Pith. sign in

REVIEW 2 major objections 4 minor 102 references

Understanding How University Guidelines Address Privacy and Security Issues of Generative AI in Academic Settings

T0 review · 2 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash

Pith's one-line read University GenAI guidelines broadly acknowledge privacy and security risks, but they are often vague, conflate sensitive-data terms, and rarely detail concrete security threats like prompt injection or jailbreaking.

desk verdict A careful qualitative mapping of privacy/security in top-ranked universities' GenAI guidelines; the generalization overreach is real but fixable. read the letter →

arxiv 2506.20463 v2 pith:M6VFCYRF submitted 2025-06-25 cs.HC cs.CY

classification cs.HCcs.CY
keywords generativeAIuniversityguidelinesprivacysecurityhighereducationqualitativecontentanalysisdataprotectionpolicy
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish what university guidelines actually say about the privacy and security risks of generative AI, and whether those guidelines give students and staff usable protection. The authors analyzed 46 GenAI-usage documents from 43 universities in 12 countries and found that institutions broadly recognize risks such as sensitive-data disclosure and system integration vulnerabilities, yet the documents are frequently vague, mix up terms for sensitive data, and skip concrete discussion of security attacks. The paper further claims that mitigation measures vary in clarity and consistency, that universities lean on existing frameworks while acknowledging their limits, and that privacy and security are positioned alongside broader academic values rather than as standalone technical requirements. A sympathetic reader would care because universities are issuing these documents faster than evidence about their effectiveness, and this study provides an in-depth picture of the gaps.

What carries the argument

The machinery is qualitative content analysis with a structured codebook. The authors collected publicly available English-language GenAI guidelines from universities listed in an international ranking, segmented the web pages into paragraphs, coded them in iterative batches (three researchers coding 15 universities, then two coders applying the refined codebook to 22 more), and reached data saturation at 46 documents. Cohen's kappa of 0.65 indicates substantial inter-annotator agreement. The coding organized guideline content into themes around privacy-sensitive data practices, exploitation and misuse of GenAI, technical limitations, safeguards, governance frameworks, and academic values, and these themes carry the paper's findings.

What would settle it

A concrete check would be to annotate the same 46 documents (or an expanded multilingual sample) for explicit mentions of named attack types such as prompt injection, jailbreaking, and data poisoning, and for the presence of definitions for sensitive-data terms; if such mentions and definitions turn out to be common and consistent, the claim of vagueness and omission would be falsified.

Watch

Extended reading notes

Core claim

On its own terms, the central discovery is that universities' GenAI guidelines recognize privacy and security as real concerns but do not carry that recognition through to specific, consistent protections. Across the sampled guidelines, sensitive data is named with overlapping terminology (proprietary, confidential, restricted) without shared definitions; security threats such as jailbreaking and prompt injection appear rarely and without academic-context detail; and mitigation advice mixes technical safeguards, individual responsibility, and operational reviews of uneven clarity. The paper also finds that institutions build on existing legal and technical frameworks, such as FERPA, GDPR, privacy impact assessments, and enterprise licensing, while acknowledging that these tools do not fully cover GenAI-specific risks, and that privacy and security are framed within academic values and ethics whose alignment varies by university. The authors take this as evidence that GenAI governance in higher education is still adapting, with individual users often left to interpret broad principles.

Load-bearing premise

The load-bearing premise is that the sampled public guidelines from top-ranked, English-speaking universities represent how higher education addresses GenAI privacy and security, and that these documents reflect what institutions actually do.

Editorial extensions

If this is right

  • If the first finding holds, students and staff cannot rely on university guidelines to tell them which inputs are safe to share or what specific attacks to watch for.
  • If the second finding holds, institutions will keep depending on licensing agreements, privacy impact assessments, and existing data-classification frameworks, and these will need GenAI-specific extensions to cover inference-based privacy risks.
  • If the third finding holds, privacy and security will remain subordinate to broad academic values, making enforcement inconsistent within and across universities.
  • The paper's recommendations imply that better assessment frameworks, context-tailored technical safeguards, and shared infrastructure across institutions would close the largest gaps.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: the vagueness documented here shifts the practical burden of risk assessment onto individual students and instructors, who are least equipped to evaluate a GenAI provider's data practices.
  • Editorial inference: the findings suggest a testable comparative hypothesis, namely that guideline specificity scales with institutional resources, so lower-resourced or non-English-speaking universities may show even larger gaps, a possibility the authors raise but do not test.
  • Editorial inference: the observed reliance on consortia and cross-university references suggests that shared guideline templates, if developed with attention to local law, could reduce vagueness faster than individual institutions acting alone.
  • Editorial inference: the paper's evidence implies that policy text alone is a weak instrument, and longitudinal tracking of guideline updates against privacy incidents would show whether recommendations ever move into practice.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. This paper reports a qualitative content analysis of 46 publicly available GenAI usage guideline documents from 43 universities across 12 countries, all written in English and drawn from institutions ranked in the 2024 QS World University Rankings. The authors use open coding and thematic analysis, report Cohen's kappa of 0.65 for inter-rater reliability, and organize their findings under three research questions: how guidelines address privacy and security risks (RQ1), what mitigation measures they evaluate (RQ2), and how privacy and security are positioned among guiding principles (RQ3). Headline findings include inconsistent references to sensitive data, limited treatment of security threats and malicious attacks, devolution of accountability to individuals, and reliance on existing regulatory frameworks. The paper also proposes four recommendations for improving GenAI privacy and security in higher education.

