Safe, Ethical and Meaningful Use of Artificial Intelligence (AI) Services at the Prague University of Economics and Business
Directive SR 3/2026
Annotation
This university-wide directive establishes rules governing the operation and use of artificial intelligence services (AI services) and all ICT technologies focused on automated processing of data and information at the Prague University of Economics and Business (VŠE).
Specific conditions governing the use of AI services in teaching, continuous assessment, and qualification theses may be further specified by faculties, course guarantors, or thesis supervisors.
The directive is based on the principles of responsible and trustworthy artificial intelligence and is aligned with applicable European Union legislation, particularly GDPR requirements and cybersecurity regulations.
Definitions
AI Competence Centre (KC-AI)
The AI Competence Centre is the team responsible for the operation and development of AI at VŠE. Its core is the AI Competence Centre department within the Information Technology Centre. The team also includes external members acting as AI mentors.
AI Service
A digital system using machine learning methods or other artificial intelligence techniques to generate or process content, data, or information, ranging from interactive chatbots to autonomous task execution.
Protected Information includes:
- Personal data protected under GDPR;
- Non-public and confidential VŠE information;
- Information whose processing by an AI service could result in infringement of copyright law, commercial law, or other legal regulations.
Risk Classification of AI Service Use
- Prohibited
- Risky
- Permitted
Article 1
Purpose and Scope
This directive establishes the fundamental principles, rules, authorities, and responsibilities governing the use of artificial intelligence services (hereinafter referred to as “AI”) at the Prague University of Economics and Business (hereinafter referred to as “VŠE”) to ensure effective, meaningful, secure, ethical, responsible, and sustainable use of AI services.
The directive applies across the entire university and governs authorized users defined in Article 2(1), who perform the following activities in connection with work or similar activities:
- Employment-related work activities;
- Service activities;
- Volunteer activities;
- Professional internships or placements;
- Studies.
Article 2
AI Governance: Roles, Authority and Responsibilities
AI services may only be used by authorized users.
Authorized users are required to use AI services responsibly, ethically, and securely.
Authorized users include:
- Employees of the Prague University of Economics and Business to the extent necessary for fulfilling teaching, research, and other professional responsibilities arising from their employment;
- Students of the Prague University of Economics and Business to the extent necessary for fulfilling study-related obligations;
- Other individuals who have been granted permission to use AI services through contractual arrangements, typically through the provision of credentials and AI service licenses.
Approval of AI services for use within VŠE depends on the provider’s data handling regime and compliance with the Czech legal framework:
- A contractual agreement exists between VŠE and the AI service provider;
- VŠE has accepted a Data Processing Agreement (DPA) guaranteeing GDPR-compliant handling of data and ensuring that the provider neither misuses institutional data nor uses them to train its models when university data are processed;
- All free or consumer-grade AI services without an institutional contract and verified DPA are prohibited.
Responsibilities of Managers
Managers are responsible for ensuring that both their own use of AI services and the use by their subordinates complies with this directive.
Responsibilities of Persons Supervising Volunteers or Contracted Individuals
University representatives responsible for volunteers or contracted personnel must ensure that those individuals are familiar with this directive and comply with it in their activities.
Responsibilities of VŠE Leadership
VŠE leadership:
- Supports the development of AI-related competencies, especially in management, economics, and decision-making;
- Approves AI ethics and security rules;
- Is responsible for establishing AI governance in compliance with Czech legal requirements;
- Ensures alignment between the university’s AI strategy and the VŠE Strategic Plan.
Responsibilities of the AI Competence Centre (KC AI)
The AI Competence Centre serves as the university’s supervisory and operational AI body and coordinates:
- Effective, meaningful, secure, and ethical use of AI;
- Development and revision of university-wide rules, standards, and methodologies;
- Transfer of know-how and dissemination of best practices;
- Development of AI literacy and user training concerning AI opportunities, limitations, risks, security, and responsible use;
- Selective or comprehensive implementation of AI services throughout their lifecycle;
- Mapping and monitoring AI initiatives.
Article 3
Fundamental Principles for the Use of AI Services at VŠE
The use of AI services at VŠE shall be governed by the following principles:
Effectiveness
AI services should support productivity and quality while minimizing financial costs.
Meaningfulness
AI services should be used only where they demonstrably contribute to the quality of teaching, learning, research, or university management.
Security
Users must ensure the protection of information, data, institutional know-how, and third-party intellectual property rights. Users remain personally responsible for information entered into AI services.
Ethics and Integrity
The use of AI services must not undermine academic integrity, honesty, or personal responsibility. Users must understand the limitations of AI and remain personally accountable for the outputs they publish.
