A licensing agreement is not a campus-wide AI strategy

Higher education’s Shadow AI problem is changing.

The first wave was easy to recognize: faculty, staff, and students using public generative AI tools without institutional oversight. Today, many colleges and universities have responded with Microsoft Copilot licenses, ChatGPT Edu agreements, Gemini access, or other approved platforms.

That progress matters.

But an enterprise license does not eliminate Shadow AI, and it does not create an institutional AI strategy.

The next wave is more complex: a growing portfolio of licensed copilots, departmental platforms, embedded AI features, specialized research tools, custom agents, and individual subscriptions operating without a common governance model. The products may be approved, or at least known, but the institution still lacks a complete view of which models are being used, what data they can access, how much they cost, and who is accountable for them.

This is Shadow AI at an institutional scale.

When approved AI still creates fragmentation

A licensing agreement gives a defined group access to a particular product. Strategy addresses a larger set of questions:

  • Who should have access, and how should access differ by role?
  • What institutional data can each tool or model use?
  • Which models are appropriate for learning, research, administration, and operations?
  • How are identity, permissions, retention, auditability, and compliance managed?
  • Who approves, monitors, and retires AI agents?
  • How does the institution understand usage and control costs across departments?
  • How can specialized use cases be supported without creating another isolated technology stack?

No single Copilot, chatbot, or model provider answers all of those questions.

Selecting one enterprise AI product can create a false sense of governance while departments keep adopting tools that better fit their local needs.

That behavior is understandable. Researchers need capabilities that general-purpose assistants may not provide. Faculty want tools suited to teaching and course design. Student services teams need experiences grounded in institutional information. Administrative units want workflow automation.

When the centrally approved option cannot meet those needs, or is not available to everyone, users find alternatives.

The result is tool and vendor sprawl: overlapping capabilities, inconsistent controls, duplicated spending, fragmented support, and multiple paths through which institutional data may reach AI systems.

Four gaps CIOs should address

For CIOs, the objective should not be to force every use case into one product.

It should be to establish an operating model broad and useful enough that departments do not need to work around it.

Four gaps deserve immediate attention:

  1. Whole-campus access

AI access limited to select employee groups leaves students, adjunct faculty, researchers, academic support teams, and operational staff to find their own tools. A campus-wide approach should provide an approved foundation while allowing access and capabilities to vary by role.

  1. Institutional data control

CIOs need to know how prompts, files, research materials, student information, and operational data are processed. That includes where processing occurs, whether information is retained or used for model training, who can review activity, and how institutional security and compliance policies are enforced.

  1. Visibility and accountability

An institution cannot govern what it cannot see.

IT leaders need visibility into models, agents, data connections, owners, usage, and costs. Every production AI capability should have an accountable owner, an approved purpose, an auditable history, and a defined lifecycle.

  1. Model and vendor flexibility

No single model, vendor, or product experience will meet every need across a university. Institutions need the ability to select models based on use case, risk, performance, and cost without rebuilding identity, security, and governance controls each time the market changes.

From AI products to an AI operating model

A campus-wide AI strategy brings these requirements into a common operating model. It connects role-based access, an approved model catalog, institutional data policies, agent lifecycle management, audit trails, retention controls, and usage reporting. It also creates a consistent path for departments to propose and deploy new use cases without building separate governance structures.

Most importantly, this approach balances control with enablement.

If governance only restricts access, it will drive more Shadow AI. The approved path must be secure, but it must also be useful, flexible, and accessible enough to earn adoption.

From individual use cases to a shared AI foundation

George Mason University offers a practical example. Working from an established governance framework and defined use cases, the university launched PatriotAI, a university-managed platform powered by nebulaONE® on Microsoft Azure. Six specialized AI agents went live in three months to support needs spanning general assistance, research, learning, course design, student services, and food-insecurity resources.

The significance is not simply that George Mason deployed six agents.

It is that the university created a shared foundation through which new use cases could be vetted, developed, and delivered. Its internal task force continues to evaluate ideas, while the platform gives the campus community a unified, institutionally managed experience.

A governed foundation, not another AI silo

nebulaONE® was built for this operating model. Deployed in Microsoft Azure and using Azure AI Foundry, it provides a governed gateway to multiple models, role-based access, agent workflows, auditability, retention controls, institutional data integration, and centralized usage and cost visibility.

The goal is not to replace every AI product or dictate one model for every task.

It is to give CIOs a common control layer that can support broad institutional access while reducing the pressure for each department to acquire and govern its own AI stack.

The strategic choice is no longer between adopting AI and avoiding it. AI is already spreading across the institution. The choice is whether that growth produces a patchwork of departmental tools and vendors or a flexible, governed capability aligned with institutional priorities.

An enterprise license may be part of that strategy.

It is not the strategy.

Ready to move from fragmented AI adoption to a governed campus-wide foundation? Request a nebulaONE® demo.

Brian Dreyer
Author

Brian Dreyer is Senior Director of Product Management at Cloudforce, where he leads with a deep commitment to human-centered design and technology-driven innovation. A seasoned product leader, Brian brings a unique blend of product management and product marketing expertise, enabling him to translate complex customer challenges into both compelling products and clear, differentiated market positioning. Brian’s diverse skill set bridges product management, product marketing, and user experience. He has led go-to-market strategies, overseen major software redesigns, and worked hands-on in user research while collaborating closely with UX design teams. This multidisciplinary approach allows him to consistently deliver user-centric products that drive customer value, accelerate adoption, and fuel long-term growth.

Recommended for you.