top of page

UCOP’s AI Buddy Program Tests Peer Learning Against Privacy Risk

The University of California Office of the President has introduced a voluntary AI Buddy Program, despite unresolved questions about privacy, accuracy, and staff time.

The program pairs experienced AI users with colleagues who want practical guidance. Participants can explore tools including ChatGPT, Claude, Google Gemini, and Microsoft Copilot through direct peer support.

That design makes the initiative more consequential than another workplace webinar. UCOP is testing whether trusted colleagues can turn general AI awareness into responsible daily practice without normalizing unsafe experimentation.

The tension sits between two credible needs. Staff need opportunities to understand systems that are already changing administrative work. They also handle institutional information that cannot safely enter every chatbot.

UCOP therefore faces a test shared by universities and other large employers. Access and enthusiasm can spread quickly, but reliable judgment develops more slowly.

UCOP Is Turning AI Training Into a Peer Relationship

The AI Buddy Program shifts workplace AI education from scheduled instruction toward voluntary, person-to-person learning.

UCOP spokesperson Stett Holbrook described the program as an internal, voluntary initiative for staff learning, according to the original report about its rollout. More experienced participants serve as buddies for colleagues who have less experience with AI tools.

The matching model recognizes a common weakness in formal technology training. A presentation can explain features, policies, and sample prompts, but it rarely follows an employee into a difficult workflow.

A peer can answer the question that appears after someone starts working. That question might concern a confusing output, a document that contains sensitive information, or whether AI belongs in the task at all.

Participants reportedly identify tools and subjects they want to explore during registration. Possible areas include AI for teaching and learning, output evaluation, and fact-checking.

Those choices matter because “AI literacy” covers several distinct abilities. Writing an effective prompt differs from evaluating a citation, protecting personal information, or deciding whether automation is appropriate.

The program also appears designed to accommodate several major platforms. That approach reflects the reality that staff members encounter different systems through university and personal accounts.

However, platform variety complicates training. Each service has different contracts, data controls, retention practices, integrations, and approved uses.

UCOP’s own software catalog illustrates this distinction. Its ChatGPT guidance says university business must use ChatGPT EDU, which is approved for information through UC’s P3 classification.

That approval does not make every prompt appropriate. Employees must still understand the data involved, the purpose of processing it, and the university rules governing the task.

Microsoft’s products create another layer of complexity. Copilot Chat, Microsoft 365 Copilot, and Copilot Studio offer different connections and capabilities, even though employees may call all three “Copilot.”

UCOP says Microsoft 365 Copilot requires manager approval. Copilot Studio can create specialized conversational agents connected to organizational systems and documents.

A buddy must therefore do more than demonstrate a clever prompt. Effective guidance must connect each workflow to the right account, approved platform, and information classification.

The initiative also asks interested employees to consult their supervisors before participating. That detail prevents a nominally voluntary learning activity from becoming invisible labor.

If AI learning happens outside normal responsibilities, participation will favor employees with flexible schedules. It can also place an unrecognized support burden on experienced buddies.

Manager involvement can protect time for learning. It can also help teams choose use cases tied to real work instead of experimenting without a defined outcome.

The first important change is therefore organizational, not technical. UCOP is creating a human support layer between enterprise AI access and day-to-day adoption.

Why UCOP Needs More Than Tool Access

UCOP’s challenge is no longer acquiring AI tools; it is helping staff use them consistently, safely, and for defensible purposes.

UC has already built much of the foundation beneath the buddy initiative. A systemwide OpenAI agreement took effect in June 2024 and covers ChatGPT Enterprise and EDU.

The UC agreement includes data privacy terms, a supplier risk assessment, and confidentiality protections for customer prompts and responses. It also establishes a shared procurement framework for participating campuses.

UCOP subsequently expanded employee access to ChatGPT and Microsoft Copilot. Its 2025 technology report says more than 1,000 licenses had been deployed, including 700 ChatGPT licenses and 300 Copilot licenses.

The report also records 230,000 prompts submitted since May 2025. It says 800 staff members used AI tools between June and October 2025.

Those figures show activity, but activity is not the same as value. Prompt counts cannot reveal whether an output was correct, whether a task improved, or whether staff avoided inappropriate data.

UCOP’s report says the organization is moving from foundation to adoption and impact. The AI Buddy Program belongs at the difficult center of that progression.

Buying enterprise accounts addresses several important risks. It can provide contractual controls, managed access, and clearer support than personal consumer accounts.

Yet procurement cannot determine whether an employee recognizes sensitive material inside a draft. It also cannot ensure that someone verifies an invented citation or notices subtle bias.

UC’s AI Council has treated education as a governance requirement, not an optional supplement. Its Knowledge, Skills, and Awareness Subcommittee is responsible for sustaining training, engagement, and best practices.

In 2026, the council also launched an AI literacy webinar series for faculty and staff. Sessions cover core concepts, practical use, ethical responsibilities, and organizational resources.

Webinars offer consistency and scale. A buddy program offers context, repetition, and a lower-friction place to admit uncertainty.

That combination resembles layered security training. Central guidance establishes the rules, while local support helps people apply them to situations that formal materials cannot anticipate.

