Approved AI Tools and Services Register

1.Purpose

This controlled register identifies AI products, service tiers and configurations that NCI has approved for Protected College Data or controlled institutional use, and categories of external tools permitted for Routine Low-Risk Institutional Content. It must be read with the Artificial Intelligence (AI) Policy and Responsible Use of AI Procedure. A product's public availability or paid status does not constitute approval for Protected College Data, procurement, installation, integration or controlled use.

2.Requesting a New Tool

A staff member who wishes to seek approval must submit an AI Tool and Use-Case Evaluation request through the IT Helpdesk. The Helpdesk ticket is the formal intake and tracking record; IT performs initial triage and the AI Governance Committee coordinates and records the decision.

3.Approval Rules

  1. Where exact approval is required, it applies only to the named product, version or model family, licence tier, NCI tenant or workspace configuration, integrations, purpose and data categories.
  2. A materially changed model, service tier, application, browser extension, connector, integration, supplier term or purpose requires re-evaluation.
  3. Free, personal or consumer AI accounts are not approved for Protected College Data. They may be used for public information or Routine Low-Risk Institutional Content where the relevant register entry permits the use and provider terms, copyright and model-training conditions are acceptable.
  4. A tool may be permitted for Level 1 low-risk use without being approved for Protected College Data. Such permission does not authorise NCI procurement, installation on College-managed devices, system integration, automation or repeated controlled processing.
  5. The AI Governance Committee will publish and maintain minimum eligibility criteria for unlisted Level 1 external tools. These criteria must address provider identity and terms, privacy, retention and model-training practices, security, intellectual-property and copyright conditions, lawful availability and suitability for Level 1 use.
  6. The AI Governance Committee may exclude or suspend a provider, product or category where its terms, security, model-training practices or intellectual-property arrangements are unacceptable. Users must check the current exclusion or suspension status before use.
  7. Each register entry must state whether prompts, uploaded files and outputs may be retained, reused or used for model training or fine-tuning, and identify any contractual or configuration controls that prevent such use.
  8. Approval of a tool does not authorise users to upload or materially alter another person's original or unpublished work without the knowledge and authority required by the AI Policy.
  9. AI software, mobile applications, agents, add-ins  and integrations may be installed or enabled on College-managed devices or systems only through the IT approval process.
  10. Routine email and document drafting is permitted where the user reviews and remains accountable for the final output.
  11. The AI Governance Committee owns the register; 
  12. IT, the DPO, Academic Council, SLT and the Research committee provide specialist review.
  13. Each approved entry must have an owner, conditions, review date and retirement decision.

4.Status Meanings

  1. ‘Approved’ or ‘Approved – conditional’ applies only to the stated tier, configuration, purpose and data. ‘Permitted – Level 1’ allows only the low-risk use and data described in the entry without an individual submission. ‘Under review’ means an active evaluation is in progress. ‘Not approved unless added following evaluation’ means the tool is not approved and no evaluation is planned or underway unless the Register also states ‘Under review’; a staff member or accountable owner must request evaluation if approval is sought.

5.Evaluation Requests

  1. To request evaluation, log an IT Helpdesk ticket using the AI Tool and Use-Case Evaluation request category/form. Include the requester and accountable owner; exact product, tier, model/version and configuration; intended purpose and users; data classification; whether student accounts, procurement, installation, integration or automation are required; anticipated benefits and risks; and proposed controls. IT provides intake and technical triage; the AI Governance Committee coordinates specialist review, records the decision and conditions, notifies the requester and updates this Register where appropriate.
  2. For structured teaching use, the programme or module academic owner must include the module/programme, learning outcomes, industry, accreditation or validation-panel rationale, intended student activity, account/licence model, data, accessibility and equity considerations, assessment implications and lab requirements. The AI evaluation and NCI's existing software/lab installation or change process will be coordinated through the same ticket, but both approvals are required where both apply.
  3. A one-off Level 1 browser-based demonstration using only public or synthetic information may proceed where the entry and academic policy permit it and no NCI purchase, managed account, installation or integration is involved. Structured or repeated student use, required accounts or licences, use in assessment, installation, integration or processing of Protected College Data requires a request and the relevant approvals.
  4. For example, the current Claude entries permit the stated Level 1 low-risk uses; they do not approve an NCI-managed Claude workspace, lab installation, structured student deployment, integration or processing of Protected College Data. A requester seeking any of those uses must follow the Helpdesk evaluation route above.

6.Evaluation Criteria

Evaluations cover security, authentication, data location and retention, model-training use, privacy and DPIA requirements, access and audit, procurement and contract terms, equity, accessibility, copyright, accuracy, integrations, supplier changes, records, environmental impact, purpose limitation, support, incident management and exit or deletion. The evaluation must distinguish between processing content to provide the service and using content to train or fine-tune a model. It must also record whether the tool supports the human-authorship, notification and objection requirements in the AI Policy.

7.Human-Authored Content Conditions

  1. Before another person's original or unpublished work is uploaded or materially altered, the user must establish appropriate authority and inform the author in accordance with the AI Policy.
  2. Protected College Data or rights-managed content must not be entered where a provider cannot give adequate assurances about model training, retention or reuse. Routine unpublished material may be used only where it meets the definition of Routine Low-Risk Institutional Content and the author or rights holder has appropriate authority under the AI Policy.
  3. Where a reasonable non-AI alternative is required under the AI Policy, the approved status of a tool does not remove the obligation to consider that alternative.

