Having an AI Policy Isn’t the Same as Governing AI
Nearly every institution has written the policy. Far fewer have built governance that reaches the instructor, the department head, and the procurement officer where the actual decisions get made — and
Most institutions have written the AI policy. They have named the committee, published the principles, and had the thoughtful conversation about safety, privacy, and academic integrity. On paper, higher education’s governance problem looks close to solved.
It is not, and the reason is worth stating precisely. A policy document is not governance. Governance is whether that policy becomes something an instructor can act on before class, something a department head can apply when a vendor emails a demo link, something a procurement officer can enforce before a contract is signed. That translation — from principle on a page to decision in a workflow — is where governance is actually won or lost. And it is where most institutions have done the least work.
Even the vendors selling into this moment know the tool is not the hard part. Matt Jubelirer, who leads education marketing at Microsoft, put it plainly in response to my questions: “AI adoption is fundamentally a people-and-process transformation challenge, not simply a technology deployment challenge.” Most institutions can acquire the tools. The harder work — the culture, the governance, the operational models that let AI be used consistently and responsibly — is the part that does not come in the license.
If that is true, then the useful question is not which principles to adopt. Nearly everyone has adopted the principles. The useful question is: what sequence moves an institution from a governance document to governance in practice? That is what the AI-Ready Institution framework is built to answer, and it is where the rest of this piece goes. But first, the test this newsletter always applies: who can actually prove their governance works? When I analyzed 139 AI use cases in higher education, only 24% could define a metric for success. So the standard is not whether a governance approach sounds right. It is whether the institution can show the number behind it. Two very different institutions can.
Florida State: Governance of Data as the Precondition for Everything Else
Florida State approached the same problem from the data layer. Its ITS organization consolidated institutional data from 47 separate source systems into a single governed analytics platform — an 11x increase over its prior environment — and cut the turnaround on a staff data request from as long as 90 days down to about five. That is a 95% reduction, and it is a governance achievement before it is an efficiency one: the institution now knows where its data lives, who can reach it, and under what controls, which is the precondition for letting AI touch that data safely at all.
On the teaching side, FSU built AI directly into the graduate data science capstone, where students use Microsoft’s Copilot Studio to develop their own tools against real datasets — learning to work inside a governed environment rather than around one. The operational win and the pedagogical one share a spine: govern the data first, and the rest of the AI strategy has somewhere safe to stand.
What Florida State can prove:
• 47 source systems consolidated into one governed platform — an 11x increase in integrated data.
• ~95% faster on staff data requests — from up to 90 days down to about five.
• A governed environment students learn to build inside, in the graduate data science capstone.
FSU is a large public research university with an IT organization to match. The obvious objection from a smaller institution is that this is a rich-school story. It is not — and the clearest proof is a mid-sized public community college I have been advising, described here without identifying detail because the pattern is what transfers, not the name.
A Community College: The Same Governance, Without the Budget
This institution had what most institutions have: a set of good instincts, a draft policy, and faculty already using AI faster than the policy could keep up. What it did not have was Florida State’s infrastructure or a large central IT team. So it governed at the altitude it could actually reach — the individual tool, the individual course, the individual data decision — and that turned out to be the right altitude anyway.
Rather than wait for a comprehensive policy, it stood up a tool-and-use review process that gave a department chair a clear, repeatable way to evaluate a specific tool for a specific course. It made the data-classification decision a prerequisite — no tool cleared review until someone answered which tier of institutional data it would touch — which is what kept an enthusiastic faculty pilot from becoming a FERPA problem. And it built the review body and the faculty training at the same time, so the people being governed were also being equipped. None of this required a supercomputer or a seven-figure budget. It required sequence and authority, which any institution has.
Florida State and this community college are not running the same play at the same scale. One consolidated 47 data systems; the other governs a handful of tools a semester. Michigan’s Maizey platform, which I have written about before, shows a third version of the same principle operating at full-university scale. But the through-line across all three is identical: governance is not a policy the institution wrote. It is a set of controls embedded where the work happens — and that is why each can point to something real, from FSU’s 95% to a community college’s clean pilot that did not leak a single record.
It is the same lesson I documented from the student-support side, where one large public university’s AI deployment could report resolution rates, staff hours saved, and registration lift across hundreds of thousands of messages — because it, too, refused to send anything it could not measure. Governance that lives in the workflow generates evidence. Governance that lives in a binder generates a false sense of readiness. The question, then, is not whether to move governance into the workflow. It is how — in what order, with what structure, and how you would know you had done it.
Coming up on the Use Case Lab Live — Thursday, July 30, 12:00 PM ET: Brett Pollak of UC San Diego on TritonGPT — the AI platform UCSD built on its own supercomputer rather than buying off the shelf, precisely so it could keep control of its own data. It’s the governance-of-data question this issue raises, taken to its furthest edge. Live session for paid subscribers; upgrade to join us in the room.
Below, for paid subscribers: the operational bridge from a governance document to governance in practice — a sequenced playbook drawn from the AI-Ready Institution framework, the cabinet-ready templates that make each step enforceable (the review-body charter, the FERPA-aligned data-tier definitions, the procurement-gate language), and a one-question diagnostic that locates your own institution on the path. It is the difference between reading about governance and installing it.


