The Three-Layer Review - AI governance readiness for higher education
From policy on paper to practice across the institution
Most institutions have issued guidance and convened a group for AI adoption. What happens next is harder - in the classroom, the aid office, and the advising appointment. We map what is actually happening across three layers, score your readiness, and deliver a prioritized action plan
The picture today
Authourity over AI decisions sits in several places at once - not by oversight, but by design. Shared governance gives instructors real authourity over their own classrooms and gives schools and departments real authourity over their own curriculum and tools. It's how institutions are built. Leadership sets direction. IT manages tools and risk. Instructors, advisors, and administrative staff make the daily calls that shared governance leaves to them, often in the absence of a settled institutional standard. Each decision can be sound on its own terms. But assembling them into one institutional picture is a separate job - and because shared governance was built to distribute authourity, not to assemble it, that job belongs to no one by default.
What no one owns
The board asks what the institution's AI position is, and the answer has to be assembled from a dozen places
Departments procure independently, by design, so no single office holds the list of what the institution actually runs
There is no agreed way to tell whether an AI investment worked, so renewal decisions rest on anecdote
The offices that can't afford to be wrong - student finance, HR, admissions - hold back, reasonably, because no one has yet agreed who is accountable when an AI output is wrong
Predictive and early-alert models go live before anyone has named who reviews them for bias or hears a student appeal
Leadership weighs AI in cost and enrolment terms while faculty weigh it in workload and teaching terms, and no forum reconciles the two
Faculty and staff absorb AI integration as unpaid labour, so adoption stalls where the work actually happens
Schools and departments procure independently, by design, so no single office holds the list of what the institution actually runs. A student can hit contradictory AI rules within a single semester - allowed in one class, banned in the next - because no venue exists where school and department policies get reconciled.
Most institutions can describe Layer 03. Very few can describe Layer 01.
Policy → Practice
Layer 03 - Institutional leadership. Executive, provost, and board. Who owns the standard, how decisions are made, how policy becomes practice.
Layer 02 - Systems and support. IT, academic technology, data, and procurement. Which tools are approved, how usage and risk are managed.
Layer 01 - Practice. Instructors, advisors, and front-line staff. How AI is actually used in teaching, advising, admissions, aid, and service delivery.
This isn’t hypothetical anymore
〰️
This isn’t hypothetical anymore 〰️
A Yale EMBA student's lawsuit alleges the university's own policy barred the AI-detection tool used against him, and that the disciplinary process that followed denied him access to key evidence. The claim isn't about whether AI detection exists - it's about who approved the tool, who reviewed the result, and who could appeal. Rignol v. Yale University, D. Conn., filed February 2025.
Middle States adopted an AI accreditation policy effective July 2025, expecting institutions to align the governance, procurement, and use of AI with accreditation standards. The Council of Regional Accrediting Commissions followed with its own statement in October 2025. The “what's our AI position” question is no longer only coming from your board.
Every semester the ownership question stays open, more of the integration work gets absorbed as unpaid faculty and staff labour - and the goodwill that costs makes the next initiative harder to fund, not easier.
Where to get started
A significant AI problem on many campuses right now is academic integrity, and it is almost always treated as a teaching problem when it is squarely a governance problem.
Some instructors are banning AI outright, reverting to pen-and-paper assessment, and writing their own course rules because no one has given them acceptable-use definitions, risk tiers, or disclosure expectations. Those bans are improvised governance instruments, built by people who shouldn't have to build them - and each one is a Layer 01 (see diagram above) decision the institution will eventually have to own.
It is also the most tractable place to start, because the problem is already visible, already urgent, and needs solving. The work will involve defining acceptable use, setting risk tiers by assessment type, building a disclosure framework, and giving departments one coherent standard to apply instead of each inventing prohibition in isolation.
The assessment
Map current AI use and decision-making across the three layers
Identify where institutional policy and daily practice have diverged
Clarify ownership, escalation paths, and unresolved decisions
Assess readiness across governance, adoption, capability, risk, and implementation
Produce a practical maturity score
Deliver a prioritized action plan matched to your context
What the research shows
30% - of higher ed administrators are unsure whether AI appears in their own institution's strategic plan. 43% say it does, 27% say it doesn't.
Ellucian AI in Higher Education, 202570% - of AI transformation success comes from organizational design, talent, and change management. Technology infrastructure accounts for 20%, the models themselves 10%.
BCG 10-20-70 principle, 2026
We begin with the person closest to the problem - typically a provost, CIO, COO, VP of student success, or chief of staff. We use that conversation to understand where AI decisions currently sit, what is happening in practice, and whether a readiness assessment would be useful.
Let's have a conversation
Meet Susan Diaz
Susan Diaz is the founder of Northlight, an AI literacy company based in Toronto. She teaches AI-forward Marketing at York University School of Continuing Study, hosts the ‘AI Literacy for Entrepreneurs’ podcast, and facilitates AI Power Circle, an implementation mastermind for entrepreneurs.
Swan Dive Backwards: From AI Curious to AI Literate is her second book. Her first was UNboring (a marketing book that's exactly what it sounds like).
Meet Eugene Chan Phd.
Eugene Chan is the founder and principal strategist of Behavieural, a consultancy that uses behavioural science to solve organizations' hardest trust problems — AI adoption, customer loyalty, brand and reputation. He is Professor of Business and Van Norman Chair of Business at Tyndale University, and has previously taught at Toronto Metropolitan University as well as in Australia and the United States. His PhD is from the Rotman School of Management, and he is the author of Managing Brand Crises: A Guide for Navigating the Storm.