1.Purpose
The purpose of this policy is to establish the principles and requirements governing the responsible, ethical, secure and effective use of Artificial Intelligence (AI) technologies across National College of Ireland (NCI). This policy is informed by the Higher Education Authority's Generative AI in Higher Education Teaching & Learning Policy Framework (2025), which establishes AI literacy as a core institutional responsibility and provides a national reference point for values-based AI adoption.
In this policy, AI includes both traditional and generative AI.
This policy aims to:
- Support innovation in research, academic activity and professional services through the appropriate use of AI.
- Ensure AI use aligns with NCI's values, strategic objectives, academic governance and legal obligations.
- Protect students, staff, partners and the College from privacy, security, bias, misinformation, intellectual property and other AI-related risks.
- Promote transparency, accountability, equity and meaningful human oversight in AI-enabled work and decision-making.
- Ensure compliance with applicable legislation, including the EU AI Act, GDPR, copyright and equality legislation, and relevant sectoral guidance.
2.Scope
This policy applies directly to all NCI employees.
Students are within scope when they use NCI-controlled AI systems, College Data, College devices or networks, or prepare institutional material for NCI. Student use of AI for learning and assessment is governed primarily by the Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy (not yet approved by LTAC)
Contractors, consultants, temporary staff, visiting researchers, collaborators, partners and third-party suppliers must comply through their contract, engagement terms or access conditions. They must disclose substantive AI use in documents, analysis, code or other deliverables prepared for NCI.
The policy covers the use, development, procurement, implementation and management of:
- Generative AI tools, including text, image, audio, video and code generation.
- AI-powered functions embedded in college or third-party systems.
- Machine learning, predictive analytics, automated decision-support and AI agents.
- AI used in research, programme administration, professional services and operational processes.
- AI used in teaching, learning and assessment, subject to the separate academic policy.
The policy applies whether systems are cloud-based, locally hosted, downloaded, installed or embedded in other software.
2.1 Key Definitions
- College Data: any information held, created, collected, received, processed or managed by NCI, including personal and non-personal information and College documents. This is an ownership and governance term. Information is not automatically restricted to an enterprise-protected AI system merely because it is College Data or has not yet been published; the applicable controls depend on its sensitivity, confidentiality, legal or contractual restrictions and the risk of the proposed use.
- Protected College Data: College Data that requires enhanced protection because it includes personal data; special-category data; student, applicant or staff records; confidential, commercially sensitive, security-sensitive or legally privileged information; credentials or secrets; non-public system architecture or proprietary source code; confidential assessment material; research participant data; restricted datasets; embargoed or patent-sensitive findings; confidential peer-review material; or information subject to contractual, ethical, funder, publisher or legal restrictions.
- Routine Low-Risk Institutional Content: content that does not contain Protected College Data and whose use presents minimal privacy, confidentiality, security, intellectual-property or contractual risk. Examples may include draft lecture notes and course materials that contain no restricted content; research ideation, methodology development and literature work based on public or lawfully accessible sources; non-confidential academic drafts; synthetic or effectively anonymised data; and generic or open-source code and technical examples that contain no credentials, secrets, internal architecture or restricted intellectual property.
- Personal Data: Any information relating to a living individual who is identified or can be identified, directly or indirectly. This includes names, identification numbers, contact details, photographs, audio or video recordings, online identifiers, location information, and information concerning an individual’s academic record, assessments, attendance, admissions, employment, performance, health, accessibility needs or behaviour.
In the context of AI, personal data includes information contained in prompts, uploaded documents, images, recordings, meeting transcripts, connected data sources, system logs and AI-generated outputs or inferences.
Pseudonymised data remains personal data where the individual could be reidentified using additional information. Data ceases to be personal data only where it has been effectively anonymised so that the individual is no longer identifiable.
