AI Tools Usage Guidelines for the Annenberg School for Communication
Updated August 26, 2026
Introduction
This document outlines guidelines for the responsible and effective use of artificial intelligence (AI) tools within the Annenberg School for Communication at the University of Pennsylvania. These guidelines align with Penn’s overarching policies and guidance on data protection, academic integrity, research, information security, privacy, and ethical conduct.
Penn now provides access to a growing number of generative AI services through University agreements. These agreements may provide improved security, privacy, data protection, and cost compared with individually purchased or publicly available AI services. The protections associated with Penn-contracted services apply only to accounts or service instances that have been explicitly provisioned under the applicable University agreement. Using an @upenn.edu email address or authenticating through Penn SSO does not, by itself, mean that an account is covered by Penn’s agreement or approved for use with Penn data.
Personal accounts and other accounts not provisioned under a Penn agreement are not covered by Penn’s contractual protections, even if Penn credentials are used to sign in. If you are unsure whether an account or service is covered, contact Annenberg IT before using it with non-public Penn data.
See Penn’s Guidance for Use of Generative AI for University-wide guidance.
A fundamental principle to remember: do not input Penn information into a non-contracted commercial AI service that you would not be comfortable treating as public information.
AI services are evolving rapidly. Before purchasing an AI subscription, establishing API access, integrating an AI service with another system, or using an AI system that can take actions on your behalf, contact Annenberg IT for guidance.
Definitions and examples of Low-Risk, Moderate-Risk, and High-Risk Data referenced throughout this document can be found in the final section and in Penn’s authoritative Data Risk Classification.
University-Contracted AI Tools
Penn maintains enterprise agreements for a growing range of generative AI services. Because availability, pricing, capabilities, models, and data protections change frequently, Penn Generative AI Tools & Resources, maintained by Information Systems & Computing (ISC), should be considered authoritative for current University-wide information.
Current Penn-supported offerings include PennChat, Microsoft Copilot Chat, Microsoft 365 Copilot, ChatGPT Edu, Grammarly, Anthropic Claude, selected Google Gemini services, Snowflake AI capabilities, and other platforms incorporating generative AI.
Current pricing is maintained by Penn and is not duplicated here. Contact Annenberg IT if you need help identifying the most appropriate or cost-effective service.
PennChat
Access: Available to the Penn community.
Data Protection: Penn currently permits Low-, Moderate-, and most High-Risk Data, with specific exceptions including Social Security numbers and credit card data.
Features: Generative AI chat using OpenAI and Anthropic large language models, with the ability to work with a variety of document formats.
For many routine uses of generative AI, PennChat should be considered before purchasing an individual commercial subscription.
See Penn Generative AI Tools & Resources for current details.
Microsoft Copilot Chat
Access: Available through Penn’s Microsoft 365 environment.
Data Protection: Penn currently permits Low-, Moderate-, and most High-Risk Data, except specified restricted information such as Social Security numbers and credit card data.
Features: General-purpose generative AI chat, web search, content creation, image generation, and other AI capabilities.
See Penn Generative AI Tools & Resources for current details.
Microsoft 365 Copilot
Access: Available to faculty and staff through participating Penn organizations. Contact Annenberg IT for access.
Data Protection: Penn currently permits Low-, Moderate-, and most High-Risk Data, with specified exclusions.
Features: Integrates generative AI with Microsoft applications including Excel, OneNote, Outlook, PowerPoint, Teams, and Word and can search information available through the user’s Microsoft 365 environment.
See Penn’s Brokered Products Portfolio for current details.
ChatGPT Edu
Access: Available to faculty and staff through Annenberg IT. Students may receive access when required for coursework or research and funded by the School, department, or instructor.
Data Protection: Penn currently permits Low- and Moderate-Risk Data. Sensitive information including HIPAA-protected information, personal health information, financial account information, Social Security numbers, and credit card data must not be entered.
Features: Full-range generative AI chat supporting text, images, and audio.
See Penn’s ChatGPT Edu FAQ.
Anthropic Claude
Access: Penn has executed an enterprise agreement with Anthropic. ASC integration and provisioning are being rolled out. Contact Annenberg IT for current access information or return to this page for updates as the rollout progresses.
Important: Anthropic may direct users with an @upenn.edu address through Penn SSO. Successful Penn SSO authentication does not necessarily mean that the Anthropic account has been provisioned under Penn’s enterprise agreement. Contact Annenberg IT to confirm that your account is covered before using it with Penn data.
