Policy · Acceptable use

Guidelines.

How UMD expects you to use generative AI — written for the moment of decision, not the moment of audit. Pick your role, get a direct answer, and drill into the canonical policy if you need the formal language.

▌ Find your answer

What can you actually do?

The questions we hear most, answered plainly. Pick your role to filter — each answer links to the canonical policy section if you need the formal text.

Faculty
"Can my students use AI on assignments?"

It depends on what you've stated in your syllabus. Per the guidelines, students should assume AI use is not permitted unless you've said otherwise. Set a clear course policy — permitted, permitted-with-disclosure, or not permitted — and put it in the syllabus.

Faculty
"Can I use AI to grade?"

AI may assist with formative feedback or rubric drafting, but you retain full ownership of grading decisions under the Human Oversight principle. Decisions can't rely solely on AI outputs.

Faculty
"Should I use AI-detection tools?"

The guidelines caution against AI-detection tools due to FERPA risks — submitting student work to a third-party detector can expose protected information. Rely on syllabus policy and disclosure expectations instead.

Student
"Can I use ChatGPT for my paper?"

Assume not — unless your syllabus or instructor says otherwise. Unauthorized use is treated as cheating or plagiarism under the academic integrity standard. Check your course policy and ask your instructor if it isn't clear.

Student
"Do I need to cite AI use?"

Yes — when applicable. The Transparency principle requires you to disclose and, when applicable, attribute GenAI use. Follow your instructor's format; if none is specified, name the tool and describe how you used it.

Student
"Will my professor know if I used AI?"

AI-detection tools are not reliable, and the guidelines caution against using them. What matters is your obligation under transparency: disclose use when applicable. Failing to disclose authorized use is still a violation.

Researcher
"Can I put my research data into Claude or ChatGPT?"

Don't input Level 3+ classified data into external tools. For confidential research data, use a UMD-approved L3-cleared service (see the catalog). Unpublished findings and confidential materials should never go into a tool you don't control.

Researcher
"Do I need to disclose AI in publications?"

Yes. Disclose AI use with proper attribution and follow your journal's and funding agency's requirements. Different publishers have different rules; the Transparency principle requires you to meet whichever is stricter.

Researcher
"Can I share unpublished findings with an external AI?"

No. The guidelines explicitly say to avoid sharing unpublished research or confidential materials with external tools. If you need AI assistance with sensitive material, use a UMD-managed service approved for the appropriate data classification level.

Staff
"Can I use AI to draft an admin email?"

Yes, for general drafting — but use only UMD-approved tools when the content involves Level 2+ institutional data. Don't paste non-public institutional information into external platforms. And disclose AI-generated content in official communications.

Staff
"What data is okay to paste into AI tools?"

Level 1 (Public) is always okay in any approved tool. Level 2+ requires a UMD-approved tool. Level 3 needs an L3-cleared service (ChatGPT Enterprise or Claude per the catalog). Level 4 needs additional review. Never paste Level 3+ data into an external tool.

Staff · Faculty
"Can I procure a new AI tool for my department?"

Contact the AI team and DIT before you purchase — even free tools require review. Any AI tool that touches UMD data, supports instruction, or costs $25k+ goes through SRM. We'd rather talk it through before you commit than after.

↑ Back to top
▌ Guiding principles

The five principles.

UMD's GenAI Guidelines rest on five principles. Every acceptable-use rule downstream traces back to one of these.

Principle 01
Human Oversight

Users retain full ownership of their work. Decisions shouldn't rely solely on AI outputs — there's always a human judgment in the loop.

Principle 02
Access

UMD commits to addressing disparities in community usage so AI's benefits aren't unevenly distributed.

Principle 03
Privacy

Compliance with USM policies, FERPA, HIPAA, and Maryland data regulations is non-negotiable. Data classification is the practical lens you apply every time you choose a tool.

Principle 04
Transparency

Disclose AI use, and attribute it when applicable. The default is openness — whether you're a student citing a tool or a researcher disclosing in a publication.

Principle 05
Accountability

Users are responsible for understanding the capabilities and limitations of the tools they use — including their biases, error rates, and what they can't do well.

↑ Back to top
▌ Acceptable uses

What's allowed where.

The rules look different in a classroom than in a research lab than at a staff desk. Three buckets, with the specific dos and don'ts in each.