- Approved AI system: an exact product, service, version, licence tier and configuration approved by NCI for specified purposes and data categories. Approval of one version or tier does not approve another. These will be logged on the Approved AI Tools and Services Register
- Formal approval is required before an AI system processes Protected College Data, is procured or deployed institutionally, connects to NCI systems or data sources, is installed on College-managed devices, or supports a controlled or high-risk use. Routine low-risk use may instead rely on a category-based permission in the Approved Approved AI Tools and Services Register
- Permitted External AI Tool: an AI tool that has not been approved to process Protected College Data or for institutional integration, but which may be used for Routine Low-Risk Institutional Content where the Register permits that category of use and the user complies with provider terms, copyright, research, academic-integrity and NCI requirements.
- Material AI contribution: AI use that substantively shapes the analysis, findings, recommendations, decisions or content of an official NCI output, rather than routine spelling, formatting, transcription or low-risk drafting assistance.
- Deployer: a person or organisation using an AI system under its own authority for professional or institutional purposes, as defined by the EU AI Act.
- High-risk AI: an AI system classified as high-risk under Article 6 and Annex III of the EU AI Act, including certain education, employment and decision-making uses.
3.Principles
3.1 Human-Centred
AI should augment, not replace, human judgement. People remain accountable for decisions and outputs.
3.2 Ethical
AI must be used fairly, transparently and responsibly, avoiding discrimination, bias or harm.
3.3 Lawful
AI use must comply with the EU AI Act, GDPR, Irish data protection legislation, copyright, equality law and NCI policies.
3.4 Secure
AI systems must be implemented in accordance with NCI cybersecurity, identity, access and information-security requirements.
3.5 Privacy and Data Protection by Design
Data protection considerations must be incorporated from the outset of every proposed institutional AI deployment or material change in use. Where an AI system or use case involves, or may reasonably involve, personal data or Protected College Data, the accountable business owner must complete an initial data-protection screening assessment before implementation. Routine Level 1 use involving only public information or Routine Low-Risk Institutional Content does not require a formal data-protection screening unless personal data may be involved. A full Data Protection Impact Assessment (DPIA) must be completed where the screening indicates that the processing is likely to result in a high risk to individuals' rights and freedoms. The Data Protection Officer must be consulted where required.
Personal data or Protected College Data must not be entered into an AI system unless the exact system, configuration, purpose and data category have been expressly approved and appropriate contractual, organisational and technical safeguards are in place. Personal data must be limited to what is necessary and, where the purpose can be achieved without identifiable data, anonymised. Where anonymisation is not possible, personal data should be pseudonymised where feasible and remains subject to all applicable data-protection controls.
3.6 Transparency
Material AI contributions must be recorded and disclosed where required. Routine use of an approved AI system or Permitted External AI Tool for spelling, formatting, low-risk drafting, research support, coding assistance or email assistance does not normally require an external disclosure unless an academic, research, contractual or local rule requires one.
3.7 Quality and Proportionality
AI outputs must be reviewed in proportion to their risk and intended use. Routine low-risk drafts may be reviewed by the author; significant public, academic, contractual, financial, employment or student-facing outputs require the normal qualified review and approval. Controls must reflect the sensitivity and risk of the information and use case: draft or non-public status alone does not make otherwise routine teaching, research or technical content Protected College Data.
3.8 Inclusivity
AI should enhance accessibility, inclusion and equitable opportunity and must not create or amplify unfair disadvantage.
3.9 Sustainability
AI should be adopted where it demonstrably improves effectiveness, efficiency or experience. AI use should be proportionate to the anticipated benefit. Environmental impacts, including energy, water and computing demands, must be considered when procuring AI systems and when deciding the scale and frequency of use.
3.10 Human Authorship and Choice
NCI respects the choice of staff and learners to produce original work without generative AI. Individuals will not ordinarily be required to use generative AI to create or materially edit content where the relevant learning or work objective can reasonably be achieved without it.
Where generative AI use is an essential learning outcome or a justified institutional requirement, the requirement must be communicated in advance, its necessity documented and a reasonable non-AI alternative considered where practicable.
Original or unpublished work attributable to another person must not be uploaded to a generative AI system, materially altered using generative AI, or used to train or fine-tune an AI model without the author's knowledge and appropriate authorisation from the relevant rights holder or institutional owner. Where personal data is involved, data-protection requirements also apply.