8.Current Register

Service Exact Tier / Configuration Status Approved Use Data Permitted Conditions Owner / Review
Microsoft 365 Copilot Chat

This service is currently being reviewed.
NCI-authenticated account with enterprise data protection; exact NCI tenant configuration Approved - conditional Routine drafting, summarisation,ideation and assistance within approved Microsoft 365 use Protected College Data within NCI classification, access and purpose limits, plus public and Routine Low-Risk Institutional Content; no special-category or highly sensitive data without specific approval Confirm enterprise-data-protection indicator; user reviews output; prompts and responses may be retained and auditable under tenant controls AI Governance Committee
Microsoft 365 Copilot licensed features Only licensed features and configurations specifically enabled by NCI Conditional / use-case specific Word, Excel, PowerPoint, Outlook, Teams or Graph-grounded assistance where enabled As approved for the exact feature and data category, including Protected College Data where expressly authorised Licence availability does not itself approve use; permissions and oversharing risks must be reviewed Director of IT&I / annual
Microsoft Teams transcription and Intelligent Recap NCI Teams tenant Under review Meeting transcription or recap after privacy and records review Provide notice; establish lawful basis; restrict access; apply retention; complete DPIA or further review where required AI Governance Committee
GitHub Copilot Individual or institutional service; repository and configuration controls must match the proposed use Permitted - low-risk coding; controlled use requires approval Generic, public or open-source coding assistance and Routine Low-Risk Institutional Content No Protected College Data, credentials, secrets, non-public architecture or restricted/proprietary source code unless specifically approved Confirm repository rights and provider terms; review generated code; IT approval is required for installation, integration or access to controlled repositories IT / on proposal
ChatGPT Free, Plus or personal accounts Consumer/personal service Permitted - Level 1 low-risk only Public information and Routine Low-Risk Institutional Content No Protected College Data Review provider terms, retention and training settings; no NCI procurement, integration or installation without approval AI Governance Committee
ChatGPT Business, Enterprise, Edu or API No NCI workspace/configuration approved unless separately recorded Level 1 low-risk use permitted; not approved for Protected College Data unless separately recorded Public information and Routine Low-Risk Institutional Content; controlled use only after exact workspace and purpose approval No Protected College Data unless specified in a separate approved entry Commercial data protections do not replace NCI due diligence, DPIA, procurement or configuration review AI Governance Committee
Claude Free, Pro, Max or personal accounts Consumer/personal service Permitted - Level 1 low-risk only Public information and Routine Low-Risk Institutional Content No Protected College Data Review provider terms, retention and training settings; no NCI procurement, integration or installation without approval AI Governance Committee
Claude for Work or Anthropic API No NCI workspace/configuration approved unless separately recorded Level 1 low-risk use permitted; not approved for Protected College Data unless separately recorded Public information and Routine Low-Risk Institutional Content; controlled use only after exact tier and purpose approval No Protected College Data unless specified in a separate approved entry

Commercial protections and retention options vary and require NCI evaluation

Use the IT Helpdesk AI Tool and Use-Case Evaluation request for institutional licensing, structured teaching deployment, College-managed installation or integration, or any proposed processing of Protected College Data.

AI Governance Committee
Other public AI services, apps, agents or extensions Any product not expressly listed as approved Permitted - Level 1 low-risk only; not approved for Protected College Data Public information and Routine Low-Risk Institutional Content, if otherwise lawful and within provider terms No Protected College Data Must meet the minimum eligibility criteria published by the AI Governance Committee; user must confirm the tool is not excluded or suspended and comply with provider terms. Approval is required for purchase, installation, integration, automation or controlled use. AI Governance Committee
Claude Code and comparable agentic or specialised coding tools External CLI, IDE, agent or specialised LLM environment; exact installation and integration subject to IT control Permitted - Level 1 low-risk coding; controlled use requires approval Generic, public or open-source code; technical learning; prototyping; and Routine Low-Risk Institutional Content No Protected College Data, credentials, secrets, internal architecture, controlled repositories or restricted/proprietary code unless specifically approved

Confirm repository and licence rights; review generated code and dependencies; IT approval is required for installation on College-managed devices or access to controlled systems

 

IT + AI Governance Committee / annual

9.Approval Levels  

(Extract from the Responsible use of AI Procedure)

Level Typical Characteristics Decision
Level 1 - Routine/low risk Approved system or register-permitted external tool; public information or Routine Low-Risk Institutional Content only; no Protected College Data, novel integration, automation or high-risk decision. No AI Governance submission is required. The user follows the Register conditions, remains accountable and obtains any normal manager, academic or business approval.
Level 2 - Institutional/controlled Protected College Data; system integration; automation; transcription; repeated controlled processing; supplier purchase; or material public, student or staff impact. AI Governance Committee review with IT, DPO, Procurement, Academic Council or Research Committee as relevant.
Level 3 - High risk/significant Potential EU AI Act high-risk use, automated significant decision, novel profiling, substantial modification or significant rights/safety risk. Documented review and SLT approval; Academic Council approval where academic or research use is affected.

10.Supplier Information Sources

Public supplier information supports, but does not replace, NCI's internal evaluation. Microsoft enterprise data protection: https://learn.microsoft.com/en-us/microsoft-365/copilot/enterprise-data-protection 

Microsoft Teams recording and transcription controls: https://learn.microsoft.com/en-us/microsoftteams/meeting-recording 

OpenAI enterprise privacy: https://openai.com/enterprise-privacy/ 

Anthropic commercial-product privacy information: https://privacy.claude.com/

11.Related Documents and Version Control

Version Control

Document Status Final Approval Body Senior Leadership Team
Policy/Procedure Manager Director of Information, Technology & Innovation Executive Owner Director of Information, Technology & Innovation
Date Approved 11/08/2026 Effective Date 11/08/2026
Date of Next Review 11/08/2027 Version Number V1.0

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.