A department head pastes budget projections into ChatGPT to “summarize this for the board.” A financial aid officer feeds student records into an unapproved chatbot. Neither believes they are making a technology decision, but both are.
Why it matters: AI has changed what it means to manage risk. Admissions offices use predictive analytics. Financial aid platforms run machine learning. Employees across every department use ChatGPT, Microsoft Copilot, and Google Gemini daily. Every leader who touches data, approves a vendor, or adopts a new tool is now making technology decisions with institutional consequences.
AI Is Simpler Than You Think
AI is software that learns from data. You feed it information, and it finds patterns and uses them to generate content or predict outcomes. Think of it as a tool that learns from whatever you give it.
That means AI is only as safe as the data it consumes. Every interaction is a data governance decision, whether the person using it realizes it or not.
The Mosaic Effect
In my graduate program, our program director, Brian Kellogg, introduced us to the mosaic theory from intelligence analysis: individual data points appear harmless alone, but when aggregated, they reveal sensitive insights. The intelligence community has warned about this for decades. AI has turned every employee into an unwitting intelligence collector.
A budget line item means little by itself. However, combine it with an org chart, a vendor contract, and a strategic plan, all pasted into the same AI tool over weeks, and it becomes an organizational intelligence profile. No single person intended to create it. The AI assembled it from fragments.
By the numbers: Research from 2025 found that 18% of enterprise employees paste data into AI tools, and more than half of those event