
Vision & Guiding Principles
Confederation College responsibly integrates artificial intelligence to support and strengthen how we learn, work, and serve our communities while honoring Indigenous knowledge, upholding data sovereignty, and preparing our students and staff to thrive in an AI-enabled world.
Human Oversight
We are responsible for the AI systems we use. All AI tools must go through institutional review, and clear accountability must exist for how they are selected and monitored.
Human Responsibility
AI is a tool to support, not replace, professional judgment or the work people do. Individuals remain accountable for the quality and integrity of their outputs.
Cultural Respect and Empowerment
AI should be used in ways that respect and empower communities and culture.
Privacy, Data Protection, and Sovereignty
AI use must comply with applicable privacy laws and institutional policies. Data should only be used in ways that are necessary, secure, and appropriate.
Ethical and Safe Use
AI must be used lawfully, safely, and in ways that reflect institutional values. Users are responsible for reviewing outputs and considering potential harm, bias, or unintended consequences.
Continuous Evaluation and Adaptability
AI systems and practices should be reviewed regularly as technologies and risks evolve. The institution must be prepared to update tools, policies, and safeguards as the technology and its risks change.
Innovation and Experimentation
The institution supports thoughtful experimentation with AI within clear boundaries. Responsible exploration within approved pathways strengthens long-term capacity.
AI Use at Confederation College
Microsoft Copilot, accessed through your Confederation College tenant login, is the only generative AI tool formally reviewed and approved for use.
A generative AI tool is any software, service, or embedded feature that uses generative models to produce, analyze, summarize, or transform content based on user input.
Copilot use follows a necessity standard: ensure you are logged in, work with the least information the task allows, enter information only where there is legal authority and a legitimate College purpose, and limit it to what is necessary. Use de-identified or generalized descriptions wherever they will serve the task. Avoid entering sensitive personal information, such as health, accommodation, or disciplinary details, unless the use has been explicitly authorized.
Meetings, recording, and transcription. Any AI system must not be used to record or transcribe meetings that touch on employment or student matters, personal or health information, legal advice, or matters that could give rise to litigation. Recording may be appropriate for low-risk activities where no personal information comes up, and every participant must be informed before any recording starts.
Approval Process for New AI Tools
All AI tools require explicit IT review before use. Any AI tool that has not been reviewed by IT requires a formal approval process before it may be used with any college data.
AI Tool Approval Status
The table below lists the AI tools currently approved for use at the College. The type of data being entered determines whether a given tool may be used. Permitted data categories are defined in the section below, refer to those definitions when interpreting the table.
Tool | Status | Permitted Data | Notes |
|---|---|---|---|
Copilot Chat, signed in with your Confederation College login (tenant login) | Approved | Public, confidential, Restricted only where strictly necessary and authorized | Reviewed by IT. Formal Microsoft vendor contract in place with Canadian data residency provisions. Enter the minimum personal information necessary and de-identify wherever possible. Do not use Highly Restricted data under any circumstances. |
All Other AI Tools (ChatGPT, Gemini, Claude, DeepSeek, Copilot without college login, and any tool not accessed through your college credentials) | Requires Review, Not Approved by Default | Public (with IT review and approval) | No vendor contract. Canadian data residency cannot be confirmed. Confidential, restricted, or highly restricted data must never be used with these tools. IT approval is required even for public data use cases. See approval process for more information. |
Requirements for Copilot Use
The following requirements apply whenever Copilot is used with College information.
- Use your College account only: Access Copilot exclusively through your Confederation College tenant login. College information must never be copied into personal Microsoft accounts, personal AI subscriptions, or any external AI tool.
- Copilot inherits your permissions: Copilot surfaces only the information your account is already authorized to access. Share Copilot outputs only with people who are authorized to see the underlying sources.
- Save outputs of ongoing value: Copilot chats and prompts are working material. If an output shapes a decision, appears in formal correspondence, or holds lasting value, save it to the appropriate College repository.
Acceptable Use of Copilot
The examples below describe how Copilot may and may not be used with College information. They are illustrative rather
than exhaustive; when a planned use falls outside them, contact IT before proceeding.
