Skip to main content

PMU AI Policy

POLICY ON THE USE OF AI SYSTEMS, IN PARTICULAR GENERATIVE AI, IN STUDIES, TEACHING, RESEARCH, AND ADMINISTRATION AT PARACELSUS MEDICAL PRIVATE UNIVERSITY (PMU)

Version: June 18, 2026
Effective as of: July 1, 2026
Policy No.: 044

Approved by: Rectorate of PMU and the Board of Paracelsus Medical Private University Salzburg – Private Foundation
Prepared by: Dr. Thomas Caspari

(translation by AI)


Preamble

Artificial intelligence (AI) is a key technology that is profoundly changing studies, teaching, research, administration, and healthcare. Paracelsus Medical Private University (hereinafter “PMU”) is committed to an open, while at the same time critically reflective and responsible, approach to AI technologies. AI is understood as a tool that supports human expertise but cannot replace scientific, didactic, organizational, ethical, or clinical responsibility.

This Policy specifies, for studies, teaching, research, administration, and other university contexts, the requirements of the Rules of Procedure of the AI and Digitalization Board (AI-DB), as well as the applicable legal framework, in particular Austrian higher education law applicable to private universities, including higher education quality assurance and accreditation requirements, Regulation (EU) 2024/1689 (AI Regulation / AI Act), the General Data Protection Regulation (GDPR), copyright law, and other applicable study-related, employment-related, and contractual provisions. It serves to ensure the lawful, transparent, responsible, and traceable use of AI systems at PMU. The responsibilities of the AI-DB for assessment, approval, register management, risk classification, and compliance remain unaffected.


I. GENERAL PROVISIONS

§ 1 Scope and Definitions

(1) This Policy applies to all students, lecturers, researchers, and administrative staff members of PMU, as well as to external lecturers and other persons, insofar as they act on behalf of or within the area of responsibility of PMU.

(2) This Policy applies to the use, procurement, development, implementation, testing, provision, and any other use of AI-supported systems at PMU, in particular generative AI systems for creating or editing text, images, audio, video, or code files, as well as for analyzing datasets. Supplementary annexes or implementing provisions to this Policy may apply to specific forms of use of AI systems, in particular in courses, examinations, research, and administration.

(3) An AI system is a machine-based system within the meaning of the AI Regulation that is designed to operate with varying levels of autonomy and that infers from inputs how to generate outputs such as predictions, content, recommendations, or decisions.


§ 2 PMU’s Roles under the EU AI Regulation

(1) Before an AI system is put into service, procured, developed, materially modified, or made available, the AI and Digitalization Board (AI-DB) shall clarify and document whether, in the specific use case, PMU acts as a deployer or as a provider within the meaning of Regulation (EU) 2024/1689.

(2) PMU acts as a deployer where it uses an AI system under its responsibility, in particular in studies, teaching, research, administration, human resources, IT, communication, clinical-adjacent, or other university contexts.

(3) PMU acts as a provider where it develops, or has developed, an AI system and places it on the market or puts it into service under its own name or trademark. The same applies where PMU develops, or has developed, a general-purpose AI model and makes it available under its own name or trademark.

(4) The role classification shall be documented in the AI Register. If the role cannot be clearly determined, or if a provider role may be involved, the AI system may be used only after express approval by the AI-DB, after completion of the required legal, data protection, security-related, and risk-related assessments, and after approval by the Rectorate and/or the Board.

(5) In the case of AI systems used exclusively for scientific research, development, or testing purposes, the AI-DB shall additionally assess whether the specific use falls within a research or development privilege under Regulation (EU) 2024/1689. This assessment shall be documented.

(6) The research or development privilege shall not apply, in particular, to regular use in studies, teaching, research, administration, human resources, IT, communication, clinical-adjacent, or other university processes. Where an AI system is transferred from a research, development, or testing context into regular operation, made available to third parties, used under the name of PMU, or tested under real-world conditions with effects on natural persons, a new role, risk, data protection, security, and, where applicable, fundamental rights assessment shall be conducted in advance.


§ 3 Relationship to the Rules of Procedure of the AI-DB and Other Requirements

(1) This Policy applies without prejudice to any further assessment, notification, documentation, and approval obligations under the Rules of Procedure of the AI-DB.

(2) AI systems and AI projects that are sensitive from a regulatory perspective, particularly intrusive from a data protection law perspective, relevant to high-risk classification, or intended for decisions with legal or similarly significant effects shall be submitted to the AI-DB before procurement, development, implementation, or material modification.

