Illustrative worked example
Campus generative AI policy review
A public, source-linked demonstration of the EX MULTIS review record
Bottom line
Adopt a 90-day controlled pilot and an interim policy, but do not authorize regulated-data workflows until provider terms, institutional controls, and applicable law have been reviewed.
Conditions for approval
- 01Define permitted, restricted, and prohibited uses by learning context rather than imposing one rule on every course.
- 02Keep instructors responsible for course-level expectations, assessment design, and disclosure requirements.
- 03Prohibit student records, confidential research, credentials, and other sensitive data in unapproved AI services.
- 04Require human review of consequential outputs and independent verification of material citations.
- 05Provide accessible alternatives, training, notice, and a process for students to question or appeal AI-assisted decisions.
- 06Measure learning value, citation defects, privacy incidents, support demand, and unequal access before broader adoption.
01 · Assignment and route
The question and decision boundary
Should North Valley Public University adopt a campus-wide generative AI policy for teaching and learning in the 2026-27 academic year?
Constraints supplied to the review
- Public university setting; federal baseline considered, but state law and local policy were not supplied.
- Teaching and learning only; admissions, employment, discipline, grading automation, and clinical uses are outside scope.
- No student personally identifiable information may enter an unapproved service during the pilot.
- Faculty retain academic authority, and final institutional approval remains human.
Higher education policy, privacy, academic integrity, accessibility, and AI governance
Elevated institutional review because the policy affects students, faculty, data handling, and assessment
Applicable law and official guidance, then institutional policy and pedagogical evidence
Policy analyst, adversarial reviewer, source verifier, and human decision owner
No regulated-data use until privacy, security, procurement, and legal owners approve the provider
02 · Independent work
Separate analyses before synthesis
Each role formed its position before reconciliation. Separation reduces cross-anchoring; it does not guarantee statistical independence or eliminate shared error.
Adopt with controls
A controlled policy can replace inconsistent informal use with common disclosure, verification, privacy, and accountability rules while leaving course-level judgment with instructors.
Delay broad authorization
A campus-wide launch could normalize unsafe data handling, unequal access, unreliable citations, and unclear enforcement before provider contracts and support capacity are ready.
Evidence supports governed experimentation, not blanket approval
The reviewed authorities support human-centered governance, documented risk management, privacy controls, and continuing evaluation. They do not prove that one campus policy will improve learning outcomes.
03 · Claim ledger and fact check
Material claims remain attributable
| Claim | Final status | Evidence record |
|---|---|---|
| FERPA categorically prohibits a university from using a third-party AI service with education records. | Contradicted | U.S. Department of Education materials describe circumstances in which a contractor or service provider may qualify under the school-official exception if the required conditions are met. Sources: S4, S5 |
| The institution should define human responsibility and document AI governance decisions. | Supported | NIST describes governance, documented roles, transparency, human review, and ongoing risk management as central practices. Sources: S1 |
| One identical classroom rule should apply across every discipline and assignment. | Disputed | The sources support coherent institutional governance while also emphasizing context, human agency, pedagogical suitability, and risk-based implementation. Sources: S1, S2, S3 |
| Faculty approval alone is enough to permit student records to be entered into any AI tool. | Contradicted | FERPA rules and Department guidance impose conditions beyond an individual instructor's approval, and other laws or institutional requirements may also apply. Sources: S4, S5 |
| A pilot should include measurement, monitoring, and a human decision before expansion. | Supported | NIST frames AI risk management as continuous and calls for measurement and governance across the lifecycle; education guidance emphasizes human-centered implementation and evaluation. Sources: S1, S2, S3 |
Correction caused by fact-checking
The roles agreed—and were still wrong.
S4: FERPA regulations, including 34 CFR 99.31 · S5: Responsibilities of Third-Party Service Providers under FERPA
04 · Dissent and human judgment
Material disagreement stays visible
Policy timing
Majority: Adopt an interim policy alongside a controlled pilot.
Minority: Delay any adoption until approved-provider and accessibility reviews are complete.
Uniformity across courses
Majority: Use institution-wide disclosure and privacy baselines.
Minority: A single disclosure rule may be too rigid for different disciplines and assignments.
Approve a 90-day pilot and interim policy; do not approve regulated-data workflows.
Illustrative decision owner: Provost with CIO, privacy, accessibility, faculty, and student representatives
Return for a stop, revise, or expand decision after the pilot evidence is reviewed.
Pilot measures- Material citation-defect and correction rate
- Privacy, security, and academic-integrity incidents
- Student and faculty usefulness, accessibility, and support demand
- Differences in access or outcomes across courses and student groups
- Frequency and rationale for human overrides
05 · Limits and source map
What remains unresolved
- No state law, collective-bargaining agreement, accreditation rule, disability accommodation record, or existing university policy was supplied.
- No specific AI provider contract, retention schedule, training-use term, security assessment, or data-residency commitment was reviewed.
- The cited sources support governance principles and legal boundaries; they do not establish that this pilot will improve learning outcomes.
- Source status and product capabilities can change. Material conclusions must be rechecked at the time of an actual decision.
Source map
- S1 · NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)National Institute of Standards and Technology · January 2023
Used for: Governance, documentation, human roles, measurement, monitoring, and lifecycle risk management
- S2 · Artificial Intelligence and the Future of Teaching and LearningU.S. Department of Education, Office of Educational Technology · May 2023
Used for: Human-centered educational implementation, policy development, opportunities, and risks
- S3 · Guidance for generative AI in education and researchUNESCO · September 2023; page updated January 2026
Used for: Privacy, human agency, inclusion, validation, policy development, and pedagogical suitability
- S4 · FERPA regulations, including 34 CFR 99.31U.S. Department of Education, Student Privacy Policy Office · Current public regulation text reviewed September 2026
Used for: Conditions under which prior consent is not required and requirements applying to outsourced service providers
- S5 · Responsibilities of Third-Party Service Providers under FERPAU.S. Department of Education, Privacy Technical Assistance Center · Department guidance
Used for: School-official exception, direct control, authorized purposes, redisclosure limits, and contracting practices
