AI
Why schools cannot govern generative AI in 2026
Generative AI has arrived in classrooms, lecture halls, and research labs across Europe. Yet most educational institutions have no centralised system to govern how these tools are used, where student data ends up, or who is accountable when something goes wrong. The result is a growing gap between rapid AI adoption and institutional readiness.
This article explains why AI governance in schools and universities is falling behind, what risks that creates, and how institutions can take back control. You will find practical steps, real-world insights from a Dutch university pilot, and an overview of how platforms like Mila from Academic Software make governed AI access possible.
Key takeaways: Why schools cannot govern generative AI
- Generative AI adoption in education is outpacing the policies, governance structures, and oversight capacity of most institutions.
- Fragmented AI tool usage creates data privacy risks, GDPR exposure, and unequal access for students and researchers.
- Centralised governance requires visibility into who uses AI, which tools they access, and how institutional data is processed.
- Academic Software helps institutions govern AI through Mila, a secure platform combining multiple AI models under one controlled environment.
- Dedicated AI leadership and clear institutional policies are essential to move from reactive firefighting to structured AI governance.
Why generative AI governance in education is falling behind
Students are already using ChatGPT, Claude, Gemini, and dozens of other AI tools every day. They use them for assignments, research, exam prep, and creative projects. Most do so without any institutional guidance or oversight.
Meanwhile, IT departments and leadership teams are still drafting their first AI policy documents. The gap between adoption speed and governance readiness keeps growing. According to a scoping review of institutional AI policy responses in European higher education, most universities still lack formalised, enforceable frameworks for generative AI.
This is not a technology problem. It is a governance problem. And it affects data protection, academic integrity, budget control, and educational equity all at once.
What does AI governance in education actually mean?
AI governance in education refers to the policies, structures, and processes an institution uses to control how AI tools are adopted, accessed, and monitored. It covers who can use which tools, under what conditions, and with what safeguards in place.
Good governance answers three core questions:
-
Where does institutional data go when someone uses an AI tool?
-
Who has oversight of which AI tools are active across the institution?
-
How does the institution ensure fair and equitable access for all students and staff?
Without answers to these questions, every individual who opens a free AI tool on campus becomes a potential compliance risk. The institution carries the liability, even if it never authorised the tool in the first place.
The difference between guidelines and governance
A set of guidelines tells users what they should or should not do. Governance, by contrast, builds the infrastructure to enforce those rules. It includes technical controls, monitoring systems, and decision-making authority.
For example, a guideline might say "do not enter personal student data into AI tools." Governance means deploying a platform that prevents personal data from leaving the institutional perimeter in the first place. One relies on trust. The other relies on architecture.
How fragmented AI adoption creates institutional risk
When students and staff each pick their own AI tools, the result is a patchwork of subscriptions, free tiers, and unvetted platforms. A pilot study at Fontys ICT in the Netherlands documented this pattern clearly: faculty expensed premium subscriptions on personal cards, students relied on free tiers with weaker privacy protections, and no one had full visibility into the tools being used.
This fragmentation introduces several concrete risks. Data may be processed on servers outside the EU, violating GDPR transfer rules. Student prompts and research inputs may be used to train commercial AI models. And institutions have no way to audit which tools touched submitted coursework.
The hidden cost of uncoordinated AI spending
The financial side of fragmented adoption matters more than many institutions realise. When individual departments purchase AI subscriptions independently, costs multiply quickly. Reimbursements, duplicate licences, and ad hoc purchases accumulate with no centralised budget tracking.
At scale, this becomes a real financial problem. The Fontys report noted that giving every staff member a single premium AI subscription would cost significantly more than operating a shared gateway infrastructure. Centralised procurement not only reduces total spend but also makes AI costs visible and predictable.
Shadow AI: The tools you cannot see
Perhaps the most difficult risk to manage is shadow AI: the tools that students and staff use without institutional knowledge. Free browser-based chatbots, mobile apps, and API integrations create invisible data flows that bypass every policy and firewall.
Shadow AI is not a matter of bad intent. Most users simply choose the most convenient option available. But convenience-driven adoption leaves institutions blind to where their data goes, how it is processed, and whether it complies with institutional or regulatory requirements.
Why GDPR compliance is harder than it looks
GDPR compliance in the context of generative AI is not a one-time checkbox. It is an ongoing responsibility that shifts every time a provider updates its terms of service or changes its data processing locations.
Most commercial AI tools process data on servers in the United States. Under GDPR Article 44, any transfer of personal data outside the EU requires a valid legal mechanism, such as Standard Contractual Clauses. But many free-tier AI tools do not offer transparent documentation about where data is stored, how long it is retained, or whether it is used for model training.
