DRAFT: Generative AI Use Policy for the Morgridge Institute for Research
This document describes the regulations for the use of generative AI tools, such as Claude and Gemini, at the Morgridge Institute for Research.
These regulations are subject to change. This document reflects the current policy as of August 11, 2026.
Accountability
- Staff using generative AI tools are as responsible for the outputs and actions of those tools as they would be if AI tools weren't used at all. Be careful to examine the function of code, the content of research, and the meaning of communication that you use AI to create to make sure it's in line with what you intended.
- When in doubt about whether it's appropriate to use a generative AI tool for a particular task, consult with your supervisor or colleagues. These are early days, and it's better for us to be in communication with each other about generative AI tool usage so we can all get our bearings.
Attribution
- When possible, flag the products of generative AI tools as being AI assisted. When using AI for editing or creating interpersonal communication, use your best judgement about whether it would be appropriate to explicitly note that an AI was used.
- There may be some cases where the use of an AI might impact the nature of communication, as in the case of using AI to craft some sensitive interpersonal feedback. Use your best judgement about whether the recipient of your communication would rather you not use AI and keep in mind that there are times when the human touch may be important.
- Funding agencies and collaborators may have their own rules about AI disclosure or use in the work you do for them. Follow those rules when they apply (see, for example, NIH's guidance on maintaining integrity in NIH-supported research when using artificial intelligence.)
Security
- Do not input secrets into generative AI tools. This includes, but isn't limited to:
- passwords
- API keys and access tokens
- other private or sensitive information
- Use caution when inputting identifying information that isn't a secret on its own, such as hostnames or other non-private personal information. Consider whether the tool needs that detail to complete the task, and remove or generalize it when reviewing your inputs and outputs. If the AI tool you're using isn't covered by an organizational policy from Morgridge or the UW, don't use any personal or identifying information with it at all, secret or not.
Legal/Privacy
- Be aware of what the privacy and legal agreements are with each vendor of a generative AI tool that you use. The UW has agreements with Google's Gemini and Microsoft's Co-Pilot, and Morgridge has an account with Anthropic.
- When working with UW-related data or systems, follow the UW-Madison generative AI use policies. Anthropic's Claude products are not yet approved for use with University of Wisconsin data, so do not use Claude with any UW data unless it is classified as "Public" under the UW data classification policy.
- Morgridge's Anthropic Team provides some protections beyond the vendor's standard terms: accounts operating under Morgridge's Team are excluded from Anthropic's model training, and Anthropic agrees that the inputs and outputs of Team accounts belong to Morgridge. Anthropic still stores this data for a period of time, however — Claude Code data for 30 days, and chats in claude.ai or Claude Desktop until deleted by the user, with exceptions for data flagged as a security concern — so be conscientious of that retention when deciding what to input.
- Beyond the legal agreements above, different AI vendors have different policies around using data provided to an AI tool for training. If you're not sure whether an AI tool you're using is covered by a privacy policy that prevents the tool from being trained on the data you input, treat any data you give to the tool like it has been published to a public website.
Training
- Introducing generative AI tools to Morgridge's workflows will probably create new challenges that we don't anticipate, and some of these will come from a new possibility for people to tackle technical problems they would not have been able to without generative AI. While AI tools don't require a lot of specific training on their own, it's worth touching base with your team when you start to use it on a new system to make sure you know the pitfalls that you might run into. Consider reaching out to a colleague for some co-working when you start working on a system you're not familiar with.
- AI is a great opportunity for us to get better about following our existing best practices, such as thorough documentation and version control. Leverage AI and these practices to document the work you do, with or without AI tools.
Ongoing Reflection
- The industry around generative AI tools is changing quickly. The Institute should continue using and practicing with a wide range of these tools to make sure we maintain familiarity with their capabilities and relative strengths.
Approved Vendors
- The field is still new and we're unsure of what tools are legally safe or unsafe to use in our environment. As it currently stands, here are the tools that are approved for use for work with Morgridge's systems:
- Anthropic's Claude, through Morgridge's Anthropic Team
- Google's Gemini and Microsoft's Co-Pilot, through the UW