{"id":33471,"date":"2026-08-21T11:12:34","date_gmt":"2026-08-21T15:12:34","guid":{"rendered":"https:\/\/www.uvm.edu\/it\/kb\/?post_type=ht_kb&#038;p=33471"},"modified":"2026-08-31T15:40:17","modified_gmt":"2026-08-31T19:40:17","slug":"agentic-ai-guidance","status":"publish","type":"ht_kb","link":"https:\/\/www.uvm.edu\/it\/kb\/article\/agentic-ai-guidance\/","title":{"rendered":"Agentic AI Guidance"},"content":{"rendered":"    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Early Release Content<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tThis is an early release of this KB article and content is subject to change. Please refer back to this article occasionally for updated guidance.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What is Agentic AI?<\/h2>\n<p><span data-contrast=\"auto\">Agentic AI refers to AI tools that can\u00a0act\u00a0on your behalf, not just answer questions\u00a0or generate output. These tools may use natural language instructions, work through multi-step tasks, interact with other applications, call external tools or APIs,\u00a0modify\u00a0files, access data, write code, or make changes in systems where you have access.<\/span><\/p>\n<p><span data-contrast=\"auto\">Unlike\u00a0Generative AI, an AI agent may continue working through a task after your\u00a0initial\u00a0instruction. For example, an agent might organize files, edit a document, update code, interact with online services, or perform actions using your account permissions. Because of this, agentic AI can be\u00a0a\u00a0powerful\u00a0tool.\u00a0It also creates\u00a0additional\u00a0responsibility and risk\u00a0considerations.<\/span><\/p>\n<p><span data-contrast=\"auto\">At UVM, Agentic AI should be used in ways that support innovation, productivity, learning, and research while protecting University data, systems, people, and institutional responsibilities. Agentic tools should be used thoughtfully, with clear limits, appropriate oversight, and careful attention to UVM policies.<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Why\u00a0Agentic AI\u00a0requires\u00a0extra care<\/span><\/h2>\n<p><span data-contrast=\"auto\">Agentic AI tools often act using your account, your permissions, and your access to systems or data. If you can open a file, access a system, or view certain data, an AI agent running under your account may be able to do the same unless its access is\u00a0specifically\u00a0limited\u00a0through technical controls and instructions.<\/span><\/p>\n<p><span data-contrast=\"auto\">Actions\u00a0taken by an AI agent should be treated as actions taken by you. If an agent moves, changes, shares,\u00a0deletes, summarizes, or sends information, you\u00a0are responsible for\u00a0making sure that action is\u00a0appropriate\u00a0and authorized.<\/span><\/p>\n<p><span data-contrast=\"auto\">Agentic AI may misunderstand your instructions, act in ways you did not\u00a0expect,\u00a0access information you did not intend to include, or interact with systems outside the original task. This is why human oversight, access limits, logging, monitoring, and careful data handling are essential.<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Security\u00a0Principles for Agentic AI Use<\/span><\/h2>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Treat AI agents as acting on your behalf<\/span><\/h3>\n<p><span data-contrast=\"auto\">Assume that an AI agent is acting\u00a0as\u00a0you when it uses your account,\u00a0credentials, files, applications, or system access. Actions taken by the agent should be considered equivalent to actions taken by the person or system account that authorized it.<\/span><\/p>\n<p aria-level=\"4\"><strong><i>Practical Guidance<\/i><\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Review what the agent is doing before, during, and after its work.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not assume an agent will interpret your request exactly as intended.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"6\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not allow an agent to take\u00a0actions\u00a0you would not\u00a0be authorized to\u00a0take yourself.<\/span><\/li>\n<\/ul>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Limit access to only what the agent needs<\/span><\/h3>\n<p><span data-contrast=\"auto\">AI agents should only be given the minimum access needed to complete a defined task. This is often referred to as \u201cleast privilege.\u201d Agents should not have broad, persistent, or unnecessary access to files, systems, credentials, or applications.<\/span><\/p>\n<p aria-level=\"4\"><strong><i>Practical Guidance<\/i><\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Provide access only to the files, data, and applications\u00a0required\u00a0for the task.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Avoid granting access to entire systems or repositories when a smaller scope\u00a0will work.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"7\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Remove access when the task is complete.<\/span><\/li>\n<\/ul>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Protect sensitive, confidential, and regulated data<\/span><\/h3>\n<p><span data-contrast=\"auto\">AI tools process\u00a0large amounts\u00a0of information quickly.\u00a0Confidential, regulated, or restricted information requires\u00a0appropriate safeguards\u00a0regardless of whether it is being handled by a person or an AI\u00a0tool. Before sharing information with an AI tool or agent, consider whether the data is\u00a0appropriate for\u00a0that environment and whether the tool has been approved for that use.<\/span><\/p>\n<p aria-level=\"3\"><strong>Practical Guidance<\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not enter confidential, regulated, or restricted University information into unapproved AI tools.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use anonymized, redacted, synthetic, or non-sensitive data whenever possible.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"8\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">When unsure whether data can be used with an AI tool, seek guidance before\u00a0proceeding.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Use approved tools and University-managed accounts<\/span><\/h3>\n<p><span data-contrast=\"auto\">Not all AI tools offer the same\u00a0level of\u00a0protection\u00a0around\u00a0privacy, security, and institutional data. UVM-approved services are reviewed to ensure that\u00a0appropriate agreements\u00a0and safeguards are in place. Using approved tools and University-managed accounts helps protect University information and provides a more secure environment for AI-assisted\u00a0work. UVM approval\u00a0doesn\u2019t\u00a0guarantee that data is\u00a0fully\u00a0private or anonymous.<\/span><\/p>\n<p aria-level=\"4\"><strong><i>Practical Guidance<\/i><\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Use University-approved AI services for\u00a0University\u00a0work.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Do not\u00a0use\u00a0personal AI accounts to process University information.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Follow University guidance\u00a0regarding\u00a0approved AI platforms and acceptable uses.