Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

Should Institutional Approval Affect Which AI Tools Researchers Use?

Institutional approval can be decisive when AI tools handle protected, confidential, or institutionally governed information. But approval establishes permission under particular conditions, not scientific validity for every research task.

79
Institutional Approval of AI Research Tools Guide 79 of 80
01 · The Question

If Your Institution Approves an AI Tool, Should That Determine What You Use?

A researcher may prefer one AI tool while their university provides another. An institution may publish a list of approved systems, prohibit particular services for sensitive data, negotiate an enterprise agreement, or require security and privacy review before external AI can process institutional information.

Should those decisions affect the researcher's choice?

Yes, sometimes decisively. Institutions have obligations involving research participants, information security, privacy, contracts, intellectual property, ethics, and regulatory compliance that individual researchers cannot simply opt out of. But institutional approval answers only some of the questions researchers need to ask.

02 · The Short Answer

Institutional Approval Matters, but It Is Not Scientific Validation

In Brief

Yes. Institutional approval should affect which AI tools researchers use when organizational policies, data classifications, ethics requirements, security controls, contracts, procurement rules, or other governance obligations apply to the proposed use.

Approval does not mean the tool is accurate, reliable, or methodologically appropriate for every research task. Researchers still need to evaluate scientific fitness and verify outputs independently.

03 · What You Need to Know

Institutional Approval and Research Validation Solve Different Problems

Why Institutions Have a Role in AI Tool Selection

An individual researcher sees an AI interface. A university or research organization may see a third-party technology provider receiving institutional data, processing personal information, creating intellectual-property risks, interacting with protected systems, and becoming part of the organization's technical supply chain.

NIST's AI Risk Management Framework explicitly places AI governance within organizational processes and calls for legal and regulatory requirements, organizational policies, third-party risks, human oversight, and risk controls to be understood and managed.

Its Generative AI Profile likewise notes that third-party generative AI can affect legal, compliance, information-technology, acquisition, privacy, security, and intellectual-property functions across an organization.

Institutional review is therefore not necessarily bureaucratic interference with tool choice. It can address risks that are difficult for individual researchers to assess or negotiate alone.

What “Institutionally Approved” Can Mean

The phrase is deceptively broad. Approval may refer to very different decisions.

An institution might approve a tool for general staff use, permit it only with public information, provide an enterprise version under a negotiated contract, approve it for certain data classifications, or authorize a particular research project to use it under specified safeguards.

Researchers should therefore ask not merely whether the tool is approved, but approved for what?

Possible institutional status What it might mean What you still need to establish
Generally available The institution provides access to the service Whether your research use and data type are permitted
Approved for public data Use is allowed with non-sensitive information Whether confidential or participant data are prohibited
Enterprise or institutional account The organization has negotiated a particular service arrangement Which contractual and data protections actually apply
Approved for a data classification The tool meets specified organizational requirements Whether your data fall within that classification
Approved by a research project or ethics process The planned use has been reviewed within a particular protocol Whether later changes remain within the approved procedure

Approval Is Not a Blank Cheque for Every Type of Data

A tool may be approved for ordinary university work without being approved for personally identifiable participant information, health data, confidential commercial information, controlled research data, unpublished peer-review material, or other sensitive categories.

The account type can matter too. Your institution may approve an organizational version of a product under negotiated conditions while prohibiting use of the consumer version for the same information.

This is why researchers should examine the privacy conditions applying to the exact AI service rather than assuming that the product name settles the question.

Institutional Approval Does Not Validate AI Accuracy

This distinction is essential.

A university may approve an AI service because it satisfies procurement, privacy, security, accessibility, contractual, or administrative requirements. That does not necessarily mean researchers at the institution have validated the system's performance for literature screening, qualitative coding, statistical analysis, data extraction, or any other methodological task.

Institutional approval The organization permits a specified use under specified governance, contractual, security, privacy, or administrative conditions.
Research validation There is sufficient evidence that the tool performs adequately for the particular methodological task and conditions in which it will be used.

You may therefore need both. An unapproved tool can be methodologically excellent but institutionally impermissible for the data. An approved tool can satisfy governance requirements while performing poorly on the research task.

Institutional Approval Can Resolve Problems Individual Researchers Cannot

Organizations may be able to negotiate contractual protections, security requirements, data-processing arrangements, support commitments, administrative controls, or other conditions that an individual subscriber cannot obtain.

NIST's Generative AI Profile specifically identifies acquisition and procurement due diligence, service-level agreements, and other existing third-party risk controls as possible mechanisms for managing external generative AI services.

This can make an institutionally managed version materially different from an ordinary consumer account even when both interfaces look nearly identical.

