StanfordUniversity IT Responsible AI for everyone
AI Catalyst

Path 04 of 07 · Staff and researchers handling sensitive data · all levels

High-Risk Data & AI

By the end: You can name which Stanford AI services are approved for High Risk data and which for PHI, place your own use case on Stanford's AI risk tiers, and choose the right tool before you paste anything.

The sequence

External Responsible AI at Stanford The definitions: Moderate and High Risk data includes addresses, passport numbers, health information, passwords, financial data, CUI, ITAR, proprietary source code and NDA material. Nothing on this list goes into an uncovered tool. Open Guide AI Playground | University IT Approved for High Risk, non-PHI data. OpenAI, Google and Anthropic models in one Stanford-managed place, with file upload and shareable conversations. The default choice for sensitive but not clinical work. Open Guide Microsoft Copilot Chat | University IT The counter-example. Free Copilot Chat is approved for Low and Moderate Risk only: no PHI, SSNs, financial account numbers or high-risk research data. The Differences table shows what the paid M365 Copilot adds. Open External Claude for Education at Stanford Classification by feature, not by product: Claude Chat for everything except PHI; Claude Code and Cowork approved for High Risk, with PHI only through the AI API Gateway; Zoom and M365 connectors off for School of Medicine users. Open Guide AI API Gateway | University IT The route for PHI in code. Approved for High Risk data and PHI, billed to a PTA. If your project touches PHI programmatically, this is the service to request. Open Guide Know Your Risks: Agentic AI Risk Classifications | University IT Stanford's Low, Moderate and High AI risk tiers with examples (literature search assistants are Low; participant screening and admissions are High). Every AI system must be classified before deployment. Place yours. Open