Section IV.1
Teaching and Learning
Classroom

For instructors, courses, and student work.

  • Students assume GenAI use is not permitted unless the syllabus says otherwise
  • Instructors set clear course policies — permitted, with disclosure, or not
  • Unauthorized use is treated as cheating or plagiarism
  • Be cautious with AI-detection tools — FERPA risks apply
Section IV.2
Research and Scholarship
Research

For investigators, grad students, and research staff.

  • Don't input Level 3+ data into external tools
  • Avoid sharing unpublished research or confidential materials
  • Disclose AI use with proper attribution in publications
  • Follow journal and funding agency requirements
Section IV.3
Administrative Work
Operations

For staff, administrators, and operational use.

  • Enhance efficiency while safeguarding sensitive information
  • Don't input non-public institutional data to external platforms
  • Use only UMD-approved tools for Level 2+ data
  • Disclose AI-generated content in official communications
↑ Back to top
▌ Data classification

What data goes where.

Before you pick a tool, know what classification level your data falls under. The Privacy principle and every Acceptable-Use rule trace back to this. UMD's IT-2 Data Classification Standard is the canonical source — this is the everyday summary.

Level 1
L1
Public
Open / Unrestricted

Information suitable for public distribution with no confidentiality restrictions.

Examples

  • Course catalogs and syllabi summaries
  • Published research and press releases
  • Public-facing UMD web content
Level 2
L2
Internal Use Only
Moderate

Intended for UMD community members but not for external distribution.

Examples

  • Internal communications and meeting notes
  • Draft documents and working files
  • Employee directories and routine operations
Level 3
L3
Confidential
High

Sensitive institutional information requiring restricted access and protection measures.

Examples

  • Student records and grades (FERPA)
  • Personnel files and performance reviews
  • Non-public research and financial records
Level 4
L4
Restricted
Highly Sensitive

Highly sensitive data with significant risk if disclosed. Requires stringent controls and additional review.

Examples

  • SSNs and financial account numbers
  • Medical records (HIPAA)
  • Highly sensitive PII
The examples above are illustrative, not exhaustive.

For the authoritative list of data types and the complete IT-2 Standard, use the official resources below. If you're unsure what level your data falls under, talk to the AI team before you choose a tool.

↑ Back to top
▌ The full policy

UMD GenAI Guidelines — verbatim.

Guidelines for the Use of Generative Artificial Intelligence (GenAI) Tools at UMD

Approved · January 15, 2025 · Effective 01/15/2025

The canonical policy as approved, preserved word-for-word. The FAQ answers above all link back to specific sections here. Use the table of contents to jump.

I. Purpose

Why these guidelines exist and what they aim to accomplish.

The University of Maryland (UMD) is committed to fostering innovation and academic excellence while prioritizing technology's privacy, security, and ethical use in its educational and research environments. Students, faculty, and staff are encouraged to explore how generative artificial intelligence (GenAI) tools can enhance their teaching, learning, and work.

These guidelines supplement established policies and provide best practices for the ethical, responsible, and equitable use of GenAI in teaching, learning, research, scholarship, and administrative functions. The goal is to promote transparency, enhance productivity, and uphold UMD's core values of integrity, inclusivity, and respect.

UMD expects its community members to follow these guidelines when using GenAI tools for teaching and learning, research, and work-related functions.

II. Scope

Who and what the guidelines apply to.

These guidelines apply to all UMD faculty, staff, students, and affiliates using GenAI tools and technologies in academic, research, or administrative activities. They cover UMD-approved tools, publicly available/externally sourced platforms (free or paid), and personally/departmentally developed applications used for UMD-related work. We encourage you to review these guidelines to ensure the responsible use of GenAI in your work and studies at UMD. This guidance will be reviewed and updated regularly as technology and best practices evolve.

III. Guiding Principles

The five principles every downstream rule traces back to.

The promise of GenAI is vast, offering the potential to reshape how we create, steward, and protect knowledge and scholarship. As members of the UMD community, we have a shared responsibility to foster a technology-rich environment where scholarship thrives while thoughtfully addressing the inherent risks of modern tools, such as data privacy, intellectual property, and content accuracy. A collective commitment to responsible and ethical use, both individually and institutionally, is crucial to navigating these evolving challenges. The following principles have been developed to guide our community's ethical and responsible design and use of GenAI tools.

