Agentic AI Guidance

Early Release Content

This is an early release of this KB article and content is subject to change. Please refer back to this article occasionally for updated guidance.

What is Agentic AI?

Agentic AI refers to AI tools that can act on your behalf, not just answer questions or generate output. These tools may use natural language instructions, work through multi-step tasks, interact with other applications, call external tools or APIs, modify files, access data, write code, or make changes in systems where you have access.

Unlike Generative AI, an AI agent may continue working through a task after your initial instruction. For example, an agent might organize files, edit a document, update code, interact with online services, or perform actions using your account permissions. Because of this, agentic AI can be a powerful tool. It also creates additional responsibility and risk considerations.

At UVM, Agentic AI should be used in ways that support innovation, productivity, learning, and research while protecting University data, systems, people, and institutional responsibilities. Agentic tools should be used thoughtfully, with clear limits, appropriate oversight, and careful attention to UVM policies.

Why Agentic AI requires extra care

Agentic AI tools often act using your account, your permissions, and your access to systems or data. If you can open a file, access a system, or view certain data, an AI agent running under your account may be able to do the same unless its access is specifically limited through technical controls and instructions.

Actions taken by an AI agent should be treated as actions taken by you. If an agent moves, changes, shares, deletes, summarizes, or sends information, you are responsible for making sure that action is appropriate and authorized.

Agentic AI may misunderstand your instructions, act in ways you did not expect, access information you did not intend to include, or interact with systems outside the original task. This is why human oversight, access limits, logging, monitoring, and careful data handling are essential.

Security Principles for Agentic AI Use

Treat AI agents as acting on your behalf

Assume that an AI agent is acting as you when it uses your account, credentials, files, applications, or system access. Actions taken by the agent should be considered equivalent to actions taken by the person or system account that authorized it.

Practical Guidance

  • Review what the agent is doing before, during, and after its work.
  • Do not assume an agent will interpret your request exactly as intended.
  • Do not allow an agent to take actions you would not be authorized to take yourself.

Limit access to only what the agent needs

AI agents should only be given the minimum access needed to complete a defined task. This is often referred to as “least privilege.” Agents should not have broad, persistent, or unnecessary access to files, systems, credentials, or applications.

Practical Guidance

  • Provide access only to the files, data, and applications required for the task.
  • Avoid granting access to entire systems or repositories when a smaller scope will work.
  • Remove access when the task is complete.

Protect sensitive, confidential, and regulated data

AI tools process large amounts of information quickly. Confidential, regulated, or restricted information requires appropriate safeguards regardless of whether it is being handled by a person or an AI tool. Before sharing information with an AI tool or agent, consider whether the data is appropriate for that environment and whether the tool has been approved for that use.

Practical Guidance

  • Do not enter confidential, regulated, or restricted University information into unapproved AI tools. 
  • Use anonymized, redacted, synthetic, or non-sensitive data whenever possible. 
  • When unsure whether data can be used with an AI tool, seek guidance before proceeding. 

Use approved tools and University-managed accounts

Not all AI tools offer the same level of protection around privacy, security, and institutional data. UVM-approved services are reviewed to ensure that appropriate agreements and safeguards are in place. Using approved tools and University-managed accounts helps protect University information and provides a more secure environment for AI-assisted work. UVM approval doesn’t guarantee that data is fully private or anonymous.

Practical Guidance

  • Use University-approved AI services for University work.
  • Do not use personal AI accounts to process University information.
  • Follow University guidance regarding approved AI platforms and acceptable uses.

Keep humans in control of important actions

AI agents can automate many tasks, but some decisions and actions should still require human judgment. Activities that affect people, data, finances, communications, or operational systems can have significant consequences if performed incorrectly. Human oversight helps ensure that important decisions remain accountable, transparent, and aligned with University values and responsibilities.

Practical Guidance

  • Review and approve important actions before they occur.
  • Require confirmation before an agent makes significant changes or takes high-impact actions.
  • Consider whether an AI agent is the appropriate tool for the task if effective oversight cannot be maintained.

Monitor and review agent activity

AI agents can perform many actions across multiple systems in a short period of time. Monitoring and reviewing agent activity helps identify mistakes, unexpected behavior, and potential security concerns before they become larger issues. Visibility into what an agent did, and the reasoning behind it, supports accountability and helps build trust in AI-enabled workflows.

Practical Guidance

  • Review agent activity, outputs, and decisions regularly.
  • Monitor interactions with files, applications, data sources, and external systems.
  • Investigate unexpected behavior or results before continuing to use an agent.

Agentic AI Usage Checklist 

Before using Agentic AI for University work, ask: 

  1. Is this an approved tool for this type of work?Use approved tools and avoid personal or unapproved AI accounts for University data or business processes.
  2. What data will the agent be able to access?Assume the agent may access data available to your account unless access is technically limited. Review external sources before linking to agents.
  3. Does the agent really need this level of access?Limit access to the minimum data, applications, and systems required for the task.
  4. Could the task involve sensitive, confidential, or regulated information?Do not place NPPD, PHI, student records, protected research data, credentials, or other sensitive data into prompts or workflows unless explicitly approved.
  5. What could go wrong if the agent misunderstands the task?Agents may interpret instructions incorrectly or act in unexpected ways; have a plan ready if/when an agent performs an unanticipated action.
  6. Will a human review important actions before they happen?Human oversight is required for high-impact actions such as data changes, external communications, financial or operational actions, and system changes.
  7. Can agent activity be reviewed afterward?Agent interactions should be logged, monitored, or reviewed.

Prompt Injection 

With all technical tools comes a level of risk around malicious compromise. One of the currently emerging methods of this related to AI is prompt injection, or hiding AI instructions in content that is entered into an AI tool. Do not assume that everything your agent reads is safe. Content from web pages, documents like PDFs, and remote services can all contain hidden instructions that agents will act on. Use caution when working with external data sources or copying and pasting content from websites directly into instructions or prompts. 

Technical Controls 

There are different technical controls to put in place when using Agentic AI tools. Some tools have these controls managed centrally while others are enforced on a per-agent basis. UVM currently has technical control guidance published for these Agentic AI tools: 

Claude Code Managed Settings KB article

More technical controls will be documented as additional tools are reviewed and approved. 

Support and Guidance 

If you have questions about Agentic AI tool usage, availability, or data/security, please reach out to the Tech Team at helpline@uvm.edu. ETS is dedicated to supporting client needs around Agentic AI and ensuring that these tools are implemented in a secure and responsible manner. 

Updated on August 31, 2026

Related Articles

Not the solution you were looking for?
Don’t worry we’re here to help!
Submit a Help Ticket