Purpose
This policy establishes guidelines and ethical standards for developing, acquiring, deploying, configuring, and using artificial-intelligence technologies at The University of Texas Rio Grande Valley (UTRGV). It is intended to enable AI to support academic, research, medical-school and health-training programs, clinical practice, medical facilities, and other University activities while meeting legal, ethical, privacy, security, fairness, and international requirements.
UTRGV supports innovation while protecting privacy, fairness, security, and academic integrity. The policy incorporates principles of fairness, transparency, accountability, human oversight, privacy by design, security by design, and continuous improvement, including the University's Code of Ethics for Responsible AI.
Scope and Applicability
This policy applies to faculty, staff, students, contractors, and vendors who design, procure, configure, or deploy AI systems for University purposes. It includes pilots and research projects that have operational impact.
Authority and Governing Requirements
AI use must comply with applicable federal law, State of Texas requirements, UT System policies, UTRGV rules and standards, international requirements when applicable, and the governance mechanisms established by this policy.
Definitions
Policy Requirements
1. Roles and Governance
UTRGV designates an AI Risk Officer (AIRO) and establishes an AI Governance Committee with representation from Legal, Privacy, Human Resources, Information Security, Information Technology, Research, Healthcare, Procurement, Academic Affairs, and other institutional areas as appropriate.
-
The AIRO ensures an AI Inventory is established and maintained, classifies AI risk, coordinates assessments and monitoring, and reports on incidents and program maturity.
-
The AI Governance Committee sets standards, reviews heightened-risk deployments, approves assessment instruments, ensures required training is available, and assists in establishing necessary controls.
-
The AI Governance Committee is chaired by the AIRO, and the policy assigns the AIRO responsibility for establishing the committee structure.
-
The AI Governance Committee supplements rather than replaces existing governance; its purpose is to ensure appropriate AI guardrails are present across UTRGV.
-
Organizational units remain responsible for ethical and compliant AI use within their operations.
-
Users are responsible for following applicable laws, rules, regulations, policies, and University requirements governing ethical and appropriate AI use.
2. Principles and General Guidelines
UTRGV expects AI development, deployment, and use to support transparency, accountability, fairness, privacy, intellectual-property protection, and responsible conduct.
2.1 Ethical Use
AI must be developed and used consistently with ethical standards, human rights, applicable law, UTRGV's code of conduct, and University values. Discriminatory, biased, malicious, or harmful AI use is prohibited.
AI development projects, AI applications, and AI-driven automated decision-making must undergo ethical review by the Data Owner to evaluate potential impacts on individuals, communities, and society. Ethical-use concerns should be sent to the appropriate University office for review and resolution.
2.2 Privacy and Data Protection
Personal data used in AI applications must be handled carefully. Users must protect privacy rights and handle personal, sensitive, and confidential data in accordance with applicable laws, regulations, and University policies.
2.3 Intellectual Property
Users must follow UTRGV and UT System guidance and applicable intellectual-property and copyright law. This includes respecting rights in software, algorithms, models, datasets, and other AI-related resources. Unauthorized distribution, copying, or modification of AI resources is prohibited.
2.4 Transparency and Accountability
AI development and use must be transparent, and responsibility for outcomes must be defined. AI-assisted decision processes must be explainable and accountable. At minimum:
-
provide clear user/public notices where applicable and do not represent AI as a human;
-
label synthetic media and use feasible content-provenance controls, such as watermarking or metadata, for generative outputs;
-
maintain system/model cards for applicable public-facing systems; and
-
provide complaint and redress channels with published response expectations.
2.5 Security
Users must protect AI systems and data, including safeguarding credentials, applying security patches, and complying with applicable laws, regulations, UTRGV policy, UT System requirements, Information Security Office requirements, and relevant security best practices to prevent unauthorized access or compromise.
2.6 Fairness and Non-Discrimination
AI models and algorithms must be designed and tested to reduce bias and discrimination and to support fair and equal treatment.
2.7 Stakeholder Involvement
Relevant stakeholders should be involved as appropriate. The source encourages participation by students, faculty, staff, administrators, regulators, and appropriate external parties who may be affected.
