Information Security Docs
Breadcrumbs

Artificial Intelligence (AI) Policy

Purpose

This policy establishes guidelines and ethical standards for developing, acquiring, deploying, configuring, and using artificial-intelligence technologies at The University of Texas Rio Grande Valley (UTRGV). It is intended to enable AI to support academic, research, medical-school and health-training programs, clinical practice, medical facilities, and other University activities while meeting legal, ethical, privacy, security, fairness, and international requirements.

UTRGV supports innovation while protecting privacy, fairness, security, and academic integrity. The policy incorporates principles of fairness, transparency, accountability, human oversight, privacy by design, security by design, and continuous improvement, including the University's Code of Ethics for Responsible AI.

Scope and Applicability

This policy applies to faculty, staff, students, contractors, and vendors who design, procure, configure, or deploy AI systems for University purposes. It includes pilots and research projects that have operational impact.

Authority and Governing Requirements

AI use must comply with applicable federal law, State of Texas requirements, UT System policies, UTRGV rules and standards, international requirements when applicable, and the governance mechanisms established by this policy.

Definitions

Click to expand...

Artificial Intelligence (AI): A field of computer science focused on systems that perform tasks usually associated with human intelligence. AI can include learning, reasoning, problem solving, self-correction, and natural-language understanding. Applications can include expert systems, NLP, speech recognition, and machine vision.

Machine Learning (ML): A subset of AI in which systems learn and improve from experience rather than relying only on explicit programming. ML algorithms process data to identify patterns and support predictions or decisions.

Deep Learning: A specialized form of machine learning based on multi-layer neural networks and useful for complex abstraction tasks such as image and speech recognition.

Algorithm: A set of rules or instructions used by an AI system to learn, make decisions, or solve problems.

Neural Network: A set of algorithms intended to recognize relationships in data through structures inspired by the way the human brain processes information; neural networks are foundational to deep learning.

Natural Language Processing (NLP): An AI field concerned with computer interaction using human language, including understanding, interpreting, and responding to language.

Ethics in AI: Principles and guidance intended to make AI development and use fair, transparent, accountable, and beneficial.

Bias in AI: Systematic and unfair discrimination that can arise from data, algorithms, or practices and produce unjust outcomes.

Data Protection: Measures and processes used to protect the privacy and security of data used in AI systems and to meet relevant legal and ethical requirements.

Artificial General Intelligence (AGI): A type of AI conceived as capable of understanding, learning, and applying knowledge in a manner indistinguishable from human intelligence across intellectual tasks.

Supervised Learning: Machine learning using labeled training data in which inputs are paired with expected outputs so the model can learn predictions.

Unsupervised Learning: Machine learning using unlabeled data in which the model identifies patterns and relationships without predefined outputs.

Reinforcement Learning: Machine learning in which an agent learns by taking actions in an environment to maximize cumulative reward.

Computer Vision: AI that enables computers to interpret visual information such as images and video and make decisions based on it.

Robotics: Technology concerned with designing, constructing, operating, and applying robots, often incorporating AI for autonomous behavior.

Generative AI: AI that creates new content, including text, images, or music, based on training data. The source provides GPT-3 and DALL-E as examples.

Explainable AI (XAI): AI designed to provide explanations that humans can understand for system decisions and actions, supporting transparency and trust.

Federated Learning: A machine-learning method that trains across multiple decentralized devices or servers holding local data without directly exchanging those local data samples, supporting data privacy.

Personal Data: Information linked or reasonably linkable to an identified or identifiable individual, such as names, contact information, identifiers, and digital identifiers. The source also includes sensitive categories under Texas law, such as racial or ethnic origin, religious beliefs, health information, biometric identifiers, precise geolocation, and data about children under 13. For AI systems, the term includes such information used for automated decisions, profiling, or inference and requires compliance with applicable privacy and AI laws, including the Texas Data Privacy and Security Act and the Texas Responsible Artificial Intelligence Governance Act (TRAIGA).

