AI Governance Framework

1. Purpose

The AI Governance Framework establishes principles, responsibilities, processes, and controls for the responsible use, development, procurement, deployment, and oversight of artificial intelligence (AI) across the University of Digital and AI Management (UniDAIM). It promotes AI innovation while protecting academic integrity, privacy, security, fairness, transparency, human judgment, and institutional trust.

2. Scope

This Framework applies to all UniDAIM departments, academic units, faculty, researchers, staff, administrators, contractors, students, and authorized representatives, and to all AI systems developed, purchased, licensed, integrated, or used by the University, including generative AI, machine learning, AI agents, automated decision systems, recommendation systems, and third-party AI services.

3. AI Governance Principles

The AI governance is based on ten principles:

  1. Human Accountability: Humans remain responsible for consequential decisions.
  2. Human Oversight: High-impact AI use requires meaningful human review.
  3. Fairness: AI must minimize unjustified bias, discrimination, and exclusion.
  4. Privacy: Data must be authorized, appropriate, and securely processed.
  5. Security: AI must be protected against misuse, manipulation, and data leakage.
  6. Transparency: AI involvement should be disclosed where appropriate.
  7. Academic Integrity: AI must support, not undermine, academic standards.
  8. Accuracy: Important AI outputs must be verified before reliance or publication.
  9. Purpose Limitation: AI must serve a legitimate, defined purpose.
  10. Continuous Improvement: Governance must evolve with technology, risks, standards, and law.

4. AI Governance Structure

UniDAIM will maintain governance separating strategic oversight, operational management, technical implementation, and individual responsibility.

4.1 AI Governance Committee

The AI Governance Committee (AIGC) oversees institutional AI governance and may include University leadership, academic affairs, IT, privacy/data protection, quality assurance, faculty, research, student affairs, and legal or advisory representatives.

The AIGC establishes AI priorities and policies, reviews high-risk systems and incidents, monitors emerging requirements, promotes AI literacy, evaluates controls, and recommends modification, suspension, or retirement of AI systems.

5. AI System Ownership

Every institutional AI system must have a designated AI System Owner responsible for its purpose, documentation, risk assessment, approvals, performance, incidents, provider obligations, monitoring, and periodic review or retirement.

6. AI Risk Classification

UniDAIM will apply a risk-based approach:

  • Level 1 – Minimal Risk: Brainstorming, drafting non-sensitive content, translation, formatting, and general assistance. Basic responsible-use requirements apply.
  • Level 2 – Moderate Risk: Chatbots, learning recommendations, workflow automation, internal analytics, and AI-assisted academic activities. Registration, risk assessment, oversight, and appropriate privacy/security review apply.
  • Level 3 – High Risk: Admissions, progression, grading, academic integrity, employment, financial eligibility, or other materially consequential decisions. Formal assessment, approval, testing, human oversight, monitoring, and periodic review are required.
  • Level 4 – Prohibited/Restricted: Unlawful or discriminatory uses, unauthorized surveillance, unapproved processing of confidential information, unsupervised high-impact decisions, deliberate deception, or fabrication of academic records, credentials, research data, or evidence.

7. AI Lifecycle Governance

Every significant AI system should follow eight stages: Identify, Assess, Approve, Develop/Procure, Test, Deploy, Monitor, and Review/Retire. Assessment should consider purpose, users, affected individuals, data, risk, privacy, security, fairness, accuracy, academic integrity, legal requirements, and third-party risks.

8. AI in Teaching and Learning

AI may support tutoring, research, brainstorming, personalized learning, language assistance, feedback, content development, coding, and accessibility. Faculty should define when AI is permitted, required disclosures or citations, and assessments requiring independent work. Students remain responsible for submitted work.

9. AI in Assessment and Grading

AI-assisted assessment may be used when appropriately validated and supervised. AI must not become the sole basis of high-impact academic decisions. Faculty remain responsible for reviewing outputs, correcting errors, considering appeals, and protecting student information.

10. AI in Research

Researchers must verify AI-generated information, protect confidential data and intellectual property, avoid fabricated data or citations, disclose AI use where required, maintain research records, and retain responsibility for research integrity. AI is not an independent author or investigator.

11. Generative AI Governance

Users must verify consequential outputs, protect confidential information, review generated content, consider intellectual-property implications, avoid fabricated sources, and follow applicable disclosure requirements. UniDAIM may maintain an approved list of institutional generative AI tools.

