Your Staff Is Already Using AI. Does Your Institution Know How?

Watch Video

Right now, on a campus somewhere, a financial aid counselor is asking ChatGPT to draft a response to an appeal. Down the hall, a registrar's office staffer is running a transfer credit question through Claude. Neither filed a ticket. Neither asked IT to vet the tool. This is Shadow AI, also known as BYOAI (Bring Your Own AI), and by most current measures, it's already the norm on college and university campuses, not the exception.

The scale of it is bigger than most leadership teams assume

More than half of higher ed staff, 56 percent, report using AI tools that their institution didn't provide for work-related tasks, according to EDUCAUSE's 2026 research on AI and work in higher education. A separate 2026 EDUCAUSE study found the number climbs even higher when the question is simply whether staff use AI at all: 94 percent of higher ed professionals reported using AI tools for work in the prior six months, while only 54 percent said they were aware of any institutional policy governing that use, per coverage of the EDUCAUSE findings. 

The gap here isn't awareness of AI. Staff clearly know it exists and clearly find it useful. The gap is visibility: institutions don't have a consistent picture of which tools are being used, by whom, or with what data.

Why banning it doesn't close that gap

The instinct to prohibit AI tools outright is understandable, and it's also the one response that consistently fails. Roundtable research from MIT's Center for Information Systems Research, conducted with more than 70 data and technology executives, lands on a simple reason: banning a tool doesn't stop staff from valuing what it does for them. It just removes the institution's ability to see it happening. The behavior doesn't disappear. It goes quiet.

Higher ed's own numbers back this up. Even though 77 percent of colleges and universities report having some level of AI strategy, only 30 percent consider AI and analytics preparedness a top institutional priority, and governance and compliance rank among the lowest priorities at just 27 percent, according to Campus Technology's analysis of the shadow AI threat. Strategy documents exist. Governance discipline mostly doesn't.

It's bigger than any individual chatbot

The instinct is to think of Shadow AI as "did someone open ChatGPT." That framing misses most of the problem. AI is now built directly into the tools staff already open every day: Microsoft's suite prompts users to let Copilot redesign a slide or summarize a spreadsheet, and a Google search returns an AI-generated summary before a single link. None of that requires downloading anything or asking permission. The real question isn't whether staff are using a chatbot. It's whether the institution has any line of sight into how AI, in any form, touches its data and its decisions.

Where the risk actually shows up

Shadow AI rarely looks dramatic. It looks like one department standardizing on the free tier of ChatGPT while the team next door works in Claude or Gemini, each producing output that's starting to sound noticeably the same, because nobody agreed on which tool to use or how. It looks like a staff member uploading a spreadsheet of student records to get a fast analysis back, which the tool genuinely does well, without stopping to ask a slower but more important question: where did that data just go, and does it include anything protected, personal, or confidential? The analysis is usually correct. The upload is the part nobody thought through.

The mistake institutions keep making

"The institutions we talk with are rarely deciding whether to ban AI or embrace it. The real work is building a governance model that protects student data and keeps critical thinking central to the learning experience, while accepting that staff and students are already using these tools every day."

Dana DeLapi, Director of Marketing, Doctums

Institutions tend to land on one of two extremes: shutting AI down entirely, or not addressing it at all. Neither holds up. The heavy-handed approach pushes use further out of view and gives an institution the illusion of control without the reality of it. Ignoring the issue leaves data governance, and academic integrity, to chance. 

What works sits in between: a governance model that accepts AI is already part of how work gets done, protects the data that moves through it, and still holds space for the critical thinking students and staff are there to build. That last part matters specifically in higher ed, in a way it wouldn't in most other industries. These are institutions built to teach people how to think, not just how to produce output faster.

A practical path forward

None of this starts with a policy document nobody reads. It starts with an honest inventory: which tools are actually in use, on which teams, touching which systems. From there, institutions can build usage guidelines that distinguish between free and paid tiers, since the two handle data very differently and that distinction is often the first thing that gets lost. Staff training matters as much as the policy itself; a rule nobody understands gets worked around the same way a ban does. And a governance structure spanning data security, operational systems, and how AI use gets documented gives an institution something concrete to point to when a board, an auditor, or an accreditor asks how AI is being managed.

This isn't a one-time project. It's an operating discipline, and the institutions that treat it that way will still have a defensible answer a year from now.

The human part doesn't go away

There's a broader shift underneath all of this: the institutions handling AI well aren't the ones removing people from the equation, they're the ones being deliberate about what AI should capture and what still needs a person's judgment. It's a distinction Doctums thinks about closely in how we build our own AI-enabled work, including through Doctums Extend.

AI tools can't replace the tacit judgment a consultant, or a faculty member, or a seasoned administrator brings to a decision. Shadow AI is what happens when that distinction gets lost by accident. Good governance is what happens when an institution draws it on purpose.

Where to start

If your institution doesn't have a clear picture of where AI is already being used, and by whom, that's the starting point, not the policy itself.

Ready to see where your institution stands?

Contact us to schedule your AI assessment.

Written by Doctums Staff