Ozyegin University Artificial Intelligence User Guide
A. Generative AI Security Risk Assessment
Generative Artificial Intelligence (GENERATIVE ARTIFICIAL INTELLIGENCE) Some risk factors may arise when using the platforms. Examples of these are "Compromise of Data" and "False and Misleading Results".
Data Compromise:
We should always use AI platforms that are known to be reliable.
In cases where we use AI platforms to draw a conclusion, we may need to share some information. We must be aware that this sharing educates the AI, the information we share becomes publicly available and may be used by the AI to generate responses in the future. Therefore, we should not share personal, corporate, sensitive or confidential information on AI platforms.
These and similar sharings may expose us, as an institution or as an individual, to situations in which we may be subject to legal sanctions or may cause a cybersecurity vulnerability depending on the nature of the data shared.
False and Misleading (discriminatory) Results
The information provided by Generative Artificial Intelligence may be incorrect or misleading. We should not completely trust the results of the UG, we should check and confirm with different methods.
UYZ can only be as impartial as the data it has access to. In other words, if the data on which UYZ is based is biased, the outputs are also inevitably biased. The data sources of UYZ do not represent a full reflection of the real world, but only consist of filtered symbols of a certain part of it. It should be kept in mind that UYZ is not yet at a sufficient level in terms of scientific accuracy and impartiality, and therefore its use in scientific research and publication should be approached with caution.
We should not use AI platforms as automated decision-making tools in critical decision-making or in situations that may lead to discriminatory outcomes, etc. In such cases, we should not forget that the results of artificial intelligence may be incorrect or misleading (discriminatory).
B. Generative Artificial Intelligence Safe Usage Principles
While using ÜYZ platforms; the basic principles we must pay attention to in order to avoid any sanctions on behalf of individuals and our University and to ensure privacy and security are as follows:
We Must Be Aware:
One of the critical steps to getting started with UYZ is increasing our awareness of how the platform we are using works.
We should use UYZ platforms with the principle of good faith, with an approach that protects the rights of individuals and institutions and facilitates the achievement of the goals we want to achieve.
We must be aware that the information we share with UYZ is transmitted to and stored on external third-party servers over which Özyeğin has no direct control. This means that information shared with UYZ may be compromised and even data loss risks may arise.
We Must Be Careful:
When using UYZ tools; we should never share personal, corporate, sensitive or confidential information (five-year strategic plan, budget study draft, clear identity information, nationality information, etc.).
We should not forget that the information shared with artificial intelligence becomes publicly available.
We should not forget that if any type of confidential, institutional or personal information owned by the university is shared with artificial intelligence tools, the responsibility lies with the person sharing it. The person sharing it must ensure that the necessary precautions are taken and is responsible for consulting the Information Security or OLTE Office about issues and situations that they are unsure about.
As an academician/administrative employee, if the written acceptance conditions of any project state that the UYZ should not be used, we must act in accordance with this condition.
If the person responsible for any course or project in which we are involved as a student specifies that the UYZ should not be used, we must act in accordance with this condition.
If it is absolutely necessary to share information via UYZ tools, we must share it by taking measures that ensure corporate and personal privacy, the details of which you will see below.
UYZ Safe Use Precautions
- A Safe AI Tool Usage: Artificial intelligence platforms that are reliable should be preferred. Opinions should be obtained from the Information Security Office and OLTE on this matter.
- Evaluating Before Sharing Data: If a need to share personal, corporate, sensitive or confidential information is detected with artificial intelligence platforms, information should not be shared. Information Security or OLTE Office should be contacted for data sharing assessment.
- Data Minimization: We should adopt the principle of sharing limited data for the purpose of benefiting from artificial intelligence. Apart from this purpose, we should never share data that is not necessary and will not contribute to the result in terms of quantity and quality with artificial intelligence platforms.
- Data Anonymization: In cases where personal corporate or confidential information needs to be shared with UYZ platforms, we must make the data anonymous. Personal data should not be entered into these systems unless it is anonymized or masked outside of UYZ systems. For data that is not anonymized, we must inform the data owners and obtain their permission before sharing.
We Must Be Transparent:
It is the clear declaration of which functions of the UYZ are used at which stages of the research and to what extent. Thanks to transparency, precautions can be taken against possible problems such as bias, factual and interpretative errors, confidentiality, privacy and data reliability brought about by the UYZ, known as the hallucination of artificial intelligence, in the stages where the UYZ is included.
If we create an assignment, work, etc. by using AI, we must inform people about how we use artificial intelligence and cite the source appropriately.
In case of a negative incident (files containing corporate data accidentally uploaded to the AI, situations where too much information is shared, situations where masking fails, etc.), we must quickly inform the university authority.
Case Study: Detecting Personal Data Entry with Artificial Intelligence
An academic will examine the relationship between students' high school success scores and university success scores using an analysis tool supported by ÜYZ, as part of a research he is working on behalf of the University.
Which UYZ tool should be preferred within the scope of the research and how should one behave when sharing data with UYZ?
Approach to the Problem
Sharing personal, corporate, sensitive or confidential information with artificial intelligence platforms poses a risk in terms of data privacy. It also means collecting, storing, transferring, using and reusing personal data in violation of legislation.
Unauthorized persons may access shared information or a data breach may occur.
Solution offers
Using a Safe Generative AI Tool: Artificial intelligence platforms that are reliable should be preferred. Opinion should be sought from the Information Security Office on this matter.
Evaluating Before Sharing Data: If a need to share personal, corporate, sensitive or confidential information is noticed on UYZ platforms, information should not be shared. Information Security or OLTE Office should be contacted for data sharing assessment.
Data Minimization: We should adopt the principle of sharing limited data for the purpose of benefiting from UYZ. Apart from this purpose, we should never share data that is not necessary and will not contribute to the result in terms of quantity and quality with UYZ platforms.
Data Anonymization: In cases where personal corporate or confidential information needs to be shared with UYZ platforms, we must make the data anonymous. Personal data should not be entered into these systems unless it is anonymized or masked outside of UYZ systems. For data that is not anonymized, we must inform the data owners and obtain their permission before sharing.