1.Purpose
This controlled register identifies AI products, service tiers and configurations that NCI has approved for Protected College Data or controlled institutional use, and categories of external tools permitted for Routine Low-Risk Institutional Content. It must be read with the Artificial Intelligence (AI) Policy and Responsible Use of AI Procedure. A product's public availability or paid status does not constitute approval for Protected College Data, procurement, installation, integration or controlled use.
2.Requesting a New Tool
A staff member who wishes to seek approval must submit an AI Tool and Use-Case Evaluation request through the IT Helpdesk. The Helpdesk ticket is the formal intake and tracking record; IT performs initial triage and the AI Governance Committee coordinates and records the decision.
3.Approval Rules
- Where exact approval is required, it applies only to the named product, version or model family, licence tier, NCI tenant or workspace configuration, integrations, purpose and data categories.
- A materially changed model, service tier, application, browser extension, connector, integration, supplier term or purpose requires re-evaluation.
- Free, personal or consumer AI accounts are not approved for Protected College Data. They may be used for public information or Routine Low-Risk Institutional Content where the relevant register entry permits the use and provider terms, copyright and model-training conditions are acceptable.
- A tool may be permitted for Level 1 low-risk use without being approved for Protected College Data. Such permission does not authorise NCI procurement, installation on College-managed devices, system integration, automation or repeated controlled processing.
- The AI Governance Committee will publish and maintain minimum eligibility criteria for unlisted Level 1 external tools. These criteria must address provider identity and terms, privacy, retention and model-training practices, security, intellectual-property and copyright conditions, lawful availability and suitability for Level 1 use.
- The AI Governance Committee may exclude or suspend a provider, product or category where its terms, security, model-training practices or intellectual-property arrangements are unacceptable. Users must check the current exclusion or suspension status before use.
- Each register entry must state whether prompts, uploaded files and outputs may be retained, reused or used for model training or fine-tuning, and identify any contractual or configuration controls that prevent such use.
- Approval of a tool does not authorise users to upload or materially alter another person's original or unpublished work without the knowledge and authority required by the AI Policy.
- AI software, mobile applications, agents, add-ins and integrations may be installed or enabled on College-managed devices or systems only through the IT approval process.
- Routine email and document drafting is permitted where the user reviews and remains accountable for the final output.
- The AI Governance Committee owns the register;
- IT, the DPO, Academic Council, SLT and the Research committee provide specialist review.
- Each approved entry must have an owner, conditions, review date and retirement decision.
4.Status Meanings
- ‘Approved’ or ‘Approved – conditional’ applies only to the stated tier, configuration, purpose and data. ‘Permitted – Level 1’ allows only the low-risk use and data described in the entry without an individual submission. ‘Under review’ means an active evaluation is in progress. ‘Not approved unless added following evaluation’ means the tool is not approved and no evaluation is planned or underway unless the Register also states ‘Under review’; a staff member or accountable owner must request evaluation if approval is sought.
5.Evaluation Requests
- To request evaluation, log an IT Helpdesk ticket using the AI Tool and Use-Case Evaluation request category/form. Include the requester and accountable owner; exact product, tier, model/version and configuration; intended purpose and users; data classification; whether student accounts, procurement, installation, integration or automation are required; anticipated benefits and risks; and proposed controls. IT provides intake and technical triage; the AI Governance Committee coordinates specialist review, records the decision and conditions, notifies the requester and updates this Register where appropriate.
- For structured teaching use, the programme or module academic owner must include the module/programme, learning outcomes, industry, accreditation or validation-panel rationale, intended student activity, account/licence model, data, accessibility and equity considerations, assessment implications and lab requirements. The AI evaluation and NCI's existing software/lab installation or change process will be coordinated through the same ticket, but both approvals are required where both apply.
- A one-off Level 1 browser-based demonstration using only public or synthetic information may proceed where the entry and academic policy permit it and no NCI purchase, managed account, installation or integration is involved. Structured or repeated student use, required accounts or licences, use in assessment, installation, integration or processing of Protected College Data requires a request and the relevant approvals.
- For example, the current Claude entries permit the stated Level 1 low-risk uses; they do not approve an NCI-managed Claude workspace, lab installation, structured student deployment, integration or processing of Protected College Data. A requester seeking any of those uses must follow the Helpdesk evaluation route above.
6.Evaluation Criteria
Evaluations cover security, authentication, data location and retention, model-training use, privacy and DPIA requirements, access and audit, procurement and contract terms, equity, accessibility, copyright, accuracy, integrations, supplier changes, records, environmental impact, purpose limitation, support, incident management and exit or deletion. The evaluation must distinguish between processing content to provide the service and using content to train or fine-tune a model. It must also record whether the tool supports the human-authorship, notification and objection requirements in the AI Policy.
7.Human-Authored Content Conditions
- Before another person's original or unpublished work is uploaded or materially altered, the user must establish appropriate authority and inform the author in accordance with the AI Policy.
- Protected College Data or rights-managed content must not be entered where a provider cannot give adequate assurances about model training, retention or reuse. Routine unpublished material may be used only where it meets the definition of Routine Low-Risk Institutional Content and the author or rights holder has appropriate authority under the AI Policy.
- Where a reasonable non-AI alternative is required under the AI Policy, the approved status of a tool does not remove the obligation to consider that alternative.
8.Current Register
9.Approval Levels
(Extract from the Responsible use of AI Procedure)
| Level | Typical Characteristics | Decision |
| Level 1 - Routine/low risk | Approved system or register-permitted external tool; public information or Routine Low-Risk Institutional Content only; no Protected College Data, novel integration, automation or high-risk decision. | No AI Governance submission is required. The user follows the Register conditions, remains accountable and obtains any normal manager, academic or business approval. |
| Level 2 - Institutional/controlled | Protected College Data; system integration; automation; transcription; repeated controlled processing; supplier purchase; or material public, student or staff impact. | AI Governance Committee review with IT, DPO, Procurement, Academic Council or Research Committee as relevant. |
| Level 3 - High risk/significant | Potential EU AI Act high-risk use, automated significant decision, novel profiling, substantial modification or significant rights/safety risk. | Documented review and SLT approval; Academic Council approval where academic or research use is affected. |
10.Supplier Information Sources
Public supplier information supports, but does not replace, NCI's internal evaluation. Microsoft enterprise data protection: https://learn.microsoft.com/en-us/microsoft-365/copilot/enterprise-data-protection
Microsoft Teams recording and transcription controls: https://learn.microsoft.com/en-us/microsoftteams/meeting-recording
OpenAI enterprise privacy: https://openai.com/enterprise-privacy/
Anthropic commercial-product privacy information: https://privacy.claude.com/
11.Related Documents and Version Control
- Artificial Intelligence (AI) Policy.
- Approved AI Tools and Services Register.
- Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy.
Version Control
| Document Status | Final | Approval Body | Senior Leadership Team |
| Policy/Procedure Manager | Director of Information, Technology & Innovation | Executive Owner | Director of Information, Technology & Innovation |
| Date Approved | 11/08/2026 | Effective Date | 11/08/2026 |
| Date of Next Review | 11/08/2027 | Version Number | V1.0 |
Comments
0 comments
Please sign in to leave a comment.