AI tools and guidance

What data are you using?

Before putting University data into an AI tool, consider what kind of information it is:

  • Public: Consumer AI tools can generally be used.

  • Confidential or Restricted: Use a University-approved AI tool (license required).
  • Highly Restricted: Do not use AI unless the specific use has been explicitly approved.

Use the tables and definitions below to determine which tool, if any, best supports your use case. 

This page provides guidance for commonly used AI tools. It is not a complete list of AI tools reviewed or used at the University of Waterloo. Some tools may be approved only for a specific use, configuration, or group of users. If the tool you are looking for is not listed, or you are unsure whether your intended use is covered, contact your IST Account Rep or Faculty IT service desk.

Approved AI tools

Tool name Tool status Approved for data made public by the source Approved for University data — Confidential or Restricted Approved for University data — Highly Restricted Cost (approximate) Notes & Limitations

Microsoft Copilot Basic (UW login)

Approved

✅ Yes

✅ Yes

❌ No

Free

Included for all users. Approved for University data up to and including Restricted when you sign in with your UW account.

Go to Copilot Chat

 

Microsoft Copilot Premium (UW login)

Appoved

✅ Yes

✅ Yes

❌ No

~$25 CAD/licence/mth

Cost is prorated to May 1, 2027

Requires a licence. Adds Copilot inside Microsoft 365 apps such as Word, Excel, Outlook and Teams. Approved for University data up to and including Restricted. Available to faculty and staff upon request.

Request an AI licence

Anthropic Claude (UW login)

Appoved

✅ Yes

✅ Yes

❌ No

$20 USD/licence/mth (Standard)

$50/licence/mth (Premium)

Cost is prorated to August 1, 2027

Requires a licence. Approved for University data up to and including Restricted when using the UW-provided account. Available to faculty and staff upon request.

  • Standard provides full access to Claude at the standard usage level
  • Premium provides about five times the usage of Standard, plus access to Claude Fable

 Request an AI licence

GitHub Copilot (Business or Enterprise, UW login)

Approved ✅ Yes ✅ Yes ❌ No

$19 USD/licence/mth (Business)

$39 USD/licence/mth (Enterprise)

GitHub Copilot is an AI coding assistant for faculty and staff who write code.

Requires a licence. Approved for University data up to and including Restricted when using UW login. Available to faculty and staff upon request.

  • Business provides core GitHub Copilot features
  • Enterprise provides everything in Business, plus more usage credits

Request an AI licence

Copilot Chat Reviewed for limited use ✅ Yes ❌ No ❌ No Free

Use only with data made public by the source.

Not approved for University-owned data that is not publicly available. This includes Copilot used without signing in, or with a personal Microsoft account.

ChatGPT Reviewed for limited use ✅ Yes ❌ No ❌ No

Free for basic

Plus (for personal account) requires a fee

Use only with data made public by the source.

Not approved for University-owned data that is not publicly available.

Claude  Reviewed for limited use ✅ Yes ❌ No ❌ No Free for personal account

Use only with data made public by the source.

Not approved for University-owned data that is not publicly available.

Important: Highly restricted data must not be used with any AI tool unless that specific use has received explicit, documented approval from the appropriate Information Steward. How an AI tool becomes approved.

Problematic tools: AI tools not approved for University data

The following tools are not approved for use with University data because identified security, privacy, or other risks could not be adequately addressed for the proposed use. Waterloo may block or restrict access to tools that present unacceptable risks to institutional systems or data.

Tool name Tool status Notes
Otter.ai + Firefies.ai Problematic These tools can join meetings automatically and record without clear user control or consent, creating substantial privacy concerns. They are not approved for use with University data.

DeepSeek (hosted versions including mobile apps)

Problematic

The publicly hosted application is not approved for use with University data. A self-hosted deployment may be evaluated by IST and considered only if it meets University security requirements.

Personal AI agents (e.g., Meta Muse) Problematic

These tools ask for ongoing access to your email, calendar, files and other accounts, then take actions on your behalf, sometimes without you reviewing each step. Meta Muse has had several publicly reported security flaws since its launch, including one that could have exposed a user's emails and files.

Do not connect your Waterloo account to a personal AI agent. Learn why and what to do if you have.

Not approved for any University data. 

Giving AI agents access to your account

Some AI tools ask you to sign in with your Waterloo account or connect it to Outlook, OneDrive, Teams or your calendar. Approving this type of request is different from typing into a chatbot; it gives the AI agent access to everything in that account, not just the item you're working on. Your email and files likely contain Confidential, Restricted or Highly Restricted data, even if you never meant to share it.

Only connect your Waterloo account to tools listed as Approved on this page.

If you have already connected to an AI tool that isn't approved, disconnect it in the tool's settings. 

Understanding University data

University data refers to information that the University creates, collects, receives, or manages in the course of its operations. This includes student records, research data, internal documents, teaching materials, and administrative information.

All University data is subject to the classification framework outlined in Policy 46 – Information Management, which categorizes information into one of the following confidentiality levels:

For support in understanding how to classify data, refer to the Guidance on Information Confidentiality Classification (Policy 46). Researchers using AI tools are advised to consult the Research data risk classification framework and guidelines to ensure appropriate handling of research information.

Quick links

Use of AI tools with University data

AI tools include:

  • Standalone AI applications (e.g., chatbots, coding assistants, data analysis tools, or tutoring/learning assistants)
  • AI capabilities embedded within existing institutional systems (e.g., AI-enabled search or recommendations, automated transcription, predictive analytics, or AI-assisted productivity features)

To use AI tools safely, it is important to understand the type of tool you are working with and how the tool relates to University data. Consider the following four categories: 

Approved

  • Reviewed by IST, including an Information Risk Assessment (IRA) and, when required, a Privacy Impact Assessment (PIA)
  • Supported by a formal contract with the vendor
  • Suitable for handling Confidential and Restricted data, with required permissions for data use obtained
  • Use with Highly Restricted data requires explicit, documented approval from the appropriate Information Steward

See table of Approved AI tools.

Reviewed for limited use

  • Reviewed by IST, with an Information Risk Assessment completed for limited use - appropriate only for the specific use case for which the tool was reviewed 
  • No contract with the vendor
  • Appropriate for use with data that has been made public by the source
  • Not suitable for university-owned data that has not been made public (i.e. confidential, restricted, or highly restricted data)

Problematic

  • Reviewed and identified as presenting significant risks
  • Not appropriate for any University data
  • May store, retain or use information in ways that pose security or privacy concern

See table of Problematic AI tools.

Unreviewed

  • No assessment completed
  • Risks are unknown
  • No contract or formal oversight
  • Not suitable for university-owned data that has not been made public (i.e., confidential, restricted, or highly restricted data)