This provision does not create a general opt-out from approved background or embedded AI functions, such as cybersecurity filtering, accessibility or routine system operations, where those functions do not materially create or alter the person's work. Concerns or objections must be considered transparently and escalated under the Responsible Use of AI Procedure.
4.Policy Statements
4.1 Acceptable Use
Approved AI systems, and Permitted External AI Tools used within the conditions of the Register, may support:
- Drafting and revising documents and emails.
- Reviewing or editing another person's work only where the author has been informed and the user has appropriate authority. Any material AI alteration must be disclosed to the person responsible for approving the final work.
- Image creation.
- Content creation, data analysis, coding and research support.
- Administrative efficiency, student support, teaching preparation and accessibility.
- Business-process automation and decision support where the required governance is in place (see section 3.5)
Email drafting is permitted when an approved system is used for the information involved. A Permitted External AI Tool may be used only where the email content is public or Routine Low-Risk Institutional Content. The sender must review the content, recipients, attachments, confidentiality, accuracy and tone before sending and remains accountable for the communication.
External AI tools that are not individually approved may be used for public information and Routine Low-Risk Institutional Content where the Approved AI Tools and Services Register permits the category of use and the tool meets the minimum eligibility criteria published by the AI Governance Committee. Users must confirm that the provider, product or category is not listed as excluded or suspended. Protected College Data must not be entered. Users must check that provider terms, retention, model-training use and intellectual-property conditions are compatible with the content and purpose. Adoption of a resulting draft as NCI work does not retrospectively make the original low-risk processing prohibited.
4.2 Prohibited Use
- Process Protected College Data in an AI system that has not been approved for that exact purpose, configuration and data category.
- Upload another person's original or unpublished work to a generative AI system, or materially alter it using AI, without the knowledge and authority required under section 3.10.
- Use Protected College Data or rights-managed third-party content to train or fine-tune an AI model unless the necessary rights, lawful basis, safeguards and AI governance approval have been documented.
- Process personal data without a lawful basis, transparency information and required safeguards.
- Generate discriminatory, offensive, deceptive or unlawful content.
- Present AI-generated content as original work where acknowledgement is required.
- Circumvent academic integrity, assessment or research-integrity requirements.
- Base a significant decision about an applicant, student or staff member solely on AI without lawful approval and meaningful human review.
- Use AI to infer emotions in education or workplace settings, except where law permits it for medical or safety reasons and NCI have expressly approved the use.
- Install AI software, agents or integrations on college-managed devices or systems unless IT has approved the exact product and version.
- Treat an AI-detection or probabilistic tool as determinative proof of academic misconduct.
4.3 Data Protection and College Data
- Users must comply with GDPR, NCI's Data Protection Policy, privacy notices and information-security requirements.
- Where AI processes personal data, affected individuals must receive appropriate information about how their data is used, including at the point of collection where required.
- Only a system approved for the exact data category and purpose may process Protected College Data.
- Public information and Routine Low-Risk Institutional Content may be processed using a Permitted External AI Tool where the Register conditions are met. The user remains responsible for verifying that no personal, confidential, restricted or security-sensitive information is included.
- A DPIA, Fundamental Rights Impact Assessment or other impact assessment must be completed where required. E.g. The significant use of AI in an automation or a new AI driven system, AI use in project for processing college or personal data.
- Data minimisation, anonymisation or pseudonymisation must be applied wherever possible.
4.4 Information Security
- AI systems processing Protected College Data must undergo security evaluation, use appropriate authentication and access controls, and meet NCI cybersecurity requirements.
- Users must apply NCI data classification and ensure prompts, files, outputs, connectors and integrations are protected.
- IT advises on security, architecture, installation and technical controls; it does not decide alone whether the institutional use is appropriate. This is determined by the AI governance committee.
- Security incidents, data leakage, unsafe integrations or unauthorised AI tools usage, must be reported through NCI incident-management channels. E.g. for data protection issues contact the DataProtection@ncirl.ie
4.5 AI Use Approval and Procurement
NCI will establish an AI Governance committee. It will coordinate institutional AI use-case and tool approval. The accountable business or academic owner must submit the intended purpose, affected people, data, risks, benefits and proposed controls through the published AI Governance Review channel.
