What data are you using?
Before putting University data into an AI tool, consider what kind of information it is:
-
Public: Consumer AI tools can generally be used.
- Confidential or Restricted: Use a University-approved AI tool (license required).
- Highly Restricted: Do not use AI unless the specific use has been explicitly approved.
Use the tables and definitions below to determine which tool, if any, best supports your use case.
This page provides guidance for commonly used AI tools. It is not a complete list of AI tools reviewed or used at the University of Waterloo. Some tools may be approved only for a specific use, configuration, or group of users. If the tool you are looking for is not listed, or you are unsure whether your intended use is covered, contact your IST Account Rep or Faculty IT service desk.
Approved AI tools
| Tool name | Tool status | Approved for data made public by the source | Approved for University data — Confidential or Restricted | Approved for University data — Highly Restricted | Cost (approximate) | Notes & Limitations |
|---|---|---|---|---|---|---|
|
Microsoft Copilot Basic (UW login) |
Approved |
✅ Yes |
✅ Yes |
❌ No |
Free |
Included for all users. Approved for University data up to and including Restricted when you sign in with your UW account.
|
|
Microsoft Copilot Premium (UW login) |
Appoved |
✅ Yes |
✅ Yes |
❌ No |
~$25 CAD/licence/mth Cost is prorated to May 1, 2027 |
Requires a licence. Adds Copilot inside Microsoft 365 apps such as Word, Excel, Outlook and Teams. Approved for University data up to and including Restricted. Available to faculty and staff upon request. |
|
Anthropic Claude (UW login) |
Appoved |
✅ Yes |
✅ Yes |
❌ No |
$20 USD/licence/mth (Standard) $50/licence/mth (Premium) Cost is prorated to August 1, 2027 |
Requires a licence. Approved for University data up to and including Restricted when using the UW-provided account. Available to faculty and staff upon request.
|
|
GitHub Copilot (Business or Enterprise, UW login) |
Approved | ✅ Yes | ✅ Yes | ❌ No |
$19 USD/licence/mth (Business) $39 USD/licence/mth (Enterprise) |
GitHub Copilot is an AI coding assistant for faculty and staff who write code. Requires a licence. Approved for University data up to and including Restricted when using UW login. Available to faculty and staff upon request.
|
| Copilot Chat | Reviewed for limited use | ✅ Yes | ❌ No | ❌ No | Free |
Use only with data made public by the source. Not approved for University-owned data that is not publicly available. This includes Copilot used without signing in, or with a personal Microsoft account. |
| ChatGPT | Reviewed for limited use | ✅ Yes | ❌ No | ❌ No |
Free for basic Plus (for personal account) requires a fee |
Use only with data made public by the source. Not approved for University-owned data that is not publicly available. |
| Claude | Reviewed for limited use | ✅ Yes | ❌ No | ❌ No | Free for personal account |
Use only with data made public by the source. Not approved for University-owned data that is not publicly available. |
Important: Highly restricted data must not be used with any AI tool unless that specific use has received explicit, documented approval from the appropriate Information Steward. How an AI tool becomes approved.
Problematic tools: AI tools not approved for University data
The following tools are not approved for use with University data because identified security, privacy, or other risks could not be adequately addressed for the proposed use. Waterloo may block or restrict access to tools that present unacceptable risks to institutional systems or data.
| Tool name | Tool status | Notes |
|---|---|---|
| Otter.ai + Firefies.ai | Problematic | These tools can join meetings automatically and record without clear user control or consent, creating substantial privacy concerns. They are not approved for use with University data. |
|
DeepSeek (hosted versions including mobile apps) |
Problematic |
The publicly hosted application is not approved for use with University data. A self-hosted deployment may be evaluated by IST and considered only if it meets University security requirements. |
| Personal AI agents (e.g., Meta Muse) | Problematic |
These tools ask for ongoing access to your email, calendar, files and other accounts, then take actions on your behalf, sometimes without you reviewing each step. Meta Muse has had several publicly reported security flaws since its launch, including one that could have exposed a user's emails and files. Not approved for any University data. |
Giving AI agents access to your account
Some AI tools ask you to sign in with your Waterloo account or connect it to Outlook, OneDrive, Teams or your calendar. Approving this type of request is different from typing into a chatbot; it gives the AI agent access to everything in that account, not just the item you're working on. Your email and files likely contain Confidential, Restricted or Highly Restricted data, even if you never meant to share it.
Only connect your Waterloo account to tools listed as Approved on this page.
If you have already connected to an AI tool that isn't approved, disconnect it in the tool's settings.
Understanding University data
University data refers to information that the University creates, collects, receives, or manages in the course of its operations. This includes student records, research data, internal documents, teaching materials, and administrative information.
All University data is subject to the classification framework outlined in Policy 46 – Information Management, which categorizes information into one of the following confidentiality levels:
For support in understanding how to classify data, refer to the Guidance on Information Confidentiality Classification (Policy 46). Researchers using AI tools are advised to consult the Research data risk classification framework and guidelines to ensure appropriate handling of research information.
Quick links
Use of AI tools with University data
AI tools include:
- Standalone AI applications (e.g., chatbots, coding assistants, data analysis tools, or tutoring/learning assistants)
- AI capabilities embedded within existing institutional systems (e.g., AI-enabled search or recommendations, automated transcription, predictive analytics, or AI-assisted productivity features)
To use AI tools safely, it is important to understand the type of tool you are working with and how the tool relates to University data. Consider the following four categories:
Approved
- Reviewed by IST, including an Information Risk Assessment (IRA) and, when required, a Privacy Impact Assessment (PIA)
- Supported by a formal contract with the vendor
- Suitable for handling Confidential and Restricted data, with required permissions for data use obtained
- Use with Highly Restricted data requires explicit, documented approval from the appropriate Information Steward
See table of Approved AI tools.
Reviewed for limited use
- Reviewed by IST, with an Information Risk Assessment completed for limited use - appropriate only for the specific use case for which the tool was reviewed
- No contract with the vendor
- Appropriate for use with data that has been made public by the source
- Not suitable for university-owned data that has not been made public (i.e. confidential, restricted, or highly restricted data)
Problematic
- Reviewed and identified as presenting significant risks
- Not appropriate for any University data
- May store, retain or use information in ways that pose security or privacy concern
See table of Problematic AI tools.
Unreviewed
- No assessment completed
- Risks are unknown
- No contract or formal oversight
- Not suitable for university-owned data that has not been made public (i.e., confidential, restricted, or highly restricted data)