Enterprise AI Solutions

The UMB AI Toolkit helps faculty, staff, and students explore AI tools available within UMB-supported platforms. Organized by UMB Data Classification level, the toolkit provides guidance to help the UMB community choose appropriate AI tools that support productivity, teaching, learning, and administrative work. To request an AI tool to be reviewed for use at UMB, complete the IT-PCS Software Request Form.

Choosing an AI Tool

Start with Microsoft Copilot Chat before exploring other AI tools.

Copilot Chat is available to all UMB faculty, staff, and students at no additional cost. It can help you draft and summarize content, brainstorm ideas, analyze information, answer questions, and simplify everyday work while helping protect institutional data. For many common productivity and research tasks, Copilot Chat may meet your needs without requiring an additional software purchase.

If your work requires advanced features, specialized capabilities, or integrations that Copilot Chat does not offer, use the guidance below to identify the approved AI solution that best fits your data sensitivity needs and check out A Practical Guide to AI Tools at UMB to determine which approved tool aligns best with your type of work. 

  • LEVEL 2: CONFIDENTIAL

     

    Highly Sensitive or Restricted
    Protected data such as education, health, financial, and research information. EPIC users must complete an IT-PCS form.

    REQUIRED Tool:

    Microsoft Copilot Chat (Free)

    Microsoft 365 Copilot (Paid *)

    * Includes Claude and GPT LLMs

     

     

    Licenses can be purchased through the Software Licensing Office.

  • LEVEL 1: INTERNAL

     

    Internal Use Only
    University data for internal use, such as staff directories, meeting agendas, and project plans. Not public or sensitive.

    Recommended Tools:

    Microsoft Copilot Chat (Free)

    Microsoft 365 Copilot (Paid *)

    * Includes Claude and GPT LLMs

     

    CITS is currently developing enterprise licensing agreements for the following:

    ChatGPT Business

    Claude For Education

    Gemini Business

     

    Licenses can be purchased through the Software Licensing Office.

  • LEVEL 0: PUBLIC 

     

    Public Information
    Information safe to share publicly, such as website content, event details, campus maps, and public announcements.

    Recommended Tools:

    Microsoft Copilot Chat (Free)

    Microsoft 365 Copilot (Paid *)

    * Includes Claude and GPT LLMs

     

    CITS is currently developing enterprise licensing agreements for the following:

    ChatGPT Business

    Claude For Education

    Gemini Business

     

    Other Approved Tools:

    Perplexity

     

    Licenses can be purchased through the Software Licensing Office.

Data Classification Examples

Data classification levels help you choose the right tools and protect university information. Review the information below to learn what each level means and how it should guide your technology decisions.

For more support, watch the short AI Tool Choice video on data levels and tool selection.

Sensitive or regulated information that requires the highest level of protection. If exposed, it could cause harm to individuals or the University. Includes data protected by federal, state, national laws or contractual obligations.

Examples:

  • Personal Information (PII): SSNs, driver’s license numbers, passport numbers, DOB + identifiers
  • Education Records (FERPA): grades, transcripts, advising notes, student ID numbers
  • Health Data (HIPAA): medical records, diagnoses, test results, counseling information
  • Financial Data: bank account numbers, credit card numbers, payroll, tax documents, financial aid records
  • Authentication Data: usernames paired with passwords, passwords, MFA codes, API keys
  • Research Data: human subject data, restricted or proprietary research, sponsor-restricted datasets

Aggregated/De-identified Data Sets:

De-identified or aggregated data is Confidential if any of the following may apply; small sample sizes, unique populations, use of quasi-identifiers, IRB rules, contractual obligations, or realistic re-identification risks apply.

Information intended for internal University use. This data is not public, but it does not contain sensitive or regulated elements. Unauthorized disclosure would be undesirable, but not seriously harmful.

Examples:

  • Internal emails, memos, meeting notes
  • Draft documents not yet approved for publication
  • Course materials and instructional content
  • Non-sensitive research data
  • Department procedures, operational documentation
  • Most system configuration details
  • Internal reports, metrics, and dashboards

Aggregated/De-identified Data Sets: Aggregated, anonymized, or de-identified datasets that no longer contain direct identifiers, unless data sets carry re-identification risk.

Information approved for public release. Sharing this data does not create institutional risk because it is already intended to be openly accessible.

Examples:

  • University website content
  • Public directory information (name, title, department)
  • Published research or reports
  • Marketing materials, brochures, event schedules
  • Campus maps and publicly distributed announcements
  • Institutional statistics approved for public release (e.g., enrollment totals, graduation rates)

Choose the Least Sensitive Option

Use the least sensitive information needed to complete your task. Avoid entering sensitive or identifiable information if a less sensitive version works.

  • Follow privacy, security, HIPAA, FERPA, IRB, and UMB requirements.
  • Use the minimum amount of information needed.
  • Use de-identified, anonymized, or aggregated data whenever possible. 

 

 

Custom AI Agents with NebulaONE

NebulaONE is UMB’s secure platform for creating custom AI agents built specifically for the university community. For a full list of available agents visit AI Solutions - AI at UMB.

Approved With Restrictions

In addition to the enterprise-wide AI tools listed above, there are other software tools that have been approved for use under specific conditions or by designated departments. Use of these tools is permitted only when the intended use case complies with the restrictions and conditions, view Approved Software List.

Note: The IT-PCS Software Request Form is the official mechanism for requesting software at UMB, including all AI tools.

Search Additional Approved AI Tools

Search the complete list of AI tools approved for use under specific conditions or by designated departments. Review the restrictions and conditions outlined in the table for each tool.  View all approved software

Prohibited AI Tools

These tools are strictly prohibited for any organizational use

Otter.ai

Prohibited

Otter AI logo

Do Not Use

Otter.ai is not approved for any organizational use due to data security and compliance concerns.

Important Warnings

  • Does not meet organizational security requirements
  • Insufficient data protection guarantees
  • Use approved alternatives: M365 Copilot or Teams transcription

Fireflies.ai

Prohibited

Fireflies logo

Do Not Use

Fireflies.ai is not approved for any organizational use due to privacy, security, and compliance concerns similar to other third-party meeting assistants.

Important Warnings

  • No institutional data protection agreement
  • May auto-join meetings and record without proper consent
  • Use approved alternatives: Zoom AI Companion or M365 Copilot