Campus AI Development Use case scenarios

Use case scenarios Discussion case 06 of 06

Discussion case 06

The vendor agent that arrived switched on

A routine release of the campus’s enterprise system turned on a new AI agent by default. It can read and update records across modules through the system’s integration account. Functional staff are already using it to fix data in bulk. No one in IT approved it.

A hypothetical composite for discussion, not an account of a real institution.

The tension

One viewSwitch it off until reviewedIt acts through a broad service account, nobody assessed it, and bulk changes to institutional records need change control.
Another viewGovern it in placeStaff find it useful, the vendor is already under contract, and switching it off loses goodwill and productivity while a review drags on.

Questions for discussion

  1. 01Does the existing vendor contract cover this feature’s data use?
  2. 02What should an agent be allowed to change without a human approving each change?
  3. 03How would you find and reverse a bad bulk update?
  4. 04Should vendor AI features require opt-in at your institution?
  5. 05Who owns the decision: the system owner, IT security or procurement?
What the framework suggests
  • Enterprise configuration is Track B on the platforms page.
  • Reach is the lens at stake: what it can write, and how much it could break.
  • Access and monitoring sit at T4; the registry should list vendor agents too.
Where reasonable people disagree
  • Default-on versus opt-in for vendor AI
  • How much review a contracted vendor feature needs
  • Whether staff who already used it did anything wrong