Key AI risks
▹ Confidential and pre-publication data leaking into commercial models
▹ Undisclosed AI use breaching funder rules (NIH, NSF)
▹ Fabricated or unverifiable AI-generated results
▹ IP and authorship disputes over AI-assisted work
Governed through the RMF Playbook
Each function pairs the outcome to reach for this domain (the Playbook's About ) with the Playbook's suggested actions .
Govern
Define the principles for AI in scholarship — ownership, disclosure, and the lines that protect confidentiality and the trust of funders.
Playbook · suggested actions
Set IP, disclosure, and confidential-review policies aligned to funder rules.
Map
Situate each use of AI in its research context — the sensitivity of the data, the funder and disciplinary rules, and the review bodies that apply.
Playbook · suggested actions
Classify data sensitivity and identify the funder and IRB rules for each project.
Measure
Assess whether AI-assisted work stays rigorous, reproducible, and honestly disclosed.
Playbook · suggested actions
Verify disclosure, reproducibility, and confidentiality controls on AI-assisted work.
Manage
Enable responsible use and respond when integrity, confidentiality, or funder compliance is at risk.
Playbook · suggested actions
Route work through research-office review and remediate any compliance gaps.
Worked case studies · the RMF Playbook applied
10 scenarios
Each step is a Playbook suggested action for that function; the evidence line is the transparency & documentation you keep.
Case 1
Case 2
Case 3
Case 4
Case 5
Case 6
Case 7
Case 8
Case 9
Case 10
Confidential grant review and a public chatbot
Office of Research · NIH proposal review
A faculty reviewer is tempted to summarize a confidential NIH proposal with a consumer AI chatbot to save time.
Govern
Policy prohibits AI-assisted peer review of confidential submissions, aligned to NIH and NSF requirements.
Map
Classify the proposal as confidential / high-sensitivity and flag the funder restriction that applies.
Measure
Confirm no proposal text reached external tools and run disclosure review on any AI-assisted analysis.
Manage
Provide an approved, contained institutional tool for permissible tasks and remediate any exposure.
Outcome — No confidential text enters external AI and the institution avoids a funder-compliance breach.
Evidence: Reviewer attestation + AI-disclosure log
AI-assisted systematic review
School of Public Health · evidence synthesis
A team wants AI to screen thousands of abstracts for a systematic review without compromising rigor.
Govern
The AI-in-research use policy permits screening when the method is documented.
Map
Classify the data as public literature and scope the protocol and reproducibility needs.
Measure
Validate AI screening against a human-coded sample and record precision and recall.
Manage
Keep humans on final inclusion decisions and disclose the AI method in the writeup.
Outcome — Screening accelerates with documented validation and transparent, reproducible methods.
Evidence: Screening validation table + methods disclosure
AI-generated analysis code in a lab
Physics · computational group
A graduate student uses an AI assistant to write data-analysis code that shapes published results.
Govern
Research-integrity standards require provenance for AI-assisted analysis.
Map
Identify the data’s sensitivity and that the code affects published results.
Measure
Require code review and reproducibility checks on AI-written analysis.
Manage
Log provenance, version the code, and disclose the AI assistance.
Outcome — The analysis is reproducible and AI assistance is documented rather than hidden.
Evidence: Data-provenance log + code-review record
Disclosing AI use in a manuscript
Faculty author · journal submission
An author drafted sections with AI and is unsure how to disclose it under the journal’s policy.
Govern
The disclosure policy aligns institutional norms with COPE, ICMJE, and publisher rules.
Map
Identify the target journal’s AI-authorship policy and what must be disclosed.
Measure
Check the manuscript’s AI-assisted content against the disclosure requirements.
Manage
Add the required disclosure statement and keep AI off the author line.
Outcome — The submission complies with the journal’s AI policy and discloses assistance clearly.
Evidence: AI disclosure statement + journal-policy checklist
IP dispute over an AI-assisted invention
Technology Transfer Office
A disclosed invention was substantially developed with generative AI, raising ownership questions.
Govern
The IP-ownership policy explicitly addresses AI-assisted inventions.
Map
Determine the human inventive contribution and the AI’s role.
Measure
Review patentability and ownership against policy and current law.
Manage
Document contributions and route the disclosure through tech-transfer review.
Outcome — Ownership is resolved with documented human contribution before any filing.
Evidence: Invention disclosure + AI-contribution record
AI with human-subjects data
Psychology · IRB-reviewed study
Researchers want to run participant data through a cloud AI service.
Govern
The AI-in-human-subjects guidance sets IRB jurisdiction and consent expectations.
Map
Classify participant-data sensitivity and identify consent and IRB scope.
Measure
Assess the service’s data handling against IRB and privacy requirements.
Manage
Use a contained or approved service, or de-identify before processing.
Outcome — Participant data stays protected and the study clears IRB review.
Evidence: IRB protocol amendment + data-handling assessment
AI transcription of interviews
Sociology · qualitative research
A researcher wants to upload recorded interviews to an AI transcription tool.
Govern
Confidentiality standards govern pre-publication and participant data.
Map
Identify participant confidentiality needs and the tool’s data retention.
Measure
Review the vendor’s data-use terms, retention, and logging.
Manage
Choose a compliant tool or de-identify audio, and document consent.
Outcome — Transcription is efficient without breaching participant confidentiality.
Evidence: Vendor data-use review + consent documentation
Fabricated AI images in figures
Research Integrity Office
A concern is raised that a submitted figure contains AI-fabricated or manipulated imagery.
Govern
Integrity standards prohibit undisclosed AI image generation in results.
Map
Identify which figures involve AI and the disclosure gap.
Measure
Run image-integrity and provenance checks on the figures.
Manage
Require raw data and disclosure and refer suspected misconduct.
Outcome — Fabrication is caught and the integrity process is applied consistently.
Evidence: Image-integrity review + provenance request
Licensing an AI research-discovery platform
University Library · database acquisition
A vendor’s AI-powered discovery platform includes training-data provisions in its license.
Govern
Procurement and library policy set licensing standards for AI-enabled databases.
Map
Identify the training-data and copyright implications in the license.
Measure
Review the terms against data-practice and copyright standards.
Manage
Negotiate protective terms jointly with the library and procurement.
Outcome — The platform is licensed with acceptable data-practice and copyright terms.
Evidence: License review + negotiated addendum
Export-controlled data in AI tools
Engineering · sponsored research
A project’s export-controlled data must never enter uncontrolled AI services.
Govern
Compliance standards bar restricted data from non-compliant tools.
Map
Classify the data under export control and identify restricted uses.
Measure
Verify that the AI environment meets the control requirements.
Manage
Route restricted work to a compliant enclave and train the team.
Outcome — Controlled data stays inside a compliant environment.
Evidence: Export-control review + enclave approval
Risk-tier examples
Assistive
AI-assisted literature-search tools.
Operational
AI analyzing research datasets containing de-identified data.
Consequential
AI processing confidential pre-publication or clinical-trial data.
Tools & artifacts
AI disclosure statement template
Approved-tool list (research)
Data-provenance log
Funder-requirement checklist
Key controls & instruments
IP-ownership policy for AI-assisted scholarship
Prohibition on AI peer review of confidential material
Research integrity & disclosure standards
Funder-compliance (NIH/NSF/DOE) standards