(3) Other statutory, charter-related, examination-related, data protection, employment law, copyright, quality assurance, or contractual requirements remain unaffected.


§ 4 General Principles of Use and Responsibility

(1) Responsibility for all content, assessments, decisions, and work products created or used with the assistance of AI in studies, teaching, research, and administration lies exclusively with the respective natural person acting or with the responsible organizational unit. AI systems do not have legal capacity and cannot be authors.

(2) All content generated with the assistance of AI systems shall be reviewed before use for substantive accuracy, plausibility, traceability, bias, risks of discrimination, and any hallucinations. The unreviewed adoption of AI outputs is not permitted.

(3) The use of AI may not serve to conceal a lack of independent work. The intellectual contribution of the respective person must remain predominant and identifiable. AI use that is not declared, or is insufficiently declared, may constitute a violation of the rules of good scientific practice or of examination-related requirements.

(4) AI systems may be used at PMU only if their use does not violate statutory requirements, this Policy, other internal requirements, or approval requirements under the Rules of Procedure of the AI-DB.

(5) The requirements of Regulation (EU) 2024/1689 shall be observed in accordance with their temporal scope of application. Requirements that already apply, in particular in connection with AI literacy and prohibited AI practices, shall be complied with. Requirements that apply only at a later date, in particular in connection with high-risk AI systems, shall be prepared for in a timely manner at the organizational level.


II. PERMISSIBILITY, TRANSPARENCY, AND PROTECTIVE OBLIGATIONS

§ 5 AI in Studies, Teaching, and Examinations

(1) The use of AI systems to support the learning process, prepare courses, and create work is permitted only within the framework of statutory requirements, this Policy, and the applicable course-specific, examination-specific, or assignment-specific requirements. For courses, examinations, written work, and other graded work, the permitted scope of AI use shall be determined according to the categories set forth in paragraph 2 and communicated to students in a timely, clear, and comprehensible manner. If no such determination is made, the default rules under paragraph 2 shall apply.

(2) For courses, examinations, written work, project work, research work, and other graded work, the responsible program director or a person delegated by the program director shall determine the extent to which AI systems may be used. One of the following categories shall be applied:

1. Category A – No AI use permitted.
The use of AI systems is prohibited. Only expressly approved aids remain permitted.

2. Category B – Only linguistic and formal aids permitted.
AI systems may be used exclusively for spelling, grammar, translation, formatting, or stylistic revision of one’s own texts. Content generation, creation of solutions, development of arguments, source research, or data analysis by AI is not permitted unless expressly approved.

3. Category C – AI use permitted, but documentation required.
AI systems may be used as supporting tools. Students remain responsible for the content, accuracy, sources, independent nature, and scientific integrity of the submitted or completed work. The type, purpose, and scope of AI use shall be documented in accordance with the requirements of the program director or a person delegated by the program director. The documentation may include, in particular, information on the AI system used, the version, the provider, the work step, the prompting, the output generated, and the student’s own review and further revision.

4. Category D – AI is part of the assignment.
The use of AI systems is didactically intended and forms part of the work. The assignment shall specify which AI systems or functions may or shall be used, how the generated results must be critically reviewed, which documentation obligations apply, and how AI use is taken into account in the assessment.

The applicable category and any additional requirements shall be communicated to students transparently, in writing, and in a permanently accessible manner no later than the beginning of the course or when the specific examination, work, or project assignment is issued. Changes during the course are permissible only for objective reasons and without disadvantage to students.

If no express classification has been made, Category A applies to supervised examinations, and Category B applies to written work, project work, and other unsupervised graded work, unless the program director or a person delegated by the program director has announced a different rule. In cases of uncertainty, students shall consult the responsible course instructor, examination supervisor, or supervising person before submitting the work or taking the examination.

(3) In written work, research work, and other examination-relevant work, the use of generative AI shall be disclosed insofar as it goes beyond merely subordinate auxiliary functions. The documentation shall in any case include:

  • the tool or system used, including the version, where known;

  • the area of application;

  • the approximate time of use;

  • in the case of substantial content generation, the relevant inputs or a sufficiently detailed substantive description of the use;

  • where relevant, the parameters or settings essential for reproducibility or classification.

(4) The mere use of spelling, grammar, or formatting aids, as well as purely translation aids for individual terms or minor linguistic polishing, does not require separate labeling, provided that no independent substantive contribution by the AI system is used.

(5) The undisclosed or misleadingly represented adoption of AI-generated content as one’s own work may be considered an attempt at deception, plagiarism in the broader sense, or another violation of examination-related or charter-related requirements.

