Generative AI -- Best Practices and Resources


This article shares key concepts and emerging best practices for using artificial intelligence in Wharton’s academic environment. For the current list of services supported by Wharton and Penn, see AI Tools and Resources.

Check Back Regularly for Updates
AI capabilities and University guidance evolve quickly. This article is reviewed regularly to reflect new tools, policies, and best practices.
Using an AI coding assistant?
Codex, Claude Code, GitHub Copilot, and similar tools can access files and take actions within the permissions you provide. Review AI Coding Assistants at Wharton: Safe Use Guidance before using one.

Frequently Asked Questions

Which AI tools may I use at Wharton?
Use a Penn or Wharton approved tool that is appropriate for your task and data. See AI Tools and Resources for the current list of services and restrictions.

Can I submit University Confidential Data to an AI tool?
Only when the tool is an approved Penn or Wharton enterprise service and the specific data is permitted for that service. Never submit University Confidential Data to a personal or unapproved service. See Security and Privacy Requirements.

Does using an enterprise account make all data acceptable?
No. Each service has its own approved data types, features, and restrictions. PII, FERPA data, High Risk Data, research data, and contractually restricted data may still be prohibited or require review.

Can an AI tool connect to a Wharton or Penn system?
Only after review. Connections to University managed applications, servers, endpoints, APIs, or data sources require an approved enterprise tool and review by Wharton Computing and the Wharton Information Security Office.

Can students use AI for coursework?
Follow the policy established by your instructor for each course. Disclose AI use when required, and do not use it in a way that replaces the learning or work the assignment is intended to measure.

Can I use AI for research or official Wharton work?
Yes, when the tool, data, and activity are approved. Confirm that any IRB, data use agreement, contract, or research agreement permits the proposed use. Work involving confidential data or University systems requires review before it begins.

How do I know whether to trust these tools?
Trust AI output in proportion to its demonstrated performance on your task, not how confident or polished it sounds. Verify important results through an independent route. See Appropriate Reliance for practices that help calibrate trust.

Am I responsible for checking AI generated content?
Yes. Review factual claims, calculations, citations, code, and other outputs before using them. Disclose AI assistance when required, and remember that entirely AI generated work may not qualify for copyright protection.

Key Concepts Everyone Should Know

Use AI Safely

  • Use a Penn or Wharton approved service that is appropriate for your task and data.
  • Do not submit confidential information to publicly available or personal AI accounts.
  • Review AI generated claims, citations, calculations, code, and other outputs before relying on them.
  • When in doubt, contact Wharton Computing and the Wharton Information Security Office.
University Confidential Data may be submitted only to a Penn or Wharton approved enterprise generative AI tool that is approved for the specific data and activity.

Use of University Confidential Data in a personal, free, or otherwise unapproved generative AI service is prohibited. Enterprise access does not automatically make every type of data acceptable.

See AI Tools and Resources for current service restrictions and Security and Privacy Requirements for examples of confidential data.

If you are considering a generative AI service for research or official Wharton use involving University Confidential Data or connections to Wharton systems, contact the your strategic partner or Wharton Information Security Office. This group can help evaluate the project, identify required reviews, and answer technical and security questions.

General Information

These guidelines apply to anyone using AI in an academic environment:

  • Stay Current: AI services, laws, University policies, and security practices change frequently. Review current guidance and be prepared to adjust how you use a service. See Additional Resources for authoritative sources.

  • Understand How Your Data Is Used: Review the service’s terms, privacy policy, retention practices, and data controls. When available, disable the use of your content for model training and limit unnecessary retention. These settings do not replace University data requirements.

  • Confirm Image Sources: When using an image generator, review available information about its training data and licensing practices. Generated content may create copyright or attribution concerns. When appropriate, identify the tool used, such as Image generated using <tool name>.

  • Consider Authorship: AI generated material may not be eligible for copyright protection without sufficient human authorship. Disclose AI assistance when required and document your own creative contribution. See Authorship for more information.

