Body
AI Tool Procurement Policy
Purpose and Intent
Booth supports the use of artificial intelligence tools to enhance productivity, research, and innovation. At the same time, these tools introduce risks related to data protection, security, and vendor management.
This policy establishes a consistent approach for acquiring AI tools so that staff, faculty, and researchers can take advantage of these technologies while ensuring institutional data and systems remain protected. It also ensures that financial and vendor relationships are managed appropriately.
Scope
This policy applies to all staff, faculty, researchers, and contractors who use or seek to use AI tools in the course of their work. It covers all external AI platforms, including widely used tools such as ChatGPT, Microsoft Copilot, Google Gemini, Claude, and similar services.
Guiding Approach to AI Tool Procurement
AI tools at Booth are acquired through two primary pathways: centrally managed solutions and self-service tools.
Booth prefers centrally managed tools, which are vetted and secured by IT with enterprise agreements. These tools offer safeguards like single sign-on, centralized billing, and oversight. Use centrally managed options when they meet your needs.
In cases where no centrally managed option is available, Booth team members may pursue a self-service tool. This model allows for flexibility and experimentation but comes with increased responsibility. Individuals requesting these tools must ensure that appropriate approvals are obtained and that the tool is used in a manner consistent with institutional policies.
Request, Review, and Approval Expectations
Regardless of how a tool is obtained, transparency and review are core expectations. Requests for AI tools, whether for access to an enterprise platform or for evaluation of a new solution, are initiated through creating a ticket with the Help Desk.
This intake process ensures that the appropriate stakeholders (such as IT, Security, and Data Governance) have visibility into how AI tools are being used across the institution. Depending on the nature of the request, additional review may be required, including security assessments, data governance evaluations, or vendor risk reviews.
This review process is particularly important when AI tools are used for data analysis, integrated with internal systems, or applied to institutional data.
Data Protection and Responsible Use
AI tools can be highly effective when used with general or non-sensitive information. However, they must be used carefully when handling institutional data.
As a baseline, publicly available and non-sensitive information may be used in AI tools with minimal review or approvals. When use cases involve student data, employee information, financial records, research data, or other confidential materials, additional oversight is required to ensure compliance with data protection standards.
Roles and Oversight
Effective governance of AI tools depends on clear ownership and accountability.
The IT organization is responsible for maintaining centrally managed tools, negotiating enterprise agreements, and conducting necessary security and vendor reviews. In addition, certain tools have designated AI Tool Coordinators who oversee licensing, usage, and compliance, and who act as points of contact for related questions or issues.
At the same time, individual users are responsible for ensuring that they follow this policy, obtain required approvals, and use AI tools appropriately in their daily work.
Financial Responsibility
The way an AI tool is funded depends on how it is procured. Centrally managed tools are typically supported through departmental budgets, research accounts, or other structured funding mechanisms, reflecting their broader, long-term use.
Self-service tools, by contrast, are generally purchased using University credit cards (GEMS) and are intended for more limited or experimental use cases. These purchases require approval and should be periodically reviewed to ensure they remain necessary and cost-effective.
Compliance and Enforcement
Adherence to this policy is required. Failure to follow the established procurement and usage processes may result in removal of access to AI tools or escalation to leadership, depending on the nature of the issue.
These measures are intended to protect both the institution and its users, while reinforcing responsible adoption of AI technologies.
Ongoing Development of AI Governance
Booth recognizes that AI technologies and associated risks are evolving rapidly. As a result, this policy will continue to mature over time. Planned enhancements include expanding the catalog of centrally managed tools, formalizing AI-related incident classification, and integrating AI considerations into incident response processes.
Getting Help
Employees who are unsure how to proceed with an AI tool request or use case should begin by submitting a Help Desk ticket or contacting the appropriate AI Tool Coordinator. This ensures that guidance is provided early and that any risks are addressed proactively.