(6) Lecturers may define more specific requirements for the permissible or impermissible use of AI systems in their courses, provided that such requirements are compatible with higher-level legal and institutional requirements.


§ 6 Transparency, Labeling, and Disclosure Obligations

(1) AI-generated content or content materially edited by AI shall be disclosed or labeled wherever this is required under this Policy, examination-related requirements, or applicable legal provisions.

(2) When generative AI is used in studies, teaching, research, or administration, it shall be ensured in an appropriate manner that the origin, degree of editing, and responsibility remain traceable.

(3) Where labeling obligations for artificially generated or manipulated content exist under the AI Regulation or other legal provisions, such obligations shall be complied with.


§ 7 Data Protection, Confidentiality, and Sensitive Data

(1) The input of personal data of patients, in particular health data within the meaning of Article 9 GDPR, into public AI systems or AI systems not approved by PMU is prohibited.

(2) Pseudonymized data may also not be entered into open or non-approved AI systems if re-identification, impermissible further processing, transmission to third parties, or transfer to a third country cannot be excluded.

(3) Lecturers, staff members, and other function holders may not upload personal data of students or student work to external AI systems unless there is a legal basis, internal approval, and appropriate data protection and contractual safeguards.

(4) Confidential information, trade and business secrets, unpublished research data, and examination-related or personnel-related content may be processed only in systems approved for this purpose.

(5) If there are doubts regarding permissibility under data protection law, professional law, research ethics, copyright law, or contract law, the AI-DB or the responsible office shall be involved before use. Any requirement to conduct a data protection impact assessment or other assessments remains unaffected.


§ 8 Synthetic Media and Deepfakes

(1) Where image, audio, or video files are artificially generated or materially manipulated by means of AI for administrative or advertising purposes, teaching purposes, research purposes, or in student work, this shall be clearly labeled insofar as required under the AI Regulation or other legal provisions.

(2) The creation or use of synthetic media may not be employed for purposes of deception, disinformation, disparagement, reputational harm, or violation of personality rights or other statutory provisions.

(3) The creation or use of deepfakes of real persons without their consent or another legal basis is prohibited. This applies in particular to students, lecturers, staff members, and patients.


§ 9 Copyright, Research Data, and Text and Data Mining

(1) When copyrighted works are entered into AI systems, it shall be assessed whether the required rights or statutory permissions exist. Uploading third-party texts, works, images, datasets, or other protected content to cloud-based systems may be relevant under copyright law.

(2) Work by students, lecturers, or staff members may not be fed into external AI systems without a legal basis, consent, or other authorization.

(3) Text and data mining for scientific purposes is permitted only within the framework of the applicable copyright and contractual requirements. Researchers shall ensure that training or analysis data are lawfully accessible and usable. The permissibility of text and data mining under copyright law does not establish a general authorization to upload protected works, databases, examination papers, manuscripts, research data, or other protected content to external AI systems, in particular where such inputs may be used for training, product improvement, or other purposes of the provider.

(4) Purely AI-generated results, taken by themselves, generally do not enjoy copyright protection. The decisive factor remains the human creative contribution.


III. GOVERNANCE, RISK MANAGEMENT, AND INSTITUTIONAL PROCEDURES

§ 10 High-Risk AI Systems and Applications Requiring Approval

(1) AI systems that are to be classified as high-risk AI systems under the AI Regulation, or for which such classification appears likely, may be procured, developed, implemented, or used at PMU only after prior assessment and written approval under the Rules of Procedure of the AI-DB.

(2) This applies in particular to AI systems in the areas of education, employment, access, selection, assessment, monitoring, or profiling decisions, as well as to other systems with significant effects on the rights, opportunities, or legal positions of students, lecturers, researchers, staff members, or third parties.

(3) Before such systems are used, in particular the risk-law classification, any data protection impact assessments, fundamental rights impact assessments, requirements for human oversight, and other applicable documentation and approval steps shall be assessed and fulfilled.

(4) Prohibited AI practices within the meaning of the AI Regulation are prohibited at PMU.

(5) AI systems intended to be used for examination assessment, automated behavioral analysis, proctoring, admission, selection, personnel decisions, or comparable sensitive processes shall in any case be reported to the AI-DB in advance.

(6) Specific forms of use, such as AI-supported simultaneous interpretation, subtitling, or transcription, are governed by the applicable annexes or implementing provisions to this Policy; forms of use requiring approval or relevant to risk shall be submitted to the AI-DB in advance.