Significance. If the findings are understood as applying to the sampled top-ranked, English-language universities, this is a useful and well-illustrated empirical contribution to a rapidly evolving policy area. The authors provide a transparent qualitative coding procedure, report inter-rater reliability, and ground each observation in direct quotations from the guideline documents. The work goes beyond prior studies by focusing on privacy and security as a distinct dimension rather than treating them as secondary to pedagogical concerns. However, the paper's central claim that 'universities broadly recognize' these risks and its assertion that the main findings 'would generalize' are not supported by the sample, which excludes South America and includes only one African and one Middle-Eastern institution. The paper also does not provide the codebook or coded data, limiting external verification. With appropriate scoping of the claims and better data availability, the contribution would be a solid and valuable one.

major comments (2)
  1. [Section 4 and F1 (Introduction)] The generalization claim is load-bearing for the headline finding. F1 states that 'universities broadly recognize' privacy and security risks, and Section 4 asserts that 'our main findings would generalize, e.g., the challenges faced in integrating privacy and security measures may be amplified for low-resourced universities.' Yet the sample (Table 1) is restricted to English-language documents from QS 2024 top-100 universities, with no South American institutions and only one African and one Middle-Eastern university. The paper itself acknowledges the skew, so the phrase 'globally representative sample' in the methodology is internally inconsistent. The argument that findings 'may be amplified' for low-resourced universities is a conjecture, not a result of the analysis. I recommend either narrowing F1 and the abstract to the sampled population or replacing the unsupported generalization with a carefully argued analytic generalization, for example based on saturation across resource levels, which the current text does not provide.
  2. [Section 3 (Qualitative coding and analysis)] The codebook and the coded data are not provided, which limits external verification of the central results. The paper reports that a codebook was developed, used by two researchers to code 22 guidelines, and yielded Cohen's kappa of 0.65, but readers cannot see the code definitions or the coded text spans that support the eleven observations. Given that the findings are entirely dependent on the coding scheme, I request that the codebook be included as an appendix or supplementary file, along with a description of which quotes map to which codes, and clarification of whether the kappa was computed per code, per document, or at the segment level.
minor comments (4)
  1. [Section 4] The sentence 'Our sampling is that though the QS World University Rankings as used by prior research [44].' is incomplete and should be revised.
  2. [Section 5.3, Observation 9] The acronym 'HIPPA' should be 'HIPAA' (Health Insurance Portability and Accountability Act).
  3. [Section 7] The phrase 'GenAI has becoming increasingly popular' is a grammatical error; it should be 'GenAI has become increasingly popular.'
  4. [Section 3 (Data collection and sampling)] The word 'globally representative' is contradicted by the acknowledged sampling skew; consider replacing it with 'geographically diverse' or 'a convenience sample of top-ranked, English-language institutions.'

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity; empirical qualitative analysis derives findings from external policy documents via coding.

full rationale

This paper is a qualitative content analysis, not a derivation. The central findings (F1–F3) are induced from 46 publicly available GenAI guideline documents through open coding, codebook refinement, and thematic analysis, with inter-rater reliability reported (Cohen's κ = 0.65). No parameter is fitted and then renamed as a prediction; no mathematical or definitional identity relates inputs to outputs. The findings are descriptive summaries of the coded corpus. The only self-citations occur in Section 6.1 recommendations: [8] (machine unlearning) and [90] (private alignment) by author Varun Chandrasekaran are cited as suggested technical directions, not as evidence for the empirical findings; they are not load-bearing for F1–F3. The limitation in Section 4 concedes geographic and English-language skew in the sample, and the claimed generalization of main findings is an external-validity risk, not a circularity defect. The skeptical reading that F1 overgeneralizes beyond the sample is a legitimate correctness concern, but it does not make the derivation circular: the coded evidence and the reported findings are distinct, with coding performed on external policy documents and verified by multiple annotators.

Assumptions & free parameters 0 free parameters · 2 assumptions · 0 invented entities

No free parameters or invented entities; the analysis depends on the representativeness and authenticity of the policy documents sampled, and on the coding process faithfully capturing their content.

assumptions (2)
  • domain assumption Publicly available university guidelines accurately reflect institutional positions and implementation
    The study relies on web-published documents as proxies for actual practices, a limitation acknowledged in Section 4: 'the GenAI guidelines we study present the public, overarching position of a university, and the actual implementation may differ.'
  • domain assumption Top-ranked, English-language universities form a representative sample for identifying general challenges
    Sampling from QS top 100 and English-only guidelines is acknowledged as skewed in Section 4, yet the paper claims 'our main findings would generalize,' which relies on this assumption.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Understanding How University Guidelines Address Privacy and Security Issues of Generative AI in Academic Settings." pith.science (2026). https://pith.science/paper/M6VFCYRF