2.8 Education and Research
UTRGV encourages AI education and research and supports responsible AI development and dissemination of AI knowledge.
3. Responsible AI Usage
-
Bias and fairness: Users should seek to remove bias and promote fairness. Developers must actively identify and mitigate bias, with ongoing monitoring and testing.
-
Accuracy and reliability: Users who use AI-generated content are responsible for independently checking its accuracy and reliability. They must apply due diligence by reviewing, validating, and confirming AI output before relying on it in critical or official contexts.
-
Accountability: Individuals remain accountable for AI-assisted actions and decisions and must not rely solely on AI recommendations for important decisions.
-
Data usage: Data used by AI must be collected in accordance with UTRGV and UT System guidance and applicable law, including notices or consent where required. Users should contact the Information Security Office for guidance on acceptable AI data use.
-
Security and privacy: Appropriate safeguards must protect AI systems and their data throughout the AI lifecycle.
-
Accessibility: AI applications and systems should be accessible to all people, including people with disabilities.
4. Prohibited Activities
Users must not engage in AI-related conduct that violates UTRGV or UT System policy, State of Texas requirements, United States law or policy, or other applicable law or regulation.
5. Permissible Data and Data Protection
-
Controlled and Confidential Data: Such data may be used only with approved AI tools that have been evaluated by Information Technology and the Information Security Office, supporting compliance with relevant laws, regulations, and University policy.
-
Public Data: Public data may be used with AI tools, but the AI tool must complete and pass required IT and Information Security technology-assessment processes.
See also Data Governance Roles Definitions for the Data Owner and related governance roles.
6. Risk and Impact Assessments for Heightened-Risk Systems
Before deployment and after material changes, AI systems must undergo appropriate assessment intended to identify security vulnerabilities, inaccurate output, operational failures, and other foreseeable harms.
-
Complete an AI Risk Assessment addressing security risk, system limitations, foreseeable harms, and operational metrics such as accuracy, latency, uptime, and error rate.
-
Complete an AI Impact Assessment addressing stakeholders, description of training data, ownership and cadence of monitoring, and retention/deletion methods.
-
Provide a Human Oversight Plan for consequential uses, including reviewer qualifications, QA sampling, escalation thresholds, and authority to stop or override the system.
-
Obtain AI Governance Committee approval and AIRO sign-off before deployment.
7. Evaluation and Adversarial Testing
-
Define and execute evaluation plans covering accuracy, robustness, fairness, toxicity, and privacy leakage, using thresholds suitable for the use case.
-
Conduct adversarial testing for prompt injection, jailbreaks, model extraction, data poisoning, and privacy leakage, and document mitigations within the secure software-development lifecycle.
-
The source points readers to Systems Design Guidelines, division/college AI policies, UTRGV Information Technology Design Standards, the UTRGV Security Program Manual, and accessibility standards for additional design considerations.
8. Monitoring and Incident Response
-
Monitor production KPIs such as accuracy, fairness, toxicity, latency, and uptime; establish rollback/retraining triggers and sunset criteria.
-
Maintain an incident taxonomy and contact matrix, make notifications to regulators or partners as applicable, and perform post-incident reviews.
-
Reassess heightened-risk systems at least semiannually and after material changes, and retain required records and logs.
9. AI Inventory and Risk Classification
Every AI system must be registered in the AI Inventory maintained by the Information Security Office before pilot or deployment. Systems are risk-classified through the Information Security Office's risk-assessment process. The source describes heightened-risk systems as those that may materially affect rights, opportunities, safety, or access to services.
10. Compliance with Federal, State, UT System, and UTRGV Requirements
AI use must comply with relevant federal laws, Texas requirements, UT System policy, and UTRGV rules. The source highlights:
-
Federal Trade Commission guidance concerning AI and data protection;
-
Texas requirements concerning privacy, data protection, technology, and AI development;
-
UT System policies concerning technology use and ethical standards; and
-
UTRGV policies and standards, including Information Technology Standards, the Information Security Program Manual, other Information Security Standards, academic/research integrity requirements, and other system/service rules as applicable.
11. International Requirements and GDPR Compliance
When international requirements apply, UTRGV recognizes European AI requirements and the General Data Protection Regulation (GDPR), including the following source expectations:
-
AI systems must comply with applicable GDPR privacy and data-protection requirements.