§ 11 Procurement, Development, and Use of External AI Systems

(1) The procurement, implementation, or material modification of AI systems and comparable digital applications at PMU shall take place in coordination with the responsible organizational units and in compliance with the requirements of the AI-DB.

(2) Before selecting or using external providers, the following in particular shall be assessed:

  • permissibility under data protection law;

  • information security;

  • contractual and licensing terms;

  • technical and organizational control options;

  • transparency, traceability, and risk appropriateness;

  • any notification, documentation, and register obligations.

(3) Non-approved external AI systems may be used for institutional purposes only insofar as this is permissible according to the nature, scope, and risk profile of the use, no personal, confidential, examination-related, clinical, or otherwise protected content is processed, and no conflicting requirements exist.


§ 12 Notification, Documentation, and Cooperation Obligations

(1) All organizational units shall notify the AI-DB of planned AI systems and AI projects before procurement, development, implementation, or material modification, insofar as provided for under the Rules of Procedure.

(2) The affected organizational units shall provide the AI-DB with the information required for assessment, documentation, register management, and compliance review in an appropriate form.

(3) The cooperation obligation includes, in particular, information on the purpose, context of use, affected groups of persons, data categories, system logic, risk profile, and intended protective measures.


§ 13 Research Exception and Transfer into Regular Operation

(1) AI systems developed or used exclusively for research purposes are subject to the regular operation and approval regime only to the extent legally provided for under the AI Regulation and the Rules of Procedure of the AI-DB.

(2) Such systems may not be transferred into regular operation, in particular into teaching, clinical practice, administration, or personnel-related procedures, without prior assessment and any required approval.


§ 14 Area-Specific Implementing Rules

(1) To further specify this Policy, area-specific implementing rules, annexes, or other implementation provisions may be issued for individual tasks and areas of application at PMU, insofar as this is indicated due to subject-specific characteristics, legal requirements, organizational needs, or increased risk situations.

(2) Area-specific implementing rules, annexes, or other implementation provisions may be considered in particular for studies and teaching, research, administration, and other sensitive or particularly regulation-sensitive contexts of AI system use. Within these areas, they may also regulate individual subareas, procedures, or use situations separately.

(3) Area-specific implementing rules, process documents, SOPs, annexes, or other implementation provisions shall be prepared or approved by the AI-DB with the involvement of the respective institutes, organizational units, stakeholders, subject areas, or faculties affected in substance. In doing so, subject-specific, data protection, examination law, employment law, quality assurance, and, where applicable, ethical aspects shall be appropriately taken into account.

(4) Area-specific implementing rules, annexes, or other implementation provisions shall be consistent with this Policy, the Rules of Procedure of the AI and Digitalization Board (AI-DB), and the applicable legal provisions. They may not conflict with this Policy.

(5) Area-specific implementing rules, annexes, or other implementation provisions shall be announced in an appropriate manner and reviewed regularly for currency, appropriateness, and legal compliance.


§ 15 AI Literacy and Training

(1) PMU offers appropriate measures to ensure the AI literacy of students and staff members within the meaning of the AI Regulation.

(2) Without prejudice to statutory, contractual, and other PMU-internal obligations, internal lecturers, researchers, staff members, and other internal users of AI systems are responsible for the appropriate, secure, and policy-compliant use of AI systems in their respective areas of responsibility. PMU’s institutional responsibility for appropriate organizational framework conditions remains unaffected. External lecturers and other external contributors shall be informed of the applicable PMU requirements by the respective program director, head of department, or a person delegated by the respective responsible leadership. Mandatory measures apply to external contributors only insofar as they have been contractually agreed, provided for in the engagement, or established as a condition for their work at PMU.

(3) The AI-DB shall prepare recommendations for training, information, and awareness-raising measures and shall coordinate them.


§ 16 Violations and Measures

(1) Violations of this Policy may have consequences in accordance with the applicable study-related, employment-related, service-related, organizational, or contractual requirements.

(2) If violations or significant risks are identified, measures may be ordered, including in particular restrictions on use, prohibitions, additional training, additional examinations, documentation requirements, or other appropriate measures.

(3) Responsibilities under the Rules of Procedure of the AI-DB, as well as other responsibilities of the Rectorate, the Board, or other organizational units, remain unaffected.


§ 17 Evaluation and Amendment

(1) This Policy shall be reviewed regularly and in any case in the event of material changes in the legal situation, organizational structure, or internal governance, and shall be amended as necessary.

(2) Area-specific implementing rules pursuant to § 14 shall be taken into account as part of this review.