Why educational data deserves extra protection
For educational institutions, the stakes are higher than for most organisations. Student data includes minors' personal information, exam submissions, research hypotheses, and creative work. A single data breach or compliance failure can result in regulatory fines, reputational damage, and a loss of trust among students, parents, and staff.
There is also the issue of informed consent. Many public AI tools learn from their users. Every prompt helps train the next version of the model. Students and researchers are often unknowingly contributing their thinking processes, texts, and preliminary analyses to commercial AI training data. That directly conflicts with academic freedom and data protection principles.
Monitoring provider changes over time
Compliance is not only about the initial assessment of a tool. Providers update their privacy policies, change data retention periods, and adjust hosting locations regularly. A tool that met GDPR requirements six months ago may no longer do so today.
Without a system to monitor these changes, institutions operate on outdated compliance assumptions. Manual tracking across dozens of AI tools is impractical. Automated governance platforms that flag policy changes and trigger reassessments are far more effective at keeping compliance current.
The problem of unequal access to AI tools
When AI access depends on personal budgets, educational equity breaks down. Students who can afford premium AI subscriptions gain a visible advantage in coursework quality, research speed, and creative output. Students limited to free tiers receive less capable tools with more restrictive usage limits.
This financial gap directly conflicts with the mission of most educational institutions: equal opportunity for every learner. The Fontys ICT pilot confirmed that this disparity emerges quickly once AI adoption goes unmanaged. Faculty who expensed premium tools outpaced colleagues who did not, and students with paid accounts produced more polished work.
How centralised access restores equity?
Centralised AI governance can close this gap by giving every student and staff member equal access to the same set of vetted, institution-approved AI models. When the institution funds and manages AI access centrally, personal financial resources no longer determine who gets the most capable tools.
This approach also means institutions can tailor access by role. Research teams might receive higher usage budgets or access to specialised models, while undergraduate students get a curated set of general-purpose tools. The key is that these decisions are made deliberately by the institution, not accidentally by the market.
Why writing AI policies is not enough
Many institutions have responded to the rise of generative AI by publishing usage guidelines. These documents outline acceptable use, remind users about academic integrity, and reference GDPR obligations. On paper, they cover the basics, but, in practice, policies without enforcement tools are largely symbolic. If an institution cannot see who is using which AI tools, how often, and for what purposes, it has no way to verify compliance. Guidelines become theoretical, and enforcement becomes reactive rather than proactive.
The missing ingredient is visibility. Institutions need a centralised system that tracks AI tool usage, applies access controls, and enforces data processing rules automatically. That is the difference between a policy on a shelf and a governance framework that actually protects students and data.
What a controlled AI environment looks like
A controlled AI environment is a centralised platform where institutions can offer multiple AI models through a single, governed access point. It replaces the patchwork of individual subscriptions with a managed system that enforces institutional policies by design.
In a controlled environment, every user authenticates through institutional credentials. The platform routes AI requests through approved infrastructure, logs usage for audit purposes, and applies budget controls at the user, group, or project level. Data stays under institutional oversight rather than flowing to unvetted third-party servers.
![]()
How Mila from Academic Software delivers controlled AI access
Academic Software built Mila for exactly this purpose. Mila brings together over 60 AI language models in a single, privacy-first environment designed for education. Students and researchers get access to tools like ChatGPT, Claude, Mistral, and Gemini through one secure login.
The institution retains full control over data processing, access rights, and cost allocation. Mila tracks usage per user, per department, and per model, giving IT teams the visibility they need to enforce governance policies and manage budgets. This is available as an add-on to the Academic Software platform, and accessible through institutional accounts.
How centralised AI management strengthens security
Security in an unmanaged AI environment is reactive by nature. IT teams discover risks after the fact, when a data processing agreement turns out to be insufficient or when a student inadvertently shares sensitive research data with a commercial AI platform.
Centralised management flips this model. When all AI access runs through a single governed platform, the institution can enforce data processing agreements at the infrastructure level. Traffic can be routed to EU-hosted servers by default. Non-EU processing becomes a deliberate, documented exception rather than an accidental default.
Single Sign-On (SSO) and Audit Trails
Academic Software's platform integrates with existing identity management systems through single sign-on, ensuring that every AI interaction is linked to an authenticated institutional account. This creates a clear audit trail and removes the risk of anonymous, untracked AI usage across campus.
Audit trails also support compliance reporting. When a data protection authority asks for evidence of GDPR compliance, the institution can point to documented usage logs, enforced access controls, and configured data processing routes rather than relying on self-reported user behaviour.
The role of institutional leadership in AI governance
Technology alone does not solve AI governance. The Fontys ICT implementation report made this point clearly: AI is no longer a support function to be aligned with strategy. AI is strategy itself.