Policy Requirements

1. Roles and Governance

UTRGV designates an AI Risk Officer (AIRO) and establishes an AI Governance Committee with representation from Legal, Privacy, Human Resources, Information Security, Information Technology, Research, Healthcare, Procurement, Academic Affairs, and other institutional areas as appropriate.

  • The AIRO ensures an AI Inventory is established and maintained, classifies AI risk, coordinates assessments and monitoring, and reports on incidents and program maturity.

  • The AI Governance Committee sets standards, reviews heightened-risk deployments, approves assessment instruments, ensures required training is available, and assists in establishing necessary controls.

  • The AI Governance Committee is chaired by the AIRO, and the policy assigns the AIRO responsibility for establishing the committee structure.

  • The AI Governance Committee supplements rather than replaces existing governance; its purpose is to ensure appropriate AI guardrails are present across UTRGV.

  • Organizational units remain responsible for ethical and compliant AI use within their operations.

  • Users are responsible for following applicable laws, rules, regulations, policies, and University requirements governing ethical and appropriate AI use.

2. Principles and General Guidelines

UTRGV expects AI development, deployment, and use to support transparency, accountability, fairness, privacy, intellectual-property protection, and responsible conduct.

2.1 Ethical Use

AI must be developed and used consistently with ethical standards, human rights, applicable law, UTRGV's code of conduct, and University values. Discriminatory, biased, malicious, or harmful AI use is prohibited.

AI development projects, AI applications, and AI-driven automated decision-making must undergo ethical review by the Data Owner to evaluate potential impacts on individuals, communities, and society. Ethical-use concerns should be sent to the appropriate University office for review and resolution.

2.2 Privacy and Data Protection

Personal data used in AI applications must be handled carefully. Users must protect privacy rights and handle personal, sensitive, and confidential data in accordance with applicable laws, regulations, and University policies.

2.3 Intellectual Property

Users must follow UTRGV and UT System guidance and applicable intellectual-property and copyright law. This includes respecting rights in software, algorithms, models, datasets, and other AI-related resources. Unauthorized distribution, copying, or modification of AI resources is prohibited.

2.4 Transparency and Accountability

AI development and use must be transparent, and responsibility for outcomes must be defined. AI-assisted decision processes must be explainable and accountable. At minimum:

  • provide clear user/public notices where applicable and do not represent AI as a human;

  • label synthetic media and use feasible content-provenance controls, such as watermarking or metadata, for generative outputs;

  • maintain system/model cards for applicable public-facing systems; and

  • provide complaint and redress channels with published response expectations.

2.5 Security

Users must protect AI systems and data, including safeguarding credentials, applying security patches, and complying with applicable laws, regulations, UTRGV policy, UT System requirements, Information Security Office requirements, and relevant security best practices to prevent unauthorized access or compromise.

2.6 Fairness and Non-Discrimination

AI models and algorithms must be designed and tested to reduce bias and discrimination and to support fair and equal treatment.

2.7 Stakeholder Involvement

Relevant stakeholders should be involved as appropriate. The source encourages participation by students, faculty, staff, administrators, regulators, and appropriate external parties who may be affected.

2.8 Education and Research

UTRGV encourages AI education and research and supports responsible AI development and dissemination of AI knowledge.

3. Responsible AI Usage

  • Bias and fairness: Users should seek to remove bias and promote fairness. Developers must actively identify and mitigate bias, with ongoing monitoring and testing.

  • Accuracy and reliability: Users who use AI-generated content are responsible for independently checking its accuracy and reliability. They must apply due diligence by reviewing, validating, and confirming AI output before relying on it in critical or official contexts.

  • Accountability: Individuals remain accountable for AI-assisted actions and decisions and must not rely solely on AI recommendations for important decisions.

  • Data usage: Data used by AI must be collected in accordance with UTRGV and UT System guidance and applicable law, including notices or consent where required. Users should contact the Information Security Office for guidance on acceptable AI data use.

