Campus AI Development Why it matters

01 — Why it matters

More than a technical choice

Choosing an approach can look like a matter of engineering taste. On campus it shapes what students learn, whether tools are fair and secure, what the institution can sustain, and whether it can meet the obligations it already has.

  1. 01Anyone can build nowThe old gate, a developer in IT, is gone. Business users, faculty and students can produce working software in an afternoon.
  2. 02The law follows what software does, not how it was builtA vibe-coded form that collects student IDs is under FERPA, just as an enterprise system is. No law exempts a prototype.
  3. 03The approach decides what you can proveCompliance is shown with evidence: what the code does, who reviewed it, what it touched. Specs, tests, review and logs produce that evidence; a chat history usually doesn’t.
  4. 04Obligations arrive without noticeThe day a prototype gets real users or real data, new rules apply, whether or not anyone decided to move it to production.

What’s at stake

Nine reasons the conversation matters

Law and policy are the most visible reasons, but rarely the first ones people feel. These are the stakes that show up in classrooms, labs and offices.

01

Students and learning

Whether students learn to build, or only to prompt, and whether assessment still shows what they can do.

Teaching practices →
02

The people a tool serves

Advising flags, chatbots and reports act on real people. Accuracy, fairness and accessibility decide whether they help or harm.

Enterprise scenario →
03

Security

Generated code often carries vulnerabilities and invented dependencies, and agents with credentials can act at machine speed.

Security evidence →
04

Research integrity

Findings are only as credible as the code behind them. Reproducibility and provenance are part of the method.

Research scenario →
05

Cost and sustainability

Every tool someone builds is a tool someone must maintain. Orphaned apps, duplicate efforts and unbudgeted token use add up.

Operating controls →
06

Equity of access

If only well-funded or technical units get licensed tools and training, the capability gap widens across campus.

Adoption →
07

Trust and reputation

One leaked record or wrong number in a board report can set back confidence in every AI effort, and public institutions answer to taxpayers.

Legal triggers →
08

Roles and the workforce

IT moves from gatekeeper to platform provider; staff and faculty become builders. Both need new skills and support.

Platforms →
09

The cost of caution

Over-governing has costs too: backlogs, workarounds and personal accounts where no controls apply. Proportion matters.

Proportionality →

Data classification

The data sets the ceiling

More than anything else, the sensitivity of the data decides which AI tools may be used, which approach fits and how much governance applies. Most institutions use a scheme like the four levels below.

  1. Level 1 · Low sensitivity Public Information meant for anyone.
    ExamplesCourse catalog, published research, public web pages, press releases
    AI toolsAny campus-approved AI tool
    Data control tierT1
  2. Level 2 · Low to moderate sensitivity Internal For campus use; little harm if disclosed.
    ExamplesInternal procedures, draft policies, non-sensitive meeting notes, de-identified aggregate figures
    AI toolsCampus-licensed tools under an institutional contract
    Data control tierT2
  3. Level 3 · Moderate sensitivity Confidential Protected by law, contract or policy; real harm if disclosed.
    ExamplesStudent education records (FERPA), employee records, financial aid data (GLBA), unpublished research, donor records
    AI toolsOnly tools approved for this level, with no-training and retention terms; data steward approval
    Data control tierT3–T4
  4. Level 4 · High sensitivity Restricted Severe harm or specific regulatory duties if disclosed.
    ExamplesSocial Security numbers, health information (HIPAA), payment card data (PCI DSS), export-controlled data, CUI, credentials, identifiable human-subjects data
    AI toolsApproved enclaves or locally hosted models only; usually barred from general AI tools
    Data control tierT4–T5

Rules of thumb

  1. 01Use your institution’s schemeNames and counts vary: three, four or five levels, or Low/Moderate/High. Map this guide to the scheme your security office publishes.
  2. 02Classify by the most sensitive elementOne Social Security number makes the whole dataset restricted.
  3. 03Combining data can raise the levelTwo internal datasets joined on student ID can produce confidential records.
  4. 04Outputs inherit the classificationA summary, report or generated code built from confidential data is confidential until reviewed.
  5. 05Prompts and logs are data tooWhat goes into a prompt, and what the tool keeps, is classified like any other copy.

And the law

What kicks in, and when

Obligations attach to what the software touches and who it affects. Each trigger below lines up with a lens in the scenario framework, so the questions on each scenario page double as a legal screen.

