with a USC Enterprise AI Tool; or 
  • ​The use of (1) Internal-Use Only or (2) Confidential data within USC locally hosted AI tools where data does not leave the local environment. 

​Note: Certain departments, schools, and units (DSUs) require local approval for AI-Tool use, even if the use is pre-authorized within this Policy. Please see the following link for DSU who have local approval requirements and the approving contacts: Local DSU Requirements for Pre-authorized AI Tool Use

Prohibited Uses of AI Tools 

​The following use cases for AI Tools are prohibited, absent extenuating circumstances and documented approval from the Offices of Cybersecurity, Ethics and Compliance, and General Counsel (and then only within the parameters specified in the approval): 

  • ​The use of Confidential – Controlled data with any AI Tool; 
  • ​The use of any AI Tool in a manner which violates any USC policy (e.g. the University’s Policy on Prohibited Discrimination, Harassment, and Retaliation). 

Approval Process for Other AI Tool Uses 

​For other use cases—the use of Confidential Data or Internal Use Only Data with non-USC Enterprise AI Tools— the risks and benefits of the specific tool and use case will be evaluated and approved on a case-by-case basis. Additional documentation regarding the process and information required to support the review process can be found here: AI Tool Review Process Overview

Policy Requirements 

​The below are requirements for the USC community related to the approved use of AI Tools. 

5.1 Protecting USC Data 

​5.1.1 AI Tools, like any technology, carry inherent risks of data exposure once data has been input. Therefore, all Covered Individuals must familiarize themselves with the following guidelines before using any AI Tools for USC purposes, on a USC network, or with USC data. 

​5.1.2 Covered Individuals and System Owners must abide by all applicable data protection and information security Policies when using AI Tools, including University information Security Policies and Standards. 

​5.1.3 In alignment with incident reporting requirements, Covered Individuals and System Owners must immediately report potential and suspected unauthorized disclosure or use of USC Confidential or Internal Use Only data. 

  • ​Possible and actual data privacy issues should be reported to a supervisor and the Office of Ethics and Compliance (compliance@usc.edu) or Report and Response (report.usc.edu) 
  • ​Possible and actual cybersecurity related issues should be reported to a supervisor and the USC Cyber Defense Team’s Security Operations Center (security@usc.edu

​5.1.4  AI tools also carry unique risks with respect to intellectual property. Covered Individuals must comply with all applicable intellectual property laws and University policies when using AI Tools. The use of AI Tools does not alter or diminish obligations relating to copyright, trademark, patent, licensing, attribution, citation, permissions, or other intellectual property requirements. Any use of AI-Tools for USC purposes must comply with applicable legal requirements and University policies governing the use of third-party intellectual property and other protected content. 

​5.1.5  USC Data may not be used to train, retrain, fine-tune, or otherwise improve third-party Artificial Intelligence or Machine Learning models unless expressly authorized by the University through an approved agreement and review process. Covered Individuals must ensure that AI tools and services are configured, where available, to disable use of USC Data for model training or product improvement. 

5.2 Protecting USC Integrity 

​5.2.1 Decisions affecting University operations, academic matters, employment actions, admissions, student outcomes, research conclusions, healthcare activities, or legal obligations may not rely solely on AI-generated outputs and require appropriate human review and judgment. 

​5.2.2 Covered Individuals may be subject to rules governing the use and disclosure of external assistance and sources, including, but not limited to AI Tools. Compliance with this Policy does not relieve an individual from their responsibility to comply will other applicable policies, including, but not limited to, the Integrity and Accountability Code, Faculty Handbook, Student Handbook, guidance issued by the Office of Research Integrity, IRB determinations, and any other specific Department, School, or Unit, or course requirements.  

5.3 Acquisition of Artificial Intelligence Tools 

​5.3.1 Contracting to purchase or receive access to any software or service that utilizes AI requires clear disclosure during the procurement process and adherence to applicable Third-Party Security Risk Management and Secure Systems Development policies and standards.  Following the approval for any AI software or service, all standard USC Procurement policies and processes are applicable to complete the purchase.  Additional review may be required during procurement-related contracting reviews. 

​5.3.1.1 Purchased AI Tools, which generally carry terms and conditions for use, must be processed in alignment with University and DSU-specific processes  

​5.3.1.2 All tools are also subject to the University’s Acceptable Use, Data Protection policies and other relevant University policies when used for USC purposes and/or when used on a USC network. 

​5.3.1.3  AI tools that create, transmit, store, or otherwise process Protected Health Information (PHI) or other HIPAA-covered data may be subject to additional requirements beyond this Policy, including (a) an executed Business Associate Agreement with the vendor, (b) approval by Keck Medicine of USC’s Office of Healthcare Compliance, (c) approval by a designated Keck Medicine of USC task force, and (d) deployment only within environments authorized for clinical or HIPAA-regulated use.  Additional details for Keck Medicine of USC relevant policies related to these requirements can be found in ISPOL-002 Acceptable Use Policy and ISPOL-039 Artificial Intelligence (AI) Responsible Use Policy. 

