01AI Is an Institutional Governance Issue
Faculty, staff, students, vendors, and existing software may use AI for teaching, writing, coding, research, recruitment, analytics, advising, meeting notes, communications, budgeting, HR, accessibility, and customer service. Some use is intentionally adopted. Some arrives through features added to products the institution already owns. Some occurs informall
02Governance Structure, Decision Rights, and Risk Tiers
AI affects responsibilities that are distributed across the institution. A governance body should include the perspectives needed to evaluate academic, technical, legal, privacy, research, accessibility, workforce, and student impacts.
03Teaching, Learning, Academic Freedom, and Integrity
Institutional policy should establish ethical and legal boundaries without pretending that every discipline has the same learning objectives. Faculty need room to decide when AI supports or undermines learning, while students need coherent baseline expectations for privacy, disclosure, integrity, and high-risk use.
04Student AI Literacy and Policy Coherence
Students need to understand when AI is permitted, how to verify output, how to disclose meaningful use, how to protect data, and how to preserve the intellectual work they are expected to learn. A policy that only describes punishment does not create AI literacy.
05Research, Scholarship, and Intellectual Property
AI may affect literature discovery, coding, data analysis, image generation, manuscript drafting, grant development, peer review, lab operations, research administration, and scholarly communication. These uses raise issues of reproducibility, confidentiality, research integrity, authorship, disclosure, copyright, intellectual property, and sponsor requireme
06Data Governance, Privacy, and Security
Prompts can contain student records, employee information, research data, donor information, financial records, legal material, health information, intellectual property, or credentials. AI governance therefore depends on the institution's broader data-classification and security program.
07Procurement, Vendors, and Contract Risk
Institutions should not assume that a previously approved product remains equivalent after a vendor introduces generative AI, automated decision-making, new data flows, or model training. Material AI changes should trigger review proportional to risk.
08High-Impact Decisions and Human Oversight
AI can summarize applications, identify patterns, rank candidates, flag concerns, recommend interventions, draft evaluations, or predict outcomes. The ethical issue becomes more serious when the system materially influences decisions about a person's access, status, employment, finances, education, or rights.
09Workforce, Transparency, and Organizational Change
AI can change job tasks, staffing assumptions, professional identity, workload, evaluation, and expectations for productivity. EDUCAUSE's 2026 workforce research shows institutions are already developing work-related AI strategies and emphasizing upskilling and reskilling.
10Incident Response and Ongoing Oversight
An AI incident may involve exposed data, biased recommendations, fabricated citations, harmful student guidance, inaccurate mass communications, generated code vulnerabilities, deepfake impersonation, inappropriate automated decisions, research-integrity failures, or a vendor model change that alters behavior.
11Institutional AI Governance Readiness Review
Rate the institution in each area as Not Started, Emerging, Established, or Mature. Then identify evidence for the rating and one next action.