Concept

How AI enters campus, and what kind it is

AI rarely arrives through a clean procurement, and it is not one thing. Naming how it enters and what type it is sharpens the governance question, without abandoning the framework's technology-agnostic stance.

Six pathways AI enters

Each pathway slips past a different control. The governance move is to recognize which one you're looking at and apply the right-sized response, not to force everything through standalone procurement.

Procured standalone AI

You evaluate and buy a dedicated AI tool.

The moveRun it through the Tool Evaluation Matrix, procurement, and HECVAT before adoption.

Tool Evaluation Matrix

Embedded / activated features

A vendor switches AI on inside software you already own, Workday, Microsoft 365, Canvas, Zoom.

The moveAn AI feature-activation review: re-check the data-processing agreement, the training opt-out, and whether it re-tiers an already-approved system.

Homegrown / in-house

Your own people build it, RAG assistants, predictors, custom GPTs, research tools.

The moveA builder checklist: data rights, pre-deployment evaluation, model cards, human-in-the-loop, and monitoring.

Shadow / BYO-AI

Individuals use personal consumer accounts for university work, unsanctioned and invisible.

The moveSurface it without punishing it: offer a sanctioned alternative and plain acceptable-use guidance.

Policies & Guidelines

Research-introduced

Faculty and grad students bring AI through grants, research computing, and collaborations.

The moveCoordinate with the IRB, research computing, and sponsored programs, while respecting academic freedom.

Shared governance

Supply-chain AI

A third party uses AI to deliver a service to you, an OPM, a transcription or marketing vendor.

The movePush AI terms into contracts and third-party risk review (HECVAT). Their AI is still your accountability.

AI Registry & Docs

AI is not one thing

The framework governs by data, behavior, and risk, so the rules survive model churn. But different modalities raise different questions, and the type should inform a tool's risk tier.

Predictive / ML analytics
Early-alert, admissions, risk scoring.

Raises Bias and fairness, due process, and whether a flagged student can see and contest the score.

Generative AI
LLMs, chatbots, content and code generation.

Raises Hallucination, IP and training-data provenance, academic integrity and disclosure, data leakage, prompt injection.

Agentic AI
Autonomous agents that take actions, not just answer.

Raises Action boundaries, human oversight, auditability, and accountability when an agent acts on its own.

Computer vision / biometrics
Remote proctoring, facial recognition, surveillance.

Raises Consent, privacy, surveillance harms, and civil-liberties and accessibility concerns.

Embodied / physical systems
Smart buildings, delivery robots, lab automation, IoT sensors.

Raises Physical safety, real-world consequences, and maintenance, governed more like facilities than software.

Generative AI, the additional considerations
  • Hallucination & accuracy, confident output that is simply wrong
  • IP & provenance, what the model was trained on, and who owns the output
  • Academic integrity & disclosure, when and how AI use must be declared
  • Data leakage & confidentiality, sensitive data leaving approved systems
  • Prompt injection & misuse, adversarial input that hijacks the system
  • Deepfakes & misinformation, synthetic media and impersonation