AI Staff Training · Charles Darwin University

CDU Generative AI Policy

A plain-language guide to the University's Generative Artificial Intelligence Policy and the related ICT, privacy, security and copyright policies that govern AI use at CDU. A core session in the CDU AI staff training series.

CDU Generative Artificial Intelligence Policy

CDU recognises generative AI as an emerging technology with social, environmental and academic implications. The University commits to educating all stakeholders about responsible and informed gen AI use, while exploring its potential for innovation across education, research and operations. This policy sets the principles for the use of generative AI at CDU. It applies to all employees and students, and frames responsible adoption while maintaining excellence and integrity.

Purpose and Scope

This policy establishes principles for the use of generative artificial intelligence (gen AI) at the University. It applies to all employees and students, and governs gen AI use across all university activities including teaching, learning, assessment, research and professional operations.

Core Principles

CDU's approach to generative AI is guided by seven principles that ensure responsible adoption across the University.

  • Exploration and learning. CDU encourages innovation and ensures all stakeholders understand ethical, effective gen AI use, building AI literacy across all areas of operation.
  • Guidance and training. The University will provide discipline-specific guidance, resources and training to support staff and students.
  • Equity. CDU will actively mitigate risks arising from inequitable access to gen AI tools, ensuring fair participation for all.
  • Transparency. Gen AI systems must be transparent; decision-making involving AI should be understandable and explainable.
  • Stakeholder notification. Users must be informed about how, when and where gen AI operates within university systems and processes.
  • Security. CDU will implement robust measures for monitoring and safeguarding all gen AI systems used within the university environment.
  • Bias mitigation. The University will address algorithmic bias and work to prevent unintended discriminatory outcomes.

Platforms and Usage

The University does not maintain a static "approved" or "endorsed" platform list. The gen AI landscape evolves rapidly, and CDU's approach reflects that reality.

Platform adoption

New platform adoption requires Design Authority approval when it involves institutional implementation, system integration, or the processing of University data. This ensures appropriate governance oversight for enterprise-level AI deployments.

Platform restrictions

Restrictions may apply when platforms present unacceptable risks related to security, privacy, data sovereignty, compliance, ethics, or Information Security Policy violations. Staff should consult IT Services if uncertain about a platform's suitability.

Integrity

Known risks

Gen AI platforms may contain incorrect, out-of-date and biased data. They can hallucinate and reference non-existent sources and facts, and outputs can appear authoritative despite being inaccurate. Users must verify all information to avoid submitting false content. Content generated by AI may also infringe copyright, so all users must comply with CDU's Copyright and Intellectual Property policies when using AI-generated material.

Student use

Academic teachers and HDR supervisors provide guidance covering which learning activities permit gen AI use, the extent of permitted usage, referencing requirements, and associated risks. Students and employees must be transparent about, and disclose, gen AI use.

Research use

Researchers must observe expected standards of integrity under the Responsible Conduct of Research Policy and associated procedures when using gen AI tools in their work.

Data, Privacy and Security

Gen AI platforms may incorporate user prompts into responses to other users. This creates significant data protection obligations for all CDU staff and students.

Do not input into gen AI platforms

Personal identifiers (names, addresses, contact details); sensitive dates and identification numbers; identifiable photographs, video or audio; employment, educational or health information; location data or linked opinions; assessment or examination content; and confidential University information.

Research data protection

Researchers must protect unpublished work by obtaining vendor assurance that data will not be used to train future models. This is critical for maintaining research integrity and intellectual property protection.

Social and Environmental Justice

Equity of access

CDU acknowledges the subscription costs and equity concerns associated with gen AI platforms. If course fees apply for gen AI platform access, this must be specified prior to student enrolment so people can make informed decisions.

Environmental impact

The University recognises that gen AI involves significant greenhouse gas emissions and the use of water and other natural resources, and encourages judicious use to minimise environmental impact.

Teaching and Learning

Gen AI challenges traditional assessment reliability. CDU commits to agile assessment reviews that keep processes current and fit for purpose given AI capabilities. The University's strategies are to ensure understanding of gen AI implications and Academic Integrity Policy compliance, to develop competent and ethical gen AI users among staff and students, and to assure learning outcomes through robust assessment design.

Assessment and marking

Gen AI use in assessment marking or feedback must comply with the data, privacy and security requirements in this policy. VET competency judgements require qualified assessors, and gen AI platforms cannot fulfil that role.

Research

Gen AI may improve efficiency in data analysis, content synthesis and output preparation. Researchers may use gen AI within the parameters of the Australian Code for the Responsible Conduct of Research (2018), University governance documents, legislation, regulation, and funding or publisher requirements.

Never acceptable in research

The following are never acceptable uses of gen AI: conducting peer review, generating substantive research output, creating HDR thesis content, and producing critical ethics application components. These require human expertise and judgement.

Researcher responsibilities

Researchers must consider privacy, security, legal and ethical implications before inputting materials into gen AI platforms. They remain accountable for all work, including gen AI-assisted content. Gen AI use must be documented transparently, describing which tools were used, when, how, and their impact on the research. HDR candidates must consult supervisors before use and develop implementation plans.