@misc{pith2026250620463,
  author       = {Pith},
  title        = {Pith review of: Understanding How University Guidelines Address Privacy and Security Issues of Generative AI in Academic Settings},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/M6VFCYRF}},
  note         = {Machine review of arXiv:2506.20463}
}
read the original abstract

Generative artificial intelligence (GenAI) is transforming the educational landscape by augmenting learning paradigms. However, state-of-the-art GenAI systems driving this transformation are predominantly developed and controlled by a small number of private companies; there is little clarity about their data retention practices and limited user control over inputs and outputs. In the context of education, end-users lack the awareness of how to safely adopt GenAI in learning. This raises significant concerns, particularly when proprietary or personally identifiable educational information may be shared with external GenAI platforms. In response to these concerns, universities are developing their own usage guidelines and policies to balance innovation with academic integrity, privacy, and security. Our research seeks to understand these emerging guidelines, with a particular focus on the privacy and security implications of integrating GenAI tools into academic environments - an area that has received little attention to date. We conducted an in-depth qualitative analysis of GenAI-usage guidelines from 43 universities across 12 countries. Our findings reveal several key challenges, including barriers faced by universities in deploying privacy measures and adopting existing security frameworks. These insights lay the groundwork for designing more robust, privacy-aware GenAI guidelines for higher education.

Figures

Figures reproduced from arXiv: 2506.20463 by the authors.

Figure 1
Figure 1. An overview of the findings and observed themes that address our three research questions. [PITH_FULL_IMAGE:figures/full_fig_p006_1.png] view at source ↗

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

102 extracted references · 65 canonical work pages

  1. [1]

    https://pypi.org/project/html-sanitizer/, 2025

    Client Challenge — pypi.org. https://pypi.org/project/html-sanitizer/, 2025. [Accessed 14-04-2025]

  2. [2]

    Analysis of generative ai policies in computing course syllabi

    Areej Ali, Aayushi Hingle Collier, Umama Dewan, Nora McDonald, and Aditya Johri. Analysis of generative ai policies in computing course syllabi. In Proceed- ings of the 56th ACM Technical Symposium on Computer Science Education V. 1 , pages 18–24, 2025

  3. [3]

    Re-envisioning paradigms of education: towards awareness, alignment, and pluralism

    Lindsay R Baker, Shanon Phelan, Nicole N Woods, Victoria A Boyd, Paula Rowland, and Stella L Ng. Re-envisioning paradigms of education: towards awareness, alignment, and pluralism. Advances in Health Sciences Education , 26:1045–1058, 2021

  4. [4]

    Balash, Dongkun Kim, Darika Shaibekova, Rahel A

    David G. Balash, Dongkun Kim, Darika Shaibekova, Rahel A. Fainchtein, Micah Sherr, and Adam J. Aviv. Examining the examiners: Students’ privacy and security perceptions of online proctoring services. In Seventeenth Symposium on Usable Privacy and Security (SOUPS 2021) , pages 633–652. USENIX Association, August 2021

  5. [5]

    Generative ai can harm learning

    Hamsa Bastani, Osbert Bastani, Alp Sungu, Haosen Ge, Ozge Kabakcı, and Rei Mariman. Generative ai can harm learning. A vailable at SSRN, 4895486, 2024

  6. [6]

    Brett A Becker and Thomas Fitzpatrick. What do cs1 syllabi reveal about our expectations of introductory programming students? In Proceedings of the 50th ACM technical symposium on computer science education , pages 1011–1017, 2019

  7. [7]

    Marina Belkina, Scott Daniel, Sasha Nikolic, Rezwanul Haque, Sarah Lyden, Peter Neal, Sarah Grundy, and Ghulam M. Hassan. Implementing generative ai (genai) in higher education: A systematic review of case studies. Computers and Education: Artificial Intelligence, 8:100407, June 2025

  8. [8]

    Machine unlearning

    Lucas Bourtoule, Varun Chandrasekaran, Christopher A Choquette-Choo, Hen- grui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. Machine unlearning. In 2021 IEEE symposium on security and privacy (SP) , pages 141–159. IEEE, 2021

Show all 102 references
  1. [9]

    Felten, and Shaanan Cohney

    Ben Burgess, Avi Ginsberg, Edward W. Felten, and Shaanan Cohney. Watching the watchers: bias and vulnerability in remote proctoring software. In 31st USENIX Security Symposium (USENIX Security 22) , pages 571–588, Boston, MA, August 2022. USENIX Association

  2. [10]

    A personalized learning system-supported professional training model for teachers’ tpack development

    Pawat Chaipidech, Niwat Srisawasdi, Tanachai Kajornmanee, and Kornchawal Chaipah. A personalized learning system-supported professional training model for teachers’ tpack development. Computers and Education: Artificial Intelligence, 3:100064, 2022

  3. [11]

    A comprehensive ai policy education framework for university teaching and learning

    Cecilia Ka Yuk Chan. A comprehensive ai policy education framework for university teaching and learning. International journal of educational technology in higher education, 20(1):38, 2023

  4. [13]

    Students’ voices on generative ai: Per- ceptions, benefits, and challenges in higher education

    Cecilia Ka Yuk Chan and Wenjie Hu. Students’ voices on generative ai: Per- ceptions, benefits, and challenges in higher education. International Journal of Educational Technology in Higher Education , 20(1):43, 2023

