Researchers at Charles Sturt University have created a new, freely available framework to help university staff (and those in other institutions including VET providers) work out if and when it is safe to use GenAI.

The S.E.C.U.R.E Framework organises GenAI-related risks into six categories:

  1. “Security Credentials – covers the handling of login details, passwords, API keys and other security-related credentials
  2. Ethical Use – entering or producing information that raises ethical issues, particularly involving First Nations Peoples’ cultural knowledge, and the ethical use of the output of GenAI
  3. Confidential Information – concerns data vital to the institution’s financial or competitive position
  4. Use of Personal Information – focuses on the use of personal, sensitive or traceable information
  5. Rights Protection – protects the rights of creators of original works from unauthorised use, and
  6. Evaluation of Outputs – ensures the output is not used without being critically reviewed for accuracy and quality by staff.”

The framework asks a total of just seven questions across these categories and staff are free to use GenAI if they can answer no to all of the questions being asked.

The framework also suggests some risk category examples for institutions to be specifically thinking about. They include the following:

  • Data from vulnerable groups
  • Using the output to harass, harm, intimidate, breach policy or break the law
  • Contracts or agreements with external partners
  • Business development plans
  • Creative works like software, art, books, music composition
  • Textbooks, student assessments
  • Using GenAI without verifying its accuracy
  • Submitting AI-generated text as an official communication without checking for errors, inconsistencies or misrepresentations
  • Relying on GenAI output alone to make a decision.