Privacy and Confidentiality Policy

CDU's Privacy and Confidentiality Policy requires staff to protect personal information under the Information Act 2002 (NT) and the Privacy Act 1988 (Cth). AI tools introduce new privacy risks that staff must actively manage. As a university, CDU collects the data it would reasonably be expected to hold in teaching, learning and research: student enrolment and academic records, staff HR records, research participant data, health and wellbeing information for student support, financial records, and communications relating to university business.

What this means for AI use

When you enter information into a gen AI platform, that data leaves CDU's systems and is processed on external servers, often offshore. You must not enter personally identifiable information about students, staff or community members into AI tools. This includes names, student IDs, contact details, health information, academic records, and any combination of data that could identify an individual. Even anonymised data can sometimes be re-identified when combined with other information. Staff in student support, HR, health services or research involving human participants must be especially vigilant.

De-identification and practical judgement

Before entering any work-related information into a gen AI tool, consider whether the data can be suitably de-identified: removing or replacing all names, IDs, dates, locations and any other details that could identify a person, directly or in combination. Consider whether the context itself could reveal identity; a description of a specific student complaint in a small cohort may be identifiable even without a name. Also weigh intellectual property implications, confidentiality obligations, and any contractual or legal restrictions on sharing the data externally.

Privacy and Confidentiality Policy (CDU)

ICT Acceptable Use Policy

The Information and Communication Technologies Acceptable Use Policy governs how staff use all university ICT resources. AI tools accessed through CDU systems, or used for CDU work, fall within its scope.

How this applies to gen AI

AI tools such as ChatGPT, Claude, Gemini and Copilot are ICT resources. When you use them for university work you must do so responsibly, ethically and in line with university guidelines, which includes not using AI to misrepresent authorship and being transparent about AI-assisted work. If you access AI tools through CDU's network or use university-licensed services such as Microsoft Copilot, you are bound by the acceptable use conditions.

Internal documents, confidentiality and intellectual property

An "internal document" is not necessarily confidential, but it may still contain university intellectual property such as curriculum designs, assessment frameworks, strategic plans, process documentation or original research. Before entering any internal content into a gen AI tool, consider whether it contains CDU IP, whether sharing it externally could undermine the University's interests, and whether the provider's terms of service grant them rights to use your input. When in doubt, treat internal material with care and consult your supervisor.

ICT Acceptable Use Policy (CDU)

Information Security and Access Policy

The Information Security and Access Policy protects university data and systems from unauthorised access, disclosure and loss. When you type something into a gen AI tool, that data is sent to external servers for processing, which may be offshore, with direct information security implications.

What this means for AI use

Most free AI tools will use your inputs to train future models by default, and even paid tiers have varying data retention policies. CDU-licensed tools like Microsoft Copilot may offer stronger protections, but you still need to be aware of the data you are handling. Do not input student records or personal details, staff HR information, unpublished research data, financial or budget information, passwords or access credentials, confidential university communications, or any data classified as sensitive or restricted under CDU policy.

Think before you paste

A useful test: if you would not email this information to a stranger, do not paste it into an AI tool. AI platforms are run by external companies, and your data may be stored, processed or accessed outside Australia. Consider whether the information is classified under CDU's data classification framework, whether it falls within confidentiality agreements, and whether the provider has adequate data protection assurances.

Information Security and Access Policy (CDU)

Copyright Policy

CDU's Copyright Policy governs intellectual property across all university activities, and AI-generated content raises copyright questions still being resolved in Australian law. Under current Australian law, copyright requires a human author, so AI-generated content may not attract copyright protection and could be freely copied by others. When you use AI to create content for CDU, consider who owns it, whether it is protectable, and whether the tool's terms grant the provider any rights. Be cautious about inputting CDU's copyrighted materials such as course content, research papers and internal documents, since many providers' terms grant broad licences to use input data, and AI outputs may inadvertently reproduce copyrighted material from their training data.

Copyright Policy (CDU)

Non-Compliance

Non-compliance with this policy constitutes a breach of applicable Codes of Conduct and is treated seriously by the University. Concerns are managed through the disciplinary procedures in the Enterprise Agreement and Code of Conduct, and complaints follow the applicable employee and student complaint procedures. All employees must report suspected fraud or corruption under the Fraud and Corruption Control Policy and Whistleblower Reporting Procedure.

Related Policy Documents

This Generative AI Policy operates alongside, and should be read with, the following CDU policies and procedures.

Information and security

Information Security and Access Policy, Privacy and Confidentiality Policy, Copyright Policy, Intellectual Property Policy.

Academic and research

Academic Integrity Policy, Responsible Conduct of Research Policy, Research Data Management Procedure, Authorship and Dissemination of Research Procedure, Higher Education Coursework Assessment Policy and Procedure, VET Assessment System Policy and Procedure, VET Trainer and Assessor Qualifications Procedure.

Governance and conduct

Code of Conduct (Employees and Students), Complaints and Grievance Policy and Procedure, Fraud and Corruption Control Policy, Whistleblower Reporting Procedure.

Read the official CDU Generative AI Policy

A campus plover swooping
If you ever find yourself in this situation on the CDU campus, stay calm and do not make any sudden movements. Unfortunately no amount of AI training and policy awareness will help here.
Last updated: 10 June 2026