Wikier

Information security

Use of ICT tools with generative artificial intelligence at NTNU - policy

This page contains the formal guidelines for students and staff regarding the use of ICT tools with generative artificial intelligence at Norwegian University of Science and Technology. For further information on practical use, guidance, and a list of approved tools, it is also recommended to consult these pages:


Norwegian version - Retningslinje for bruk av IKT-verktøy med generativ kunstig intelligens ved NTNU


1. Purpose

The guideline shall ensure that the use of ICT-tools with generative artificial intelligence (AI tools) at NTNU:

  • takes place legally, responsibly, and in accordance with requirements for information security, privacy, ethics, academic integrity, and sound administrative practice.
  • ensures accountability, transparency, and verifiability.
  • maintains trust in NTNU’s research, education, other academic activities, and administration.
  • takes place through the use of AI tools that are suitable and approved for the type of information being processed and for the purpose for which the tool is used.

By “ICT-tools with generative artificial intelligence” is meant tools that use an AI system in accordance with the definition in Article 3 of the EU AI Act, limited to AI systems that can generate new content, such as text, images, audio, video, or code, based on the user’s instructions or other information input into the tool.

2. Scope

The guideline apply to all use of ICT tools with generative artificial intelligence in connection with work, studies, or assignments at NTNU, regardless of the purpose and which tool or service the AI functionality is part of.

3. Requirements for Sound and Responsible Use of AI Tools

3.1 Requirements for all users

All Users refers to students, employees, or those performing work on behalf of NTNU

All users

All users are required to:

  • ensure that the use of AI tools complies with applicable laws and guidelines, including rules on information security, privacy, copyright, research ethics, academic integrity, discrimination, and the exercise of public authority, see Chapter 5.
  • be aware of the limitations of AI tools, complete necessary basic training before using such tools, and only use AI tools that are approved for the type of information being processed and for the intended purpose, see Chapter 3.2.
  • not enter personally identifiable information into AI tools that are not approved for the purpose of the data processing, see Chapter 3.2.
  • be critical of AI-generated content and verify that information is accurate, relevant, and academically sound before using it.
  • uphold academic integrity and responsibility when using AI-generated content and results. This applies to content and results that are wholly or partially used, published, or relied upon in work or studies.
  • be transparent about the use of AI tools where this has influenced the final result.
  • ensure that the use of AI tools that have been part of or influenced case processing, administrative decision-making processes, or academic assessments can be explained and verified, for example by retaining relevant chat logs or other documentation.
  • clearly label content that is entirely or largely generated by AI and that may be perceived by the recipient as authentic or evidentiary.
  • reflect on sustainability considerations when using generative AI. The development, training, and use of artificial intelligence involve significant energy consumption and may have major environmental impacts if the technology is not used responsibly.
  • never use AI tools for prohibited purposes, see Chapter 3.3.
  • report undesirable or improper use of AI to their immediate supervisor or through NTNUs deficiencies reporting system.

Students

Students are also required to:

  • not use AI tools in a way that undermines the purpose of a learning or assessment activity.
  • familiarize themselves with the rules that apply to the use of AI in each course and assessment situation and follow guidance from the lecturer or course coordinator regarding the use of AI and disclosure of AI use.
  • use AI tools in a manner consistent with requirements for academic integrity, including never presenting AI-generated content as their own work or using AI-generated content as an academic source.

Lecturers and course coordinators

Lecturers and course coordinators are also required to:

  • not require students to create user accounts in AI services that are not approved by NTNU in order to participate in teaching, complete mandatory activities, or submit exams.
  • assess and facilitate the use of AI where it is academically relevant, communicate permitted use and applicable frameworks in the course, and design assessment methods that uphold requirements for academic integrity and independent work.

Researchers

Researchers are also required to.

  • use AI tools in research in a way that safeguards the integrity and trustworthiness of the research, and exercise particular caution when using AI in sensitive research activities such as peer review or the evaluation of applications.
  • ensure that the use of AI in research processes, publications, or dissemination is documented in a transparent and verifiable manner in accordance with applicable academic standards and guidelines, including the European Commission’s Living guidelines on the responsible use of generative AI in research published.
  • ensure that the use of AI tools in research complies with requirements for privacy, confidentiality, intellectual property rights, and the responsible handling of research data.
  • ensure that the use of AI tools in research projects is consistent with the requirements of project agreements, funding conditions, and any ethical or regulatory approvals applicable to the project.

Administrative staff

Administrative staff are also required to:

  • use AI tools in administrative tasks and case processing in a manner that ensures proper case handling, professional integrity, transparency, documentation, and verifiability.
  • archive documentation relating to the use of AI in case processing in the archive system when AI-generated content has influenced assessments, recommendations, or decisions in a case.
  • ensure that the use of AI tools in NTNUs defined case processes complies with established frameworks for the specific process (see Chapter 4.4, Process Owner).

Se oversikt over KI-verktøy ved NTNU (in Norwegian)

3.2 Use of AI Tools based on type of Information and Purpose

As an employee at NTNU, you are, as a general rule, required to use NTNU-approved tools in connection with your work tasks. Apart form this, the choice of AI tools must be made in accordance with the type of information being processed and the purpose for which the tool is used.

Open AI services may only be used for open information (Open/green). Information that requires protection (Internal/yellow or Confidential/red) may only be processed in AI tools that are approved by NTNU for such use. Information is considered processed when it is entered into prompts, attachments, or other input to an AI tool.

Processing of personal data using AI tools must be approved before such processing can take place.

Information that requires protection

Information that requires protection may only be processed in AI tools that are approved by NTNU for such use. This includes, among other things, personal data, internal documents, confidential information, scientific research articles, unpublished research data and results, and other research material protected by copyright, as well as exam papers and exam answers.

