Most AI risk at a university does not start with a hacker. It starts with a student, a faculty member, or a researcher copying something out of the learning management system and pasting it into a personal AI account, where every safeguard written into the institution's enterprise licenses no longer applies. In this episode of the Changing Higher Ed® podcast, Dr. Drumm McNaughton speaks with Dean Scontras, Vice President of SLED (State, Local Government, and Education) at Island. The conversation covers the three AI issues facing presidents: academic integrity, compliance around sensitive data, and responsible AI use aligned with institutional guidelines and mission. Scontras has spent his career bringing new security and identity technology into state government and higher education, with prior public sector leadership roles at Duo, Auth0, and Wiz. He explains why the visibility an institution needs is about safety rather than policing, why AI has become a board-level decision with more stakeholders than the CISO alone, and why a policy without the tools to enforce it cannot be enforced. This conversation is especially relevant for presidents, boards, provosts, CIOs, and research leaders deciding how much AI to allow, where to allow it, and how to enforce the line they draw. Topics Covered Why there is no single definition of academic integrity when AI policies vary by college, department, and professor Shadow AI and the first step of seeing which AI tools are in use, by whom, and with access to what data How personal AI accounts bypass the protections of sanctioned enterprise licenses Compliance exposure for CUI and CMMC-governed research data Reputational, financial, and research-funding risk from AI-related breaches The roles of state governments, technology firms, and institutions in AI safety Whether institutions should standardize on a single sanctioned AI platform Real-World Examples Discussed One institution reporting a roughly 30% increase in test scores, and a Berkeley study Scontras cites on a rise in A grades R1 and R2 research data governed by CUI and CMMC controls, where an unsanctioned AI tool can circumvent existing compliance A blog post by Auburn's CIO, "The Phantom Menace," on how personal AI use undoes enterprise license protections States passing AI policy, then asking what technology stack will implement it The California State University system contracting with a single AI vendor Three Key Takeaways for Higher Education Leadership Establish an AI policy or playbook first. Every control depends on knowing what the institution allows, for whom, and where. Make sure the technology can implement the policy. A "no AI" rule without visibility into what tools are in use and what data they reach cannot be enforced. Educate users and the board, and partner with companies whose goals align with AI safety. AI decisions now involve more stakeholders than any single officer. Read the transcript: https://changinghighered.com/ai-governance-in-higher-education/ #AIinHigherEducation #HigherEducation #ChangingHigherEdPodcast