12. Data Governance and Privacy

AI use must comply with UniDAIM data protection and security requirements. Before processing institutional information, users should consider the data involved, authorization, storage location, access, provider training/retention practices, deletion, and contractual protections. Restricted information must use approved systems with appropriate safeguards.

13. Third-Party AI Providers

External AI services should undergo proportionate due diligence covering reliability, privacy, security, data retention, model training, intellectual property, subprocessors, resilience, contractual protections, termination, and data retrieval. High-risk providers require enhanced review.

14. AI Security

Appropriate controls may include authentication, role-based access, encryption, logging, monitoring, secure configuration, input/output controls, rate limiting, abuse prevention, incident response, and recovery. Systems should be assessed for prompt injection, malicious inputs, data disclosure, model manipulation, and inappropriate automated actions.

15. AI Transparency

Where material, individuals should be informed when interacting with AI, the system’s purpose and limitations, whether human review occurs, and how human assistance may be requested. Transparency should be proportionate to risk.

16. AI Incident Management

Significant AI incidents involving privacy, security, discrimination, misinformation, academic harm, unauthorized decisions, data leakage, operational disruption, or reputational harm must be reported. UniDAIM may investigate, suspend systems, correct decisions, notify affected parties, implement controls, document lessons, and escalate where required.

17. AI Documentation

Moderate- and high-risk systems should maintain an AI System Record covering ownership, purpose, provider, technology, data, users, risk classification, limitations, testing, oversight, security, privacy, approvals, monitoring, incidents, and review or retirement status.

18. AI Literacy and Training

UniDAIM will promote AI literacy covering responsible use, limitations, misinformation, privacy, cybersecurity, academic integrity, bias, intellectual property, security, and human oversight. Personnel managing high-risk systems should receive additional training.

19. AI Ethics Review

An AI Ethics Review may be required for significant ethical, academic, social, or human-impact concerns. Reviews may consider benefits, harms, fairness, proportionality, necessity, alternatives, and meaningful human recourse.

20. AI Governance Decision Rights

University leadership oversees institutional strategy; the AIGC oversees governance policy and high-risk matters; System Owners oversee individual systems; IT oversees technical security; appropriate privacy authorities oversee data protection; academic and research leadership oversee academic and research use; relevant functions jointly manage incidents and periodic reviews.

21. AI Governance Controls

Controls operate across five layers: Governance (policies, ownership, risk, approval); People (training, accountability, oversight); Process (assessment, procurement, testing, monitoring, incidents); Technology (access, security, data protection, validation); and Assurance (reviews, audits, documentation, evaluation).

22. AI Governance Metrics

UniDAIM will monitor AI registrations, high-risk systems, ownership, completed assessments, incidents and resolutions, training completion, third-party reviews, periodic reviews, and suspended or retired systems.

23. Accountability

AI does not remove human responsibility. Anyone approving, deploying, operating, or relying on AI remains accountable for applicable UniDAIM requirements and professional obligations.

24. Exceptions

Exceptions require appropriate institutional approval and documentation of the request, reason, affected system, risks, safeguards, duration, and responsible owner. High-risk exceptions require documented review.

25. Review and Continuous Improvement

This Framework will be reviewed at least annually and when significant changes occur in AI technology, law, standards, University operations, risks, or institutional strategy.

Appendix A — Minimum AI Use Rules

  1. Do not enter confidential or restricted information into unapproved AI tools.
  2. Verify important AI-generated information and sources.
  3. Do not fabricate records, credentials, research data, evidence, or citations.
  4. Do not use AI for discriminatory or harmful purposes.
  5. Maintain human responsibility for consequential decisions.
  6. Follow academic integrity and disclosure requirements.
  7. Protect personal and institutional data.
  8. Report significant AI incidents or misuse.
  9. Follow UniDAIM policies and applicable requirements.

Appendix B — Framework Alignment

UniDAIM may reference recognized frameworks including the NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001, ISO/IEC 23894, OECD AI Principles, and applicable AI legislation and regulatory requirements. External frameworks support, but do not replace, UniDAIM’s own institutional risk assessment.


Version: 1.0
Effective Date: August 26, 2026
Last Updated: August 27, 2026

Scroll to Top