top of page

Why AI Governance Isn't Just an IT Responsibility

  • Writer: Bruce Sarte
    Bruce Sarte
  • 21 hours ago
  • 9 min read

For decades, colleges and universities have looked to Information Technology departments to evaluate, secure, implement, and support emerging technologies. So, as artificial intelligence rapidly enters higher education, it is understandable that many institutions are looking toward IT to answer the big questions.


  • Which AI tools should we allow?

  • How do we protect institutional data?

  • What policies should we establish?

  • How do we prevent inappropriate use?

  • What about FERPA, privacy, security, intellectual property, and academic integrity?


These are important questions, and IT absolutely needs a seat at the table. But IT cannot be the entire table.


After more than three decades working in education and technology, as an IT leader, educator, and administrator, I believe one of the greatest mistakes institutions can make with AI is treating AI and its governance as a technology problem.


AI and AI governance isn't an IT initiative.


It is an institutional responsibility.



Why is AI Different?

We’ve navigated major technology changes before. When cloud computing emerged, we had to rethink where our systems and data lived. The rise of mobile technology changed how students, faculty, and staff expected to access institutional resources. Cybersecurity forced us to think differently about risk and responsibility. Learning management systems transformed the relationship between the classroom, the instructor, and the student.


Each of those changes required institutions to adapt. But for the most part, we could identify the technology, evaluate its risks and benefits, implement it, and establish processes around its use.


AI feels different.


Artificial intelligence isn’t simply changing the technology people use. It is beginning to influence how people think, create, teach, learn, communicate, analyze information, make decisions, and ultimately perform their jobs. That distinction becomes clear when you walk across a college campus and consider how many different conversations are already taking place.


A faculty member may be wondering whether using AI to help develop a course is fundamentally different from using other instructional tools. Across the hall, a student may be trying to understand whether using AI to brainstorm an assignment supports the learning process or crosses a line academically.


Meanwhile, an admissions counselor sees an opportunity to use AI to create more personalized communications for prospective students. Advancement may see the potential to better understand donor information. Human Resources may be exploring AI to develop job descriptions or assist with recruiting. Institutional Research may be considering how AI can help interpret increasingly complex datasets. And somewhere on campus, an executive may be tempted to paste a confidential document into an AI platform and ask for a quick summary.

Suddenly, what initially appeared to be a technology question has become something much larger.


IT can — and should — determine whether an AI platform meets the institution’s standards for security, privacy, integration, data protection, and technical reliability. Those responsibilities are firmly within our expertise.


But should IT decide what constitutes appropriate AI-assisted learning? Should we determine when AI-generated communication authentically represents the institution? Should technology professionals establish the boundaries for AI in hiring, student assessment, research, or executive decision-making?


I don’t believe we should.


IT can help determine whether an AI tool is safe to use. The institution, collectively, must determine how and when it should be used.


That is what makes AI different, and why governing it requires a much broader conversation.


Governance Must Follow the Institution's Mission

Effective AI governance needs participation from across the institution.

Academic leadership must consider how AI affects teaching, learning, assessment, and academic integrity.

  • Faculty need a meaningful voice because they understand what happens inside the classroom.

  • Students need to be part of the conversation because policies designed without understanding how students actually use technology frequently fail.

  • Legal, compliance, and information security leaders must evaluate privacy, data protection, intellectual property, and regulatory risks.

  • Human Resources needs to consider how AI affects employees, hiring, professional development, and changing job responsibilities.

  • Institutional Research must consider data quality, analytics, transparency, and the potential consequences of AI-assisted decision-making.

  • Communications and Marketing need to understand when and how AI-generated content should represent the institution.

  • And executive leadership must ultimately determine how AI aligns with institutional mission, values, strategy, and risk tolerance.


IT connects many of these conversations. It should not own all of them.