Copilot may be used for the following:
- Drafting and refining internal content: Produce working drafts of memos and messages, condense meeting notes, tighten tone and clarity, and pull action items out of internal College material, with human review before anything is shared or relied on.
- Supporting routine work: Assemble agendas, turn rough notes into task lists, outline documents before drafting, and reformat existing content, with the output checked before use.
- Analyzing data you are authorized to access: Work with documents and datasets already within your permissions, handled under the data classifications defined below.
- Preparing teaching and learning materials: Develop aids and course resources from unrestricted content, provided no personal information about students or employees is disclosed.
Copilot must not be used for the following:
- Entering personal information without authority: Personal information may be collected, used, disclosed, or entered into Copilot only where legal authority and a legitimate College purpose exist, limited to what is strictly necessary under the necessity standard above. Sensitive personal information, including health, human resources, and legal material, must not enter Copilot.
- Making decisions about individuals: Copilot must not determine outcomes that affect a person’s rights, employment, academic standing, or legal interests. Any decision informed by its outputs requires meaningful human review and documentation.
- Producing high-stakes content without review: Content where an error could endanger health or safety, harm the College’s reputation, or create legal exposure requires full human review and the normal approval chain before release.
- Working with Indigenous data or knowledge: Indigenous data, stories, languages, or knowledge must not be entered into Copilot without the express authorization of the community concerned.
Data Classifications
College data refers to any information the institution creates, collects, receives, or manages in the course of its operations, including student records, research data, internal documents, teaching materials, and administrative information. All such data falls into one of the four confidentiality levels described below. Use these definitions to self-identify what category your data falls into before engaging any AI tool.
Tier 1: Public Data
Public data is information that has been intentionally released or approved for release to the general public. Its disclosure carries no meaningful risk of harm to individuals or the institution.
Examples (Including, but not limited to): Published course descriptions, program information, public directory information, approved press releases, public research outputs, public website content, news articles, external job postings, publicly available government or regulatory documents.
AI Use: May be used with Copilot (tenant login) or, with prior IT approval for the specific use case, with other tools. Approval must be obtained before use, do not assume public data is freely usable with any tool without confirmation.
Tier 2: Confidential Data
Confidential data is institutional information intended for internal use or a defined audience, and is not approved for public release. Unauthorized disclosure could result in moderate harm, including loss of privacy, competitive disadvantage, damage to institutional reputation, or erosion of trust in programs or partnerships.
Examples (Including, but not limited to): Internal meeting notes and minutes, draft institutional policies, internal memos, non-public research data, de-identified operational and financial data, internal email communications, vendor proposals under review, internal project plans, enrolment data not yet released publicly.
AI Use: Only Copilot (tenant login) may be used. All other AI tools are not permitted. Anonymize or de-identify data wherever possible before use.
Tier 3: Restricted Data
Restricted data is sensitive personal or institutional information whose unauthorized disclosure could cause significant harm, including serious violations of individual privacy, substantial financial loss, legal liability, or major damage to the institution’s standing.
Examples (Including, but not limited to): Personally identifiable information (PII) such as dates of birth, personal contact details, home addresses, student ID numbers (which are now classified as private PII), personnel files, salary records, disciplinary files, accommodation or accessibility records, information shared in confidence, sensitive research participant data, immigration status, and information protected under FIPPA or PIPEDA.
AI Use: Only Copilot (tenant login) may be used, and only when strictly necessary, with legal authority and a legitimate College purpose. Anonymize or de-identify all data before use. Human review is required before any decisions are made based on AI-processed restricted data.
Tier 4: Highly Restricted Data
Highly Restricted data is the most sensitive category. Its unauthorized disclosure could cause extreme harm, including severe risks to personal safety or critical damage to institutional operations or legal standing. Access is limited to specifically named and authorized individuals.
Examples (Including, but not limited to): Social insurance numbers (SINs), credit card and banking details, personal medical and mental health records, biometric data, highly sensitive legal files, authentication credentials and passwords, data whose exposure would trigger mandatory breach notification under applicable privacy legislation.
AI Use: Not permitted with any AI tool. This applies even to institutionally approved tools such as Copilot. This data must never be entered into any AI system.