-
AI development and use must align with applicable European ethical standards and guidance.
-
Applicable global legal, regulatory, and best-practice frameworks should be incorporated.
-
When personal data is processed, UTRGV applies privacy by design and security by design, completes required privacy reviews, and respects individual rights.
-
Where GDPR applies, complete a DPIA addendum addressing lawful basis by purpose and, when special-category data is involved, the applicable Article 9(2) basis.
-
Where EU AI Act high-risk or general-purpose AI requirements apply, attach the applicable EU module addressing quality-management linkage, conformity-assessment documentation, post-market monitoring, serious-incident reporting, and supply-chain role mapping.
Editorial preservation note: The source page combines the final two international requirements into a malformed line containing a stray character. This normalized version separates them for readability while retaining both requirements.
12. Additional Requirements
-
All non-student UTRGV account holders who can access UTRGV resources must complete Information Security Office AI training annually.
-
Any system that provides AI technology as part of a service, application, appliance, or software product must complete a Technology Assessment through approved UTRGV workflows before purchase, including open-source and free products/services, and again at intervals required by applicable law, regulation, UT System policy, or UTRGV policy.
-
Development of AI solutions must comply with applicable approval and change-management procedures required by law, regulation, UTS 165, and UTRGV policy. Development must also follow the Implementation Steps and Procedures for AI Technologies and supplemental Information Security Office requirements.
-
AI procurement and vendor requirements must be followed. At minimum:
-
contracts must require alignment with the NIST AI Risk Management Framework, transparency documentation such as system/model cards, material-change notifications, defined security posture, and audit rights;
-
generative-AI acquisitions should require feasible content-provenance capabilities and evidence of fairness/robustness evaluation; and
-
heightened-risk vendor systems must undergo periodic reassessment.
-
This policy is intended to make AI use responsible and ethical while enabling positive contributions to UTRGV's academic, research, medical, and institutional missions.
Roles and Responsibilities
Roles are defined principally in Section 1. In summary:
-
AI Risk Officer: AI inventory, risk classification, assessment/monitoring coordination, incident and maturity reporting, committee leadership, and required sign-off.
-
AI Governance Committee: standards, heightened-risk review, assessment instruments, training oversight, and required controls.
-
Organizational units: ethical and compliant AI operations within their areas.
-
Users: compliance with law and University requirements, verification of AI output, responsible use, and data/security obligations.
-
Data Owners: ethical review of AI development, applications, and AI-driven automated decision-making as specified by the source.
-
Information Security Office / Information Technology: AI inventory, risk assessment, technology assessment, security requirements, and approved-tool evaluation as described above.
Compliance and Enforcement
Non-compliance may result in suspension of system access or system use and other actions consistent with University policy. Required training, inventory registration, risk assessment, monitoring, testing, and periodic reassessment are compliance mechanisms within the policy.
Exceptions
The source does not establish a general AI-policy exception process. Systems must follow applicable UTRGV approval, risk-assessment, technology-assessment, governance, and change-management processes. Any exception mechanism should be aligned to an authoritative UTRGV Security Exception Standard/Process if adopted or published.
Related UTRGV Documents
-
Systems Design Guidelines (referenced by source; no page was exposed in the reviewed Information Security navigation)
-
UTRGV Information Technology Design Standards (referenced by source; no page was exposed in the reviewed Information Security navigation)
-
UTRGV Security Program Manual (referenced by source; no page was exposed in the reviewed Information Security navigation)
-
Implementation Steps and Procedures for AI Technologies (referenced by source; no page was exposed in the reviewed Information Security navigation)
External References
Source references retained:
-
NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative AI
-
NIST AI RMF Playbook
-
EU Regulation 2024/1689, Artificial Intelligence Act
-
EU GDPR, Articles 27, 37, and 39 (as listed by the source)
-
Texas Senate Bill 1964 / TAC 219 / Texas Government Code references as published by the source; see review report for current-law citation concerns
-
IAPP AI Governance Best Practices Report 2024
-
IAPP Responsible and Ethical AI Guidance
Additional current official references for owner/legal validation:
Review and Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823