106 AI Administrative Governance Policy

1.0 Purpose

The University of Alaska Anchorage adopts artificial intelligence (AI) to improve the quality, efficiency, and reach of its administrative and business operations. AI systems increasingly read University data, invoke University systems, and take actions that were historically performed only by authenticated people, and they do so at machine speed and scale. That capability creates value, but it also creates new risks to the security of University information systems, the confidentiality and integrity of University data, the accountability of University actions, and the University’s compliance with law, regulation, and contractual obligation. This Policy exists to establish the University’s guiding principles and standards to managing technical, data, cybersecurity risk for governing AI in University administrative business, so that the University can adopt AI capability deliberately and on a sound risk basis rather than by default.

This Policy protects the University’s interests in secure and reliable information resources, in properly classified and protected data, in decisions that remain accountable to identifiable people, and in compliance with the legal and regulatory regimes that govern University information. It establishes the authority of the UAA Chief Information Officer (CIO) to issue standards that govern both the use of AI in the University’s administrative and business functions and the technology and infrastructure layer that provides, supports, and manages AI capability for University business use.

2.0 Policy

The University will govern the adoption and operation of AI in its administrative business functions on a risk basis, under the established guiding principles below through its child standards. Every use of AI that touches University information resources in the conduct of University business is subject to this Policy and to the standards issued under it.

2.1 Scope

This Policy applies to all University units, employees, students, and affiliates acting in an administrative or employment capacity who develop, procure, configure, deploy, or operate AI systems that are used in the University’s administrative or business functions or that authenticate to or access University information resources for those functions. It applies regardless of the source of funding, the hosting location, or whether the AI is University-built, commercially procured, or embedded within a broader platform. It applies to the AI technology and infrastructure layer — the platforms, services, connectors, gateways, and identities that provide, support, and manage AI capability for University business use — wherever that layer is operated.

This Policy establishes authority and principle; it does not itself prescribe the detailed, compliance-required controls that implement it. Those controls are set in the child standards.

2.1.1 Not-In-Scope

This Policy does not govern the use of AI in teaching, learning, or research activities. Decisions about whether and how AI may be used in instruction, coursework, scholarship, and research rest with the University’s academic and research governance and with the applicable academic and research-integrity policies, not with this Policy.

The technology and infrastructure layer that supports and manages AI for teaching, learning, and research is, however, in scope. When the University provides, supports, secures, or manages the platforms, services, identities, or infrastructure that deliver AI capability — including AI used for academic or research purposes — that infrastructure and platform support and management is governed by this Policy and the standards under it. In short: the pedagogical and research use of AI is out of scope; the technology layer that provides and manages the AI capability is in scope. Uses excluded here remain subject to the University’s acceptable-use, data-classification, and information-security requirements.

2.2 Authority

This Policy is established by the UAA CIO. Under it, the CIO holds the authority to establish, issue, interpret, maintain, and enforce standards governing (a) the integration of AI into the University’s administrative and business systems and data and (b) the AI technology and infrastructure layer that provides, supports, and manages AI capability for University business use. The CIO is the approval authority for those standards and for exceptions and variances granted under them.

The CIO does not determine the appropriate thresholds of human-in-the-loop standards such as which steps in a business process must be performed by a human and not by AI, except within the context of IT business processes.

2.3 Guiding Principles

The following principles govern AI in University administrative and business functions and direct the standards issued under this Policy.

  • Human accountability and oversight. AI supports and augments human judgment; it does not replace human accountability. Consequential decisions and actions — approvals, commitments of funds, actions on regulated data, and irreversible operations — remain reserved to identifiable people. AI may prepare or recommend; a human decides and is answerable.
  • Responsible and human-centered adoption. AI is designed, selected, and deployed with attention to the potential impacts of automated decision-making, including fairness, bias, transparency, and effect on people.
  • Security and zero trust. AI systems are treated as untrusted until authenticated and authorized. Each AI system, wherever technically possible, operates under a verifiable identity, receives only the access its function requires, reaches University resources through controlled and monitored paths, and is subject to the University’s information-security controls, consistent with a zero-trust posture.
  • Least privilege. AI systems are granted the minimum access necessary for a defined function, for the minimum necessary duration, and never more than the people or processes they serve. Where possible access to hardware and operating systems should be time-limited to the duration for the specific assigned task.
  • Attribution and non-repudiation. Every AI action against a University resource is attributable to a specific, verifiable identity (department or individual) and, where the AI acts for a person, to that person. Actions taken under a user’s identity are the responsibility of that user. AI activity is logged so that who or what did what, on whose behalf, can be reconstructed and cannot be credibly denied.
  • Data protection by classification. AI access to University data is governed by the data’s classification — Public, Internal Use, and Restricted — under University Regulation R02.07.093. More sensitive data receives stronger controls, and Internal Use or Restricted data is not exposed to AI systems or services that lack the required protections.
  • Compliance with law and regulated-data regimes. AI use conforms to Board of Regents Policy, University Regulation, University acceptable-use requirements and codes of conduct, and applicable state, federal, and international law — including regimes such as FERPA, HIPAA, GLBA, PCI DSS, export controls, and copyright and other intellectual-property law — where the AI use case touches data or activity those regimes govern.
  • Risk-based adoption. AI capability is adopted in proportion to the risk it presents. The University weighs the value of an AI use against its risk to security, data, accountability, and compliance, and applies controls, review, or restriction accordingly rather than permitting or prohibiting AI categorically.
  • The University is clear about where and how AI is used in its business functions, what data an AI use case involves, and who is accountable for it, so that AI activity is visible to those who govern, audit, and rely on University systems.

3.0 Procedures

Standards and guidelines under this Policy are issued, updated, and retired by the CIO. They are reviewed on a regular cycle and additionally when there are significant changes in AI capability, vendor platform features, the University’s risk posture, or applicable law, regulation, or higher University authority.

4.0 Definitions

See UAA IT Policies and Standards Definitions.

5.0 References

Governing authority (binding on this Policy). This Policy conforms to these; where they and this Policy both apply, they govern.

  • University of Alaska Board of Regents Policy and University Regulation, Chapter 02.07 – Information Resources.
  • University Regulation R02.07.090–.094, Data Classification (Public, Internal Use, Restricted), including R02.07.093.
  • University of Alaska Accounting & Administrative Manual, Section 400 – Information Technology (e.g., 400A-01, IT Security Program).

Related University standards:

  • UAA Generative AI Security Standard.
  • UA Information Resource Data and System Classification Standard.
  • UAA IT Policies and Standards Definitions; UAA Acceptable Use of Information Technology Resources; related UA OIT standards in the UA IT Standards Library.

Frameworks and external references.

  • NIST AI Risk Management Framework (AI RMF 1.0) and NIST AI 600-1, Generative AI Profile.
  • NIST Cybersecurity Framework (CSF) 2.0, including the GOVERN function.
  • NIST SP 800-53 Rev. 5, Security and Privacy Controls; NIST SP 800-207, Zero Trust Architecture; NIST SP 800-37, Risk Management Framework.

6.0 Policy Information

Policy Effective Date: 08/03/2026
Policy Revision Date: 08/03/2026
Policy Owner: Ryan McDaniel - Associate Vice Chancellor and CIO
Policy Author: Ryan McDaniel - Associate Vice Chancellor and CIO