  1. Human Oversight — Anyone using GenAI tools for any activity should take full ownership of the resulting product. Decisions affecting academic or administrative outcomes should include oversight by UMD officials with academic and/or administrative authority. Such decisions should not be based solely on outputs generated by GenAI tools.
  2. Access — UMD will strive to address potential disparities in access or usage within our community.
  3. Privacy — The use of GenAI should comply with the University System of Maryland (USM) and UMD data privacy policies and applicable laws and regulations, including but not limited to the Maryland Personal Information Protection Act, Family Educational Rights and Privacy Act (FERPA), and Health Insurance Portability and Accountability Act (HIPAA).
  4. Transparency — All users, including students, faculty, and staff, should disclose and, when applicable, make proper attribution when using GenAI tools in teaching, learning, research, scholarship, and administrative activities.
  5. Accountability — Faculty, staff, and students are responsible for understanding the capabilities and limitations of GenAI tools and ensuring appropriate use.

IV. Acceptable Uses

The three buckets — Teaching, Research, Administrative — with specific dos and don'ts.

At UMD, we are collectively responsible for maintaining intellectual honesty and scholarly integrity, both of which could be compromised by presenting GenAI-generated content as one's own work. Faculty, staff, and student-employees should use UMD-approved GenAI tools, such as TerpAI when working and teaching on behalf of UMD. GenAI tools should not be used to fabricate, falsify, or misrepresent information, impersonate individuals, or generate deceptive content except when intentionally employed by instructors or researchers for pedagogical or research purposes in a controlled and ethical manner.

They should also be aware that accepting click-through agreements using UMD credentials without delegated signature authority may result in personal responsibility for compliance with the terms and conditions of the AI tool. UMD strongly recommends that all students utilize UMD-approved tools for study, as they are deployed in alignment with institutional security and compliance requirements.

1. Teaching and Learning

Instructors are strongly encouraged to establish a course-specific policy that defines the appropriate and inappropriate use of GenAI tools. Students should assume that the use of GenAI tools to complete course assignments and assessments is not allowed unless otherwise specified in the course syllabus or assignment/assessment instructions. While using GenAI tools as a learning aid—such as for practicing problems, exploring concepts, or reviewing definitions—is a common practice, students should confer with their instructors about academic integrity policies within their particular courses and assignments.

Students — Students should consult with their instructors, teaching assistants, and mentors to clarify expectations regarding the use of GenAI tools in a given course. When permitted by the instructor, students should appropriately acknowledge and cite their use of GenAI applications. When conducting research-related activities (e.g., theses, comprehensive exams, dissertations), students should refer to the guidance below for research and scholarship. Allegations of unauthorized use of GenAI will be treated similarly to allegations of unauthorized assistance (cheating) or plagiarism and investigated by the Office of Student Conduct.

Faculty and Instructors — Instructors are encouraged to help students develop critical thinking skills about the use of GenAI tools, fostering workforce readiness and preparing them to navigate the technology-rich world we all inhabit. This can be achieved through class discussions, assignments, or by incorporating the AI Literacy module developed by the Teaching and Learning Transformation Center and University Libraries into ELMS-Canvas course spaces.

It will be at the course instructor's discretion to determine whether GenAI may be used, to what extent, and for which assignments and assessments. Instructors are strongly encouraged to establish a course-specific policy that defines the appropriate and inappropriate use of GenAI tools, fostering transparency and understanding between instructors and students. These expectations should be clearly outlined in the course syllabus (see suggested language), shared through relevant course policies, and reinforced during class discussions. Explicit and transparent decisions about limiting or integrating GenAI tools into coursework can strengthen students' understanding of academic integrity while promoting meaningful learning.

If using GenAI to create course materials or assist in grading processes, instructors are advised to use the same level of oversight and transparency they would expect of students using these tools in their academic work.