- Approval criteria must cover lawful purpose, necessity and proportionality, security, data protection, records management, procurement, accessibility, equity, academic governance, intellectual property, vendor terms, environmental impact and value.
- The governance model must provide a proportionate Level 1 pathway under which staff may use Permitted External AI Tools for Routine Low-Risk Institutional Content without submitting each tool or task for individual approval.
- NCI does not mandate a single AI provider for all teaching, research or technical work. Tool selection should reflect the capability required and the classification and risk of the content. Formal approval remains mandatory for Protected College Data, institutional procurement, installation, integration, automation, repeated controlled processing and high-risk uses.
- The AI Governance Committee will publish and maintain minimum eligibility criteria for unlisted Level 1 external tools and may exclude or suspend a provider, product or category where its terms, security, model-training practices or intellectual-property arrangements are unacceptable.
- A Register status of ‘Under review’ means that an active evaluation is in progress. ‘Not approved unless added following evaluation’ means that the tool is not approved and that no evaluation should be assumed to be planned or underway. A staff member who wishes to seek approval must submit an AI Tool and Use-Case Evaluation request through the IT Helpdesk. The Helpdesk ticket is the formal intake and tracking record; IT performs initial triage and the AI Governance Committee coordinates and records the decision.
- The requester must complete the sections of the standard request covering the need, accountable owner, users, data classification, risks, exact tool/tier/configuration and proposed controls. This documentation is required for Level 2 or Level 3 use and for requests involving institutional procurement, structured teaching deployment, College-managed accounts, lab or device installation, integration or automation. Routine Level 1 use that remains within the Register conditions and requires none of these actions does not require an AI Governance submission.
- The evaluation must record how the supplier uses prompts, uploaded files and outputs, including whether they may be retained, reused or used for model training or fine-tuning, and whether contractual or configuration controls prevent such use.
- Approval applies only to the named product, version, licence tier, configuration, integrations, purpose and data categories. A paid tier does not automatically provide enterprise protection or NCI approval.
- Material changes to the system, provider, model, configuration, data or purpose require re-evaluation.
- Approved tools must be entered in the separate Approved AI Tools and Services Register with an owner, conditions, review date and retirement process.
- Tools must be monitored, reviewed at least annually and suspended or retired where risks, supplier changes, poor performance or lack of continuing need justify it.
4.6 Academic Use
AI may assist with the structure, comparison and administrative drafting of programme validation, revalidation, annual monitoring, programme review and pre-validation review documents. Academic staff and programme teams retain ownership of the academic rationale, curriculum, module content, learning outcomes, assessment strategy and all academic decisions; AI must not replace that ownership.
Use in programme delivery, learning, teaching and assessment must comply with the Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy and relevant Academic Council requirements. Academic-integrity investigations must use dialogue and evidence-based evaluation; AI-detection tools must not be relied on as determinative evidence.
Draft lecture notes, teaching plans and course materials may be prepared using a Permitted External AI Tool where they contain only Routine Low-Risk Institutional Content. Personal data, confidential assessment content, restricted third-party materials and other Protected College Data require an appropriately approved system.
Teaching and learning about AI may require staff and students to access and compare a range of AI systems, including systems that are not approved for general institutional use. Such instructional use may be permitted where it forms part of an approved learning activity and appropriate safeguards are applied.
Unless the system is separately approved for the relevant data, users must use only public, synthetic or specifically prepared teaching content and must not enter Personal Data, Protected College Data, confidential information, unpublished third-party material, credentials or other restricted information. Instructional access does not constitute NCI approval of the tool for general institutional or professional use.
Teaching activities must provide reasonable alternatives where registration, age restrictions, accessibility, cost, terms of service or other conditions would prevent a learner from using a particular system.
Where an AI tool is proposed for structured student teaching, to meet programme learning outcomes or in response to industry, accreditation or validation-panel expectations, the programme or module academic owner must submit the AI Tool and Use-Case Evaluation request through the IT Helpdesk. The AI evaluation and the existing software/lab installation or change process are separate processes: Academic Leadership confirms the curricular need; IT evaluates security, technical compatibility and installation; the DPO reviews privacy where relevant; Procurement reviews licensing and supplier terms; and the AI Governance Committee records the overall approval or conditions. Material programme or assessment changes follow the relevant APQC, LTAC or Academic Council pathway.