Peer learning can also expose differences between written policy and actual work. If many staff members ask the same question, the problem may require clearer guidance or a better approved tool.

That feedback is especially valuable inside a complex institution. UCOP serves functions that include procurement, legal affairs, academic policy, finance, communications, and systemwide administration.

One universal prompt guide cannot cover those environments equally well. The risks surrounding a public press release differ from those surrounding personnel, legal, health, or student information.

The program can succeed if it turns recurring questions into institutional knowledge. Useful examples might become approved templates, training cases, or updates to the AI resource hub.

Without that feedback loop, the initiative risks becoming an informal help network. Employees would receive inconsistent answers, while central teams would learn little about adoption barriers.

Organizations exploring similar programs should treat shared guidance as part of a wider AI workflow. People need reusable processes, not isolated prompt tricks.

UCOP’s pressure comes from its own progress. Once enterprise tools reach hundreds of employees, informal experimentation becomes an operating reality that policy alone cannot manage.

Peer Learning Makes AI Approachable, but It Also Spreads Mistakes

The program’s greatest strength and its central weakness come from the same source: employees are learning from people they already trust.

A colleague often understands local language, constraints, and recurring tasks better than an outside instructor. That familiarity can make guidance immediately useful.

An experienced staff member can show how to summarize a public document, restructure a draft, generate meeting questions, or compare nonconfidential alternatives. The learner can then test the method on relevant work.

This approach also reduces the embarrassment surrounding basic questions. Employees may hesitate to ask a large training group why a chatbot produced inconsistent answers or how prompts are stored.

A buddy relationship creates room for those questions. It can help participants learn that uncertainty is normal and verification is part of responsible use.

The model also recognizes that AI adoption is social. People watch how respected colleagues use a tool before deciding whether it belongs in their own work.

That mechanism can promote cautious habits when buddies model restraint. They can explain why they removed sensitive details, chose an approved account, or rejected an answer.

The same mechanism can spread bad practice just as efficiently. A confident employee can misunderstand data rules, repeat an unreliable technique, or present anecdotal success as established evidence.

Experience with an AI product does not automatically make someone qualified to advise others. Frequent users may be skilled at generating outputs while remaining weak at source verification or privacy analysis.

UCOP therefore needs a clear definition of the buddy role. Buddies should help colleagues learn, but they should not become unofficial privacy officers, lawyers, or security reviewers.

They also need an escalation path. Questions involving protected data, procurement, accessibility, legal interpretation, or automated decisions should move to the responsible office.

A useful model would distinguish three categories of activity.

First, low-risk exploration can include public information, invented examples, and drafts without confidential details. Buddies can guide these activities directly.

Second, controlled work can involve approved enterprise tools and information permitted under specific university terms. Participants still need documented rules and human review.

Third, high-risk work should require specialist approval or remain outside the program. This category includes consequential decisions and information whose exposure would create significant harm.

UC’s existing governance materials support that structure. The university warns about accidental disclosure, discrimination, due process, intellectual property, and policy violations.

The UC governance framework says AI applications should receive the same caution and compliance analysis as other uses of institutional data.

That principle prevents a common mistake. A conversational interface can feel less formal than an enterprise database, even when both process sensitive information.

The social setting introduces another risk: accidental disclosure between colleagues. A learner might share a prompt, source document, or output that the buddy was not authorized to see.

Program guidance should therefore cover peer-to-peer disclosure, not only data sent to a vendor. Participants need sanitized examples whenever access rights differ.

The buddy relationship must also remain voluntary in practice. An employee should not feel pressured to disclose uncertainty, performance concerns, or tool usage to a colleague.

Matching can create subtle power dynamics when participants have different seniority, employment classifications, or reporting relationships. A safe program needs a confidential way to request reassignment.

Accessibility requires similar care. Some employees may benefit from AI-assisted drafting, summarization, or speech tools, while others may encounter inaccessible interfaces or unreliable outputs.

A buddy can help someone explore options, but accessibility decisions should not depend on informal goodwill. Approved accommodations and specialist support must remain available.

These controls do not undermine peer learning. They define where peer learning is useful and where institutional responsibility must take over.

Privacy Depends on the Prompt, the Account, and the Data

An enterprise license reduces vendor risk, but privacy still depends on what employees submit and what they do with the response.

UC operates with multiple information sensitivity levels. Public material sits at one end, while highly restricted health, financial, legal, and identity information sits at the other.

A staff member may combine several levels without noticing. An ordinary document can include a student identifier, an internal strategy, or comments about employee performance.

That makes data classification a practical skill. Participants must learn to inspect a task before selecting a tool or composing a prompt.

UC’s systemwide guidance has repeatedly emphasized controlled environments. Licensed services generally provide stronger institutional protections than open consumer accounts.

However, “enterprise” is not a universal permission label. Each product has approved uses, contract terms, technical configurations, and data boundaries.

UCOP says its approved ChatGPT EDU environment can handle information through P3. That statement still requires employees to know whether their material falls within P3.

UC San Diego’s detailed assistant guidelines demonstrate how complicated real-world use becomes. They address consent, meeting capture, approved storage, sensitive discussions, and public-record obligations.

