Pillar 3Governance Produces: Policy or Guidance Draft
AI Policies & Guidelines
Translate values into operating rules that survive the next model release.
Aligns withNIST · GovernFERPAEU AI ActProcurement & data-classification policy
The idea
Policies and guidelines are the point at which principles become enforceable. The word “policy” actually covers a family of instruments that are frequently conflated but carry very different binding force, from binding policies and measurable standards, through advisory guidelines, to enabling and governance mechanisms (the page below lays them out). Selecting the wrong instrument is itself a failure: a rigid policy where guidance is appropriate constrains practice unnecessarily, while guidance where a binding rule is required leaves a gap. The task is to match the instrument to the decision, and to let each move at its own speed.
A common error at this stage is to write policy around a specific current product. This pillar is operationalized through audience-specific acceptable-use guidance keyed to the institution's data-classification levels; a campus-wide course-expectations framework so that every syllabus states its AI rules; and lifecycle mechanisms (review cycles, exception paths, and version control) that allow rules to remain valid as products are discontinued and replaced. Rules written at the level of behavior, data, and risk remain applicable longer than the products they govern.
Critically, most institutions are not starting from a blank page, and the right response depends on what kind of question AI raises. Where AI is simply a new input to a process that already has rules, procurement and vendor review, data classification and handling, records retention, information security, the move is to amend and extend those existing policies rather than write a separate AI version that duplicates and eventually contradicts them. Where AI raises genuinely new questions that no current policy answers, disclosure of AI-generated work, academic-integrity expectations, when a human must stay in the loop on an AI-assisted decision, accountability when one goes wrong, the institution does need new, AI-specific guidance, because there is no existing document to fold it into. The discipline is matching the response to the question: extend what already governs the operational and risk side, and author only what is genuinely new. Done this way, the rules inherit the authority and the owners of the policies people already follow, and the institution avoids both the contradictions of a parallel rulebook and the silence of having no answer at all.
Why it matters
Policy is the institution's answer to 'am I allowed to do this?' The question every faculty member, student, and staffer is already asking. Answered well, it removes the paralysis and the shadow AI that fill the vacuum; answered badly, or not at all, people either freeze or improvise, and the institution carries the risk either way.
How you can tell
When it's working
Acceptable-use guidance is published, audience-specific, and keyed to data-classification levels.
A campus framework requires every syllabus to state its AI expectations in aligned language.
Policies are written around behavior, data, and risk, not specific product names.
AI is folded into existing security, privacy, procurement, and records policies wherever it's just a new input to a process those already govern.
Policy is brought through shared governance and ratified by the bodies that hold legitimacy (senate, councils), not issued top-down.
New, AI-specific guidance is written only for the questions no existing policy answers, disclosure, academic integrity, human-in-the-loop, accountability.
There are defined review cycles, an exception path, and version control.
When it's missing
No AI-specific guidance exists; people apply generic IT policy that doesn't answer their questions.
Every course sets contradictory unwritten rules and students navigate by guesswork.
Policy names a specific product that is later discontinued, stranding the rule.
Guidance exists but most faculty can't find it, so functionally it doesn't.
A parallel AI rulebook is written from scratch, duplicating (and sometimes contradicting) the security, privacy, and procurement policies already in force.
The reverse failure: AI is treated as purely an extension of existing policy, leaving the genuinely new questions (disclosure, integrity, accountability) with no answer at all.
This is where the pillar stops being a principle and becomes work. Each practice below is something you can build, assign, and evidence, with a concrete first move, an owner, and what proof looks like. Move one practice up one level at a time.
1
AI acceptable-use guidance
Practical, audience-specific rules for AI use with institutional data and systems.
1Guidance exists somewhere, but the people it affects can't find it, a communication gap mistaken for a policy gap.
3A single front door (site or portal) indexes all AI guidance; major changes are announced.
5Findability and comprehension are tested with real users; support channels answer questions within defined times.