4.7 Research
Researchers using AI must comply with research ethics, funder, data-governance, intellectual-property, publication and research-integrity requirements and obtain approval where required. Researchers may use approved systems or Permitted External AI Tools according to the classification and risk of the content.
Permitted low-risk research uses may include ideation, methodology development, literature discovery or synthesis using public or lawfully accessible sources, non-confidential drafting, generic coding, and work with synthetic or effectively anonymised data, provided provider terms and copyright, funder, publisher and ethical obligations permit the use.
Protected research information - including identifiable participant data, confidential or licensed datasets, embargoed or patent-sensitive findings, confidential peer-review material, restricted source code and information subject to ethics, funder or contractual controls - may be processed only in a system approved for that exact purpose and data category. No single AI provider is mandated for all research workflows.
4.8 Transparency and Disclosure
Material AI use in official reports, policies, publications, research, analysis, code, formal recommendations, decisions or third-party deliverables must be recorded and disclosed where appropriate. A suitable declaration is: 'AI was used to support [purpose]. The named author reviewed and verified the output and takes responsibility for the final content.'
Routine drafting of documents, spelling, formatting, transcription or email assistance using an approved tool does not normally require a declaration unless another policy, assessment rule, research standard, contract or recipient context requires it.
Where generative AI has materially altered content attributable to another individual, that use must be disclosed to the individual or to the responsible institutional approver, as appropriate. A declaration that work was produced without generative AI must not be removed or contradicted by subsequent undisclosed AI editing.
4.9 Human Oversight and Output Review
- The individual using AI remains responsible for checking relevance, accuracy, bias, confidentiality, copyright, citations and suitability.
- Routine low-risk drafts may be checked by the author. Higher-impact outputs require the normal business or academic approval.
- Significant academic, admissions, assessment, employment, financial or student decisions must not rely solely on AI.
- Affected people must have access to human review, correction, explanation and appeal where applicable.
4.10 AI Literacy
All NCI employees must complete NCI's mandatory baseline AI-literacy training, or an approved equivalent, appropriate to their role and AI use. Completion will be recorded through the College's learning or HR records. Training content will be reviewed at least annually and updated following material legal, policy, system or risk changes.
Students are expected to complete the mandatory Epigeum training designated by NCI, including guidance on AI use. The Library Team and academic supports will provide guidance to help students use AI and sources lawfully and comply with assessment and academic-integrity rules.
Relevant contractors and partners must receive proportionate guidance or training from their parent company. In the absence of training being provided they may take the NCI training.
NCI will publish supporting guidance (Approved Tools register, FAQ’s). In addition the AI governance committee may also publish decision criteria, declaration wording, checklists and templates.
NCI may publish additional guidance for specific functions or activities where AI use presents particular operational, legal, ethical or reputational considerations. Such guidance will supplement this policy and must be followed alongside it
4.11 NCI's Role under the EU AI Act
NCI will generally act as a deployer when it uses an AI system under its own authority for institutional or professional purposes. NCI is accountable for the context in which the system is selected, configured and used and for the deployer obligations applicable to that use.
NCI may acquire provider obligations where it develops or has a system developed and places it in service under its name, substantially modifies a high-risk system, or changes an intended purpose so the system becomes high-risk. Such proposals require specific legal, technical and governance evaluation before implementation and should undergo a DPIA and approval by the AI governance committee.
4.12 Potential High-Risk AI Uses in Education
Under Article 6 and Annex III of the EU AI Act, an AI system may be high-risk where its intended purpose is to:
- Determine access or admission to NCI or assign applicants or students to programmes or courses.
- Evaluate learning outcomes, including marking, grading or assessment decisions, or use outcomes to steer a student's learning.
- Assess the level of education a person will receive or access, including progression decisions.
- Monitor or detect prohibited behaviour during tests or examinations, including AI-enabled remote proctoring.
A narrow procedural, preparatory or assistive use may not be high-risk where it does not materially influence the outcome, and the Article 6 conditions are met; a documented classification is still required. Recruitment, selection, work allocation or performance evaluation may fall within other Annex III categories.
