Information Security Guidelines
The CISO has created various guidelines that provide a framework for implementing various measures and projects.
(Parts of this page were translated using AI - including this sentence.)
New: Guidelines for the Use of AI Systems (AI Guidelines)
AI systems must be used appropriately and responsibly at all times in day-to-day work to mitigate associated risks and comply with applicable laws and UZH regulations. These AI Guidelines are intended to provide guidance in this regard.
Guidelines for the Use of AI Systems
The AI Guide in a Nutshell
Key Principles:
- Accountability: Humans always remain in charge. AI never makes decisions on its own. It’s not just about “humans in the decision-making process,” but “humans at the helm.”
- Transparency: Label AI-generated content. Avoid misunderstandings about what is AI-generated and what is human-made.
- Ethics and fairness: Declare AI support in decision-making. Disclose to all affected parties that AI was involved in the decision-making process.
- Skepticism: Question and verify AI output. AI distorts (bias) and invents (hallucinations). Never accept output without a plausibility check! Always verify the information provided and its sources!
Legal requirements apply:
- AI use does not take place in a legal vacuum; in particular, data protection, copyright, and contract law must be observed. (Topics: purpose limitation, profiling, erasure)
- Own AI agents: Agents available in approved tools can be used responsibly by users with sufficient application expertise.
- AI should be used correctly, lawfully, and securely.
- Free versions of AI systems may not be used with copyrighted works and may only be used for public information.
Questions and answers on practical topics related to the use of AI at UZH can be found in the recording of the lunch event “What Can I Do with AI at UZH?” featuring Prof. Markus Christen. (German only)
Go directly to the section in the video on copyright-protected applications using AI
The full recording of the lunch event.
How do I choose the right tool?
- Step 1: Determine the confidentiality level of the information to be used with the AI, in accordance with the guidelines for classifying information.
- Step 2: Select an AI system from the list of Centralized IT (or in consultation with your own IT department) that is approved for this confidentiality level.
- Step 3: Read and follow the relevant information sheet, and adhere to the AI guidelines.