  5. [14]

    Uncovering privacy and security challenges in k-12 schools

    Jake Chanenson, Brandon Sloane, Navaneeth Rajan, Amy Morril, Jason Chee, Danny Yuxing Huang, and Marshini Chetty. Uncovering privacy and security challenges in k-12 schools. In Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems , pages 1–28, 2023

  6. [15]

    A survey on evaluation of large language models

    Yupeng Chang, Xu Wang, Jindong Wang, Yuan Wu, Linyi Yang, Kaijie Zhu, Hao Chen, Xiaoyuan Yi, Cunxiang Wang, Yidong Wang, et al. A survey on evaluation of large language models. ACM transactions on intelligent systems and technology, 15(3):1–45, 2024

  7. [16]

    Beyond numbers: Creating analogies to enhance data comprehension and communication with generative ai

    Qing Chen, Wei Shuai, Jiyao Zhang, Zhida Sun, and Nan Cao. Beyond numbers: Creating analogies to enhance data comprehension and communication with generative ai. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1–14, 2024

  8. [17]

    Comprehensive assessment of jailbreak attacks against llms

    Junjie Chu, Yugeng Liu, Ziqing Yang, Xinyue Shen, Michael Backes, and Yang Zhang. Comprehensive assessment of jailbreak attacks against llms. arXiv preprint arXiv:2402.05668, 2024

  9. [18]

    Ai governance in research libraries: A case study of the university of toronto libraries

    CIGI. Ai governance in research libraries: A case study of the university of toronto libraries. Technical report, CIGI: Centre for International Governance Innovation, 2024. [Accessed 14-04-2025]

  10. [19]

    Thematic analysis

    Victoria Clarke and Virginia Braun. Thematic analysis. The journal of positive psychology, 12(3):297–298, 2017

  11. [20]

    Virtual classrooms and real harms: Remote learning at u.s

    Shaanan Cohney, Ricardo Teixeira, David Kohlbrenner, Arvind Narayanan, Mi- hir Kshirsagar, Yan Shvartzshnaider, and Madelyn Sanfilippo. Virtual classrooms and real harms: Remote learning at u.s. universities. In Proceedings of the 17th Symposium on Usable Privacy and Security ...

  12. [21]

    Cu committee re- port: Generative artificial intelligence for education and pedagogy

    Cornell University Committee on Generative AI. Cu committee re- port: Generative artificial intelligence for education and pedagogy. https://teaching.cornell.edu/generative-artificial-intelligence/cu-committee- report-generative-artificial-intelligence-education, 2023. [Access...

  13. [22]

    Security and privacy challenges of large language models: A survey.ACM Computing Surveys, 57(6):1– 39, 2025

    Badhan Chandra Das, M Hadi Amini, and Yanzhao Wu. Security and privacy challenges of large language models: A survey.ACM Computing Surveys, 57(6):1– 39, 2025

  14. [23]

    Gemini — deepmind.google

    Deepmind. Gemini — deepmind.google. https://deepmind.google/technologies/ gemini/, 2025. [Accessed 14-04-2025]

  15. [24]

    Real or fake text?: Investigating human ability to detect boundaries between human-written and machine-generated text

    Liam Dugan, Daphne Ippolito, Arun Kirubarajan, Sherry Shi, and Chris Callison- Burch. Real or fake text?: Investigating human ability to detect boundaries between human-written and machine-generated text. InProceedings of the AAAI Conference on Artificial Intelligence, volume ...

  16. [25]

    Communities demand transparency after ed, lausd’s ai chatbot, fails

    Edsource. Communities demand transparency after ed, lausd’s ai chatbot, fails. https://edsource.org/2024/communities-demand-transparency-after-ed- lausds-ai-chatbot-fails/717772, 2024. [Accessed 14-04-2025]

  17. [26]

    money makes the world go around

    Anirudh Ekambaranathan, Jun Zhao, and Max Van Kleek. “money makes the world go around”: Identifying barriers to better privacy in children’s apps from developers’ perspectives. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems , CHI ’21, New York,...

  18. [27]

    Impact of digital literacy and online privacy concerns on cybersecurity behaviour: The moderating role of cybersecurity awareness

    Musaddag Elrayah and Saima Jamil. Impact of digital literacy and online privacy concerns on cybersecurity behaviour: The moderating role of cybersecurity awareness. International Journal of Cyber Criminology , 17(2):166–187, 2023

  19. [28]

    The impact of hallucinated information in large language models on student learning outcomes: A critical examination of misinforma- tion risks in ai-assisted education

    Hassan Elsayed. The impact of hallucinated information in large language models on student learning outcomes: A critical examination of misinforma- tion risks in ai-assisted education. Northern Reviews on Algorithmic Research, Theoretical Computation, and Complexity , 9(8):11–23, 2024

  20. [29]

    Children’s online privacy protection rule, 2013

    Federal Trade Commission. Children’s online privacy protection rule, 2013. [Accessed 09-04-2025]

  21. [30]

    Generative ai in higher educa- tion: Balancing innovation and integrity

    Nigel J Francis, Sue Jones, and David P Smith. Generative ai in higher educa- tion: Balancing innovation and integrity. British Journal of Biomedical Science , 81:14048, 2025