4.13 Additional Governance for High-Risk AI
General acceptable-use or tool approval is not sufficient. A suspected or confirmed high-risk system must not be procured, piloted or deployed until the AI governance committee has approved it following documented review. High-risk academic uses also require Academic Council approval.
- Record the provider, version, intended purpose, affected groups, operator role, classification rationale, accountable owner and approval in the AI register.
- Review provider conformity evidence, registration, instructions, performance limitations, technical information and contractual commitments.
- Complete a DPIA and, where Article 27 applies, a Fundamental Rights Impact Assessment, with equality, accessibility, academic-governance and ethical review.
- Nominate competent, trained and authorised human overseers and maintain meaningful decision-making, explanation, correction and appeal.
- Ensure input data under NCI's control is relevant and sufficiently representative and validate accuracy, robustness, cybersecurity, accessibility and bias risk.
- Inform affected persons when high-risk AI makes or assists a decision about them and provide staff or representative notices where applicable.
- Use the system within instructions, retain logs under NCI's control for at least six months unless another legal requirement applies, monitor impacts, report serious incidents, suspend use where required and re-evaluate material changes.
- Where NCI deploys a high-risk AI system. NCI must cooperate with lawful requests, monitoring, investigations and corrective actions undertaken by the relevant competent authorities e.g. the AI national office.
4.14 Monitoring, Assurance and Reporting
- Users, managers and system owners monitor day-to-day compliance, output quality and approved conditions.
- IT monitors technical security, access, integrations and incidents.
- DPO oversees data-protection assurance; neither IT nor the DPO function alone determines academic integrity or institutional appropriateness.
- Academic Council oversees AI in academic programmes and research.
- APQC monitors programme design, validation and review;
- LTAC oversees learning, teaching and assessment policy; RIC oversees research ethics and integrity.
- Academic-integrity concerns are addressed through academic processes and evidence. AI-detection tools are not determinative proof and must not be used as a general security-control mechanism.
- The AI Governance Group reviews the AI register, use approvals, monitoring results, incidents, training completion, tool changes and outstanding actions at least quarterly.
- The Director of Information, Technology & Innovation will prepare an annual report for SLT and Academic Council on policy effectiveness, impact, risk, incidents, training, approved systems and recommendations. Relevant risks and mitigations will be reported onward to Governing Body and its Risk Committee through established reporting arrangements.
5.Key Roles and Responsibilities
| Role | Key Responsibilities |
| Governing Body and Risk Committee | Receive assurance on significant institutional AI risks, controls and mitigations through established reporting. |
| Senior Leadership Team (SLT) | Provide strategic oversight; approve this policy, the AI governance model, receive the annual report. |
| Academic Council | Approve and oversee AI policy and high-risk use affecting academic programmes, learning, teaching, assessment and research; receive academic assurance and the annual report. |
| Registrar | Ensure governance structures operate through Academic Council and its committees for programme design, delivery, review, research integrity, teaching, learning and assessment, with proportionate disciplinary processes. |
| AI Governance Committee |
Coordinate use-case and tool approval; maintain decision criteria and the institutional AI register; review monitoring, incidents, changes and retirements; Escalate and/or make recommendations to SLT and Academic Council on high-risk or otherwise significant AI deployments; Own and coordinate the evaluation workflow and decision; publish the request route, form and status meanings; assign specialist reviews; record conditions and notify the requester. |
| Director of Information, Technology & Innovation | Lead implementation; chair or coordinate institutional AI governance; oversee architecture, suppliers, cybersecurity and the register; coordinate EU AI Act classifications and prepare the annual report. |
| Data Protection Officer (DPO) |
Advise on lawful processing, privacy information, DPIAs, Fundamental Rights Impact Assessments, data-subject rights and data-protection incidents. Record whether privacy advice, screening, a DPIA or other data-protection controls are required for a submitted proposal. |
| Information Technology Team |