  • Security and privacy: Appropriate safeguards must protect AI systems and their data throughout the AI lifecycle.

  • Accessibility: AI applications and systems should be accessible to all people, including people with disabilities.

4. Prohibited Activities

Users must not engage in AI-related conduct that violates UTRGV or UT System policy, State of Texas requirements, United States law or policy, or other applicable law or regulation.

5. Permissible Data and Data Protection

  • Controlled and Confidential Data: Such data may be used only with approved AI tools that have been evaluated by Information Technology and the Information Security Office, supporting compliance with relevant laws, regulations, and University policy.

  • Public Data: Public data may be used with AI tools, but the AI tool must complete and pass required IT and Information Security technology-assessment processes.

See also Data Governance Roles Definitions for the Data Owner and related governance roles.

6. Risk and Impact Assessments for Heightened-Risk Systems

Before deployment and after material changes, AI systems must undergo appropriate assessment intended to identify security vulnerabilities, inaccurate output, operational failures, and other foreseeable harms.

  • Complete an AI Risk Assessment addressing security risk, system limitations, foreseeable harms, and operational metrics such as accuracy, latency, uptime, and error rate.

  • Complete an AI Impact Assessment addressing stakeholders, description of training data, ownership and cadence of monitoring, and retention/deletion methods.

  • Provide a Human Oversight Plan for consequential uses, including reviewer qualifications, QA sampling, escalation thresholds, and authority to stop or override the system.

  • Obtain AI Governance Committee approval and AIRO sign-off before deployment.

7. Evaluation and Adversarial Testing

  • Define and execute evaluation plans covering accuracy, robustness, fairness, toxicity, and privacy leakage, using thresholds suitable for the use case.

  • Conduct adversarial testing for prompt injection, jailbreaks, model extraction, data poisoning, and privacy leakage, and document mitigations within the secure software-development lifecycle.

  • The source points readers to Systems Design Guidelines, division/college AI policies, UTRGV Information Technology Design Standards, the UTRGV Security Program Manual, and accessibility standards for additional design considerations.

8. Monitoring and Incident Response

  • Monitor production KPIs such as accuracy, fairness, toxicity, latency, and uptime; establish rollback/retraining triggers and sunset criteria.

  • Maintain an incident taxonomy and contact matrix, make notifications to regulators or partners as applicable, and perform post-incident reviews.

  • Reassess heightened-risk systems at least semiannually and after material changes, and retain required records and logs.

9. AI Inventory and Risk Classification

Every AI system must be registered in the AI Inventory maintained by the Information Security Office before pilot or deployment. Systems are risk-classified through the Information Security Office's risk-assessment process. The source describes heightened-risk systems as those that may materially affect rights, opportunities, safety, or access to services.

10. Compliance with Federal, State, UT System, and UTRGV Requirements

AI use must comply with relevant federal laws, Texas requirements, UT System policy, and UTRGV rules. The source highlights:

  • Federal Trade Commission guidance concerning AI and data protection;

  • Texas requirements concerning privacy, data protection, technology, and AI development;

  • UT System policies concerning technology use and ethical standards; and

  • UTRGV policies and standards, including Information Technology Standards, the Information Security Program Manual, other Information Security Standards, academic/research integrity requirements, and other system/service rules as applicable.

11. International Requirements and GDPR Compliance

When international requirements apply, UTRGV recognizes European AI requirements and the General Data Protection Regulation (GDPR), including the following source expectations:

  • AI systems must comply with applicable GDPR privacy and data-protection requirements.

  • AI development and use must align with applicable European ethical standards and guidance.

  • Applicable global legal, regulatory, and best-practice frameworks should be incorporated.

  • When personal data is processed, UTRGV applies privacy by design and security by design, completes required privacy reviews, and respects individual rights.