  22. [31]

    General Data Protection Regulation (GDPR) – Legal Text — gdpr- info.eu

    GDPR-Info. General Data Protection Regulation (GDPR) – Legal Text — gdpr- info.eu. https://gdpr-info.eu/. [Accessed 14-04-2025]

  23. [32]

    The promise and challenges of generative ai in education

    Michail Giannakos, Roger Azevedo, Peter Brusilovsky, Mutlu Cukurova, Yannis Dimitriadis, Davinia Hernandez-Leo, Sanna Järvelä, Manolis Mavrikis, and Bart Rienties. The promise and challenges of generative ai in education. Behaviour & Information Technology, page 1–27, September 2024

  24. [33]

    GitHub Copilot · Your AI pair programmer — github.com

    Github. GitHub Copilot · Your AI pair programmer — github.com. https: //github.com/features/copilot, 2025. [Accessed 14-04-2025]

  25. [34]

    Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection

    Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz. Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection. In Proceedings of the 16th ACM Workshop on Artificial Intelligen...

  26. [35]

    Our universities | Russell Group — russellgroup.ac.uk

    Russell Group. Our universities | Russell Group — russellgroup.ac.uk. https: //www.russellgroup.ac.uk/our-universities, 2025. [Accessed 14-04-2025]

  27. [36]

    Engineering privacy by design

    Seda Gürses, Carmela Troncoso, and Claudia Diaz. Engineering privacy by design. Computers, Privacy & Data Protection , 14(3):25, 2011

  28. [37]

    We must fix the lack of transparency around the data used to train foundation models

    Jack Hardinges, Elena Simperl, and Nigel Shadbolt. We must fix the lack of transparency around the data used to train foundation models. Harvard Data Science Review, Special Issue 5, May 2024. [Accessed 12-04-2025]

  29. [38]

    Summary of the hipaa privacy rule

    HHS. Summary of the hipaa privacy rule. https://www.hhs.gov/hipaa/for- professionals/privacy/laws-regulations/index.html, 2025. [Accessed 14-04- 2025]

  30. [39]

    Generative ai in education: From foundational insights to the socratic playground for learning

    Xiangen Hu, Sheng Xu, Richard Tong, and Art Graesser. Generative ai in education: From foundational insights to the socratic playground for learning. arXiv preprint arXiv:2501.06682, 2025

  31. [40]

    A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions

    Lei Huang, Weijiang Yu, Weitao Ma, Weihong Zhong, Zhangyin Feng, Haotian Wang, Qianglong Chen, Weihua Peng, Xiaocheng Feng, Bing Qin, et al. A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions. ACM Transactions on Informatio...

  32. [41]

    Knowledge networks and universities: Locational and organisational aspects of knowledge transfer interactions

    Robert Huggins, Andrew Johnston, and Chris Stride. Knowledge networks and universities: Locational and organisational aspects of knowledge transfer interactions. Entrepreneurship & Regional Development, 24(7-8):475–502, 2012

  33. [42]

    Do llms store personal data? this is asking the wrong ques- tion

    IAPP Staff. Do llms store personal data? this is asking the wrong ques- tion. https://iapp.org/news/a/do-llms-store-personal-data-this-is-asking-the- wrong-question, 2024. [Accessed 11-04-2025]

  34. [43]

    The global landscape of academic guidelines for generative ai and llms

    Junfeng Jiao, Saleh Afroogh, Kevin Chen, David Atkinson, and Amit Dhurandhar. The global landscape of academic guidelines for generative ai and llms. Nature Human Behaviour, pages 1–5, 2025

  35. [44]

    Generative ai in higher education: A global perspective of institutional adoption policies and guidelines

    Yueqiao Jin, Lixiang Yan, Vanessa Echeverria, Dragan Gašević, and Roberto Martinez-Maldonado. Generative ai in higher education: A global perspective of institutional adoption policies and guidelines. Computers and Education: Artificial Intelligence, 8:100348, June 2025

  36. [45]

    Towards responsible development of generative ai for education: An evaluation-driven approach

    Irina Jurenka, Markus Kunesch, Kevin R McKee, Daniel Gillick, Shaojian Zhu, Sara Wiltberger, Shubham Milind Phal, Katherine Hermann, Daniel Kasenberg, Avishkar Bhoopchand, et al. Towards responsible development of generative ai for education: An evaluation-driven approach. arX...

  37. [46]

    Empowering education through generative ai: Innova- tive instructional strategies for tomorrow’s learners

    Kadaruddin Kadaruddin. Empowering education through generative ai: Innova- tive instructional strategies for tomorrow’s learners. International Journal of Business, Law, and Education, 4(2):618–625, 2023

  38. [47]

    Trust, because you can’t verify: Privacy and security hurdles in education technology acquisition practices

    Easton Kelso, Ananta Soneji, Sazzadur Rahaman, Yan Shoshitaishvili, and Rak- ibul Hasan. Trust, because you can’t verify: Privacy and security hurdles in education technology acquisition practices. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communicati...