Governance Shouldn't Mean Saying "No"

One of the risks I see as institutions begin building AI governance structures is that governance can quickly become synonymous with restriction. We’ve seen this before with emerging technologies. Something new arrives, we identify the risks, and our natural institutional response is to establish controls. We create committees, develop policies, determine which tools are approved, and establish rules about what people can and cannot do.


There is certainly a place for those guardrails. AI introduces legitimate concerns around privacy, security, intellectual property, academic integrity, and institutional data. Ignoring those risks would be irresponsible.


But there is another risk we need to consider: becoming so focused on preventing the wrong uses of AI that we make it difficult for our communities to discover the right ones.


The reality is that our students, faculty, and staff aren't waiting for us to finish developing an AI strategy. They are already experimenting. A faculty member is trying a new way to develop an assignment. A staff member has discovered that AI can turn a task that once took two hours into twenty minutes. A student is using it to better understand a difficult concept. Somewhere else, someone may be putting information into an AI platform that they probably shouldn't.


All of those things may be happening on the same campus, on the same day.

We can respond by trying to control every interaction with AI. But I'm not convinced that's either realistic or productive.


Instead of beginning with the question, "How do we stop people from using AI inappropriately?", I think we should start with a more useful one:

"How do we help our community understand when and how to use AI responsibly, ethically, securely, and effectively?"


That subtle change in the question changes the role of governance.


Governance becomes less about building fences and more about creating the conditions for responsible experimentation. It means giving people enough room to discover where AI genuinely improves teaching, learning, and institutional operations while establishing clear boundaries around the places where experimentation introduces unacceptable risk.


And that can't be accomplished simply by publishing an acceptable-use policy.

We have to help people understand why those boundaries exist, recognize situations where additional caution is necessary, and develop the judgment to make good decisions when there isn't a policy covering the exact situation in front of them.


In other words, good AI governance isn't simply about control.


AI Literacy May Be More Important Than AI Policy

Policies and guidelines absolutely have a place in AI governance. Institutions need to establish expectations, define appropriate use, protect sensitive information, and create boundaries around risk. But I've spent enough of my career implementing technology to know that publishing a policy doesn't necessarily change behavior.


We can write a thoughtful AI policy, approve it through all the appropriate committees, post it on the institutional website, and announce it to the campus community. But if people don't understand why those guidelines exist—or how they apply to the decisions they make every day—we haven't really solved the problem.

This is where I believe AI literacy becomes so important.


Imagine a faculty member sitting at their desk experimenting with an AI tool for the first time. Their questions probably aren't going to be about the wording of the institutional AI policy.


They're going to be much more practical:

Can I use this to help develop an assignment? Can my students use it? How do I know whether what it produces is accurate? What does this mean for the way I assess learning?


A staff member may have completely different questions. They've discovered that AI can take a repetitive task that normally consumes an afternoon and complete much of it in minutes. That's exciting. But do they know what information is appropriate to give the tool? Do they understand what happens to that data afterward? Can they recognize when an AI-generated response needs human review?


Students face another challenge. If our only message to them about AI is a list of things they aren't allowed to do, we're missing an enormous educational opportunity. They need to understand the boundaries around academic integrity, certainly, but they also need opportunities to learn how AI can appropriately support research, creativity, problem-solving, and learning. Perhaps most importantly, we have a responsibility to prepare them for workplaces where working effectively and responsibly with AI may increasingly be expected.

And AI literacy can't stop with students, faculty, and staff.


Presidents, cabinets, and trustees will be asked to make increasingly significant decisions about AI—decisions involving investments, institutional risk, workforce changes, academic strategy, and the future direction of their institutions. They don't need to become AI engineers, but they do need sufficient understanding to ask good questions, recognize both opportunities and risks, and make informed decisions.


That's why I increasingly think of AI governance as a professional development challenge as much as a policy challenge. Different members of our communities need different levels and types of AI literacy. The goal isn't to turn everyone into an AI expert. It's to give people the knowledge and judgment they need to make responsible decisions when AI intersects with their work.