  • Calibrate Your Trust: Rely on AI output in proportion to its demonstrated performance on your task, not how confident or polished it sounds. Verify important results through an independent route. See Appropriate Reliance for practices that help calibrate trust.

AI Coding Assistants

AI coding assistants such as Codex and Claude Code can read files, edit work, inspect repositories, and run commands within the access you provide. Because these tools create risks beyond ordinary chat, review AI Coding Assistants at Wharton: Safe Use Guidance before using one.

Security and Privacy Requirements

This section describes common examples of University Confidential Data and the review requirements for connecting AI services to University managed systems.

Contact the Wharton Information Security Office and Wharton Computing with questions or requests for review.

Examples of University Confidential Data include, but are not limited to:

Personal Information Financial and University Information Intellectual Property and Research
  • Personally Identifiable Information (PII)
  • Payment Card Industry data (PCI)
  • Unpublished research data, subject to data owner and IRB restrictions
  • Protected Health Information (ePHI)
  • Financial information
  • Penn owned intellectual property, including code
  • Biometric data
  • Nonpublic Penn policies, system designs, budgets, plans, and documentation
  • Federal government research data
  • Student, faculty, and staff information or records, including directory information
  • System credentials

  • Data restricted by a University signed contract

For the complete University standard, see Wharton's Data Classification and Management Standard

Connections to University Systems

Connecting a generative AI service to a University managed system or application, including through an API, requires an approved Penn or Wharton enterprise tool and review by the Wharton Information Security Office and Wharton Computing.

An interconnection is a direct integration or connection between an AI service and a system managed by the University. Examples include:

  • Wharton Computing managed computers, printers, and other endpoints
  • Servers
  • On premises and cloud applications
  • Repositories and data sources
  • APIs
  • IoT devices
Remember: Information submitted to a nonenterprise AI service may be retained by the provider, used for model training, or exposed through service features or security failures.

Account and Service Considerations

  • Terms and Privacy Policies: Review the service’s terms of use and privacy policy periodically. These documents may change as the service and its business practices evolve.

  • Penn Email: Using a Penn or Wharton email address to register for an AI service is not prohibited. Use a unique password that is not used for any other Penn or Wharton service. Remember that an email address may identify you and your University affiliation.

  • Business Continuity: For an approved service used by a team, use an appropriate shared or managed account when available rather than relying on an individual account. This can help preserve access during absences or staff changes.

For detailed definitions of data sensitivity, see Wharton's Data Classification and Management Standard.

Authorship

Questions remain about the relationship between human authorship and machine generated work. The US Copyright Office provides guidance about copyrightability and the use of generative AI, including its January 2025 report on copyrightability.

Key considerations include:

  • Machines cannot be recognized as authors under current United States copyright law.

  • Works generated entirely by AI, without sufficient human authorship, are not copyrightable.

  • AI assisted works may be copyrightable when the human contribution is sufficiently creative. This is evaluated case by case.

  • Prompts alone are generally not considered sufficient human authorship.

  • The human author should make meaningful creative choices involving selection, arrangement, revision, or other traditional elements of authorship.

  • Authors should disclose their use of AI when required by an instructor, publisher, funder, professional standard, or other applicable policy.

Faculty

Faculty may also want to review AI Best Practices: Teaching and Research, which provides additional guidance for teaching and research activities. This article requires Knowledge Base login.

For login instructions, see Logging into the Wharton Computing Knowledge Base.

Staff

Wharton staff use AI for a wide range of activities, and the appropriate requirements depend on the service, task, data, and systems involved. Contact Wharton Computing and the Wharton Information Security Office before using an AI service with confidential data or University systems.

Students

Students should follow the guidance on this page and the AI policy established by each instructor or program.

Additional Resources

Questions?

Contact your Wharton Computing representative with questions about technology and the use of AI. When requesting help, include as much of the following information as possible:

  • Is this a new or existing project?
  • Which AI services are being considered?
  • Who will use the service?
  • What types of data will be submitted or accessed?
  • Who will receive or use the output?
  • Will the service connect to any University system, application, repository, API, or data source?
  • Are specialized services such as prompt engineering, model customization, or fine tuning required?