AI is usable at institutional scale when it is controllable.
At a university it is not enough that an AI solution works. You need to know which data it can reach, who may use it, what it may do, how it can be checked, and which rules apply to it.
We fit GoSchool's solutions to those institutional requirements.
Risk is determined by the use.
A learning assistant answering from course material, an internal administrative knowledge search, and an AI system that assesses people or supports decisions carry very different requirements.
So we do not start from a single general “AI policy”.
- what task the AI performs
- which data it can reach
- who uses it
- what consequences its answers or decisions may have
- whether human review is needed
- which institutional and legal requirements apply to it
Who can reach what is not decided by the AI.
Permissions
- institutional identity
- SSO
- roles
- course
- organisational unit
- specific data sources or functions
The university can determine
- which AI functions may be used
- which data may be used
- which models may be connected
- what operations an agent may perform
- where human approval is required
Institutional data is not automatically AI data.
When designing an AI integration we treat separately the question of what information the AI needs to see in order to do its job.
Our principle is to minimise the access required.
- reaching only the material of a given course
- using only one specified institutional data source
- excluding personal data
- access bound to a role
- separate authorisation for sensitive operations
The specific data-handling and operational architecture is worked out together with the institution and the use case.
Not every task should be automated.
We fit the AI's role to the risk of the task. Where the consequences warrant it, the AI is not the final decision-maker but supports a person's work.
- a source of information
- an assistant
- a suggester
- part of a workflow
- or, in certain cases, an agent that runs on its own
A student tutor can answer a question about course material on its own.
An administrative agent can prepare a process.
A decision with significant consequences may require human review and approval.
The institution has to understand what the system does.
When designing an AI solution we aim to make the following traceable for the institution:
- which AI model runs behind it
- which data sources it uses
- which system it connects to
- what operations it may perform
- what access it holds
- where human control happens
Depending on the system and the use case, logging and auditability can also be part of the solution.
We do not tie the university to one model or one deployment.
The right technical solution depends on the use case, the data-handling requirements, the model capabilities needed, the institution's existing infrastructure, and cost and operational expectations.
- the use case
- the data-handling requirements
- the model capabilities needed
- the existing institutional infrastructure
- cost and operational expectations
- a managed cloud service
- more private infrastructure
- a model chosen for institutional requirements
- an on-premise solution where justified
We do not assume that every institution needs the same architecture.
For the AI Act too, the specific application is what counts.
The EU AI Act applies risk-based regulation.
The classification of an AI system is therefore not determined merely by its being used in education or at a university, but primarily by what it is used for and what effect it may have on those concerned.
Certain educational applications — for example AI systems determining access, admission or the assessment of student performance — may fall into the AI Act's high-risk category. Different requirements may apply to other applications.
So for every institutional rollout we start from the specific use case, not from a general risk label.
- the system's purpose
- the group of users
- the data involved
- the decisions the system makes or supports
- the need for human oversight
- the regulatory requirements applying to that use case
Responsible AI adoption is not only a technical task.
The people using an AI system also have to understand its possibilities and its limits.
That matters especially at a university, where students, instructors, administrative staff, leadership and IT specialists use the same technology for very different purposes.
- AI training for teaching staff
- staff training
- leadership workshops
- use-case-specific preparation
- establishing AI governance
- drawing up usage guidelines
AI literacy is an institutional obligation that also appears in the EU AI Act for organisations operating and using these systems.
Governance is not added to the system at the end of the project.
For a new AI use case we work through these at the start of design:
What do we want to achieve?
What is the real problem, and does it need AI at all?
What does it need to reach?
Which data and which system functions does the task require?
What can it do on its own?
Where is a suggestion enough, where may it act, and where is human control needed?
Who may use it?
Which roles and permissions are required?
How can it be checked?
What logging, traceability or oversight is warranted?
How do we roll it out?
We try it in a pilot, measure it, and scale only what genuinely works.
Is there an AI use case you need to solve in an institutional setting?
Let's look together at its technical, data-handling and organisational conditions.