  1. 01 · When It touches student education records
    In forceData
    FERPA A vendor or tool that receives personally identifiable information from education records must qualify under the school-official exception: an institutional function, under the institution’s direct control, with no unauthorized redisclosure. Consumer AI accounts generally can’t meet this; contract-covered tools can.
  2. 02 · When Students, staff or the public use it
    2027 / 2028Audience
    ADA Title II, Section 504 Public institutions’ web content and mobile apps must meet WCAG 2.1 AA under the DOJ’s 2024 rule. An April 2026 interim final rule moved the deadlines to April 26, 2027 for larger entities and April 26, 2028 for smaller ones. Private institutions face Title III and Section 504 obligations without a set technical standard.
  3. 03 · When It handles financial aid or student financial data
    In forceData
    GLBA Safeguards Rule Institutions in federal student aid programs must keep an information security program covering customer financial information, including risk assessment, access controls and oversight of service providers.
  4. 04 · When It handles health information
    In forceData
    HIPAA Covered components such as academic medical centers and some clinics fall under HIPAA. Student health records at a campus clinic are often education records under FERPA instead; the privacy office decides which applies.
  5. 05 · When It uses regulated research data
    In forceData
    Common Rule, export controls, CUI rules IRB-approved protocols, data use agreements, export-controlled technical data (EAR, ITAR) and controlled unclassified information (NIST SP 800-171, and CMMC for defense contracts) each restrict which tools and environments may process the data.
  6. 06 · When It makes or shapes decisions about people
    From Jan 2027 (CO)Audience
    Civil rights law; state automated-decision laws Admissions, aid, discipline, hiring and advising flags are subject to Title VI, Title IX, Section 504 and the ADA however they are built. Colorado’s replacement AI law (SB 26-189) adds notice, human-review and record-keeping duties for consequential automated decisions from January 1, 2027.
  7. 07 · When It serves people in the EU
    2026 / Dec 2027Audience
    GDPR, EU AI Act GDPR covers personal data of people in the EU, such as applicants and study-abroad students. The AI Act’s Article 50 transparency rules (for example, telling people they are talking to an AI) have applied since August 2, 2026. Its high-risk rules, which list education uses such as admissions and assessment, apply from December 2, 2027.
  8. 08 · When It collects data from children under 13
    In forceData
    COPPA Pre-college programs, camps and K–12 outreach that collect data from children online need verifiable parental consent and limits on data use.
  9. 09 · When The code is released, sold or reused
    Copyright, licenses, institutional IP policy The U.S. Copyright Office’s 2025 report says purely AI-generated material isn’t protected without human authorship. Open-source licenses and the institution’s IP policy decide what may be released, and by whom.
  10. 10 · When A public institution keeps prompts, outputs or logs
    Varies by stateLifespan
    Public records and retention laws At public institutions, AI prompts, outputs and agent logs created for institutional business may be public records subject to disclosure requests and retention schedules. Check with the records officer.
  11. 11 · When It is bought or funded
    Procurement rules, grant terms Institutional and state procurement rules, contract terms on data and training, and federal grant conditions apply. The Department of Education’s July 2025 guidance says federal grant funds may support AI uses that fit the program and comply with existing law.
  12. 12 · When It runs on institutional systems
    From day oneReach
    Institutional policy Acceptable use, data classification, information security, IP and academic integrity policies apply from the first prompt, before any law does.

This is an orientation, not legal advice. Status as of October 2026; dates and scope change. Confirm with counsel, the privacy office and the accessibility office before relying on it.

Key dates

The calendar to plan against

The U.S. has no comprehensive federal AI statute. A December 2025 executive order (EO 14365) seeks to challenge state AI laws, but an executive order can’t preempt them on its own, and it leaves state government use and procurement of AI alone. For public institutions, state rules on government use of AI may apply directly.

  1. Feb 2, 2025 · in effectEU AI Act prohibited practices and AI literacy provisions begin
  2. Aug 2, 2026 · in effectEU AI Act transparency rules (Article 50) apply
  3. Jan 1, 2027Colorado automated-decision law (SB 26-189) takes effect
  4. Apr 26, 2027ADA Title II web rule: public entities of 50,000+
  5. Dec 2, 2027EU AI Act high-risk rules, including education uses
  6. Apr 26, 2028ADA Title II web rule: smaller public entities

Where the approach comes in

Same law, different evidence

No band is exempt. What changes along the continuum is how easily you can show that the software complies.

Bands 01–02Vibe coding, AI-assistedThe same laws apply. In band 01, keep regulated data out entirely. In band 02, use only contracted tools approved for that data; the developer’s line-by-line review becomes the evidence.
Bands 03Agentic with reviewReview and version history start to produce evidence. Scoped credentials limit what an agent can reach.
Bands 04–05Spec-driven, multi-agentSpecs, traceability and audit logs let you show what the software does, which is what regulators, auditors and courts ask for.

Next: see how these obligations show up for eight kinds of builders, then work through the governance checklist.

Sources for this page

  • U.S. Department of Justice. (2024). Nondiscrimination on the basis of disability; accessibility of web information and services of state and local government entities (ADA Title II final rule); interim final rule extending compliance dates (April 2026). ada.gov
  • U.S. Department of Education, Student Privacy Policy Office. FERPA guidance on the school-official exception and online educational services. studentprivacy.ed.gov
  • U.S. Department of Education. (2025, July 22). Dear Colleague Letter on the use of federal grant funds for artificial intelligence. ed.gov
  • Regulation (EU) 2024/1689 (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI). eur-lex.europa.eu
  • Colorado SB 26-189, concerning automated decision-making technology (signed May 14, 2026). leg.colorado.gov
  • Executive Order 14365. (2025, Dec. 11). Ensuring a National Policy Framework for Artificial Intelligence.
  • U.S. Copyright Office. (2025). Copyright and Artificial Intelligence, Part 2: Copyrightability. copyright.gov