A policy can tell someone where the boundaries are. AI literacy helps them understand why those boundaries exist, and gives them the judgment to navigate everything that happens between them.


And developing that kind of institutional understanding requires educators, administrators, students, technology professionals, security leaders, and executive leadership working together.


It's another reason AI governance can never belong exclusively to IT.


IT's Role May Actually Become More Important

None of this diminishes IT's responsibility. Quite the opposite. Technology leaders have a unique opportunity to become conveners rather than gatekeepers.


  • We understand the technology.

  • We understand data.

  • We understand cybersecurity and privacy.

  • We frequently work across nearly every functional area of an institution.


And because we've led institutions through previous waves of technological change, we understand something else that matters enormously right now:

Technology implementation is relatively easy. Organizational change is hard.


The most successful technology initiatives I've been involved with throughout my career weren't successful simply because we selected the right product. They succeeded because people understood the problem we were trying to solve.


  • Stakeholders participated in the process.

  • Leadership supported the change.

  • People received appropriate training.


And, most importantly, technology was connected to an institutional outcome rather than deployed simply because it was new.


AI shouldn't be any different.


From AI Policy to AI Strategy

Ultimately, I think this is where our conversations about AI need to go.

Many institutions began their AI journey by asking a very reasonable question: “What should our AI policy be?” We needed to respond quickly to concerns about academic integrity, privacy, security, intellectual property, and the rapid emergence of generative AI tools. Policies and guidelines gave our communities some much-needed boundaries at a time when the technology was moving faster than most institutions could respond.


But policy was never meant to be the destination.


At some point, the conversation has to move from “How do we control AI?” to “What do we want AI to help our institution accomplish?”


That is a much more interesting conversation. Imagine bringing together faculty, students, administrators, technology professionals, and institutional leaders and starting there. Could AI help us identify barriers to student success earlier? Could it eliminate some of the repetitive administrative work that consumes hours of our employees' time? Could it give faculty more time to teach, mentor, conduct research, and engage with students? Could it help us make learning more accessible? Could it help us understand institutional data in ways that allow us to make better decisions? And perhaps most importantly, how do we prepare our students for what comes next?


The students sitting in our classrooms today will enter professions where working alongside AI may simply be part of the job. Our responsibility cannot be limited to teaching them what they aren't allowed to do with these tools. We also have an opportunity—and I would argue an obligation—to help them develop the judgment, curiosity, critical-thinking skills, and AI literacy they will need to use them responsibly and effectively.

Of course, strategy also means knowing when not to use AI.


There will be decisions where efficiency shouldn't be the primary consideration. here will be interactions where empathy matters more than automation. There will be information that should never be entered into an AI platform. And there will be moments when human experience, judgment, creativity, and relationships must remain at the center of what we do.


Determining where those lines belong isn't something an IT department can decide on behalf of an institution. And maybe that's the larger lesson in all of this.

Throughout my career in education technology, I've seen technologies come and go. I've also learned that successful transformation is rarely about the technology itself. The technology may create the opportunity, but people determine what happens next.


AI is giving us another one of those moments, and just maybe one of the most significant we've encountered.


IT should absolutely help lead the conversation. We should help our institutions understand the technology, protect their data, evaluate risk, establish appropriate guardrails, and create environments where responsible experimentation can occur.

But we also need to invite others to the table.


Because the most important questions surrounding AI aren't ultimately questions about platforms, licenses, security controls, or technology architecture.


They are questions about teaching and learning. About people and work. About ethics and trust. About access and opportunity. About the skills our students will need. And about the kind of institutions we want to become.


Those aren't IT questions.


They're institutional questions.


And that's why AI governance can never belong exclusively to IT.



Comments


Using Mobile Phones

Stay Connected with Bruce Sarte's BLOG

Contact Bruce Sarte

bottom of page