探花视频

Mastering AI Risk: Governing Innovation Across the Modern Campus

By Brian Adair | By Jacob Graves |

September 22, 2026

Higher education institutions are moving quickly to adopt generative artificial intelligence (AI), and the numbers show it. A recent survey cited by found that 78% of surveyed education employees knew of colleagues using unauthorized AI tools. In comparison, just 31% said their institution had clear, well-documented AI policies. The gap between adoption and governance is where risk lives.

As AI capabilities embed themselves into everyday campus applications, from research platforms to student services, IT and security leaders face a defining question: how can institutions harness AI鈥檚 productivity gains while protecting sensitive data, meeting compliance obligations and maintaining institutional trust?

The Policy-Enforcement Gap

Many institutions have already published AI use policies for students, faculty, staff and research teams, reflecting a genuine commitment to transparency in the Public Sector. The challenge is not the absence of policy, but the absence of a reliable way to monitor and enforce it in real time. Signed acceptable use agreements help with after-the-fact accountability, but they do little to prevent risky behavior in the moment, and most users forget the details soon after signing.

Traditional network tools compound the problem: firewalls generally operate at the DNS layer, blocking known AI-related URLs, but they cannot keep pace with the six or seven new AI tools and embedded AI features that emerge industry-wide every day. Similarly, cloud access security brokers and network proxies struggle with encrypted traffic and lack the natural language understanding needed to evaluate what is being asked inside a prompt.

Closing this gap requires visibility into intent, not just destination. Institutions need the ability to:

  • Classify and inspect data before it leaves the organization, not after
  • Apply real-time coaching and enforcement during AI use, rather than relying on training alone
  • Maintain audit logs and evidence trails that satisfy compliance and public records requirements
  • Detect new and embedded AI tools as they appear, rather than relying on periodic manual review

Sensitive Data and Compliance Risk Across Campus Functions

AI risk on campus rarely resembles a traditional cyberattack. More often, it originates with well-intentioned users, students, faculty, researchers and staff, who share sensitive information with AI tools in pursuit of productivity. That information can include student records protected under the Family Educational Rights and Privacy Act (FERPA), health information governed by the Health Insurance Portability and Accountability Act (HIPAA), financial data subject to the Gramm-Leach-Bliley Act (GLBA) or research data tied to Department of War (DoW) grants and International Traffic in Arms Regulations (ITAR) requirements. A researcher working with federally funded, sensitive data, for example, may have no malicious intent but could inadvertently expose that data simply by using a free, consumer-grade AI account with no institutional oversight.

Compliance obligations extend further than most institutions initially plan for. State-level legislation addressing AI use is emerging rapidly, and many states already have rules pending that will affect public colleges and universities. Public records and Freedom of Information Act (FOIA) requests add another layer of complexity, as institutions must determine whether AI chat logs and prompt histories are discoverable, a question some cities have already confronted directly. Breach notification requirements are evolving as well, with several states now requiring notification to State auditors within a defined window, a category of incident that increasingly includes AI-related exposures rather than only traditional malware or ransomware events.

Governance at the Point of Interaction

SentinelOne, Modern Campus, blog, embedded image, 2026

Many institutions have instinctively restricted AI use outright, either by blocking specific tools or by limiting approved use to a small set of vetted applications such as Microsoft Copilot or Google Gemini. In practice, this approach often falls short. Devices today are capable enough that a user determined to bypass a block can simply photograph a screen with a personal phone, moving the activity into a channel with no visibility or controls at all. Even a fully 鈥渁pproved鈥 tool carries risk once it is connected to internal systems: because Copilot may have access to shared drives, for instance, any improperly secured documents across the organization become newly discoverable through a simple prompt.

The more effective strategy is to govern AI at the point of interaction, where the true risk originates. Rather than restricting which sites users can reach, institutions can apply controls to the prompts and data being exchanged once users arrive at an AI tool. This allows security teams to answer harder, more meaningful questions: what data is leaving the institution, where is it going and does the interaction align with policy? Establishing this kind of governance also allows institutions to give users real-time feedback in the moment, which research shared during the discussion suggests meaningfully improves behavior over time, particularly among users who are otherwise resistant to changing habits.

Shadow AI and Embedded/Agentic AI Expansion

AI adoption on campus is no longer confined to users deliberately seeking out a chatbot. Increasingly, AI capabilities are appearing inside applications that faculty, staff and students have relied on for years, often without warning. A platform used for a core function for a decade may introduce an AI assistant overnight, and institutions may have little advance notice of what that assistant is capable of or what compliance considerations it introduces. This dynamic, often described as shadow AI, extends beyond unauthorized standalone tools to include AI features quietly embedded within already-approved software.

Agentic AI adds a further layer of complexity. Where a single prompt once produced a single response, agentic tools can take dozens or hundreds of actions on a user鈥檚 behalf, reading email, browsing internal systems or interacting with other applications with minimal direct oversight. Institutions building their own AI applications, such as chatbots supporting prospective students or internal research tools, face a related risk: these applications can be manipulated into revealing information they were never intended to share, or into responding in ways that create legal exposure. Addressing this expanding surface area requires the ability to inventory both traditional and agentic AI use across campus, apply governance controls appropriate to each and maintain the audit trail needed to demonstrate compliance when questions arise.

Building a Path Forward

AI adoption across higher education is not slowing, and institutions that treat governance as a one-time policy exercise will consistently fall behind the pace of change. The path forward requires visibility into how AI is used, controls that act at the moment of interaction rather than after the fact, and audit capabilities that give compliance, legal, and security teams confidence when questions arise. Institutions that build this foundation position themselves to embrace AI鈥檚 productivity benefits without compromising the trust of students, faculty and the broader public they serve.

To explore these strategies in greater depth, including a live demonstration of how institutions can gain visibility and control over AI use across campus, watch SentinelOne and 探花视频鈥檚 webinar,

探花视频. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator鈥痜or our vendor partners, including SentinelOne, we deliver鈥solutions鈥痜or Geospatial, Cybersecurity, MultiCloud, DevSecOps, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Explore the 探花视频 Blog to learn more about the latest trends in Government technology markets and solutions, as well as 探花视频鈥檚 ecosystem of partner thought-leaders.


Related Articles