  39. [48]

    Robust distortion-free watermarks for language models

    Rohith Kuditipudi, John Thickstun, Tatsunori Hashimoto, and Percy Liang. Robust distortion-free watermarks for language models. arXiv preprint arXiv:2307.15593, 2023

  40. [49]

    Kumar, Marshini Chetty, Tamara L

    Priya C. Kumar, Marshini Chetty, Tamara L. Clegg, and Jessica Vitak. Privacy and security considerations for digital technology use in elementary schools. In Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems , CHI ’19, page 1–13, New York, NY, USA, 2...

  41. [50]

    Privacy concerns of student data shared with instructors in an online learning management system

    Monika Blue Kwapisz, Avanya Kohli, and Prashanth Rajivan. Privacy concerns of student data shared with instructors in an online learning management system. 2024

  42. [51]

    Deepfakes, phrenology, surveillance, and more! a taxonomy of ai privacy risks

    Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jodi Forlizzi, and Sauvik Das. Deepfakes, phrenology, surveillance, and more! a taxonomy of ai privacy risks. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, pages 1–19, 2024

  43. [52]

    Exploring and evaluating hallucinations in llm- powered code generation

    Fang Liu, Yang Liu, Lin Shi, Houkun Huang, Ruifeng Wang, Zhen Yang, Li Zhang, Zhongqi Li, and Yuchi Ma. Exploring and evaluating hallucinations in llm- powered code generation. arXiv preprint arXiv:2404.00971, 2024

  44. [53]

    Prompt injection attack against llm-integrated applications

    Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Zihao Wang, Xiaofeng Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, et al. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499, 2023

  45. [54]

    Understanding llms: A comprehensive overview from training to inference

    Yiheng Liu, Hao He, Tianle Han, Xu Zhang, Mengyuan Liu, Jiaming Tian, Yutong Zhang, Jiaqi Wang, Xiaohui Gao, Tianyang Zhong, et al. Understanding llms: A comprehensive overview from training to inference. Neurocomputing, page 129190, 2024

  46. [55]

    originality

    Jiahui Luo. A critical review of genai policies in higher education assessment: A call to reconsider the “originality” of students’ work. Assessment & Evaluation in Higher Education, 49(5):651–664, 2024

  47. [56]

    they think it’s totally fine to talk to some- body on the internet they don’t know

    Sana Maqsood and Sonia Chiasson. “they think it’s totally fine to talk to some- body on the internet they don’t know”: Teachers’ perceptions and mitigation strategies of tweens’ online risks. In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems , CHI...

  48. [57]

    Gener- ative artificial intelligence in higher education: Evidence from an analysis of institutional policies and guidelines

    Nora McDonald, Aditya Johri, Areej Ali, and Aayushi Hingle Collier. Gener- ative artificial intelligence in higher education: Evidence from an analysis of institutional policies and guidelines. Computers in Human Behavior: Artificial Humans, 3:100121, March 2025

  49. [58]

    Interrater reliability: the kappa statistic

    Mary L McHugh. Interrater reliability: the kappa statistic. Biochemia medica, 22(3):276–282, 2012

  50. [59]

    Iso/iec 27018 - microsoft compliance

    Microsoft. Iso/iec 27018 - microsoft compliance. https://learn.microsoft.com/en- us/compliance/regulatory/offering-iso-27018, 2023. [Accessed 14-04-2025]

  51. [60]

    Microsoft products and services data protection addendum (dpa)

    Microsoft. Microsoft products and services data protection addendum (dpa). https://www.microsoft.com/licensing/docs/view/Microsoft-Products- and-Services-Data-Protection-Addendum-DPA, 2023. [Accessed 14-04-2025]

  52. [61]

    Trust no bot: Discovering personal disclosures in human-llm conversa- tions in the wild

    Niloofar Mireshghallah, Maria Antoniak, Yash More, Yejin Choi, and Golnoosh Farnadi. Trust no bot: Discovering personal disclosures in human-llm conversa- tions in the wild. arXiv preprint arXiv:2407.11438, 2024

  53. [62]

    The Privacy Act — oaic.gov.au

    OAIC. The Privacy Act — oaic.gov.au. https://www.oaic.gov.au/privacy/privacy- legislation/the-privacy-act. [Accessed 14-04-2025]

  54. [63]

    Chatgpt overview

    OpenAI. Chatgpt overview. https://openai.com/chatgpt/overview/. [Accessed 14-04-2025]

  55. [64]

    Data controls faq

    OpenAI Help Center. Data controls faq. https://help.openai.com/en/articles/ 7730893-data-controls-faq, 2024. [Accessed 12-04-2025]

  56. [65]

    Beyond compliance: Students and ferpa in the age of big data

    Cecelia Parks. Beyond compliance: Students and ferpa in the age of big data. Journal of Intellectual Freedom & Privacy , 2(2):23–33, 2017

  57. [66]

    PDPC | PDPA Overview — pdpc.gov.sg

    PDPC. PDPC | PDPA Overview — pdpc.gov.sg. https://www.pdpc.gov.sg/ overview-of-pdpa/the-legislation/personal-data-protection-act. [Accessed 14- 04-2025]

  58. [67]

    The role of individual capabilities in maximizing the benefits for students using genai tools in higher education

    Jia Qi, Ji’an Liu, and Yanru Xu. The role of individual capabilities in maximizing the benefits for students using genai tools in higher education. Behavioral Sciences, 15(3):328, 2025

