{"id":33481,"date":"2026-08-21T11:12:48","date_gmt":"2026-08-21T15:12:48","guid":{"rendered":"https:\/\/www.uvm.edu\/it\/kb\/?post_type=ht_kb&#038;p=33481"},"modified":"2026-08-31T15:40:02","modified_gmt":"2026-08-31T19:40:02","slug":"agentic-ai-dos-and-do-nots","status":"publish","type":"ht_kb","link":"https:\/\/www.uvm.edu\/it\/kb\/article\/agentic-ai-dos-and-do-nots\/","title":{"rendered":"Agentic AI Dos and Do Nots"},"content":{"rendered":"    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Early Release Content<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tThis is an early release of this KB article and content is subject to change. Please refer back to this article occasionally for updated guidance.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p>Agentic AI tools can help you complete complex tasks, interact with applications, and take actions on your behalf. These capabilities can support innovation and productivity, but they also require careful oversight. The following dos and don\u2019ts provide practical guidance for using Agentic AI responsibly while protecting University data, systems, and people.<\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Dos<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><strong>Do treat AI agents like\u00a0they have your system access<\/strong><\/p>\n<p><span data-contrast=\"auto\">By\u00a0default,\u00a0AI\u00a0agents use your\u00a0permissions and\u00a0user account. Make sure\u00a0all actions taken\u00a0by\u00a0the\u00a0agent\u00a0are\u00a0intentional and\u00a0monitored.<\/span><\/p>\n<p><strong>Do enforce least privilege access<\/strong><\/p>\n<p><span data-contrast=\"auto\">Restrict the\u00a0access of the\u00a0agent\u00a0so\u00a0it can only use the data,\u00a0applications, and\u00a0systems\u00a0required. This is often referred to\u00a0as least\u00a0privilege\u00a0access\u00a0and\u00a0is important\u00a0for protecting you and\u00a0UVM.<\/span><\/p>\n<p><strong>Do protect sensitive data<\/strong><\/p>\n<p><span data-contrast=\"auto\">Use anonymized\u00a0or non-sensitive data unless explicitly approved\u00a0by the Information Security Office and\/or Contract Review\u00a0for protected\u00a0data\u00a0(e.g., NPPD, research data).\u00a0Please refer to\u00a0UVMs\u00a0article on\u00a0<\/span><a href=\"https:\/\/www.uvm.edu\/compliance\/news\/privacy-matters\"><span data-contrast=\"none\">AI privacy<\/span><\/a><span data-contrast=\"auto\">\u00a0for more information.<\/span><\/p>\n<p><strong>Do implement logging and monitoring<\/strong><\/p>\n<p><span data-contrast=\"auto\">Capture\u00a0and\u00a0monitor\u00a0agent\u00a0actions to other\u00a0applications,\u00a0data\u00a0sources,\u00a0and\u00a0decisions. Actions\u00a0should be\u00a0monitored\u00a0for unexpected behavior such as\u00a0access to data you\u00a0didn\u2019t\u00a0specify\u00a0or\u00a0to\u00a0the\u00a0agent\u00a0sending the data\u00a0elsewhere.<\/span><\/p>\n<p><strong>Do require human oversight for high-impact actions<\/strong><\/p>\n<p><span data-contrast=\"auto\">Keep humans in the loop for\u00a0actions involving\u00a0data\u00a0(especially modifications or deletions),\u00a0other applications, or external communications.<\/span><\/p>\n<p aria-level=\"3\"><strong>Do consult UVMs approved list of\u00a0AI\u00a0tools<\/strong><\/p>\n<p><span data-contrast=\"auto\">The approved list of tools can be found\u00a0<\/span><a href=\"https:\/\/www.uvm.edu\/ai\/supported-and-approved-ai-tools\"><span data-contrast=\"none\">here<\/span><\/a><span data-contrast=\"auto\">.\u00a0Do make sure you understand the\u00a0<\/span><a href=\"https:\/\/www.uvm.edu\/d10-files\/documents\/2025-07\/Data_Risk_Classification_Matrix.pdf\"><span data-contrast=\"none\">UVM Data Classification Matrix<\/span><\/a><span data-contrast=\"auto\">\u00a0before putting any work or research data into an AI\u00a0tool.<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Do Nots<\/span><\/h2>\n<p><strong>Do not expose confidential or regulated data to unapproved AI tools<\/strong><\/p>\n<p><span data-contrast=\"auto\">Only university\u00a0approved\u00a0tools\u00a0can provide you with robust\u00a0data protection\u00a0agreements.