03 · What You Need to Know
Institutional Approval and Research Validation Solve Different Problems
Why Institutions Have a Role in AI Tool Selection
An individual researcher sees an AI interface. A university or research organization may see a third-party technology provider receiving institutional data, processing personal information, creating intellectual-property risks, interacting with protected systems, and becoming part of the organization's technical supply chain.
NIST's AI Risk Management Framework explicitly places AI governance within organizational processes and calls for legal and regulatory requirements, organizational policies, third-party risks, human oversight, and risk controls to be understood and managed.
Its Generative AI Profile likewise notes that third-party generative AI can affect legal, compliance, information-technology, acquisition, privacy, security, and intellectual-property functions across an organization.
Institutional review is therefore not necessarily bureaucratic interference with tool choice. It can address risks that are difficult for individual researchers to assess or negotiate alone.
What “Institutionally Approved” Can Mean
The phrase is deceptively broad. Approval may refer to very different decisions.
An institution might approve a tool for general staff use, permit it only with public information, provide an enterprise version under a negotiated contract, approve it for certain data classifications, or authorize a particular research project to use it under specified safeguards.
Researchers should therefore ask not merely whether the tool is approved, but approved for what?
| Possible institutional status |
What it might mean |
What you still need to establish |
| Generally available |
The institution provides access to the service |
Whether your research use and data type are permitted |
| Approved for public data |
Use is allowed with non-sensitive information |
Whether confidential or participant data are prohibited |
| Enterprise or institutional account |
The organization has negotiated a particular service arrangement |
Which contractual and data protections actually apply |
| Approved for a data classification |
The tool meets specified organizational requirements |
Whether your data fall within that classification |
| Approved by a research project or ethics process |
The planned use has been reviewed within a particular protocol |
Whether later changes remain within the approved procedure |
Approval Is Not a Blank Cheque for Every Type of Data
A tool may be approved for ordinary university work without being approved for personally identifiable participant information, health data, confidential commercial information, controlled research data, unpublished peer-review material, or other sensitive categories.
The account type can matter too. Your institution may approve an organizational version of a product under negotiated conditions while prohibiting use of the consumer version for the same information.
This is why researchers should examine the privacy conditions applying to the exact AI service rather than assuming that the product name settles the question.
Institutional Approval Does Not Validate AI Accuracy
This distinction is essential.
A university may approve an AI service because it satisfies procurement, privacy, security, accessibility, contractual, or administrative requirements. That does not necessarily mean researchers at the institution have validated the system's performance for literature screening, qualitative coding, statistical analysis, data extraction, or any other methodological task.
Institutional approval
The organization permits a specified use under specified governance, contractual, security, privacy, or administrative conditions.
Research validation
There is sufficient evidence that the tool performs adequately for the particular methodological task and conditions in which it will be used.
You may therefore need both. An unapproved tool can be methodologically excellent but institutionally impermissible for the data. An approved tool can satisfy governance requirements while performing poorly on the research task.
Institutional Approval Can Resolve Problems Individual Researchers Cannot
Organizations may be able to negotiate contractual protections, security requirements, data-processing arrangements, support commitments, administrative controls, or other conditions that an individual subscriber cannot obtain.
NIST's Generative AI Profile specifically identifies acquisition and procurement due diligence, service-level agreements, and other existing third-party risk controls as possible mechanisms for managing external generative AI services.
This can make an institutionally managed version materially different from an ordinary consumer account even when both interfaces look nearly identical.
Ethics Approval and Institutional Tool Approval Are Also Different
A university's IT or information-security office may approve a platform. That does not necessarily mean your research ethics committee or institutional review board has approved the proposed use of participant data within your study.
Conversely, an ethics protocol may describe AI-assisted processing while the institution still requires separate technical or security approval for the external service.
Researchers should identify which approvals apply to which aspect of the workflow rather than treating “the university approved it” as one universal permission.
Participant Consent Can Still Limit an Approved Tool
Suppose your institution provides an approved generative AI environment. Participant consent or the approved research protocol may nevertheless restrict third-party processing, automated analysis, international transfer, secondary use, or particular forms of disclosure.
Institutional availability cannot retrospectively expand what participants agreed to or what an ethics process authorized.
The relevant permissions need to align.
Contracts and Data-Use Agreements May Override Convenience
Research data can arrive with contractual restrictions from government agencies, commercial partners, archives, collaborators, funders, data repositories, or other providers.
An institutionally approved AI tool does not automatically satisfy those agreements. The contract governing the dataset may prohibit external processing or impose specific security requirements.
Before transferring controlled material, check the obligations attached to the data themselves.
Publishers and Funders May Impose Additional Rules
Institutional approval does not override requirements imposed by a journal, publisher, funder, or other research actor.
The European Commission's 2026 Living Guidelines address researchers, research organizations, and research funding organizations separately, reflecting the fact that responsible AI use operates across several levels of the research ecosystem. The guidelines emphasize research integrity, accountability, transparency, responsibility, privacy, intellectual-property protection, and sensitive knowledge.
Researchers may therefore need to satisfy institutional requirements and external requirements simultaneously.
Approval Should Be Specific Enough to Be Useful
“AI is allowed” is not much of a governance policy. Neither is “AI is prohibited” if the institution cannot distinguish low-risk brainstorming from processing identifiable participant data.
NIST's risk-management approach emphasizes that controls should reflect context, application scope, organizational risk tolerance, and potential impacts. UNESCO similarly argues for institutional validation and policy frameworks for responsible generative AI use in education and research.
Useful institutional guidance should therefore help researchers distinguish permitted uses, restricted data, approved services, necessary safeguards, and escalation routes when the answer is unclear.
Researchers Still Need to Evaluate the Approved Tool
Once governance requirements are satisfied, methodological evaluation remains.
If you plan to use the approved AI system for literature screening, data extraction, classification, coding, analysis, or another consequential task, evaluate its performance before embedding it into the research workflow.
Approval tells you that you may use the tool under certain conditions. Evaluation tells you whether you should use it for this methodological purpose.
An Unapproved Tool Is Not Necessarily a Bad Tool
Researchers should also avoid the reverse inference. If an institution has not approved a particular AI system, that does not prove the system is inaccurate, insecure, or unethical.
The tool may simply not have been reviewed. Procurement may be incomplete. The institution may lack an agreement with the provider. The product may be too new. Another tool may have been selected for administrative simplicity.
Institutional status is therefore evidence about organizational permission, not a universal quality ranking.
Approval Can Change
AI products, provider policies, organizational requirements, and legal conditions evolve. A system approved under one set of conditions may later change its model, data practices, integrations, contractual terms, or security arrangements.
NIST's AI RMF treats risk management as continuous across the AI lifecycle and calls for ongoing monitoring of third-party resources and change management.
Researchers should therefore check current institutional guidance rather than relying indefinitely on an old email, workshop slide, or colleague's recollection of what was permitted last year.