Data Risk and Privacy: what you need to know
Maintaining data security is a shared responsibility, and it’s important for everyone to do their part.
When you input data into any AI tool, it is important to understand the risk level of the data you are entering, and know how to keep that data safe. At the same time, Virginia Tech and our technology partners are also responsible for ensuring that data remains secure within the university environment, and is not used to train current or future AI models. This page provides a brief primer on data risk and offers tips for preserving privacy. It will help you understand what you need to consider before entering anything sensitive.
What is a data risk level ?
Virginia Tech classifies data into three risk levels: low, moderate, and high. The graphic below summarizes each level and gives typical examples of what data each classification might include. The full reference is the Risk Classifications Standard (PDF).
Data risk: quick reference
| Level | Examples |
|---|---|
| High risk | SSNs, financial account numbers, protected health information (HIPAA), export-controlled research data (CUI / ITAR / EAR), individually identifiable sensitive research data where disclosure could place a person at risk of criminal or civil liability or damage their financial standing, employability, educational advancement, or reputation, and research data with contractual requirements that meet or exceed the VT minimum standard for protecting high-risk data. |
| Moderate risk | Student records (FERPA), personnel records, internal university communications, unpublished research, draft grant proposals. |
| Low risk | Published research, public university information, course catalog content, general knowledge questions. |
Details on which university-approved tools can be used with each risk level, including for high-risk data, can be found on our Tools page.
How can I protect the privacy of data I am entering?
These are steps you can take to safeguard the information that is under your control.
- First, be sure to use university-approved tools, and sign in with your VT credentials.
- Signing in with your VT credentials ensures that your use is protected by Virginia Tech's agreement with the AI vendor, which includes specific data-handling terms. For example, with HokieAI, our vendor agreement with Cloudforce stipulates that user inputs will not leave Virginia Tech custody, and that they will not be used to train current or future AI models. Personal accounts and unapproved tools are not covered by those agreements, even if the service looks identical. Of course, no vendor agreement guarantees zero risk, but a carefully negotiated vendor agreement is the best assurance we have. So, before entering data, confirm you are logged into the VT instance of the tool, not a personal account.
- Second, think twice before entering moderate- or high-risk data.
- Consider if there might be a way to complete the task you wish to complete while hashing or removing the portion of the data that makes it high risk. For example, if you had a list of people’s names and hereditary illnesses that have occurred in their ancestry, you might consider whether there is a way to remove the names before entering the data into the AI tool, perhaps by replacing each name with an assigned number. This might allow you to complete the task without providing the health information directly tied in with names. Always anonymize or aggregate information, if possible.
- Third, avoid entering sensitive data into unapproved tools.
- If a tool is not listed on the Tools page, treat it as unapproved and limit use to low-risk, public data. Remember that free tools offered to the general public are harvesting all data inputs for their purposes.
- Fourth, when in doubt, reach out for guidance.
- Contact 4Help IT Support with questions about tool approval, availability, data classifications, or troubleshooting. 4Help can also connect you with consultation resources in Advanced Research Computing, Enterprise Cloud and AI Platforms, or Technology-enhanced Learning and Online Resources if you have more complex questions. Additional AI guidance and support may also be available through the University Libraries, or Office for Research and Innovation.
Last Updated: August 8, 2026