That shift demands dedicated leadership. Decisions about which AI models to offer, where data is processed, how budgets are allocated, and how compliance is monitored require someone with both technical understanding and institutional authority. Existing IT or privacy roles rarely combine these competencies.
Why traditional IT roles are not enough
IT managers understand infrastructure. Privacy officers understand regulation. But AI governance sits at the intersection of both, plus educational strategy and budget management. No single existing role covers all of these dimensions.
Many institutions are now exploring the creation of an AI Officer role or an AI Governance Committee. This function would bridge IT infrastructure, legal compliance, educational strategy, and research facilitation. It would set the criteria for which AI models are acceptable, manage cross-border data routing decisions, and coordinate stakeholder communication. Without this dedicated capacity, governance decisions remain ad hoc, inconsistent, and reactive.
What European institutions can learn from the Fontys pilot
The Fontys ICT pilot at a Dutch university of applied sciences ran for six months with 300 users. It tested a gateway architecture that connected multiple AI providers through one institutional platform, with EU-first data routing, scoped budget controls, and mandatory consent flows. Several findings are relevant for any European institution:
-
Commercial AI subscriptions do not meet institutional governance needs because they optimise for consumer convenience, not institutional control.
-
Geographic data routing must be a deliberate policy choice, not an accidental default.
-
Model cards and consent mechanisms can turn every AI interaction into a moment of informed decision-making.
Governance as an educational opportunity
The pilot also showed that governance infrastructure creates educational opportunities. When students must choose a model, review its privacy posture, and manage a budget, they build transferable AI literacy skills alongside their coursework.
This is a significant finding. AI governance does not have to be a burden on the educational process. Done well, it becomes part of the learning experience, teaching students to evaluate tools critically, consider privacy trade-offs, and make cost-conscious decisions. These are exactly the skills they will need in their professional careers.
How Academic Software supports institution-wide AI governance
Academic Software addresses the governance gap by giving institutions a centralised platform for AI, software, and cloud tool management. Rather than leaving AI adoption to individual choice, the platform puts control in the hands of IT teams and institutional leadership.
With Mila, Academic Software offers secure, moderated access to a wide range of AI models. Usage tracking, cost management, and GDPR-aligned data processing are built into the platform. Institutions can see who uses AI, how much it costs, and whether data stays in approved processing locations.
The broader Academic Software services portfolio includes consultancy on digital infrastructure, application management, and integration with existing identity systems. This means AI governance fits into a wider digital strategy rather than standing as a separate, siloed project.
More than 2,500 institutions trust Academic Software
Academic Software already supports more than 2,500 schools and educational institutions across the UK and Europe. This installed base means that AI governance through Mila can be deployed on top of existing infrastructure, reducing implementation time and complexity.
Institutions using the Academic Software Deployment Platform benefit from centralised licence management, automated software distribution, and real-time usage dashboards. Adding AI governance through Mila extends these capabilities to generative AI, creating a unified digital management layer for the entire institution.
Steps to build an AI Governance framework for your institution
Building effective AI governance does not require starting from scratch. Most institutions already have data protection policies, identity management systems, and software procurement processes. The goal is to extend these existing structures to cover generative AI.
Step 1: Map your current AI usage
Start by auditing current AI usage across your institution. Identify which tools students, staff, and researchers are using today. Document where data is being processed, what compliance gaps exist, and where shadow AI tools have crept into daily workflows. This audit gives you a realistic baseline rather than a set of assumptions.
Step 2: Define your governance principles
Next, define your governance principles. Decide where data may be processed, which AI models meet your ethical and compliance standards, and how you will ensure equitable access. Determine whether non-EU data processing is acceptable under specific conditions or whether EU-only routing is a hard requirement. Document these decisions clearly so they can be enforced, not just recommended.
Step 3: Select a centralised platform
Finally, select a centralised platform that can enforce these principles at scale. Look for single sign-on integration, usage monitoring, budget controls, and the ability to add or remove AI models as your needs evolve. A platform like Mila from Academic Software is designed to do exactly this for educational institutions across Europe.
Conclusion: Taking control of generative AI in education
Generative AI is already part of education. The question is not whether students and staff will use it, but whether institutions will govern it responsibly. Unmanaged adoption creates real risks: data leaks, GDPR violations, academic integrity concerns, and unequal access.
The solution is not to ban AI or to let adoption run unchecked. It is to build governance structures that give institutions visibility, control, and accountability. That means centralised platforms, clear policies with enforcement mechanisms, and dedicated leadership.
Academic Software helps institutions take this step with confidence. Through Mila and the broader Academic Software platform, schools and universities gain a secure, governed environment for AI that protects data, controls costs, and ensures every student has equal access to the tools shaping the future of learning.