Evaluate security, architecture, identity, access, integration and installation; implement approved controls; monitor technical risks and incidents. IT does not act as the sole gatekeeper for institutional appropriateness. Provide the IT Helpdesk intake and initial triage; evaluate security, architecture, installation, integration and lab compatibility; and record the technical recommendation. Helpdesk intake or IT installation approval does not by itself constitute AI governance approval. |
| Academic Leadership (Deans/Vice-Deans) |
Own responsible academic use in programmes; identify potential high-risk admissions, assessment, progression or examination use; ensure academic ownership, oversight, integrity and appeals. Sponsor requests for structured use of AI tools in teaching and document the curricular, programme-validation, industry or accreditation rationale and any required academic approvals. |
| Academic Programmes Quality Committee (APQC) | Review and monitor AI use in programme design, validation, revalidation, annual monitoring and programme review. |
| Learning, Teaching and Assessment Committee (LTAC) | Oversee College policy and guidance on generative AI in learning, teaching and assessment. |
| Research and Innovation Committee (RIC) | Oversee AI ethics and integrity in research and support compliance with ethics, funding, data and intellectual-property requirements. |
| Functional Lead (Manager or Lead in an area) | Developing or maintaining appropriate local guidance for AI use within their area where specific operational, regulatory, reputational or professional requirements apply. |
| Role | Key Responsibilities |
| Procurement | Ensure procurement follows approved governance; obtain supplier, conformity, contractual, privacy, accessibility, equity and lifecycle evidence for the exact product and tier. |
| AI System / Business Owner | Prepare the use case and evaluation; implement controls; maintain approval, records and logs; nominate overseers; monitor performance, bias, incidents, notices, explanations and appeals. |
| Managers | Ensure staff complete training and follow approved uses; review routine use proportionately; escalate proposed or changed uses through the correct governance channel. |
| Staff |
Complete required AI training (If using AI); use approved systems and Permitted External AI Tools within their conditions; classify and protect information; review outputs; record and disclose material use; and report risks and incidents. Initiate an evaluation through the IT Helpdesk where approval is required; complete the relevant sections of the AI Tool and Use-Case Evaluation request; and retain or supply the evidence required for their steps. |
| Students | Comply with the separate academic AI policy and assessment rules see Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy. Complete required Epigeum training; protect Protected College Data; and use approved or register-permitted services responsibly. |
| Library Team | Provide student and staff guidance on source evaluation, copyright, citation, responsible AI use and academic integrity supports. |
| External Parties and Suppliers | Comply with contractual AI, security and data requirements; disclose substantive AI use in NCI deliverables; provide evidence needed for approval, monitoring and incidents. |
6.Policy Governance, Management and Version Control
Academic Council governs academic and research use through APQC, LTAC and RIC. SLT governs institutional and operational use. The Director of Information, Technology & Innovation coordinates implementation and annual assurance. Significant risks and mitigations are reported to Governing Body and its Risk Committee through established arrangements.
As AI is developing so fast, this policy will be reviewed every 6 months.
Supporting Controlled Documents
- Responsible Use of AI Procedure.
- Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy.
- Approved AI Tools and Services Register.
The operational procedure and approved-tools register are maintained separately so they can be updated without reopening this policy, subject to their own approval and version controls.
All related policies will be reviewed for alignment before this policy is approved and whenever a legal, policy or system change materially affects them.
Relevant EU AI Act provisions include Articles 3(3)-(4), 4, 5, 6, 26, 27 and 86 and Annex III of Regulation (EU) 2024/1689. The policy is also informed by GDPR, ISO/IEC 42001 and the HEA Generative AI in Higher Education Teaching & Learning Policy Framework (2025).
Related policies include the Operations Security Policy, Data Protection Policy, Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy, Code of Practice for Academic Honesty and Integrity, Research Ethics Policy, Records Management Guidelines and User Security Policy.
Version Control
| Document Status | Final | Approval Body | Senior Leadership Team |
| Policy/Procedure Manager | Director of Information, Technology & Innovation | Executive Owner | Director of Information, Technology & Innovation |
| Date Approved | 11/08/2026 | Effective Date | 11/08/2026 |
| Date of Next Review | 11/08/2027 | Version Number | V1.0 |
Comments
0 comments
Please sign in to leave a comment.