The Division of Academic Affairs advises against incorporating GenAI detection tools into course policies. However, if an instructor plans to use such tools, they should clearly communicate to students the reasons for their use and how they will be interpreted and acted on. Results from GenAI detection tools should be treated only as potential indicators of misconduct, not definitive proof. These results should not serve as the sole basis for grading decisions. While information from these tools may be included in referrals to the Office of Student Conduct, such information alone will not solely determine a student's responsibility. GenAI detection tools may expose students' information to third parties without proper authorization, potentially violating FERPA, other privacy laws, or institutional policies. This risk persists even if an individual's name is removed from an assignment. Faculty should exercise caution about inputting student work into these tools. For guidance on GenAI and de-identification, contact the Privacy Office at umd-privacy@umd.edu.

Teaching Assistants (TAs), Graders, and Tutors — TAs, graders, and tutors must ensure alignment with instructors and/or program-specific guidance regarding the use of GenAI tools within a given course. They should adhere to the instructors' and/or programs' expectations regarding whether, how, and when students may use GenAI tools. TAs, Graders, and Tutors should only use GenAI to assist students, create course materials, and grade assignments with the instructor's approval. They are advised to use the same level of oversight and transparency expected of instructors using GenAI tools.

2. Research and Scholarship

Researchers are encouraged to consult with co-investigators, advisors, collaborators, funding agencies, and field experts to evaluate the appropriateness of using GenAI technology in research activities.

Maintaining research integrity and safeguarding intellectual property, confidentiality, and ethical standards are essential when using GenAI tools. All users should review and evaluate the output for accuracy and potential bias and should disclose the use of GenAI with proper attribution.

Researchers should follow specific policies set by journals, funding agencies, and professional societies when reporting research. Many federal agencies use tools to detect AI-generated content, as GenAI tools often paraphrase from other sources, raising concerns regarding plagiarism and intellectual property. Researchers should take extra caution before inputting confidential, proprietary, or sensitive data classified as high risk (Level 3) or higher into GenAI tools, even those approved by UMD. If you are uncertain, it is advisable to consult the DIT Privacy Office by contacting umd-privacy@umd.edu.

Researchers should not input federal, state, or UMD data into externally sourced GenAI tools due to the high risk of exposing sensitive information to public or open-source domains. They should also avoid using GenAI-automated meeting tools to record or capture discussions involving sensitive data or topics. If unsure about the recording practices of external hosts, vendors, or subcontractors, researchers should seek clarification to ensure compliance and appropriateness. If a host insists on using GenAI-automated tools despite concerns, UMD researchers are advised to decline participation to protect institutional data integrity and privacy.

Externally sourced GenAI tools remain subject to the State of Maryland and UMD procurement policies and procedures. Researchers should not upload unpublished research data or other confidential information into GenAI tools that have not undergone proper review. Entering information into tools that have not been reviewed and authorized may compromise future intellectual property protections, lead to unauthorized disclosure of research data, and/or create privacy violations for research subjects or collaborators. Confidential materials, such as unpublished manuscripts, funding proposals under peer review, or personal information about research subjects, should not be shared with GenAI tools. For instance, uploading interview data could result in quotations or sensitive information being inadvertently made public.

Researchers should exercise caution, as AI-generated outputs may infringe on third-party intellectual property rights. GenAI responses are derived from preexisting works, and their use in research may require additional scrutiny to avoid legal or ethical conflicts. For research that may result in invention, the US Patent and Trademark Office recognizes AI-assisted inventions, and patent protection may be sought where one or more persons have made a significant contribution to the invention.

All research at UMD is subject to institutional policies, including the UMD Policy on Intellectual Property, the Policy on Copyrights, the UMD Code of Academic Integrity, Policy and Procedures Concerning Scholarly Misconduct, and the Policy on Conflict of Interest and Conflict of Commitment. Researchers should familiarize themselves with these and all related policies, which can be accessed through institutional websites.

3. Administrative Work

GenAI tools are encouraged to enhance work efficiency and productivity. However, their use should align with institutional policies, safeguard sensitive information, and ensure outputs are accurate, unbiased, and appropriate for the intended purpose.

In addition to the above guidance for teaching, learning, research, and scholarship, GenAI tools may also be utilized for administrative purposes, including, but not limited to, streamlining workflows, assisting with business processes, drafting communications, and assembling information to inform decision-making. When leveraging GenAI for administrative tasks, ensuring full compliance with privacy standards and all relevant institutional policies, standards, and guidelines is essential. Administrative staff should not input any institutional data that is not publicly available into externally sourced platforms (free or paid) using GenAI tools. This restriction applies to any confidential or proprietary business information belonging to UMD. In such cases, administrative staff must rely exclusively on UMD-approved GenAI tools, such as TerpAI, which are deployed in alignment with institutional security and compliance requirements. While conducting work on behalf of UMD, faculty, and staff should not input institutional data classified as moderate risk (Level 2) or higher into publicly available/externally sourced platforms (free or paid) using GenAI tools.

