Why AI Governance Fails in Schools: The Three-Layer Problem Worth Solving

Most universities have an AI policy but very few of them have AI governance. Could the gap between the two be why students are getting penalized expelled for using AI the same way faculty use it to grade?

I talked about this recently with Dr Eugene Chan, founder of Behavieural (a consultancy using behavioral science to solve organizations' trust challenges) and professor of business and marketing at Tyndale University, on my podcast. He frames policy as the ideal while governance is what actually happens day to day. Most institutions have written the first and never built the second.

Policy Isn't Governance

Policy is a set of objectives, do this, don't do that. Governance is the finer-grained work of establishing guidelines around actual behaviour. Governance is also where behaviour gets confused with literacy. Most institutions have handed out LLM licenses and assumed adoption follows automatically. It doesn't. Access isn't the same as knowing how to use something well, and that gap is where most AI governance failures live.

For a business, this distinction is inconvenient. For a university, it's structurally harder, because a university doesn't have one hierarchy making these decisions. It has three.

Three Layers, Three Different Sets of Assumptions

In most educational institutions, the structure looks a little something like this:

Layer one: technology. IT gets asked first, almost by default, because AI still gets categorized as a tech problem. But IT can tell you what tools are approved. It can't tell you whether a philosophy seminar should use AI differently than an accounting class.

Layer two: academic leadership. Deans, provosts, VPs, the people setting institution-wide direction. They're thinking about liability, accreditation, and reputation, real concerns, but ones that tend to produce broad, cautious policy rather than usable guidance for a specific classroom.

Layer three: the instructors themselves. At the actual classroom level, each instructor decides, in practice, how AI gets used or doesn't. Eugene made the point that even within one university, a marketing professor, an accounting professor, and a philosophy professor will land in three completely different places, because their disciplines demand different things. Philosophy leans on critical thinking. Accounting leans more on precision and calculation. A single institution-wide AI rule can't serve all three well.

Layer three is where it gets more complex, because within a university, you're not just governing two groups (leadership and employees) the way a company would. You're governing three: faculty, administrative staff, and students, and each group is often using entirely different tools. Students are mostly on general LLMs like ChatGPT or Claude. Faculty and staff often have access to more specialized institutional tools. Multiply that across a business school, a medical school, and an arts faculty, and "one governance policy for the whole institution" stops being realistic.

The Punitive Trap

Here's where most institutions default, and where I think the real damage happens. Absent a workable governance model, the fallback becomes enforcement: catch students using AI, penalize them. Turnitin flags a percentage match. Some faculty have started hiding instructions in white text inside assignment documents, so if a student pastes the prompt into ChatGPT, the AI picks up hidden text designed to catch them.

I sympathize with instructors here. Grading has gotten genuinely harder. Nearly anyone can produce a fluent, well-structured piece of writing now, and figuring out whether a student actually thought something through is a real, unsolved problem. But punitive detection has a ceiling. Turnitin flags a percentage match; it doesn't tell you whether that match is a warranted reuse of the student's own earlier work or actual plagiarism/lazy due diligence, and AI detectors generally aren't reliable enough to build a fair system on top of. Banning AI outright doesn't work either. You can't enforce it technologically, and pretending otherwise is like banning the use of a calculator. It's already the world students and instructors are living in.

The deeper problem with a purely punitive model: it teaches compliance, not judgment. Eugene drew a comparison to speed cameras. They work, they do measurably reduce speeding, but they only produce compliance in the presence of enforcement, not judgment that holds up once nobody's watching. If the entire governance model rests on catching people, it produces the same result: people learn to avoid detection, not to think critically about when AI use is appropriate and when it isn't.

What Works Instead: Teaching the Review, Not Banning the Tool

I've been running a version of this in my own classes for a while: rather than banning AI, I tell students to use it the way you'd use a search engine or gather research from any other source. But then they have to defend their work, present it, explain their reasoning, answer questions on it from me and a class of their peers, the same way a thesis gets defended.

Eugene's framing on why this works is that it teaches what governance circles call "human in the loop", not as a compliance checkbox, but as an actual skill. Students have to review the AI's output, catch its errors, and add their own thinking before defending it as theirs. That's a genuine skill, and it's one a lot of adults using AI professionally haven't developed either. AI is right most of the time. It's the smaller percentage where it's confidently wrong that requires a human who's actually paying attention, not just accepting the first output.

This is the same principle behind good delegation in any organization; it isn't AI-specific. The gap between excellent and average work has never been about who did the first draft. It's about how well the person reviewing knows what "good" looks like and can catch what's missing. Teaching students to review AI output critically is teaching them the exact skill that separates a strong manager from a weak one later in their career.

What This Means If You're Building Governance for an Educational Institution

Real governance needs to flex at the discipline or faculty level, because a philosophy course and an accounting course have legitimately different relationships with AI-assisted work.

Separate the three governance layers explicitly, technology, academic leadership, and instructors, and be clear about what each layer actually owns. IT shouldn't be setting classroom-level norms. Instructors shouldn't be expected to solve institution-wide liability questions on their own.

Move the default away from pure enforcement. Detection tools have a real, useful role, but a governance model built entirely on catching violations produces compliance without judgment. Teaching students to review, defend, and take ownership of AI-assisted work builds the skill that actually matters once they're out of a graded environment. (Further reading: The Three Fences Model for AI Governance)

Recognize that access isn't adoption. Handing out LLM licenses to faculty, staff, and students doesn't produce good AI use on its own. That gap between access and actual literacy is where governance needs to do real work, not just where policy needs to exist on paper. (Further reading: What is Governance vs. Compliance)

You can hear the full conversation with Eugene Chan, including his read on where accountability for AI actually sits inside an organization, on episode 277 of AI Literacy for Entrepreneurs.

If your institution is building or rethinking its AI governance model, the Northlight AI Readiness Audit is a useful internal starting point for mapping where the gaps actually are. Run the audit now.


Next
Next

Best AI Consulting Firms for Mid-Market Companies (2026)