  59. [68]

    The impact of generative ai on education

    Mike Quartararo. The impact of generative ai on education. https://aceds. org/the-impact-of-generative-ai-on-education-aceds-blog/, 2023. [Accessed 12-04-2025]

  60. [69]

    A comprehensive survey of bias in llms: Current landscape and future directions

    Rajesh Ranjan, Shailja Gupta, and Surya Narayan Singh. A comprehensive survey of bias in llms: Current landscape and future directions. arXiv preprint arXiv:2409.16430, 2024

  61. [70]

    Reidenberg and Florian Schaub

    Joel R. Reidenberg and Florian Schaub. Achieving big data privacy in education. Theory and Research in Education , 16(3):263–279, 2018

  62. [71]

    Saturation in qualita- tive research: exploring its conceptualization and operationalization

    Benjamin Saunders, Julius Sim, Tom Kingstone, Shula Baker, Jackie Waterfield, Bernadette Bartlam, Heather Burroughs, and Clare Jinks. Saturation in qualita- tive research: exploring its conceptualization and operationalization. Quality & Analyzing Security and Privacy Challeng...

  63. [72]

    The power of analogies for imagining and governing emerging technologies

    Claudia Schwarz-Plaschg. The power of analogies for imagining and governing emerging technologies. NanoEthics, 12(2):139–153, August 2018. Company: Springer Distributor: Springer Institution: Springer Label: Springer number: 2 publisher: Springer Netherlands

  64. [73]

    Guide on the use of generative artificial intelligence

    Treasury Board of Canada Secretariat. Guide on the use of generative artificial intelligence. https://www.canada.ca/en/government/system/digital- government/digital-government-innovations/responsible-use-ai/guide-use- generative-ai.html, May 2024. [Accessed 14-04-2025]

  65. [74]

    Micro-learning in designing professional development for ict teacher leaders: The role of self-regulation and perceived learning

    Tamar Shamir-Inbal and Ina Blau. Micro-learning in designing professional development for ict teacher leaders: The role of self-regulation and perceived learning. Professional Development in Education , 48(5):734–750, 2022

  66. [75]

    Large language model alignment: A survey

    Tianhao Shen, Renren Jin, Yufei Huang, Chuang Liu, Weilong Dong, Zishan Guo, Xinwei Wu, Yan Liu, and Deyi Xiong. Large language model alignment: A survey. arXiv preprint arXiv:2309.15025, 2023

  67. [76]

    it’s been lovely watching you

    Elisa Shioji, Ani Meliksetyan, Lucy Simko, Ryan Watkins, Adam Aviv, and Shaanan Cohney. " it’s been lovely watching you”: Institutional decision-making on online proctoring software. In 2025 IEEE Symposium on Security and Privacy (SP), pages 18–18. IEEE Computer Society, 2024

  68. [77]

    Generative ai and intellectual property rights

    Jan Smits and Tijn Borghuis. Generative ai and intellectual property rights. In Law and artificial intelligence: Regulating AI and applying AI in legal practice , pages 323–344. Springer, 2022

  69. [78]

    Beyond mem- orization: Violating privacy via inference with large language models

    Robin Staab, Mark Vero, Mislav Balunović, and Martin Vechev. Beyond mem- orization: Violating privacy via inference with large language models. arXiv preprint arXiv:2310.07298, 2023

  70. [79]

    Online proctoring: Privacy invasion or study alleviation? discovering acceptability using contextual integrity

    Arnout Terpstra, Alwin De Rooij, and Alexander Schouten. Online proctoring: Privacy invasion or study alleviation? discovering acceptability using contextual integrity. 2023

  71. [80]

    Mapping tomorrow’s teaching and learning spaces: A systematic review on genai in higher education

    Tanja Tillmanns, Alfredo Salomão Filho, Susmita Rudra, Peter Weber, Julia Dawitz, Emma Wiersma, Dovile Dudenaite, and Sally Reynolds. Mapping tomorrow’s teaching and learning spaces: A systematic review on genai in higher education. Trends in Higher Education, 4(1):2, 2025

  72. [81]

    The role of generative ai in personalized learning for higher education

    Chinemelum Goodness Udeh. The role of generative ai in personalized learning for higher education. 2025

  73. [82]

    About fippa | the office of the governing council, fipp, Jun 2019

    University of Toronto. About fippa | the office of the governing council, fipp, Jun 2019

  74. [83]

    Department of Education

    U.S. Department of Education. Family educational rights and privacy; final rule,

  75. [84]

    Generative ai in higher educa- tion: Seeing chatgpt through universities’ policies, resources, and guidelines

    Hui Wang, Anh Dang, Zihao Wu, and Son Mac. Generative ai in higher educa- tion: Seeing chatgpt through universities’ policies, resources, and guidelines. Computers and Education: Artificial Intelligence , 7:100326, December 2024

  76. [85]

    Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems , 36:80079–80110, 2023

    Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems , 36:80079–80110, 2023

  77. [86]

    ’do i have to take this class?’: A review of ethics requirements in computer science curricula

    James Weichert, Dayoung Kim, Qin Zhu, and Hoda Eldardiry. ’do i have to take this class?’: A review of ethics requirements in computer science curricula. In Proceedings of the 56th ACM Technical Symposium on Computer Science Education V. 1, pages 1197–1203, 2025