Transparency
Use of AI services must be documented, and the sources underlying AI-generated claims must be traceable. AI-generated outputs should be clearly identified as such. Users remain responsible for outcomes produced with AI assistance.
Risk-Based Approach
The nature and level of risk associated with a particular use case must be considered, especially where AI may affect the rights, obligations, evaluation, or status of students, employees, or other individuals.
Human Oversight and Critical Verification
AI-generated outputs must always be reasonably verified by a human, especially where they can influence decision-making, assessment, research, or the rights and obligations of others.
Non-Discrimination and Fairness
Users must consider the risks of bias, discrimination, and lack of objectivity in AI-generated outputs.
Proportionality
Rules and restrictions governing AI use must correspond to the specific purpose, level of risk, and potential impact on individuals and the academic environment.
Article 4
Ethics of Using AI Services
AI services and their outputs must be used in accordance with general ethical principles and the principles contained in the Code of Ethics of the Prague University of Economics and Business (VŠE). At a minimum, the following ethical requirements must be met:
- AI services should serve as a tool to support decision-making, not as a substitute for human decision-making.
- Responsibility for any work product always remains with the individual user of the AI service.
- It should always be clearly indicated when a text, image, or piece of code has been created using an AI service.
- Non-public personal data, confidential information, trade secrets, or copyrighted content may not be entered into publicly available AI services without an appropriate legal basis or approval from the AI Competence Centre, if such content could subsequently be used by the AI provider.
- Decisions made by AI services that significantly affect the rights, obligations, or status of students, employees, or other individuals must not be made solely through automated processing without appropriate human review.
Article 5
Transparency in the Use of AI Services
Users of VŠE information services must be informed whenever they are communicating with an AI system or service.
Content generated by AI services and used in teaching, administration, or communication must be clearly identified as AI-generated.
AI-generated deepfakes and synthetic media must be explicitly labelled.
If the output of an AI service is used as a basis for a decision or evaluation concerning a specific individual, that person must, upon request, be provided with an appropriate explanation of how AI was used and given access to human review of the outcome.
Results produced by AI-content detection tools must not, by themselves, be considered evidence of misconduct or a breach of study or employment obligations. Such results must always be subject to individual human assessment.
Article 6
Permitted and Recommended Uses of AI Services
Recommended uses of AI services at VŠE include:
- Explaining concepts or procedures and brainstorming ideas.
- Consulting on data-processing methods.
- Preparing study materials.
- Structuring texts.
- Summarising information.
- Generating alternative solutions.
- Conducting literature searches and identifying scholarly sources.
- Providing indicative summaries of literature.
- Proofreading spelling and grammar.
- Formatting references and citations.
- Improving formatting and style of texts, tables, and charts, provided the meaning is not altered.
The use of AI services for machine translation of text included in submitted work is permitted, provided that:
- The translated text does not replace the author’s original intellectual contribution.
- If the translated material originates from another source (for example, a passage from a book), it must be properly cited according to applicable citation standards.
The use of AI services as language, technical, or support assistance does not in itself constitute a breach of academic integrity, provided it does not replace the author’s own professional, analytical, or creative contribution.
The use of AI services for autonomous actions, automation, or agent-based behaviour is permitted only if:
- Protected information is neither modified nor deleted.
- The operation of VŠE information systems is not negatively affected.
The obligation to disclose the use of AI should be proportionate to the extent of the AI service’s contribution to the final output.
The use of AI services must never result in abandoning one’s own professional judgement, critical thinking, or responsibility for the final outcome.
Article 7
Prohibited and High-Risk Uses of AI Services
The following activities are prohibited:
- Using AI services that are not registered, approved, or are explicitly prohibited by the AI Competence Centre.
- Using personal accounts with public AI services for work involving non-public or internal university information.
- Entering personal data, sensitive data, or non-public information into AI services in violation of GDPR requirements or internal VŠE regulations.
- Presenting outputs generated by AI services as one’s own professional or creative work without appropriate disclosure of AI use.
- Using AI services to circumvent study obligations, assessment procedures, or control mechanisms.
- Any use of AI services intended to obtain an unauthorized or unearned personal benefit, whether financial or non-financial.
- Using AI services in a manner that infringes intellectual property rights.
High-Risk Use of AI Services
High-risk use of AI services must always be consulted with a supervisor and, where uncertainty exists regarding the intended use or applicable legal framework, with at least one of the following:
- The AI Competence Centre;
- The course guarantor;
- The principal investigator of the relevant research project.
The following are considered high-risk uses of AI services:
- Presenting AI-generated content as original work without proper acknowledgement where disclosure is required.
- Using autonomous AI agents to extract data or information from VŠE information systems without approval from the AI Competence Centre.
- Using AI in student assessment.