The guidelines prohibit AI capture in certain administrative meetings involving P4 data. Examples include health, financial, loan, and undocumented-student information.

They also restrict some P3 discussions, including attorney-client communications, performance deliberations, and information involving reproductive or gender-affirming care.

Those examples show why general warnings are insufficient. “Do not enter confidential data” leaves employees to interpret both confidentiality and the boundaries of a conversation.

Meeting assistants create particular problems because they can collect every speaker’s contribution. Participants may not know which service is recording, where the transcript goes, or how long it remains available.

A buddy should never resolve that uncertainty by intuition. The safe response is to consult campus privacy, security, records, or legal guidance before enabling capture.

Accuracy presents a related governance concern. A chatbot can produce fluent text that includes fabricated facts, citations, or policy interpretations.

Fact-checking must involve external evidence, not another prompt asking whether the first response was correct. The reviewer needs the original document or an authoritative source.

Staff should also separate brainstorming from decision-making. AI can generate options, but a person with appropriate responsibility must evaluate those options against policy and evidence.

This distinction becomes critical when an output affects access, employment, academic standing, procurement, or resource allocation. A polished recommendation can hide weak assumptions.

UC’s earlier AI working group identified fairness, transparency, accountability, privacy, and safety as systemwide concerns. Those principles apply even when staff use a general chatbot.

The buddy program can make them concrete through short scenarios. One scenario might ask whether a public report can be summarized in ChatGPT EDU.

Another could involve a spreadsheet containing employee information. Participants would identify the data class, approved environment, access rights, and necessary human checks before proceeding.

Scenario-based learning can also reveal when AI adds little value. Sometimes removing sensitive details takes longer than completing the original task.

That is a legitimate outcome. Responsible adoption includes recognizing when not to use an AI system.

The program’s credibility will depend on whether it rewards that restraint. If every pairing is expected to produce a new AI workflow, participants may force unsuitable tasks into the technology.

UCOP should instead recognize sound decisions, including cases where teams narrow a use, choose a different system, or avoid AI entirely.

Three Signals Will Show Whether the Program Works

The next test is whether UCOP can measure better judgment and useful work without turning voluntary learning into employee surveillance.

The first signal is participation quality. Enrollment totals matter less than whether pairings remain active and serve employees with different roles and starting skill levels.

UCOP should examine whether participants meet, complete agreed learning goals, and report greater confidence with specific tasks. It should also track whether buddies receive protected time.

A high registration count followed by inactive pairings would suggest that staff lacked time, useful matches, or managerial support. That outcome would weaken the peer-learning model.

Sustained participation would support a different conclusion. It would show that employees find value in contextual guidance beyond formal courses and documentation.

The second signal is the quality of use cases produced. Strong examples should identify the task, approved tool, permitted data, verification method, human owner, and measured result.

UCOP’s 2025 report already supplies an adoption baseline. It records licenses, users, prompts, and events, but the buddy program needs evidence closer to outcomes.

Useful measures might include reduced processing time, fewer revisions, improved accessibility checks, or faster retrieval of approved public information. Each claim requires a defined comparison.

UC Tech News has described one promising model. A cross-campus team configured a GPT to perform an initial review against WCAG 2.1 and UC brand guidance.

The accessibility reviewer handles a tedious first pass and provides suggested changes. Human owners still need to validate its findings and complete the work.

That kind of bounded workflow is more informative than a broad claim about productivity. It specifies what the system reviews, which standards apply, and where human judgment remains.

The third signal is the program’s safety feedback. UCOP should monitor recurring questions, near misses, escalation requests, and confusing policy areas without collecting unnecessary prompt content.

An increase in questions would not automatically mean the program created more risk. It might show that employees are recognizing issues they previously missed.

The important measure is whether those questions reach the right experts. Program leaders should also document how answers become updated guidance for future participants.

Privacy-preserving measurement will require restraint. UCOP does not need a complete archive of employee prompts to understand which topics generate uncertainty.

Aggregated categories can reveal whether staff struggle with data classification, hallucinations, meeting capture, copyright, accessibility, or account selection.

The next one to three months should show whether peer learning becomes part of UCOP’s broader AI governance structure. Three developments deserve attention.

First, UCOP should publish or internally circulate clearer buddy standards. These should define role boundaries, escalation routes, safe exercises, and supervisor expectations.

Second, the organization should identify reusable workflows with documented human review. That would demonstrate movement from casual experimentation toward accountable operational practice.

Third, program feedback should produce visible policy or training updates. That result would prove that learning moves in both directions, from central experts to staff and back.

Other employers should resist copying the name without copying the controls. A buddy program succeeds when it combines trust, practical work, protected time, and clear institutional accountability.

Employees considering a similar initiative should begin with one question: Can every participant explain which data, account, evidence, and human reviewer a proposed workflow requires?

If the answer becomes consistently clear, UCOP will have created more than another adoption campaign. It will have built a repeatable way for staff to learn together while recognizing where AI should stop.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

​Add Search Bar in Your Brain

Just Ask remio

Remember Everything

Organize Nothing

bottom of page