§ 18 Entry into Force and Approval

(1) This Policy shall enter into force on July 1, 2026, after approval by the Rectorate of PMU in agreement with the Board of the Private Foundation as the legal entity responsible for PMU.

(2) Before approval, the final draft shall be submitted to the AI-DB for substantive review and recommendation. The Data Protection Officer, Legal Department, IT/Information Security, Quality Management, Central Study Coordination, the leadership team for Studies and Teaching, and Research/Research Services shall be involved insofar as they are affected in substance.

(3) The Policy, including its annexes, shall be announced internally at the university in an appropriate manner after approval.


Approved by the Rectorate of PMU and the Board of the Private Foundation as the legal entity responsible for PMU.

Salzburg, July 1, 2026

 


Annex 1 – AI-Supported Simultaneous Interpretation, Subtitling, and Transcription in Courses

1. Purpose and Scope

This Annex specifies the Policy on the Use of AI Systems at PMU with respect to the use of AI-supported simultaneous interpretation, subtitling, and transcription in in-person, hybrid, and online courses.

It applies to all courses, teaching formats, and other university events in which speech, audio, images, subtitles, or transcripts are processed, translated, transcribed, or reproduced by AI systems.


2. Permissibility of Use

The use of AI-supported simultaneous interpretation, subtitling, or transcription is permitted only if the system used has been institutionally approved and the requirements of the Policy and this Annex are complied with. Prior to approval, a threshold assessment shall be carried out by the Data Protection Officer pursuant to Articles 6 and/or 9 GDPR.

The use of non-approved systems is prohibited where personal data, confidential content, course recordings, audio or video data, transcripts, or comparable content are processed.


3. Supporting Function and Non-Binding Nature

AI-generated translations, subtitles, and transcripts serve exclusively to support comprehensibility, multilingual access, accessibility, and participation.

They do not replace:

  • the original statements of the lecturer;

  • official teaching materials;

  • professionally reviewed translations;

  • examination-relevant requirements;

  • binding orders or statements of PMU.

Appropriate notice shall be given regarding the potential susceptibility of AI-generated translations, subtitles, and transcripts to errors.


4. Information for Participants

Participants shall be informed clearly and comprehensibly before the start of the course about the use of the system.

The information shall include in particular:

  • the purpose of the use;

  • the system or provider used, where known;

  • the type of data processed;

  • an indication of whether audio, video, translation, or transcription data are stored;

  • a notice regarding the susceptibility of AI-generated results to errors;

  • contact information for data protection or other inquiries.


5. Principle of Live Processing

Processing shall be limited to what is necessary for live interpretation, subtitling, or transcription.

As a rule, audio, video, transcripts, or translations are not stored.

Deviations are permissible only if:

  • separate institutional approval has been granted;

  • a valid legal basis exists;

  • the affected persons have been informed transparently;

  • the purpose of storage, storage period, access authorizations, and deletion periods have been defined;

  • data protection and information security requirements are fulfilled.


6. No Use for Training, Analysis, or Profiling Purposes

Use of the processed content by providers or third parties for training, product improvement, analysis, profiling, or other secondary purposes shall be excluded contractually and through technical and organizational measures, unless a separate legal assessment, data protection safeguard, and institutional approval exist.


7. Protection of Special Categories of Data and Confidential Content

Special categories of personal data, in particular health data, identifiable patient data, confidential information, unpublished research data, and non-approved copyrighted content may not be entered into such systems.

The data protection, confidentiality, and secrecy obligations under the Policy remain unaffected.


8. External Providers

Where external providers are used, the following in particular shall be assessed and documented in advance:

  • permissibility under data protection law;

  • necessity of a data processing agreement;

  • technical and organizational measures;

  • storage locations and third-country transfers;

  • subprocessors;

  • deletion concept;

  • information security;

  • contractual and licensing terms;

  • exclusion of impermissible secondary use.


9. Quality Assurance

The responsible lecturer or organizational unit shall ensure that AI-generated translations, subtitles, and transcripts are not used without review as substantively binding.

In the case of substantively sensitive content, in particular medical, pharmaceutical, legal, ethical, or safety-relevant content, particular susceptibility to errors shall be indicated. Where necessary, professionally reviewed materials shall be provided.


10. Additional Requirements Imposed by the AI-DB

The AI-DB may define additional requirements for certain systems, courses, degree programs, or forms of use, in particular regarding:

  • transparency;

  • quality assurance;

  • accessibility;

  • data protection;

  • information security;

  • documentation;

  • approval;

  • deletion;

  • evaluation.