Data Protection: Penn’s current Anthropic Enterprise offering is approved for Low- and Moderate-Risk Data. Do not enter High-Risk Data, PHI, financial account information, Social Security numbers, credit card data, or other sensitive information not permitted under Penn’s current guidance.
Features: Penn’s enterprise offering includes Claude Chat and Claude Code. Current service levels also include defined API usage allocations. Availability and configuration of individual features may change as the service is deployed.
See Penn’s Brokered Products Portfolio for current University information.
Grammarly for Education
Access: Available through Penn as a paid service. Contact Annenberg IT for access.
Data Protection: Penn currently permits Low-, Moderate-, and most High-Risk Data, except Social Security numbers and credit card data.
Features: Writing assistance including grammar and spelling support, outlining, citation assistance, and revision.
chat.asc.GPT
Access: Available through Annenberg IT.
Data Protection: Suitable for Low- and Moderate-Risk Data. Contact Annenberg IT before using the service for data whose classification or permitted use is unclear.
Features: An ASC-managed AI gateway that provides flexibility to make different AI models available depending on the use case, licensing, technical requirements, and security considerations. Depending on current configuration, this may include models from OpenAI, Anthropic, Google, or appropriately hosted open-weight models.
Model availability and capabilities change over time, and particular models or integrations may be enabled for specific applications or projects.
Cost: Usage may be metered. Contact Annenberg IT for information about a particular use case.
Other Penn AI Services
Additional Penn-supported services include selected Google Gemini offerings, Google NotebookLM, Snowflake AI capabilities, Zoom AI Companion, and other platforms that incorporate generative AI.
Penn also provides centralized access to some AI-assisted development tools, including GitHub Copilot through AI Coding Tools @ Penn.
Because these offerings and their permitted uses change frequently, consult Penn Generative AI Tools & Resources or contact Annenberg IT rather than relying on a static product list on this page.
AI Chat, APIs, Coding Tools, and Agentic AI
Not all uses of AI are the same. The security, privacy, financial, contractual, and operational risks can differ substantially depending on how an AI service is being used.
Penn’s Office of Information Security provides additional guidance relevant to AI applications, coding tools, and automated systems in its Guidance on Large Language Models.
AI Chat
AI chat services such as PennChat, ChatGPT Edu, Claude, Gemini, and Microsoft Copilot are generally interactive tools in which a user asks questions, uploads information, or requests content.
For ordinary chat use, Penn now provides several centrally supported options. In many cases there is no need to purchase an individual commercial AI subscription.
Before purchasing one, users should contact Annenberg IT to determine whether an existing Penn-supported service meets the need.
API Access
An application programming interface (API) allows software, scripts, research systems, websites, or other applications to communicate directly with an AI model rather than through a normal chat interface.
API use raises additional considerations, including:
- where data is transmitted, processed, and stored;
- what Penn agreement, if any, governs the particular API;
- authentication and protection of API credentials;
- usage-based costs and limits;
- research or contractual restrictions on data;
- logging and retention;
- integration with other Penn or third-party systems; and
- the possibility of substantial or unexpected usage charges.
Access to a vendor’s chat product should not be assumed to include access to that vendor’s API, developer services, or every other product offered by that company. API rights and protections are service- and contract-specific.
Some Penn AI agreements now include API capabilities or usage allocations, while others do not. These arrangements continue to evolve.
Anyone planning to use an AI API with Penn data, Penn-funded research, Penn systems, or University funds should consult with Annenberg IT before implementation or purchase. Annenberg IT can help identify an appropriate existing service and, when necessary, coordinate with ISC, Procurement, the Privacy Office, the Office of Information Security, or other University offices.
API keys, access tokens, passwords, and similar credentials should be treated as credentials and protected accordingly. They should not be pasted into AI prompts, embedded unnecessarily in source code, or shared through insecure means.
Coding Assistants and Agentic AI
AI coding assistants and newer agentic AI tools can do substantially more than generate text. Depending on how they are configured, these tools may be able to:
- read, create, and modify files;
- execute commands or computer code;
- install software;
- interact with websites or cloud services;
- access source-code repositories;
- query databases;
- send or modify information through connected services;
- access credentials, API keys, or authenticated sessions; or
- perform sequences of actions with limited human intervention.
Examples include AI-enabled development environments, command-line assistants, coding agents, autonomous research tools, Claude Code, GitHub Copilot, and similar systems.
These capabilities can be extremely useful, but they introduce risks that ordinary chat tools generally do not. An AI agent operating on a computer or through an account may be able to act with many of the same permissions as the user running it.
Agents that read websites, documents, email, source code, or other outside content can also be exposed to prompt injection or indirect prompt injection, in which instructions embedded in content attempt to cause the AI system to behave in an unexpected or unauthorized way.
Penn OIS discusses these and related risks in its Guidance on Large Language Models.
AI-generated computer code can contain errors or security vulnerabilities. Generated code should be reviewed and understood before use and should follow the same testing, security review, change-management, and production practices that would apply to code written by a person.
Use of agentic AI for Penn work should therefore include consultation with Annenberg IT before the tool is given access to Penn systems, credentials, research data, source code, cloud resources, shared drives, databases, or other non-public information.
Where appropriate:
- test agentic systems in isolated or constrained environments;
- give the system only the minimum data and permissions necessary for the task;
- avoid providing unnecessary or long-lived credentials;
- review generated code and proposed changes before deployment;
- maintain human review before consequential actions occur in other systems; and
- monitor the system’s activity and outputs rather than assuming that an automated action is correct or authorized.
Users remain responsible for work produced with AI and for actions taken by AI-enabled systems acting on their behalf.
Guidelines for Non-Contracted AI Tools
Many commercial and publicly available AI tools are not covered by a Penn agreement.
Penn notes that public AI tools generally do not have the same contractual protections as University-managed services. Review Penn’s Guidance for Use of Generative AI when considering these services.
Prohibited Data
Do not enter:
- Moderate-Risk or High-Risk Penn Data;
- unpublished or confidential research data;
- non-public personal information;
- confidential or proprietary Penn information;
- information governed by a research agreement, sponsor requirement, IRB protocol, data-use agreement, nondisclosure agreement, or other contractual restriction; or
- information that you are not authorized to disclose to a third party.
Inputs to public AI services may be retained or used in ways that differ from Penn-contracted services. Terms of service, ownership provisions, data-retention practices, and use of inputs for model improvement or training vary by provider and can change.
A business or research need for a non-contracted AI service involving Moderate- or High-Risk Data requires more than an individual decision to use the service. Appropriate contractual protection and University review may be required.
Contact Annenberg IT, which can help coordinate with Procurement, Penn’s Privacy Office, the Office of Information Security, or other appropriate offices.
Appropriate Uses
Public AI tools may generally be appropriate for activities involving only public or Low-Risk information, including:
- publicly available information;
- general research questions that do not expose non-public research data;
- creative writing involving non-confidential topics;
- coding assistance involving non-proprietary code;
- mathematics and problem-solving; and
- general learning and exploration.
When in doubt, use a Penn-supported service or contact Annenberg IT.
Research, IRB, and Intellectual Property Considerations
AI use in research may be subject to requirements beyond Penn’s general AI and data-classification guidance.
Researchers should comply with applicable federal and international requirements for informed consent and with all applicable Institutional Review Board requirements. Penn’s generative AI guidance states that IRB approval should be obtained before exposing research participant data to AI tools.
See Penn’s Guidance for Use of Generative AI and the Penn Institutional Review Board for authoritative guidance.
Particular caution is required for research involving High-Risk Data, personally identifiable information, and research participant health information. This concern can apply to health information even when it has been de-identified. The fact that an AI service is available through Penn does not supersede an IRB protocol, participant consent, sponsor requirement, data-use agreement, or other research restriction.
Researchers should also review sponsor policies and contractual restrictions before using AI with research data.
Confidential or proprietary research information may have intellectual-property implications. Researchers should avoid uploading confidential or proprietary information to an AI platform before determining whether patent, copyright, or other intellectual-property protection should first be pursued.
Questions concerning potential intellectual property should be referred to the Penn Center for Innovation as appropriate.
Best Practices
- Always verify AI-generated content. AI systems can produce incorrect, misleading, incomplete, biased, or fabricated information even when their responses appear authoritative.
- Be transparent about AI use. Penn’s AI guidance recommends disclosure when a work product was created wholly or partially using AI and, when appropriate, how AI contributed to the work.
- Protect Penn data. Confirm that the service is approved for the classification of data you intend to use.
- Use your Penn account. Enterprise protections associated with Penn-contracted services generally do not apply when using a personal account. Authentication through Penn SSO alone does not establish that an account is covered by a University agreement.
- Use the minimum information necessary. Avoid supplying additional confidential or identifying information simply because a tool is technically permitted to receive it.
- Review sponsor, research, and IRB requirements. Approval of an AI service for a particular Penn Data Risk Classification does not override research-specific requirements.
- Maintain academic integrity. AI use must comply with applicable course, School, University, publication, research, and professional requirements.
- Maintain human oversight. Users remain accountable for work produced with AI and for actions performed by AI-enabled systems.
- Review AI-generated code. AI-generated software should be understood, tested, and reviewed for security and correctness before production use.
- Protect credentials. Passwords, API keys, access tokens, and similar secrets require appropriate protection and should not be unnecessarily exposed to AI systems.
- Consider cost before purchasing. Penn may already provide an equivalent or more appropriate service through an institutional agreement.
- Consult ASC IT for API, integration, coding-agent, or agentic use. These uses may involve security, contractual, privacy, research, or operational considerations that are not apparent from a normal AI chat interface.
Getting Access to Protected Tools
Contact Annenberg IT Support at support@asc.upenn.edu for assistance with Penn-supported AI tools.
Depending on the request, we may ask for:
- your PennKey and Penn email address;
- the AI tool or capability you are considering;
- the intended use;
- the type and classification of data involved;
- whether the service will access other Penn systems;
- whether API, coding-assistant, integration, or agentic functionality is involved; and
- the anticipated funding source.
Annenberg IT can help determine whether a centrally supported Penn service may eliminate the need for a separately purchased AI subscription and can coordinate additional University review when necessary.
Support and Guidance
General AI questions and access:
Annenberg IT Support — support@asc.upenn.edu
Current Penn-supported AI tools, pricing, and data protections:
Penn Generative AI Tools & Resources
University guidance on AI use:
Guidance for Use of Generative AI
Penn information-security guidance for AI and LLMs:
Office of Information Security Guidance on Large Language Models
Data classification:
Penn Data Risk Classification
Privacy and use of personal data:
Penn Office of Privacy
Research and IRB:
Penn Institutional Review Board
Academic integrity:
Penn Code of Academic Integrity
Intellectual property:
Penn Center for Innovation
Data Risk Classifications and Permitted AI Usage
The following examples are intended as a general guide. Penn’s authoritative Data Risk Classification and service-specific guidance govern when there is any conflict or uncertainty.
The fact that one service is approved for a particular risk classification does not mean that every service from the same vendor has the same protections.
Low-Risk Data
Low-Risk Data is generally information intended for public disclosure or information whose loss would have no adverse impact on Penn or an individual.
Examples may include:
- public-facing information;
- PennKey usernames and PennID numbers;
- policy and procedure manuals specifically designated as public;
- published or otherwise publicly releasable research data;
- public directory information; and
- other information approved for public disclosure.
Low-Risk information may generally be used with Penn-contracted AI services and, with appropriate caution, public AI services.
Moderate-Risk Data
Moderate-Risk Data is information that is not generally available to the public or whose loss could have a mildly adverse effect on Penn or an individual.
Examples may include:
- some student education records, subject to FERPA and other applicable privacy requirements;
- non-public Penn policies and contracts that do not concern sensitive matters;
- internal Penn memos, email, and reports;
- internal budgets, plans, and financial information that do not contain High-Risk Data;
- engineering, design, and operational information about Penn infrastructure;
- restricted directory information; and
- unpublished research data, subject to the data owner’s discretion and any IRB, sponsor, contractual, or other restrictions.
Moderate-Risk Data should be used only with Penn-contracted services that Penn specifically authorizes for Moderate-Risk Data.
High-Risk Data
High-Risk Data includes information whose protection is required by law or regulation or whose compromise could have a significant adverse effect on Penn or an individual.
Examples may include:
- health information, including Protected Health Information (PHI);
- mental-health records;
- biometric data;
- passwords and other system credentials;
- Social Security numbers;
- credit card numbers;
- financial account numbers;
- government-issued identification numbers;
- certain location data that actively tracks an individual;
- disciplinary records;
- certain sensitive Human Resources records;
- donor contact information and non-public gift information;
- K-12 student records and other protected data concerning minors;
- sensitive research participant information; and
- export-controlled information.
Not all information that relates to finances or to an identifiable individual is automatically High Risk. For example, Penn classifies ordinary non-public budgets and financial information that do not themselves contain High-Risk Data as Moderate Risk, while financial account numbers and credit card numbers are High Risk.
High-Risk Data requires special care and may only be used with an AI service when Penn explicitly authorizes that service for the specific category of information involved.
Some Penn AI services permit most High-Risk Data while specifically excluding categories such as Social Security numbers, credit card data, or other particular types of sensitive information. Other Penn AI services are approved only for Low- and Moderate-Risk Data.
Always review the current service-specific restrictions in Penn Generative AI Tools & Resources before submitting High-Risk information.
When uncertain about the classification of data, the requirements associated with research data, or whether a particular AI service is appropriate, contact Annenberg IT before using the service.