Ethics Approval and Institutional Tool Approval Are Also Different

A university's IT or information-security office may approve a platform. That does not necessarily mean your research ethics committee or institutional review board has approved the proposed use of participant data within your study.

Conversely, an ethics protocol may describe AI-assisted processing while the institution still requires separate technical or security approval for the external service.

Researchers should identify which approvals apply to which aspect of the workflow rather than treating “the university approved it” as one universal permission.

Participant Consent Can Still Limit an Approved Tool

Suppose your institution provides an approved generative AI environment. Participant consent or the approved research protocol may nevertheless restrict third-party processing, automated analysis, international transfer, secondary use, or particular forms of disclosure.

Institutional availability cannot retrospectively expand what participants agreed to or what an ethics process authorized.

The relevant permissions need to align.

Contracts and Data-Use Agreements May Override Convenience

Research data can arrive with contractual restrictions from government agencies, commercial partners, archives, collaborators, funders, data repositories, or other providers.

An institutionally approved AI tool does not automatically satisfy those agreements. The contract governing the dataset may prohibit external processing or impose specific security requirements.

Before transferring controlled material, check the obligations attached to the data themselves.

Publishers and Funders May Impose Additional Rules

Institutional approval does not override requirements imposed by a journal, publisher, funder, or other research actor.

The European Commission's 2026 Living Guidelines address researchers, research organizations, and research funding organizations separately, reflecting the fact that responsible AI use operates across several levels of the research ecosystem. The guidelines emphasize research integrity, accountability, transparency, responsibility, privacy, intellectual-property protection, and sensitive knowledge.

Researchers may therefore need to satisfy institutional requirements and external requirements simultaneously.

Approval Should Be Specific Enough to Be Useful

“AI is allowed” is not much of a governance policy. Neither is “AI is prohibited” if the institution cannot distinguish low-risk brainstorming from processing identifiable participant data.

NIST's risk-management approach emphasizes that controls should reflect context, application scope, organizational risk tolerance, and potential impacts. UNESCO similarly argues for institutional validation and policy frameworks for responsible generative AI use in education and research.

Useful institutional guidance should therefore help researchers distinguish permitted uses, restricted data, approved services, necessary safeguards, and escalation routes when the answer is unclear.

Researchers Still Need to Evaluate the Approved Tool

Once governance requirements are satisfied, methodological evaluation remains.

If you plan to use the approved AI system for literature screening, data extraction, classification, coding, analysis, or another consequential task, evaluate its performance before embedding it into the research workflow.

Approval tells you that you may use the tool under certain conditions. Evaluation tells you whether you should use it for this methodological purpose.

An Unapproved Tool Is Not Necessarily a Bad Tool

Researchers should also avoid the reverse inference. If an institution has not approved a particular AI system, that does not prove the system is inaccurate, insecure, or unethical.

The tool may simply not have been reviewed. Procurement may be incomplete. The institution may lack an agreement with the provider. The product may be too new. Another tool may have been selected for administrative simplicity.

Institutional status is therefore evidence about organizational permission, not a universal quality ranking.

Approval Can Change

AI products, provider policies, organizational requirements, and legal conditions evolve. A system approved under one set of conditions may later change its model, data practices, integrations, contractual terms, or security arrangements.

NIST's AI RMF treats risk management as continuous across the AI lifecycle and calls for ongoing monitoring of third-party resources and change management.

Researchers should therefore check current institutional guidance rather than relying indefinitely on an old email, workshop slide, or colleague's recollection of what was permitted last year.

04 · A Practical Example

When the Better-Performing AI Tool Is Not the Permitted One

Hypothetical Example

Choosing AI for Interview Analysis

A research team compares two AI systems for preliminary coding of interview transcripts. Tool A performs slightly better in the team's pilot. Tool B is provided through the university under an institutional agreement and is approved for the relevant category of research data. The consumer version of Tool A is not approved for those transcripts.

Compare methodological performance Tool A produces somewhat more useful preliminary codes during testing, although both systems require researcher review.
Check data governance The team confirms that the transcripts cannot be uploaded to Tool A under the institution's current requirements.
Examine the approved option Tool B meets the applicable institutional conditions and performs adequately under the team's validation procedure.
Make the decision The researchers use Tool B with documented human verification rather than treating the marginal performance advantage of Tool A as permission to bypass data-governance requirements.
Preserve the distinction The team reports Tool B's methodological limitations honestly. Institutional approval does not transform adequate performance into excellent performance.

The decision involves two thresholds. The tool must be permissible for the data, and it must be sufficiently fit for the research task. Passing one threshold does not automatically satisfy the other.

05 · What Researchers Often Get Wrong

Common Misunderstandings About Institutional AI Approval

Misconception

If My University Provides the Tool, I Can Upload Any Research Data

Institutional access may apply only to specified data types, account configurations, or use cases. Check the actual approval conditions before providing sensitive information.

