AI Literacy / AI governance
Who should govern AI at a college or university?
Not a new standing committee. In most institutions the answer is clearer decision rights inside the governance you already have.
AI governance means deciding who has authority over which AI decisions, and writing that down. It is a decision-rights problem, not a committee problem. The most common failure is creating a new AI committee with broad membership and no authority, which produces meetings rather than decisions.
For most institutions the workable structure is three layers: the board sets principles and risk tolerance, the cabinet holds decision authority for procurement and institutional use, and existing academic governance owns anything touching curriculum and academic standards. A small working group staffs those bodies rather than deciding for them.
The committee trap
The reflex when a technology arrives is to form a committee. For AI this reflex produces a specific and predictable failure. The committee is large, because everyone has a stake. Its charge is broad, because nobody yet knows what the real questions are. And it has no delegated authority, because that would have required a decision the institution has not made.
What follows is eighteen months of meetings. The committee produces a landscape scan, a list of concerns, and possibly a draft principles statement. Meanwhile faculty adopt tools individually, staff paste student data into consumer products, and a department signs a vendor agreement nobody reviewed. The governance structure exists and governs nothing.
The problem is not the people. It is that a body without decision rights cannot govern, and adding members makes this worse rather than better.
A committee without delegated authority does not produce governance. It produces minutes.
Three layers, with authority named
Who decides what, and what each body should never be asked to decide.
| Body | Owns | Should not own |
|---|---|---|
| Board | Principles, risk tolerance, and policy adoption. The institutional position on AI and employment, and on student data. | Tool selection, vendor evaluation, or anything requiring technical judgment. A board asked to approve products will either rubber-stamp or stall. |
| Cabinet | Procurement authority, institutional deployments, data classification, and administrative use. The named executive owner sits here. | Course-level rules and academic standards, which are not cabinet's to set regardless of urgency. |
| Academic senate | Curriculum implications, academic integrity standards, syllabus requirements, and program-level decisions. | Enterprise procurement and data security configuration, which are management responsibilities. |
| Working group | Analysis, vendor review, drafting, and monitoring. Staffs the three bodies above. | Deciding. This is the distinction that makes the structure work. |
The working group should be small - five to seven people - and should include someone from institutional research, someone from IT, a faculty member, and someone who handles student records. Its output is options with trade-offs, not recommendations dressed as decisions.
What governance has to cover
- What student and employee data may enter which class of tool
- Which AI purchases require review, and at what dollar threshold
- Whether AI may be used in admissions, advising, or financial aid decisions
- Whether AI may be used in personnel evaluation
- Disclosure requirements for AI-assisted institutional communication
- Accessibility conformance for any deployed tool
- Who responds when something goes wrong, and how
The admissions, advising, and financial aid question is the one institutions most often leave unanswered, and it carries the most exposure. An AI system influencing who gets admitted or how aid is packaged is making consequential decisions about students, and the institution needs a defensible position on whether that is permitted, under what human review, and with what auditability.
The personnel evaluation question is equally live and almost always has bargaining implications. Treating it as an HR technicality rather than a governance decision is how institutions end up in grievance.
Neither question requires deep technical knowledge to answer. Both require someone with authority to answer them.
Governance failures we see
- No named ownerIf no single executive is accountable for AI decisions, every decision escalates to the president or stalls. One name, written down.
- Governance without literacyA board cannot set risk tolerance for a technology it does not understand. Briefings come before decisions, not after.
- Procurement outside the structureDepartments buying AI-enabled tools with discretionary funds is the most common way governance gets bypassed. The trigger has to be low enough to catch it.
- Confusing principles with policyA principles statement is not governance. It is the input to governance. Institutions frequently publish one and consider the work done.
- No monitoringGovernance that never reviews what was deployed cannot tell whether its decisions worked. A twice-yearly review to cabinet is the minimum.
Who does this work
Former chancellors and system executives who have held cabinet authority and reported to elected boards.
Do we need a separate AI governance committee?
Usually not. Most institutions get further by naming decision rights inside existing governance - board, cabinet, academic senate - and adding a small working group that staffs those bodies rather than deciding for them. A new standing committee with broad membership and no delegated authority is the most common structural failure we see.
Who should be the executive owner of AI at a college?
One cabinet-level person, named in writing. Which seat matters less than the fact that it is a single accountable owner with actual authority over procurement and deployment. Institutions that assign it to a committee or leave it implicit find every decision escalating to the president.
What should the board approve regarding AI?
Principles, risk tolerance, the institutional position on AI and employment, the position on student data, and the policy itself. Boards should not be asked to evaluate specific products, which requires technical judgment they do not have and creates the appearance of oversight without the substance.
How does AI governance interact with shared governance?
Anything touching curriculum, academic standards, or student academic conduct belongs in academic governance, and routing it around the senate invalidates the outcome regardless of its merits. Procurement, data security, and administrative deployment are management decisions. Naming that boundary early prevents most of the conflict.
What is the difference between AI policy and AI governance?
Policy is the document stating what is permitted and required. Governance is the structure that decides, approves, monitors, and revises it. A policy without governance goes stale and unenforced; governance without a policy leaves people guessing. Institutions need both, and governance has to come first because it is what produces the policy.
Brief the people who have to decide.
Board and cabinet AI briefings are among our most requested sessions, because a body cannot set risk tolerance for something it has not been taught.
Related