\u00a0Using\u00a0unapproved\u00a0tools,\u00a0or\u00a0tools\u00a0managed\u00a0with a\u00a0personal\u00a0account,\u00a0do not provide\u00a0you with robust\u00a0data protection agreements.<\/span><\/p>\n<p><strong>Do not grant broad or persistent access<\/strong><\/p>\n<p><span data-contrast=\"auto\">Agent permissions and\u00a0access should be granted\u00a0on\u00a0an as-needed basis for\u00a0only\u00a0as long\u00a0as\u00a0required.\u00a0Giving\u00a0an\u00a0agent persistent\u00a0and\u00a0robust\u00a0permissions\u00a0expose\u00a0you\u00a0to data related risks.<\/span><\/p>\n<p><strong>Do not bypass security controls<\/strong><\/p>\n<p><span data-contrast=\"auto\">Neither you\u00a0or your\u00a0agent\u00a0may\u00a0modify\u00a0or bypass\u00a0authentication, authorization, or\u00a0monitoring\u00a0mechanisms.<\/span><\/p>\n<p><strong>Do not assume AI interactions are private<\/strong><\/p>\n<p><span data-contrast=\"auto\">While UVM\u00a0offers\u00a0robust data\u00a0protection\u00a0for\u00a0AI\u00a0tools\u00a0including\u00a0agents,\u00a0all vendors\u00a0maintain\u00a0the right to\u00a0retain\u00a0and review prompts and\u00a0outputs\u00a0for\u00a0security reasons.\u00a0Do not assume\u00a0anything\u00a0provided\u00a0to a\u00a0UVM approved AI tool\u00a0is\u00a0anonymous.<\/span><\/p>\n<p><strong>Do not allow fully autonomous operation for high-risk tasks<\/strong><\/p>\n<p><span data-contrast=\"auto\">Do not allow your agent to perform any unsupervised actions involving sensitive data, financial actions, or system changes. All agent actions taken on your behalf are your responsibility. For that reason, you need always be aware of what your agent is doing.<\/span><\/p>\n<p aria-level=\"3\"><strong>Do not allow AI systems to make autonomous decisions about humans<\/strong><\/p>\n<p><span data-contrast=\"auto\">If an AI\u00a0agent\u00a0is\u00a0producing outputs that could affect, or are related\u00a0to,\u00a0a\u00a0human,\u00a0you must\u00a0supervise the\u00a0actions taken\u00a0and\u00a0review\u00a0output. AI\u00a0agents and systems\u00a0cannot be held accountable for actions\u00a0taken,\u00a0so you must review anything produced by them.<\/span><\/p>\n<p><strong>Do not assume everything your agent reads is safe<\/strong><\/p>\n<p><span data-contrast=\"auto\">Content from web pages, documents, or remote services can\u00a0contain\u00a0hidden instructions that your agent will act on. Be especially careful when working with outside data sources.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Agentic AI tools can help you complete complex tasks, interact with applications, and take actions on your behalf. These capabilities can support innovation and productivity, but they also require careful oversight. The following dos and don\u2019ts provide practical guidance for using Agentic AI responsibly while protecting University data, systems, and&#8230;<\/p>\n","protected":false},"author":117,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","_monsterinsights_skip_tracking":false,"footnotes":""},"ht-kb-category":[662],"ht-kb-tag":[],"class_list":["post-33481","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-ai"],"_links":{"self":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/users\/117"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/comments?post=33481"}],"version-history":[{"count":2,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33481\/revisions"}],"predecessor-version":[{"id":33557,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb\/33481\/revisions\/33557"}],"wp:attachment":[{"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/media?parent=33481"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb-category?post=33481"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.uvm.edu\/it\/kb\/wp-json\/wp\/v2\/ht-kb-tag?post=33481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}