Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Technology Policy topic
No spam. Unsubscribe anytime.
CT State committee reviews rewritten security policy and draft generative-AI guidance
Summary
Committee Chair Cherry Yang presided over the Connecticut State Colleges and Universities committee meeting on Feb. 26, 2025, where Interim Chief Information Officer Michael Mondrain presented updates on two systemwide policy efforts: a rewritten security policy and a draft generative-artificial-intelligence policy.
Get email alerts on the Technology Policy topic
No spam. Unsubscribe anytime.
Committee Chair Cherry Yang presided over the Connecticut State Colleges and Universities committee meeting on Feb. 26, 2025, where Interim Chief Information Officer Michael Mondrain presented updates on two systemwide policy efforts: a rewritten security policy and a draft generative-artificial-intelligence (AI) policy.
Mondrain told the Regents the security policy rewrite began from a determination that the prior text was largely “unimplementable” and “extremely difficult to understand.” He said the rewrite was intended to be written “in plain language” and to be actionable, explaining, “These are the things you can do. These are the things you can't do.” He said the new draft is less NIST-centric and less of an auditing document and that CIOs across the system have indicated the draft is “much more understandable.”
The interim CIO said the security policy is in the institutional review process and that he expects colleges’ academic senates to weigh in. He described the near-term plan as another draft round to incorporate senate feedback, followed by a broader public comment period and then routing the policy to this committee and the full board for ratification. Mondrain said he is aiming to complete that timeline “by the end of this fiscal year” unless substantial public comments require additional revisions.
On the generative-AI policy, Mondrain said that draft grew out of security concerns—particularly the risk that users might submit confidential data to external AI services—but that it has broadened to address academic and disclosure issues. He noted existing obligations under student-privacy rules and referenced the Family Educational Rights and Privacy Act (FERPA). He said the draft includes placeholders and sections that need additional clarity from the academic side of the house and that the policy’s goal is not to ban AI but to clarify “what people can and shouldn't do with respect to AI” and “what their obligations are, what the risks are, and that they can… use it.”
Regents and committee members urged clear examples, standards and guidelines to accompany the AI policy. One member said practical examples showing “how it can be used” will help faculty and staff adopt the guidance. Mondrain outlined a three-tier approach—policy (board-ratified), standards (detailed, mandatory to meet policy), and guidelines (non-mandatory examples/tools)—and said standards and guidelines would be developed to make the policy implementable at campus level.
Committee members reported they had received the drafts through the board Teams channel; Mondrain said he would forward the Feb. 26 draft to the committee. Walter Schwartz, identified in the meeting as “the CIO from Southern,” joined an academic-senate briefing and provided supportive feedback that the security rewrite moved closer to best practices, Mondrain said. The committee asked that the academic senates’ feedback be used to shape further drafts before public distribution.
After discussing timing and the possibility of broader informational sessions about AI use across campuses, the committee moved into executive session under Connecticut General Statute 1-200-6(c). The open portion of the meeting concluded with the chair stating that any votes listed for executive session would be taken there and that no further committee action would follow the closed session.
Votes at a glance: The public portion of the meeting recorded procedural motions (agenda adoption and approval of minutes) and a motion to move into executive session; each motion was adopted by voice vote with no roll-call tally recorded in the public transcript.
Ending: The live stream was stopped and the committee continued in executive session with Chief Financial Officer Blanchard and Interim CIO Michael Mondrain invited to join.