Next moves
Build one campus AI front door that indexes every policy, guideline, and approved tool.
Test the five-minute findability standard with actual students, faculty, and staff.
Announce every material change through channels each audience actually reads.
Who owns it
Communications · CIO
Evidence it exists
AI front-door page
Findability test results
Change-announcement log
In practice
Worked example
A policy that outlives the tool
An institution writes its AI policy around a single named chatbot. Eighteen months later the product is discontinued and three successors exist; the policy is suddenly meaningless. Rebuilt under this pillar, the policy instead governs by data classification and behavior ('no Level-3 student data in any unapproved external AI service') with an exception path and an annual review on the governance calendar. When the next tool arrives, nothing needs rewriting: it is simply classified and slotted into rules that already exist.
Watch for
Tool-specific rules that rot at the speed of the vendor market.
Publishing one long legal document instead of short, audience-specific versions people will actually read.
No exception path, so the policy is either ignored or routed around.
Building a freestanding AI policy that ignores the security, privacy, and procurement rules already on the books, creating overlap, contradiction, and an orphaned document no office owns.
Principles for durable policy
Before drafting anything, adopt the stance that keeps AI rules useful as the technology shifts. Two moves matter most: build on the policy you already have, and govern technology-neutrally so the rules outlive any single tool.
Build on what you already have
Most institutions are not starting from a blank page. Where AI is just a new input to a process that already has rules, extend the existing policy, security, privacy, procurement, records, academic integrity, rather than writing a parallel AI rulebook that duplicates and eventually contradicts it.
DoAmend the policy that already governs the process.
NotStand up a separate AI policy for a question existing policy already answers.
Govern the behavior, not the product
Write around data, behavior, and risk, never a single tool or vendor. Use durable language such as “AI and emerging technologies” so the policy survives model churn and the next product cycle. A policy built around one named tool is meaningless the moment that tool is renamed, replaced, or discontinued.
DoFrame rules by data sensitivity, behavior, and risk tier.
NotName specific products or vendors in the binding text.
Right-size the carve-outs
Technology-neutral does not mean one-size-fits-all. Some capabilities raise questions general language can't cover, agentic / autonomous AI above all (action boundaries, human-in-the-loop, auditability, accountability when it acts on its own). Add targeted provisions for those, without fragmenting the rest of the policy.
DoAdd focused provisions where a capability genuinely demands them.
NotLet one high-risk capability force a separate rulebook for everything.
Write only the new, and build in renewal
Reserve new, AI-specific guidance for the genuinely new questions no existing policy answers, disclosure, integrity, human oversight, accountability. Pair every policy with a named owner, a review cadence, and an exception path so it adapts as the technology shifts instead of rotting on the shelf.
DoGive each policy an owner, a review cycle, and an exception path.
NotTreat AI as purely an extension and leave the new questions unanswered.
Policies and guidelines are not the same thing
“Policy” is shorthand for five different instruments, and they carry different levels of compliance. A binding, enforced policy is not the same as an advisory guideline, and treating them alike either over-controls low-risk use or under-protects high-risk use. Naming the type sets the right expectation, and lets each move at its own speed: binding policy changes slowly through shared governance, while guidelines and enablement adapt quickly as the technology does.
Before any of these, the instruments answer to a layer above them
Laws & regulationsBinding floor
Federal (FERPA, HIPAA, ADA / Section 508), state (e.g., Colorado AI Act, NYC Local Law 144), and extraterritorial (the EU AI Act, if you enroll EU students or operate there). Policy can exceed these but never fall below them.
Recognized standards & frameworksAdopted by choice
NIST AI RMF, ISO/IEC 42001, OECD AI Principles. Voluntary references, not binding until your institution adopts them, then they flow into your own standards.
Mission, values & principlesThe internal “why”
Pillars 1 and 2: the institutional purpose and commitments every instrument has to serve.
