How AI enters campus, and what kind it is
AI rarely arrives through a clean procurement, and it is not one thing. Naming how it enters and what type it is sharpens the governance question, without abandoning the framework's technology-agnostic stance.
Six pathways AI enters
Each pathway slips past a different control. The governance move is to recognize which one you're looking at and apply the right-sized response, not to force everything through standalone procurement.
Procured standalone AI
You evaluate and buy a dedicated AI tool.
The moveRun it through the Tool Evaluation Matrix, procurement, and HECVAT before adoption.
Tool Evaluation MatrixEmbedded / activated features
A vendor switches AI on inside software you already own, Workday, Microsoft 365, Canvas, Zoom.
The moveAn AI feature-activation review: re-check the data-processing agreement, the training opt-out, and whether it re-tiers an already-approved system.
Homegrown / in-house
Your own people build it, RAG assistants, predictors, custom GPTs, research tools.
The moveA builder checklist: data rights, pre-deployment evaluation, model cards, human-in-the-loop, and monitoring.
Shadow / BYO-AI
Individuals use personal consumer accounts for university work, unsanctioned and invisible.
The moveSurface it without punishing it: offer a sanctioned alternative and plain acceptable-use guidance.
Policies & GuidelinesResearch-introduced
Faculty and grad students bring AI through grants, research computing, and collaborations.
The moveCoordinate with the IRB, research computing, and sponsored programs, while respecting academic freedom.
Shared governanceSupply-chain AI
A third party uses AI to deliver a service to you, an OPM, a transcription or marketing vendor.
The movePush AI terms into contracts and third-party risk review (HECVAT). Their AI is still your accountability.
AI Registry & DocsAI is not one thing
The framework governs by data, behavior, and risk, so the rules survive model churn. But different modalities raise different questions, and the type should inform a tool's risk tier.
Raises Bias and fairness, due process, and whether a flagged student can see and contest the score.
Raises Hallucination, IP and training-data provenance, academic integrity and disclosure, data leakage, prompt injection.
Raises Action boundaries, human oversight, auditability, and accountability when an agent acts on its own.
Raises Consent, privacy, surveillance harms, and civil-liberties and accessibility concerns.
Raises Physical safety, real-world consequences, and maintenance, governed more like facilities than software.
- Hallucination & accuracy, confident output that is simply wrong
- IP & provenance, what the model was trained on, and who owns the output
- Academic integrity & disclosure, when and how AI use must be declared
- Data leakage & confidentiality, sensitive data leaving approved systems
- Prompt injection & misuse, adversarial input that hijacks the system
- Deepfakes & misinformation, synthetic media and impersonation