Best Practices: Using Generative AI

robot hands and human hands on keyboard

What is Generative AI Use?

Generative AI systems can help create content, summarize information, answer questions, and support learning, research, and productivity.

These tools can provide significant benefits, but they also introduce risks related to privacy, security, accuracy, intellectual property, and data protection. Understanding these risks can help you use AI safely and responsibly. 

Some AI tools can do more than generate content. They may search connected files, send messages, modify documents, execute code, call external services, or complete tasks on your behalf. The more access and autonomy an AI tool has, the more carefully you should evaluate what it can see, what it can do, and who remains responsible for the result. 
 

Common Risks

CategoryWhy It Matters
Sensitive Information Exposure
Information entered into an AI tool may be stored, processed, logged, retained, or shared in ways that are not appropriate for sensitive Harvard data.
Inaccurate or Misleading Outputs
AI systems can generate incorrect, incomplete, or misleading information that appears convincing.
Connected Data & Applications
An AI tool may access connected files, email, calendars, repositories, or third-party services, sometimes with more access than intended. 
Persistent Memory & Context
Certain tools may retain information across conversations or sessions, or use prior context to personalize future interactions.
Prompt Injection and Malicious Content
Instructions embedded in documents, websites, messages, or other content may attempt to manipulate an AI system into disclosing information or taking unintended actions.
Unapproved Tools or Features
Experimental models, external applications, browser extensions, and consumer accounts may not meet Harvard's privacy or security requirements.
Academic, Research, and Professional Integrity
Using AI-generated content without appropriate review, attribution, disclosure, or authorization may violate academic, research, or professional expectations.

Best Practices

Use University-Approved Tools

  • Use the Harvard-offered version of a service for University work rather than a personal or consumer account.
  • Understand what protections apply to the specific tool, model, workspace, and feature you are using.
  • Avoid using personal or consumer AI accounts for University business unless explicitly permitted. 

Protect Sensitive Information

  • Do not enter regulated, restricted, or highly sensitive information into AI tools unless specifically authorized. 
  • Follow Harvard data classification and data handling requirements.
  • Remove unnecessary personal, confidential, proprietary, or identifying information before sharing content with an AI system.

Understand Connected Features

  • Review what files, applications, accounts, and services the AI tool can access.
  • Determine whether the tool can only read information or can also create, modify, delete, send, approve, or execute actions.
  • Grant only the permissions needed for the task. 
  • Disconnect integrations that are no longer necessary.

Review AI-Generated Content and Actions

  • Verify important information against trusted sources. 
  • Carefully review summaries, recommendations, and generated content before using or sharing them. 
  • Do not assume AI-generated actions or suggestions are correct simply because they were produced by AI.
  • Remain responsible for the accuracy, security, quality, and appropriateness of work produced with AI assistance.

Be Mindful of Privacy, Copyright, and Disclosure

  • Respect privacy, confidentiality, intellectual property, copyright, and contractual requirements.
  • Do not upload information about others unless authorized to do so. 
  • Consider whether content contains copyrighted, proprietary, restricted, or third-party material.

Use AI Responsibly in Academic and Professional Work

  • Follow course, departmental, research, and workplace expectations regarding AI use. 
  • Cite or disclose AI assistance when required. 
  • Remember that you remain responsible for the accuracy and quality of your work. 

Use Meeting and Recording Tools Carefully

  • Use AI meeting assistants and note-taking tools only when approved by the University. 
  • Inform participants when AI tools are recording, transcribing, or summarizing a meeting. 
  • Follow applicable privacy and consent requirements. 

Related Resources

Use these resources to take the next step, find University guidance, or explore trusted external references.