  • Where GDPR applies, complete a DPIA addendum addressing lawful basis by purpose and, when special-category data is involved, the applicable Article 9(2) basis.

  • Where EU AI Act high-risk or general-purpose AI requirements apply, attach the applicable EU module addressing quality-management linkage, conformity-assessment documentation, post-market monitoring, serious-incident reporting, and supply-chain role mapping.

Editorial preservation note: The source page combines the final two international requirements into a malformed line containing a stray character. This normalized version separates them for readability while retaining both requirements.

12. Additional Requirements

  1. All non-student UTRGV account holders who can access UTRGV resources must complete Information Security Office AI training annually.

  2. Any system that provides AI technology as part of a service, application, appliance, or software product must complete a Technology Assessment through approved UTRGV workflows before purchase, including open-source and free products/services, and again at intervals required by applicable law, regulation, UT System policy, or UTRGV policy.

  3. Development of AI solutions must comply with applicable approval and change-management procedures required by law, regulation, UTS 165, and UTRGV policy. Development must also follow the Implementation Steps and Procedures for AI Technologies and supplemental Information Security Office requirements.

  4. AI procurement and vendor requirements must be followed. At minimum:

    • contracts must require alignment with the NIST AI Risk Management Framework, transparency documentation such as system/model cards, material-change notifications, defined security posture, and audit rights;

    • generative-AI acquisitions should require feasible content-provenance capabilities and evidence of fairness/robustness evaluation; and

    • heightened-risk vendor systems must undergo periodic reassessment.

This policy is intended to make AI use responsible and ethical while enabling positive contributions to UTRGV's academic, research, medical, and institutional missions.

Roles and Responsibilities

Roles are defined principally in Section 1. In summary:

  • AI Risk Officer: AI inventory, risk classification, assessment/monitoring coordination, incident and maturity reporting, committee leadership, and required sign-off.

  • AI Governance Committee: standards, heightened-risk review, assessment instruments, training oversight, and required controls.

  • Organizational units: ethical and compliant AI operations within their areas.

  • Users: compliance with law and University requirements, verification of AI output, responsible use, and data/security obligations.

  • Data Owners: ethical review of AI development, applications, and AI-driven automated decision-making as specified by the source.

  • Information Security Office / Information Technology: AI inventory, risk assessment, technology assessment, security requirements, and approved-tool evaluation as described above.

Compliance and Enforcement

Non-compliance may result in suspension of system access or system use and other actions consistent with University policy. Required training, inventory registration, risk assessment, monitoring, testing, and periodic reassessment are compliance mechanisms within the policy.

Exceptions

The source does not establish a general AI-policy exception process. Systems must follow applicable UTRGV approval, risk-assessment, technology-assessment, governance, and change-management processes. Any exception mechanism should be aligned to an authoritative UTRGV Security Exception Standard/Process if adopted or published.

  • Acceptable Use Policy

  • Computer Security Standard

  • Multi-Factor Authentication Standard

  • Data Governance Roles Definitions

  • Systems Design Guidelines (referenced by source; no page was exposed in the reviewed Information Security navigation)

  • UTRGV Information Technology Design Standards (referenced by source; no page was exposed in the reviewed Information Security navigation)

  • UTRGV Security Program Manual (referenced by source; no page was exposed in the reviewed Information Security navigation)

  • Implementation Steps and Procedures for AI Technologies (referenced by source; no page was exposed in the reviewed Information Security navigation)

External References

Source references retained:

  • NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative AI

  • NIST AI RMF Playbook

  • EU Regulation 2024/1689, Artificial Intelligence Act

  • EU GDPR, Articles 27, 37, and 39 (as listed by the source)

  • Texas Senate Bill 1964 / TAC 219 / Texas Government Code references as published by the source; see review report for current-law citation concerns

  • IAPP AI Governance Best Practices Report 2024

  • IAPP Responsible and Ethical AI Guidance

Additional current official references for owner/legal validation:

Review and Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823