Chat with us, powered by LiveChat

Protecting Privacy Within Civil Rights Investigations in the Age of AI

Published on: August 12, 2026

An ATIXA Tip of the Week by Daniel C. Swinton, J.D., Ed.D.

Over the past few months, we have seen an alarming trend of college and school civil rights offices uploading resolution process materials, including confidential, private, and copyrighted content, into generative artificial intelligence (AI) platforms, including large language models (LLMs) like ChatGPT. In some cases, the consequences have been serious. In others, we worry that individuals may never realize the risks they are taking.

Consider these scenarios:

  • A Title IX Coordinator enters an investigation report into an AI platform to help structure feedback on the report. The Coordinator then does not review the AI’s response.
  • A decision-maker uploads an investigation report into an AI platform to draft an outcome letter.
  • An investigator uploads all relevant evidence into an AI platform, then copies the AI-generated summary into their report with minimal edits.
  • A Title IX Coordinator uploads police reports, a student’s disciplinary history, and the NABITA Risk Rubric into an AI platform to assess whether an emergency removal is warranted.
  • An institution-appointed advisor uploads an investigation report into an AI platform to draft hearing questions.

Do any of these sound familiar? We hope not. We also hope that each one gives you pause.

AI in Civil Rights Work

As AI tools become more widespread, they are increasingly intersecting with civil rights-related work at colleges and schools. As a field, we must follow strict guidelines around the use of generative AI with resolution process materials, including interview notes and transcripts, investigation records, hearing and decision-making records, outcome letters, and appeals. We also need to engage in due diligence to prevent parties, parents, and advisors from uploading sensitive consent to AI.

Generative AI systems are not fully transparent about how they retain, learn from, or reuse input data, even when the models are set to not “learn” from the uploaded data. The last thing anyone wants is for sensitive, private, confidential, or privileged information to enter a network the institution does not fully control. As the scenarios above illustrate, resolution process materials contain highly sensitive information about students, employees, and third parties. Entering this information into AI tools, even those operating within your institution, can potentially expose everything contained in those materials.

“Okay, but we redact personally identifiable information from work product before we upload it,” you say. Well, that’s better than violating FERPA, which is what you’d be doing if you uploaded a student’s records without redaction (and all civil rights complaint files involving students are protected by FERPA).

Beware of the assumptions inherent in that practice (and of spotty redaction practices, which are common). You may think that de-identifying a record may preserve its privacy or confidentiality, and with current AI technology, that is likely the case. But, AI is advancing so quickly that we can’t know how long it will be before Claude (and the like) can take your anonymous facts and connect them to the identity of those involved. We suspect it won’t be long at all, and then you’ll have disclosed information that does real harm, even if you don’t intend for those dots to be connected.

This creates a significant risk that sensitive content could be disclosed to, reused by, or accessed by unintended parties. Once uploaded, information may be difficult or impossible to remove. The consequences of that could include violating FERPA, destroying legal privilege, and/or breaching the trust placed in us to protect privacy.

Privacy is not the only concern. Title IX and other civil rights investigations require individualized human judgment based on the full record. AI-generated summaries may omit context, mischaracterize testimony, or fabricate information entirely. Believe us, we’ve tested it. It’s not even close to there yet, so is it really saving you time or being helpful? It can summarize interviews, sure, but when it comes to analysis, it’s only hitting about a third of what a well-trained human can achieve.

Best Practices for AI Use

Institutional policies should address AI use by employees, as well as parties, parents, advisors, and other participants in the resolution process.

For Institutions and Practitioners:

  • Do not upload resolution process materials into public or unapproved AI tools. This includes investigation reports, interview transcripts, evidence, notices, correspondence, hearing materials, and other information shared as part of the resolution process. Even redaction isn’t safe.
  • Even institutionally-approved enterprise AI tools may not be safeguarded for sensitive information and should not be considered private or confidential.
  • Develop a clear and well-defined internal policy regarding when, how, and in what capacity AI may be used in your work. Involve legal counsel and Information Technology in developing these policies.
  • Require written authorization before using AI to summarize, analyze, reproduce, translate, or modify investigation materials.
  • Train all investigators, decision-makers, appeal officers, deputy coordinators, and other personnel on institutional AI use policies and the importance of maintaining privacy and confidentiality of resolution process-related information.
  • Use AI (if at all) to support, not replace, professional judgment. Investigators, decision-makers, and other practitioners remain responsible for reviewing the underlying information, evaluating context and credibility, and making individualized determinations based on the complete record. Civil rights complaints are highly nuanced, and AI isn’t… yet.
  • If you must use AI, use it wisely, and never assume its output is accurate. Review, verify, and proofread everything before using it. Always independently verify AI-generated content against the complete record.
  • Document approved AI use when appropriate. Consider whether and how the use of AI in a resolution process should be documented as part of the internal case file.
  • Be aware that removing names or attempting to anonymize materials does not eliminate obligations or risks.
  • If you use outside vendors, law firms, or colleagues from other schools and campuses, ensure they are aware of your policy and respect your AI use boundaries.

For Parties, Parents, Advisors, and Other Participants:

  • Add AI-specific language to advisor agreements, nondisclosure agreements, notices, and other process documents. Warn that uploading materials may compromise privacy, create additional copies, publicize allegations, and/or violate institutional policy.
  • Discuss AI use with the parties involved and strongly advise them against entering any resolution process information into AI tools, even if names are removed or reports are “anonymized.”
  • Review institutional policies. Unauthorized use of AI may already be a policy violation. If current policies do not adequately address AI use by those involved in the resolution process, consider whether additional guidance or restrictions are needed.
  • Anticipate that parties may use AI to draft complaints, respond to reports, prepare for hearings, draft appeals, and otherwise participate in the resolution process, recognizing that AI use is now part of the reality of conducting Title IX and other civil rights investigations. Clearly define permitted and prohibited uses, including using AI as an aid versus uploading resolution process materials into it.

Prepare for Two Sides of Technology’s Impact on Civil Rights Work

Learn to use AI and emerging technologies responsibly in ATIXA’s Leveraging Technology in Civil Rights Investigations Workshop, and how to respond effectively to misconduct involving digital platforms and AI in ATIXA’s Addressing Technology-Facilitated Sexual Misconduct Workshop.