- Using AI in personnel-related decision-making.
- Profiling individuals.
- Automated recommendation or classification of individuals.
- Processing sensitive or non-public information.
- Using AI in disciplinary or compliance proceedings.
Violations
Violations of the rules governing AI use shall be addressed in accordance with applicable laws and internal regulations. Depending on the context, misconduct may be handled by
- The Faculty Disciplinary Committee (student-related cases);
- The Dean, Ethics Committee, or Internal Auditor (employment-related cases);
- The Legal Department (contractual and commercial matters);
- The AI Competence Centre or Internal Auditor (other situations).
Article 8
Registry of AI Services
The Information Technology Centre maintains a central registry of AI services used within:
- Administration;
- Teaching;
- Research;
- Infrastructure;
- Information systems.
The registry of each AI service must include:
- Name of the AI service;
- AI model, provider, and data-handling regime (including zero-data-retention arrangements and defined processing scope);
- Scope of permissions required within VŠE systems and method of operation (desktop application, web client, REST API interface, etc.);
- Whether the AI service exhibits agentic or non-agentic behaviour;
- Purpose of use at VŠE;
- Expected benefits of the selected AI solution;
- Designated AI Service Owner;
- Types of processed data;
- Funding model and source.
Registration must be completed before the AI service begins operation.
The registration requirement applies particularly to AI services that affect VŠE’s legal obligations, especially those that are:
- Used systematically across the institution;
- Integrated into VŠE systems;
- Used for processing non-public, sensitive, or otherwise significant institutional data.
The use of unregistered AI services falling within the categories defined above is prohibited.
Article 9
Security of AI Services
The security framework for AI services is intended to ensure compliance with applicable legal obligations, including:
- Protection and processing of personal data in cloud and internet-based AI services in accordance with GDPR;
- Protection of research and scientific data in accordance with Act No. 328/2025 Coll., on Research, Development, Innovation and Knowledge Transfer;
- Information security and cybersecurity in accordance with Act No. 264/2025 Coll., on Cybersecurity;
- Protection of copyright and related intellectual property rights in accordance with Act No. 121/2000 Coll. (the Copyright Act).
The security framework is designed to minimize potential harm and other negative consequences arising from the operation of AI services at VŠE.
Responsibilities of AI Service Users
Users of AI services:
- May use only approved and authorized AI service standards specified in Article 11.
- May use AI services only in the permitted ways described in Articles 4 and 6.
- Are responsible for carefully verifying the reliability, accuracy, currency, truthfulness, and safety of AI-generated outputs.
- Must not use agentic AI services against university information systems, as such activity may negatively affect system availability and interfere with the detection of anomalous behaviour used to distinguish legitimate from illegitimate system activity.
Audit Logging Requirements
AI services operated by VŠE must support auditable logging of activities.
Logs must include, at a minimum:
- User identification;
- Time of use;
- AI model or service used;
- AI Inputs and outputs;
- Decision-making metadata;
- Information concerning automated actions.
AI service logs must be:
- Automatically generated;
- Protected against unauthorized modification;
- Retained for at least six months;
- Available for audit and security analysis.
The security of AI services is monitored by the AI Competence Centre.
Article 10
Security Incidents Related to AI Services
The following are considered security incidents related to AI services in particular:
- Data leakage through an AI service.
- Unauthorized use of an AI service.
- Manipulation of AI-generated outputs.
- AI hallucinations that negatively affect internal workflows or university processes.
- Compromise of an AI service.
- Unauthorized autonomous (agentic) behavior of an AI service.
Any security incident related to AI services must be reported immediately to the Information Technology Centre’s Cybersecurity Manager. The Cybersecurity Manager maintains records of AI-related security incidents and is responsible for their evaluation.
Article 11
Standards for AI Services in Operations, Administration, Creative Activities, and Education
Approved AI service standards at VŠE:
- Are approved by the University Management in accordance with the AI Competence Centre’s strategy.
- Are registered by the AI Competence Centre.
- Are published on the Information Technology Centre’s website.
The AI tool DeepSeek is prohibited pursuant to requirements issued by the National Cyber and Information Security Agency (NÚKIB).
- Its use is monitored by the security tools of the Information Technology Centre.
- Any confirmed use of DeepSeek is considered a security incident.
- Violations of this prohibition may be assessed as breaches of internal security regulations.
Article 12
Final Provisions
This Directive enters into force on the date of its signature by the Rector.
The Directive will be reviewed and updated regularly, particularly in response to:
- technological developments,
- regulatory changes,
- emerging security risks,
- practical experience gained from the use of AI services at VŠE.
This Directive is binding for all organizational units of the Prague University of Economics and Business (VŠE).