The use of GenAI tools for administrative purposes must also align with unit-specific guidance to ensure consistency with operational and legal standards. Before integrating GenAI tools into their work processes, individuals must consult with their supervisors to discuss appropriate use in their specific roles, clarify expectations, and determine the scope of permissible applications. Furthermore, any AI-generated content in official communications, documents, or reports should be disclosed and appropriately attributed.

To promote transparency and accountability in using administrative applications of GenAI, individuals should ensure that AI-generated outputs meet quality and accuracy standards before using or distributing them. Retaining records of AI-generated drafts or outputs is recommended, particularly when assembling information to inform decision-making or drafting external communications.

V. Implementation

UMD's right to monitor, periodic review, and how misuse is reported.

GenAI tools are treated as any other IT system or platform used to conduct UMD business, with robust safeguards to ensure privacy, security, and responsible use. UMD-approved GenAI tools meet institutional standards for data protection, comply with privacy laws, and align with UMD policies. These tools undergo rigorous evaluation to ensure they are safer and more secure than publicly available alternatives, which may lack adequate safeguards for sensitive information, intellectual property, or user privacy. By utilizing UMD-approved GenAI tools, individuals can minimize risks while supporting the responsible and effective integration of these technologies.

Data and Prompts Management — Pursuant to UMD's Privacy Policy and Standards, UMD reserves the right to access and review prompts, outputs, or other information from GenAI tools—similar to any other IT system or platform provided by UMD—for purposes such as monitoring for and flagging inappropriate content, improving model performance, and investigating actual or suspected misconduct or incidents that pose risks to the UMD community or third parties. Any investigation will be conducted in compliance with UMD's privacy policies, ensuring that the review process itself does not violate individual privacy.

Periodic Review — These guidelines will be reviewed periodically to reflect advancements in GenAI technologies and ensure alignment with UMD's mission and values.

Report Misuse — Similar to any other IT system or platform UMD provides, individuals should report any potential compliance or ethical concerns related to using GenAI tools to their department leadership or directly to Project NEThics.

GenAI Tools Feedback — UMD has designated dit-ais@umd.edu as the primary communication channel for submitting questions, reporting concerns, sharing feedback, and suggesting improvements regarding UMD-approved GenAI tools and related practices.

VI. Procuring AI Tools/Software (including free tools)

Contact DIT before accessing or purchasing — even free tools require review.

UMD recognizes the financial and operational implications of providing campus-wide access to GenAI tools. While these technologies offer meaningful benefits, their costs—particularly for GenAI maintenance—are expected to rise as companies adjust pricing models to achieve profitability. UMD is committed to regularly evaluating these tools, including cost projections and value assessments, to ensure investments align with institutional priorities, fiscal responsibility, and long-term sustainability.

To mitigate risks and ensure compliance, individuals intending to use UMD credentials to access or purchase products or tools with GenAI functionality should contact the Division of IT at it-support@umd.edu before signing up. This requirement holds true even if the product is offered for free or as open source. DIT's compliance team will route the request to resources to help validate the vendor's product and verify that the contract language does not introduce undue risk to UMD.

VII. Selected Available Resources

Reference links organized by topic.

General Information

Teaching & Learning

Research

IT Support

Related Policies and Procedures

Academic Publishers' Guidelines and Policies on AI in Research

VIII. Attribution

How the guidelines document itself was prepared.

To refine the final language, this document was edited with the help of Grammarly (2024) and Terp-OpenAI (2024).

IX. Contact Information

Who to reach with questions about the guidelines.

For questions or further information about these guidelines, please contact:

Office of the Senior Vice President & Provost
provost@umd.edu
301.405.5252

X. History

Approval and revision history.

Approved: 01/15/2025
Effective Date: 01/15/2025

↑ Back to top
▌ Where to next

Apply the rules.

Guidelines on their own don't pick a tool. These do.