Laws are not one of the five instruments below, they sit above them as the binding floor. Institutional policy translates the law into operating rules, which is also why this pillar says to amend existing security, privacy, and procurement policy: those already encode the legal obligations. Compliance is operated in Pillar 4, Governance & Risk.
Policies
Binding requirements, with real enforcement behind them.
BindingMust comply
SlowChange deliberately, through shared governance.
Standards
The specific, measurable requirements that make a policy testable. Internal standards are binding once adopted; external ones (NIST, ISO) are references until you adopt them.
Binding once adoptedMust comply
MediumUpdated as practice and technology settle.
Guidelines
Advisory best practices and recommended approaches, not mandates.
AdvisoryShould follow
FastAdapt quickly as tools evolve.
Enablement mechanisms
Innovation support: sandboxes, approved-tool lists, incentives, and training.
EnablingMay use
FastExpand as capacity and trust grow.
Governance mechanisms
The structural processes, bodies, and reviews that keep all the rest current.
StructuralRuns the system
OngoingOperate on a standing cadence.
These five instruments run across all nine AI governance domains, from teaching to procurement, so the same vocabulary describes a syllabus rule and a vendor standard. Two tests decide whether any instrument is actually working: is it calibrated to risk (an AI writing assistant should not face the same scrutiny as an algorithm that affects financial aid), and can the people it governs find it? A policy no one can locate in five minutes is not governing, it is only documented.
Acceptable-use grid
A starting Red / Yellow / Green map of common AI uses by audience. It turns the policy into an at-a-glance answer to “am I allowed to do this?” Adapt every cell to your own institutional rules before publishing.
Generally OK, Allowed with good judgment and disclosure where relevant.Caution, Allowed only with conditions, review, disclosure, or no sensitive data.Not without approval, Prohibited or requires formal governance review first.
Use case
Students
Faculty
Staff
Researchers
Administrators
Drafting routine email & internal textLow-stakes productivity; verify before sending and avoid sensitive content.
G
G
G
G
G
Summarizing public readings & documentsFine for non-sensitive material; check accuracy of summaries.
G
G
G
G
G
Brainstorming & outlining ideasIdea generation carries little risk; the human stays the author.
G
G
G
G
G
Coursework & assignmentsFor students, governed by each course's stated AI policy, disclosure usually required.
Y
G
G
G
G
Generating or drafting assessment itemsFaculty may draft with review; students may not create their own graded items.
R
Y
Y
G
Y
Analyzing data with sensitive/PII contentOnly in approved systems with the right data classification, never public tools.
R
Y
Y
Y
Y
Student records / FERPA-protected dataRequires an approved, contracted environment and data-governance review.
R
R
Y
Y
Y
Decisions on grades, admission, aid, or conductHigh-stakes automated decisions require governance review and human authority.
R
R
R
R
R
Public-facing content in the institution's nameBrand and accuracy risk, requires review and disclosure of AI involvement.
R
Y
Y
Y
Y
Syllabus statement bank
Ready-to-adapt syllabus language so every course can state its AI expectations in aligned terms. Pick the stance that matches the assignment, then tailor it.
You are welcome to use generative AI tools (such as chatbots and writing assistants) to support your learning in this course, for brainstorming, feedback, and revision. When you do, include a brief note describing which tool you used and how. You remain responsible for the accuracy, integrity, and originality of everything you submit.
Readiness & maturity questions
Readiness asks: are we prepared? Use these to surface blind spots before you build, honest “no” answers are where the work is. Representative prompts for reflection, not a scored test \u2014 for the scored version, use the Maturity Assessment.
Do we have institution-wide AI policies?
Are they role-specific (student, staff, faculty)?
Do they cover specific AI types (generative, predictive)?
Is there training on interpreting the policies?
Are the policies integrated into student conduct codes?
Is there a process for updating or revising policies?
Are policies designed to support innovation as well as protection?
Are ambiguities or edge cases considered (e.g., tutoring bots)?
Are guidelines adapted for classroom vs. administrative AI?
Are student rights and responsibilities clearly explained?