Generative AI Policy & Guidelines

Committment to Responsible AI Use

Hawkeye Community College encourages the responsible use of Generative AI. Its use must align with our mission, vision, and core values and comply with all state, federal, and institutional regulations.

Because AI technology rapidly evolves, these guidelines will be updated regularly. Please check back periodically for updates.

1. Responsible Use and Accountability

Using AI to assist with materials or projects within your normal job duties requires approval by your supervisor. Supervisors and Deans are authorized to establish blanket approvals for routine administrative and instructional tasks using Level 1 data.

AI-generated material can include information that is incorrect, inaccurate, outdated, biased, fabricated, or subject to copyright. Generative AI and large language learning models are not a replacement for critical thinking, and you are responsible for any content generated by AI that you publish or share.

Any AI-generated graphics, images, video, or promotional materials that feature or reference Hawkeye Community College's name, logos, or brand must be reviewed and approved by Marketing before release.

Always disclose when AI has been substantially used to generate written content, graphics, or official college documentation by including a brief attribution line (e.g., Content generated with the assistance of AI and verified by the author.). Substantial usage is defined as generating full drafts, solving key analytical steps, writing core code modules, or structuring an entire document.

2. Protection of Confidential Data and Using AI

All use of Generative AI tools at Hawkeye Community College must align with the confidentiality and sensitivity of the data being processed. Hawkeye Community College categorizes data into four classification levels based on sensitivity and importance to ensure appropriate security measures.

For complete definitions and their potential adverse impact on the college, review the Policy Governing Access To and Use of Hawkeye Community College Information Technology Resources [PDF].

Data must be consistently protected throughout its lifecycle, from creation to permanent destruction, in a manner commensurate with its sensitivity, regardless of where it resides or what purpose it serves.

 Any subset, summary, or copy of data retains the exact same classification level and security measures as the original source data.

3. Data Classification & AI Decision Matrix

Employees must adhere to the following guidelines when determining whether AI usage is appropriate for a specific task and which AI platforms are authorized for each data level.

Risk Level

Highest risk / regulatory

Approved AI Platform

  • Hawkeye Enterprise Licensed Gemini Account only.

Permission is required before using another AI platform. Complete the Non-Standard AI Tool Evaluation Request to request approval.

AI Use Rule

  • Use extreme caution.
  • Input into public/open AI tools is strictly prohibited.
  • Mandatory redaction of personal identifiable information (PII) is required.
  • Cabinet member and supervisor written permission required.

Examples of Data

  • Iowa Code 22.7
  • Social security numbers
  • Credit card numbers
  • Student account details
  • Personal identifiable information (PII)
  • Driver's licenses
  • Passport numbers
  • Authentication credentials

Risk Level

High Risk / Statutory and FERPA

Approved AI Platform

  • Hawkeye Enterprise Licensed Gemini Account only.

Permission is required before using another AI platform. Complete the Non-Standard AI Tool Evaluation Request to request approval.

AI Use Rule

  • Use high caution.
  • Input into public/open AI tools is strictly prohibited.
  • Mandatory redaction of personal identifiable information (PII) is required.
  • Written supervisor permission required.

Examples of Data

Risk Level

Moderate Risk / Non-Public

Approved AI Platform

  • Hawkeye Enterprise Licensed Gemini Account only.

Permission is required before using another AI platform. Complete the Non-Standard AI Tool Evaluation Request to request approval.

AI Use Rule

  • Use Caution.
  • Input into public/open AI tools is prohibited.
  • Mandatory redaction of personal identifiable information (PII) is required.
  • Standard supervisor approval required (blanket approvals permitted).

Examples of Data

  • Internal research data
  • Employment applications
  • Employee phone and home address
  • Unreleased schedules
  • Internal emails
  • Census facts

Risk Level

Limited or No Risk

Approved AI Platforms

  • Hawkeye Enterprise Licensed Gemini Account
  • Public/Third Party AI

AI Use Rule

  • Permitted freely.
  • May be used to draft, summarize, analyze, or format.
  • Users must verify outputs for accuracy and brand alignment prior to release.

Examples of Data

4. Compliance and Support

Failure to recognize these levels of Data Classification or adhere to these AI restrictions may result in unauthorized data exposure and potential compliance violations. Employees may be subject to disciplinary action up to termination.

AI technology is changing fast, and staying safe while innovating its use is a team effort. If you are unsure which category your data falls into or are interested in using another paid AI platform, please contact the Chief Information Officer, Brian McCormick at 319-296-4050 or email Brian McCormick.

Non-Standard AI Tool Evaluation Request