Agentic AI tools can help you complete complex tasks, interact with applications, and take actions on your behalf. These capabilities can support innovation and productivity, but they also require careful oversight. The following dos and don’ts provide practical guidance for using Agentic AI responsibly while protecting University data, systems, and people.
Dos
Do treat AI agents like they have your system access
By default, AI agents use your permissions and user account. Make sure all actions taken by the agent are intentional and monitored.
Do enforce least privilege access
Restrict the access of the agent so it can only use the data, applications, and systems required. This is often referred to as least privilege access and is important for protecting you and UVM.
Do protect sensitive data
Use anonymized or non-sensitive data unless explicitly approved by the Information Security Office and/or Contract Review for protected data (e.g., NPPD, research data). Please refer to UVMs article on AI privacy for more information.
Do implement logging and monitoring
Capture and monitor agent actions to other applications, data sources, and decisions. Actions should be monitored for unexpected behavior such as access to data you didn’t specify or to the agent sending the data elsewhere.
Do require human oversight for high-impact actions
Keep humans in the loop for actions involving data (especially modifications or deletions), other applications, or external communications.
Do consult UVMs approved list of AI tools
The approved list of tools can be found here. Do make sure you understand the UVM Data Classification Matrix before putting any work or research data into an AI tool.
Do Nots
Do not expose confidential or regulated data to unapproved AI tools
Only university approved tools can provide you with robust data protection agreements. Using unapproved tools, or tools managed with a personal account, do not provide you with robust data protection agreements.
Do not grant broad or persistent access
Agent permissions and access should be granted on an as-needed basis for only as long as required. Giving an agent persistent and robust permissions expose you to data related risks.
Do not bypass security controls
Neither you or your agent may modify or bypass authentication, authorization, or monitoring mechanisms.
Do not assume AI interactions are private
While UVM offers robust data protection for AI tools including agents, all vendors maintain the right to retain and review prompts and outputs for security reasons. Do not assume anything provided to a UVM approved AI tool is anonymous.
Do not allow fully autonomous operation for high-risk tasks
Do not allow your agent to perform any unsupervised actions involving sensitive data, financial actions, or system changes. All agent actions taken on your behalf are your responsibility. For that reason, you need always be aware of what your agent is doing.
Do not allow AI systems to make autonomous decisions about humans
If an AI agent is producing outputs that could affect, or are related to, a human, you must supervise the actions taken and review output. AI agents and systems cannot be held accountable for actions taken, so you must review anything produced by them.
Do not assume everything your agent reads is safe
Content from web pages, documents, or remote services can contain hidden instructions that your agent will act on. Be especially careful when working with outside data sources.