Artificial intelligence has quietly crossed a line in higher education. It is no longer an experiment. It is part of the institutional infrastructure. Generative AI tools draft emails, summarize research, screen applicants, support student services, and are embedded within enterprise SaaS platforms. The faculty are experimenting, the staff is optimizing workflows, and vendors are layering AI into the products that institutions already use. But here is the governance question: Who is overseeing the risk?
In advising our executive team on technology governance, I have seen how quickly AI adoption can outpace oversight structures. AI initiatives are often driven by efficiency and innovation. Governance frameworks tend to follow later—if at all.
For executive leaders, artificial intelligence is not merely a technology issue. AI risk must be included in board conversations, as its widespread capabilities raise fiduciary responsibilities, legal liabilities, and insurance exposures that must be addressed.
Institutional Risk, Not a Departmental Experiment

AI adoption tends to begin in silos. For example, admissions evaluates predictive tools, IT enables generative copilots, and student affairs deploys chatbots. All of these tools are individually manageable, but together they are collectively material to an institution's risk exposure.
Each AI tool introduces risk across multiple domains:
Data privacy when institutional data enters external systems
Bias risk in admissions, financial aid, and academic analytics
Intellectual property and training-data exposure
Vendor liability gaps
Reputational harm from inaccurate outputs
Some institutions enter configuration data, contract drafts, and internal policy content into AI tools without pausing to ask whether that data should leave institutional control at all. The issue is not bad intent; instead, it is the absence of a structured risk review.
Boards would never approve a financing structure or major capital project without documented oversight. Yet AI systems capable of influencing institutional decisions are often deployed without comparable governance. It is this asymmetry that is beginning to attract attention from insurers.
Institutions unable to demonstrate structured risk oversight may find insurance renewal conversations complicated.
AI Is on the Renewal Application
Underwriters are increasingly incorporating AI into renewal discussions. The questions are not technical but are governance-focused.
Institutions are being asked questions like these:
Does the organization have a written policy governing the use of generative AI?
Does the board receive reporting on emerging technology risk, including AI?
Are AI tools that process sensitive data subject to risk assessment prior to deployment?
Are third-party AI vendors reviewed for data retention and model training rights?
Does the organization use AI in admissions, hiring, or other decisions that materially affect individuals?
Does a human review AI outputs prior to reliance?
These are not hypothetical questions. They are starting to appear in cyber, Directors and Officers (D&O), and professional liability applications.
Carriers are attempting to understand whether AI exposure is governed or merely tolerated. Institutions unable to demonstrate structured risk oversight may find insurance renewal conversations complicated.
Fiduciary Duty in Practice
Boards have a duty of care to oversee material risks, and artificial intelligence now qualifies as one of these risks. Institutional leaders need clarity on the following:
What AI systems are in use across the institution?
Who approves new AI use cases?
How are risks tiered and assessed?
What institutional data is shared externally?
How is AI governance incorporated into enterprise risk management reporting?
A common governance gap is the assumption that AI oversight belongs solely within IT. In practice, AI risk intersects legal exposure, vendor contracting, data governance, academic autonomy, and leader accountability.
From Experimentation to Structured Oversight
Effective AI governance does not require banning AI or freezing innovation. It requires thoughtful planning and policy decisions.
Five elements provide a practical starting point:
Visibility: Maintain a documented inventory of AI-enabled tools, including those embedded in enterprise systems.
Risk Tiering: Not all AI use cases carry equal exposure. Low-risk productivity tools differ from systems influencing admissions or student outcomes. Higher-risk applications should trigger a cross-functional review.
Contractual Discipline: Institutions should evaluate relative to AI:
Data ownership and retention
Vendor rights to train models on institutional data
Indemnification and limitation-of-liability terms
Audit and transparency rights
At the same time, institutions should resist the impulse to manage AI risk through sweeping prohibitions. Blanket clauses banning vendors from using “any AI,” or requiring disclosure every time a team member uses an AI-assisted tool, are unrealistic or unenforceable. AI is embedded in development environments and enterprise platforms. Attempting to police every instance of AI assistance may create friction without meaningfully reducing risk exposure.
A more defensible approach is risk-based: define boundaries around the use of institutional data, ask about material AI usage, and assess contractual protections in light of actual risk.
Policy and Training: Clear guidance should address what data may be entered into AI tools, when disclosure is required, and where human review is mandatory.
Board Reporting: AI oversight should be incorporated into enterprise risk reporting. Documentation matters—not only for governance, but for litigation defense and insurance underwriting.
The Human Boundary
Higher education is relational. Decisions affecting admissions, discipline, academic standing, and student well-being require contextual judgment. AI may augment analysis, but human accountability must remain central in high-impact areas.
Institutions that define clear human-in-the-loop boundaries strengthen both ethical integrity and defensibility.
BOTTOM LINE
Artificial intelligence can enhance efficiency, expand insight, and foster innovation. However, unmanaged AI adoption introduces enterprise risk exposures affecting governance, legal compliance, and insurance coverage.
The institutions that treat AI as a governance priority, rather than a technical experiment, will be better positioned to demonstrate fiduciary diligence and preserve insurability. Institutions that wait for the first AI-related claim, regulatory inquiry, or coverage dispute to clarify their posture will have waited too long. AI oversight belongs in the boardroom now—not after coverage counsel is called.
AI oversight should be incorporated into enterprise risk reporting. Documentation matters—not only for governance, but for litigation defense and insurance underwriting.