Misconception

An Approved AI Tool Has Been Scientifically Validated

Institutional review may focus on security, privacy, contracts, procurement, accessibility, or governance. Researchers still need evidence that the tool performs adequately for the methodological task.

Misconception

If the Tool Is Not on the Approved List, It Must Be Unsafe

Absence from an institutional list can have many explanations. Treat it as a governance status, not a scientific verdict. Follow the institution's process for determining whether the proposed use is permitted.

Misconception

Ethics Approval Automatically Covers the AI Platform

An ethics review and an institutional technology or security review may address different risks. Depending on the institution and project, both may be necessary.

Misconception

Researchers Can Ignore Institutional Rules if No Sensitive Data Are Involved

Some institutional requirements apply to software procurement, intellectual property, acceptable use, cybersecurity, or research integrity beyond personal-data protection. Determine which policies actually govern the proposed use.

06 · What This Means for You

Ask Two Separate Questions: May I Use It, and Should I Use It?

A simple decision framework

If your institution requires approved AI tools for the relevant data or activity
Treat that requirement as a boundary on tool selection rather than an optional recommendation.
If a tool is institutionally approved
Confirm what products, account types, data classifications, and use cases the approval actually covers.
If the approved tool will perform a substantive research task
Evaluate its methodological performance separately rather than assuming institutional approval establishes reliability.
If your preferred tool is not approved
Use the institution's review or exception process where available instead of quietly moving the research outside approved controls.
If institutional guidance conflicts with another research obligation
Resolve the conflict through the appropriate research-governance, ethics, privacy, legal, or data-management channel before proceeding.

This creates a useful sequence. First establish whether the proposed system is permissible for the information and context. Then ask whether it is scientifically fit for the job. Neither institutional permission nor technical performance should be allowed to answer both questions.

07 · A Quick Checklist

Before Using an Institutionally Approved AI Tool for Research

Check what the approval actually covers:
Product: Is the exact AI service and account type I plan to use covered by the institutional approval?
Use case: Is the proposed research activity within the permitted scope?
Data: Is the relevant category of research information permitted in the system?
Ethics: Does the planned AI use remain consistent with the approved research protocol and participant consent?
Contracts: Do data-use agreements, collaborator agreements, publisher licenses, or other restrictions permit the processing?
External rules: Do relevant funder, publisher, disciplinary, or regulatory requirements impose additional conditions?
Methodological fit: Has the tool been evaluated for the actual research task rather than merely approved administratively?
Current status: Is the institutional guidance still current for the version and service I intend to use?
08 · Frequently Asked Questions

Questions About Institutional Approval of AI Research Tools

Do I have to use only AI tools approved by my university?

Follow the policies that apply to your institution, project, data, and role. Some organizations may restrict particular data or activities to approved systems, while others may allow broader use under specified conditions.

Does university approval mean an AI tool is accurate?

No. Institutional approval may address governance, security, privacy, procurement, contracts, or related concerns. Researchers should separately validate performance for consequential methodological uses.

Can I use my personal AI subscription if my university provides the same tool?

Do not assume the accounts are equivalent. Institutional versions may operate under different contractual, administrative, privacy, or security conditions. Check which account is approved for the intended research material.

Does ethics approval mean I can use any AI tool with participant data?

Not necessarily. The ethics approval must actually cover the proposed processing, and separate institutional technology, security, privacy, contractual, or data-governance requirements may also apply.

What should I do if the AI tool I need is not institutionally approved?

Use the institution's review, procurement, security-assessment, or exception process where one exists. Explain the research need, proposed data, intended use, and relevant safeguards rather than bypassing the process.

Can an institutionally approved AI tool still be inappropriate for my research?

Yes. It may perform inadequately on your task, lack necessary source coverage, introduce unacceptable methodological limitations, or conflict with requirements specific to your project even though the institution generally permits the service.

Should institutional approval be part of choosing an AI tool?

Yes when institutional requirements apply. Treat approval as one selection criterion alongside task fit, reliability, transparency, source verification, privacy, cost, and other requirements relevant to the research.

09 · The Bottom Line

Institutional Permission and Research Reliability Are Two Different Gates

The Bottom Line

Institutional approval should affect AI tool selection whenever organizational policies or research-governance requirements apply, but approval means the tool is permitted under particular conditions, not that it has been scientifically validated for every research task.

Ask two questions separately: “May I use this system with these data?” and “Is this system good enough for this methodological job?” Responsible research may require a yes to both. University approval gets you through one gate. It does not quietly award the software a methods degree.

10 · Sources and Further Reading

Sources and Further Reading

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes