
Week 1
Draft an Enterprise AI Use Policy
Client Background
Westfield University is adopting AI across administration (admissions review, grant writing, HR drafting) and teaching (faculty using AI assistants; students submitting AI-assisted work). After a faculty member pasted a student's confidential financial-aid appeal into a public AI chatbot, the Provost commissioned an enterprise AI use policy to set enforceable boundaries.
Business Environment
You are the AI governance consultant. Westfield shared current Acceptable Use guidance, the data classification standard, and notes from academic, HR, and IT councils. Your job is to draft a practical AI Use Policy covering permitted/prohibited uses, data handling, approvals, and accountability.
Security Incident
No breach; the engagement is a proactive policy commission triggered when a faculty member pasted a student's confidential financial-aid appeal into a public AI chatbot, prompting the Provost to set enforceable AI-use boundaries before the next academic term.
Scope
Policy drafting covering AI use by staff, faculty, and students, with references to existing data classification and acceptable use standards. Excludes building technical enforcement tooling and academic-integrity bylaw changes.
Objectives
- Define permitted and prohibited uses of AI across Westfield
- Establish data-handling rules aligned to the data classification standard
- Create an AI tool approval and exception process
- Draft an enforceable, plain-English AI Use Policy with accountability
- Add policy provisions for autonomous AI agents and high-risk uses (e.g., admissions triage), including mandatory bias auditing, human-in-the-loop review, and transparency disclosures per the EU AI Act's global reach.
Required Deliverables