5.4 Use of Artificial Intelligence Tools 

​5.4.1 Covered Individuals must ensure that University-managed or otherwise authorized devices where AI Tools are directly installed meet USC security requirements, including current security updates for operating system and applications, minimum endpoint security coverage, and all other applicable requirements defined in USC information security Polices and Standards.  

​5.4.2 Access to an AI tool approved under this Policy must occur through an approved USC account or authentication method. Personal or unmanaged accounts must not be used for University business unless expressly authorized. 

​5.4.3 Covered Individuals must not connect an AI Tool to University systems, repositories, or third-party services without approval from the system or service owner. 

​5.4.4 Covered Individuals must not connect an AI Tool to University systems, repositories, or third-party services in a manner that expands data access beyond the authorized data type for the AI Tool and use case. 

5.5 Specific AI Use Case Considerations 

​5.5.1 Generative AI tools can provide value in creating new and novel content, but this comes with the inherent risk of inaccuracy, bias, and errors in generation which may result in fabrications (“hallucinations”), among other issues. Covered Individuals are responsible for checking outputs from Generative AI tools for accuracy and completeness. They are further responsible for any output generated by their use of an AI Tool when that output is used in USC work product. 

​5.5.2 Use of Agentic AI systems for USC business purposes requires appropriate human oversight and accountability. Covered Individuals may not deploy or utilize Agentic AI systems that: 

  • ​Independently make final decisions regarding admissions, academic standing, employment, discipline, healthcare, research compliance, or other matters that materially affect individuals or University operations without meaningful human review;  
  • ​Access or modify USC systems, records, or data repositories without authorization and appropriate technical safeguards;  
  • ​Automatically transmit USC data to external systems or third parties except as expressly permitted by University policy and applicable agreements; or 
  • ​Circumvent University security, privacy, or procurement requirements.  

​Covered Individuals remain responsible for all actions taken by Agentic AI systems operating on their behalf and must ensure outputs and actions are reviewed for accuracy, appropriateness, and compliance with University policy. For additional guidance on Agentic AI systems and USC access, refer to the resources listed on the USC Trojan Secure page. 

​5.5.3 Machine Learning systems developed, procured, or deployed for USC business purposes must be implemented in a manner consistent with applicable University policies relating to privacy, information security, ethics, and data governance. Machine Learning systems which perform the following may require additional review by the Office of Ethics and Compliance, Office of Cybersecurity, Office of the General Counsel, or other designated University offices: 

  • ​Process Confidential or Confidential – Controlled data;  
  • ​Make or materially support decisions affecting individuals (such as admissions decisions or employment decisions);  
  • ​Utilize personal information for profiling or automated decision-making; or  
  • ​Continuously train on USC data. 

​Where feasible, Covered Individuals and System Owners should maintain documentation describing the purpose of the model, data sources, limitations, performance characteristics, and monitoring processes used to assess accuracy, fairness, and reliability. 

6. Procedures

  • ​​Third Party Security Risk Management Process – Office of Cybersecurity 
  • ​Software Security Assessment Process – Office of Cybersecurity  
  • ​Policy Exception Process – Office of Cybersecurity​ 

7. Forms

None

8. Responsibilities

​​Responsibility for evaluating the risks of AI involves many groups, from individuals identified in Section 3 above, to the teams that support execution of the Policy including, but not limited, to the following: 

  • ​USC Office of Cybersecurity 
    • ​USC’s centralized cybersecurity team includes various groups responsible for data security. In the event of a possible security incident, the Cyber Defense team is responsible for investigating and mitigating damage. When security risks over vendors and AI Tools are shared, a combination of Third-Party Risk Management, Security Architecture, and Risk Assessment works to provide guidance on safe use of add-ins and tools. 
  • ​Office of Ethics and Compliance (OEC) 
    • OEC comprises several areas of expertise which support proper governance and compliance at USC. For example, when privacy concerns or possible incidents involving regulated data are identified, OEC’s Privacy Team are notified and provide guidance. In the event there are questions about the use of AI Tools in research compliance, OEC’s Research Compliance Team should be involved.​ 

9. Related Information

​​​Associated Policies and Standards 

Compliance Measurement  

​USC Cyber and the Office of Audit Services are responsible for ensuring compliance with this policy, USC’s information security policies and standards, and applicable federal and state laws and regulations. Compliance with cybersecurity related policies will be monitored regularly in conjunction with USC’s monitoring of its cybersecurity program. Audit Services will conduct periodic internal audits to ensure compliance. 

Non-Compliance  

​Violation of this Policy may be classified as serious misconduct, which is grounds for discipline in accordance with the Faculty Handbook, staff employment policies, and the Student Handbook as appropriate. Any disciplinary action under this Policy will consider the severity of the offense and the individual’s intent and could include termination of access to the USC network, USC systems, software, and/or applications, as well as employment actions up to and including termination. 

 10. Contacts

 Please direct any questions regarding this policy to:

OFFICEPHONEEMAIL
USC Office of Cybersecurity secgovrn@usc.edu