<\/span><\/li>\n<\/ul>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Keep humans in control of important actions<\/span><\/h3>\n<p><span data-contrast=\"auto\">AI agents can automate many tasks, but some decisions and actions\u00a0should still\u00a0require human judgment. Activities that affect people, data, finances, communications, or operational systems can have significant consequences if performed incorrectly. Human oversight helps ensure that important decisions\u00a0remain\u00a0accountable, transparent, and aligned with\u00a0University\u00a0values and responsibilities.<\/span><\/p>\n<p aria-level=\"4\"><strong><i>Practical Guidance<\/i><\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Review and approve important actions before they occur.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Require confirmation before an agent makes significant changes or takes high-impact actions.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"10\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Consider whether an AI agent is the\u00a0appropriate tool\u00a0for the task if effective oversight cannot be\u00a0maintained.<\/span><\/li>\n<\/ul>\n<h3 aria-level=\"3\"><span data-contrast=\"none\">Monitor and review agent activity<\/span><\/h3>\n<p><span data-contrast=\"auto\">AI agents can perform many actions across multiple systems in a short period of time.\u00a0Monitoring and reviewing agent activity helps\u00a0identify\u00a0mistakes, unexpected behavior, and potential security concerns before they become larger issues. Visibility into what an agent did, and the reasoning behind it,\u00a0supports accountability and helps build trust in AI-enabled workflows.<\/span><\/p>\n<p aria-level=\"4\"><strong><i>Practical Guidance<\/i><\/strong><\/p>\n<ul>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"11\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Review agent activity, outputs, and decisions regularly.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"11\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Monitor interactions with files, applications, data sources, and external systems.<\/span><\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"11\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Investigate unexpected behavior or results before continuing to use an agent.<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Agentic AI Usage Checklist<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Before using\u00a0Agentic AI for University work, ask:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Is this an approved tool for this type of work?<\/strong> &#8211; <\/span>Use approved tools and avoid personal or unapproved AI accounts for University data or business processes.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>What data will the agent be able to access?<\/strong> &#8211; <\/span>Assume the agent may access data available to your account unless access is technically limited. Review external sources before linking to agents.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Does the agent really need this level of access?<\/strong> &#8211; <\/span>Limit access to the minimum data, applications, and systems\u00a0required\u00a0for the task.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Could the task involve sensitive, confidential, or regulated information?<\/strong> &#8211; <\/span>Do not place NPPD, PHI, student records, protected research data, credentials, or other sensitive data into prompts or workflows unless explicitly approved.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>What could go wrong if the agent misunderstands the task?<\/strong> &#8211; <\/span>Agents may interpret instructions incorrectly or act in unexpected ways; have a plan ready if\/when an agent performs an unanticipated action.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Will a human review important actions before they happen?<\/strong> &#8211; <\/span>Human oversight is required for high-impact actions such as data changes, external communications, financial or operational actions, and system changes.<\/li>\n<li aria-setsize=\"-1\" data-leveltext=\"%1.\" data-font=\"\" data-listid=\"12\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Can agent activity be reviewed afterward?<\/strong> &#8211; <\/span>Agent interactions should be logged, monitored, or reviewed.<\/li>\n<\/ol>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Prompt Injection<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">With all technical tools comes a level of risk around malicious compromise. One of the currently emerging methods of this related to AI is prompt\u00a0injection, or\u00a0hiding AI instructions in content\u00a0that is entered into an AI tool. Do not assume that everything your agent reads is safe. Content from web pages, documents like PDFs, and remote services can all\u00a0contain\u00a0hidden instructions that agents will act on.\u00a0Use caution when working with external data sources or copying and pasting content from websites directly into instructions or prompts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Technical Controls<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">There are different technical controls to put in place when using Agentic AI tools.\u00a0Some tools have these controls managed centrally while others are enforced on a per-agent basis. UVM currently has technical control guidance published for these Agentic AI tools:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.uvm.edu\/it\/kb\/article\/claude-code-managed-settings\/\"><span data-contrast=\"auto\">Claude Code Managed Settings KB article<\/span><\/a><\/p>\n<p><span data-contrast=\"auto\">More technical controls will be documented as\u00a0additional\u00a0tools are reviewed and approved.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Support and Guidance<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">If you have questions about Agentic AI tool usage, availability, or data\/security, please reach out to the Tech Team at\u00a0<\/span><a href=\"mailto:helpline@uvm.edu\"><span data-contrast=\"none\">helpline@uvm.edu<\/span><\/a><span data-contrast=\"auto\">.\u00a0ETS is dedicated to supporting client needs around Agentic AI and ensuring that these tools are implemented in a secure and responsible manner.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is Agentic AI? Agentic AI refers to AI tools that can\u00a0act\u00a0on your behalf, not just answer questions\u00a0or generate output. These tools may use natural language instructions, work through multi-step tasks, interact with other applications, call external tools or APIs,\u00a0modify\u00a0files, access data, write code, or make changes in systems where&#8230;<\/p>\n","protected":false},"author":117,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","_monsterinsights_skip_tracking":false,"footnotes":""},"ht-kb-category":[662],"ht-kb-tag":[],"class_list":["post-33471","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-ai"],"_links":{"self":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33471","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/users\/117"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/comments?post=33471"}],"version-history":[{"count":7,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33471\/revisions"}],"predecessor-version":[{"id":33558,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33471\/revisions\/33558"}],"wp:attachment":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/media?parent=33471"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb-category?post=33471"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb-tag?post=33471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}