The assessment of whether information requires protection must be based on the content and sensitivity of the information, in accordance with NTNU’s Policy for Classification of Information Assets.

Information subject to special protection

Information subject to special protection, such as information covered by statutory confidentiality obligations, special categories of personal data, or particularly protected research data, shall as a general rule not be processed in AI tools.

Open information

Open information, such as publicly available information or other material that does not contain data requiring protection, may be processed in AI tools made available by NTNU or in AI services that the user adopts independently. Before entering information into such services, the user must always assess the risks, including those related to storage, further use, loss of control over data, profiling, or disclosure to third parties.

AI functionality may be integrated into many standard ICT-tools, such as word processing, email, or collaboration tools. The rules apply regardless of whether the AI functionality is part of a standalone AI tool or embedded within standard ICT-tools.

3.3 Prohibited Use of AI Tools

Certain forms of use of AI tools are prohibited because they conflict with legislation, fundamental rights, or NTNUs requirements for the responsible and ethical use of technology. The following uses of AI tools are not permitted at NTNU:

  • creating, reinforcing, or disseminating disinformation.
  • generating or publishing AI-generated audio, images, or video of identifiable individuals without consent or another valid legal basis.
  • uses that are prohibited under the AI Act, including systems that recognize emotions, manipulate or mislead people in a way that may cause harm, social scoring, and biometric categorization of individuals.
  • automated assessments or decisions about individuals without human evaluation.

4. Roles and Responsibilities

4.1 Rector

The Rector has the overall responsibility for NTNU’s management of generative AI. The Rector has delegated authority to the Director of Organization and Infrastructure to approve, coordinate, and implement necessary measures.

4.2 The Director of Organization and Infrastructure

The Director of Organization and Infrastructure have the authority and responsibility to approve and coordinate measures that ensure that activities are carried out in accordance with NTNU’s objectives, overarching guidelines, and legal requirements, and to ensure that the information security functions satisfactorily. The Director of Organization and Infrastructure shall:

  • approve and follow up on guidelines for generative AI within the organization.
  • require Faculties and administrative units to implement measures that ensure responsible use and satisfactory management of generative AI at NTNU.

4.3 Leaders

Leaders are responsible for following up on the responsible use of AI within their own unit. Leaders shall:

  • ensure that employees in the unit are aware of and comply with NTNU’s guidelines for the use of AI.
  • ensure that the use of AI within the unit is in accordance with applicable regulations, internal guidelines, and frameworks established by process owners.
  • facilitate necessary training and competence development for the use of AI tools.
  • follow up on undesirable or improper use of AI within the unit in accordance with applicable procedures for deficiencies and internal control.

4.4 Owners, Process Owners, and Departments in the Joint Administration

Responsibility for the governance, management, facilitation, and follow-up of the use of generative AI at NTNU is distributed among system owners, process owners, and the AI governance environment in the Joint Administration

The system owner shall:

  • ensure that the use of AI functionality in the system has been assessed in accordance with requirements for information security, privacy, and applicable regulations.
  • ensure that the system’s AI functions and deployment are documented, and that any limitations or conditions for use are known to users.
  • ensure that a necessary risk assessment has been conducted before AI functionality is implemented or significantly modified.
  • follow up on suppliers and system updates that affect AI functionality in the system.

The process owner shall:

  • define and communicate frameworks and requirements for the use of AI in administrative processes where AI is used and for which the process owner is responsible.
  • assess whether and how AI tools can be used in the process, including ensuring that necessary evaluations of risk, privacy, and information security have been carried out, and that the use of AI is consistent with requirements for proper case handling, documentation, and verifiability.
  • register the use of AI tools in the record of processing activities when AI is part of processes that involve the processing of personal data.

The IT Division shall:

  • ensure that AI tools and AI functionality made available through NTNU’s IT services are assessed in accordance with requirements for information security, privacy, and applicable regulations.
  • provide up-to-date information on which AI tools have been assessed and approved for which types of information and purposes.
  • Contribute with technical guidance and support to system owners and units that are considering the use of AI tools.

Development, Financial and Governance shall:

  • carry out annual internal control of administrative processes, including compliance with the guidelines for generative AI.
  • ensure that the procurement of AI tools includes necessary assessments and requirements for suppliers to enable safe and legally compliant use.
  • ensure that the guidelines for the use of AI are revised as needed in line with changes in legislation, technological developments, and NTNU’s needs.

HR and HSE shall:

  • implement necessary measures for training and competence development in the use of AI tools for employees.

The Education Division shall:

  • implement necessary measures for training and competence development in the use of AI tools for students and lecturers.

The Research, Innovation and External Relations Division shall:

  • Contribute to developing and make available information and guidance in the use of AI tools for researchers and research administration
  • Coordinate development in connection to the use of AI tools in research administration.

5. Relevant legal and governance documents

To ensure that NTNUs guidelines for the use for generative AI are in line with the legal and governance-framework, the following relevant laws, regulations and policies that give a legal framework for the use of generative AI at NTNU.

About

Formal information about the guidelines

  • Document type: Policy
  • Managed by: Director of Organization and infrastructure, with delegation to the Development, Financial and Governance Division
  • Approved by: Director of Organization and infrastructure
  • Effective form: 22.05.2026
  • Classification: Public
  • ISO reference: Not assessed
  • Reference to internal documents: The policy for the use of artificial intelligence at NTNU is subject to NTNU’s Information Security Policy and ICT Regulations

Guidelines as PDF

Download the guideline as a PDF (revision 22.06.26)