  78. [87]

    State education agency governance, virtual learning, and student privacy: Lessons from the covid-19 pandemic

    Cadence Willse. State education agency governance, virtual learning, and student privacy: Lessons from the covid-19 pandemic. Educational Policy (Los Altos, Calif.), page 08959048231153609, February 2023

  79. [88]

    Llms in the classroom: Out- comes and perceptions of questions written with the aid of ai

    Gavin Witsken, Igor Crk, and Eren Gultepe. Llms in the classroom: Out- comes and perceptions of questions written with the aid of ai. arXiv preprint arXiv:2503.18995, 2025

  80. [89]

    QS World University Rankings 2024 — top- universities.com

    QS World University Rankings. QS World University Rankings 2024 — top- universities.com. https://www.topuniversities.com/world-university-rankings/ 2024, 2024. [Accessed 19-04-2025]

  81. [90]

    Privately aligning language models with reinforce- ment learning

    Fan Wu, Huseyin A Inan, Arturs Backurs, Varun Chandrasekaran, Janardhan Kulkarni, and Robert Sim. Privately aligning language models with reinforce- ment learning. arXiv preprint arXiv:2310.16960, 2023

  82. [91]

    A survey of calibration process for black-box llms

    Liangru Xie, Hui Liu, Jingying Zeng, Xianfeng Tang, Yan Han, Chen Luo, Jing Huang, Zhen Li, Suhang Wang, and Qi He. A survey of calibration process for black-box llms. arXiv preprint arXiv:2412.12767, 2024

  83. [92]

    Global data constraints: Ethical and effectiveness challenges in large language model

    Jin Yang, Zhiqiang Wang, Yanbin Lin, and Zunduo Zhao. Global data constraints: Ethical and effectiveness challenges in large language model. arXiv e-prints, pages arXiv–2406, 2024

  84. [93]

    Discovering privacy harms from education technology by analyzing user reviews

    Tianyi Yang and Rakibul Hasan. Discovering privacy harms from education technology by analyzing user reviews. In Proceedings of the 23rd Workshop on Privacy in the Electronic Society, page 186–192, Salt Lake City UT USA, November

  85. [94]

    Generative ai and the future of higher education: a threat to academic integrity or reformation? evidence from multicultural perspectives

    Abdullahi Yusuf, Nasrin Pervin, and Marcos Román-González. Generative ai and the future of higher education: a threat to academic integrity or reformation? evidence from multicultural perspectives. International Journal of Educational Technology in Higher Education, 21(1):21, 2024

  86. [95]

    Why johnny can’t prompt: how non-ai experts try (and fail) to design llm prompts

    J Diego Zamfirescu-Pereira, Richmond Y Wong, Bjoern Hartmann, and Qian Yang. Why johnny can’t prompt: how non-ai experts try (and fail) to design llm prompts. In Proceedings of the 2023 CHI conference on human factors in computing systems, pages 1–21, 2023

  87. [96]

    Knowledge workers’ perspectives on ai training for responsible ai use

    Angie Zhang and Min Kyung Lee. Knowledge workers’ perspectives on ai training for responsible ai use. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems , pages 1–18, 2025

  88. [97]

    Jailguard: A universal detection framework for prompt-based attacks on llm systems

    Xiaoyu Zhang, Cen Zhang, Tianlin Li, Yihao Huang, Xiaojun Jia, Ming Hu, Jie Zhang, Yang Liu, Shiqing Ma, and Chao Shen. Jailguard: A universal detection framework for prompt-based attacks on llm systems. ACM Transactions on Software Engineering and Methodology

  89. [98]

    Educational technology in the post-pandemic era: Current progress, potential, and challenges

    Zhuojing Zhang and Sarrah Wasie. Educational technology in the post-pandemic era: Current progress, potential, and challenges. page 40–46, 2024

  90. [99]

    ‘i make up a silly name’: Understanding children’s perception of privacy risks online

    Jun Zhao, Ge Wang, Carys Dally, Petr Slovak, Julian Edbrooke-Childs, Max Van Kleek, and Nigel Shadbolt. ‘i make up a silly name’: Understanding children’s perception of privacy risks online. In Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems , CHI ...

  91. [100]

    i’m going to trust this until it burns me

    Victoria Zhong, Susan McGregor, and Rachel Greenstadt. "i’m going to trust this until it burns me" parents’ privacy concerns and delegation of trust in k-8 educational technology. In 32nd USENIX Security Symposium (USENIX Security 23), pages 5073–5090, Anaheim, CA, August 2023...

  92. [101]

    Meet Zoom AI Companion, your new AI assistant! Unlock the benefits with a paid Zoom account — zoom.com

    Zoom. Meet Zoom AI Companion, your new AI assistant! Unlock the benefits with a paid Zoom account — zoom.com. https://www.zoom.com/zh-cn/blog/ zoom-ai-companion/. [Accessed 14-04-2025]

  93. [2011]

    [Accessed 9-04-2025]

  94. [2019]

    Association for Computing Machinery

Pith tools

Reviewed August 6, 2026 · model on record in the stance chip above.