Building AI we can stand behind. APEI is increasing its capability to meet AI-accelerated threats while enabling responsible AI adoption across the institution, governed through the structures and policies already in place.
AI is reshaping the threat landscape and APEI's own operations at the same time. The governance programme responds to both: strengthening defences against AI-accelerated attacks while giving the business a safe, consistent way to adopt AI.
Charter presented to the Board with no objection. The committee draws stakeholders from across the business so AI decisions are made with the right input, not in isolation.
19 existing policies identified for AI-specific updates, integrated into the current security library rather than written as a separate AI rulebook.
Deployer classification confirmed. Obligations for use-case documentation, risk assessment, and human oversight feed directly into the policy programme.
A like-for-like MSSP replacement at reduced cost, moving to a more mature security operations platform. The capability uplift is the point: stronger detection and response against AI-driven threats.
Behavioural AI on M365 that catches what Defender misses. The POC quantified the gap: targeted attacks reaching executives and finance teams that traditional controls let through.
Every critical pull request is auto-scanned for OWASP issues, secrets, and CVEs, with critical findings blocking merge automatically. Beyond scanning, Claude is reducing GRC cycle time on policy, risk assessment, and control review work.
| Policy | Gap Summary | Owner | Status |
|---|---|---|---|
| AI Acceptable Use | No current policy covering AI tool usage by staff and faculty | CISO | Not Started |
| AI Risk Assessment Framework | No formal risk tier classification for AI systems | InfoSec | Not Started |
| Data Classification for AI | Existing classification does not address AI training or inference data | InfoSec | Not Started |
| AI Incident Response | Existing IR playbook has no AI-specific scenarios | InfoSec | Not Started |
| Security Awareness for AI | No AI-specific guidance in current awareness programme | InfoSec | Not Started |
| Policy | Gap Summary | Owner | Status |
|---|---|---|---|
| Identity & Access for AI | No RBAC requirements specific to AI system access | IT / InfoSec | Not Started |
| Vulnerability Management | Process not updated for AI system and model vulnerabilities | InfoSec | Not Started |
| IR Playbooks | No AI-augmented threat scenarios in current playbooks | InfoSec | Not Started |
| Email Security | Policy does not reflect AI-crafted phishing patterns | InfoSec | Not Started |
| Generative AI Usage | No institutional position on GenAI for coursework or productivity | Academic Affairs / CISO | Not Started |
| AI Model Governance | No lifecycle management policy for AI models in production | IT / InfoSec | Not Started |
| AI Ethics Review | No ethics review process prior to AI deployment | CISO / Legal | Not Started |
| AI Audit & Logging | No requirement for audit trails on AI-assisted decisions | InfoSec / Compliance | Not Started |
| Policy | Gap Summary | Owner | Status |
|---|---|---|---|
| Student Data & AI | FERPA obligations not explicitly mapped to AI data flows | Legal / Registrar | Not Started |
| AI Third-Party Risk | Supply chain risk not assessed for the AI vendor stack | Procurement / InfoSec | Not Started |
| AI Continuity & Resilience | BCP/DR does not address AI system dependencies | IT / InfoSec | Not Started |
| AI Change Management | Process not updated for model updates or retraining | IT | Not Started |
| AI in HR Processes | No guidance on AI use in hiring or workforce decisions | HR / Legal | Not Started |
| Policy | Gap Summary | Owner | Status |
|---|---|---|---|
| AI Sustainability | No policy addressing the environmental impact of AI compute usage | Facilities / IT | Not Started |
Primary governance framework. Structures risk management across the Govern, Map, Measure, and Manage functions.
Student data compliance. AI data flows touching student records must preserve FERPA obligations.
Defence-adjacent use cases. Controls applied where AI systems touch CUI or federal programmes.
Deployer classification confirmed. August 2026 compliance deadline on track.
Items under consideration for Q3 and Q4 2026. No commitments implied.
The charter establishes the AI Governance Committee under authority of the CISO, providing cross-functional oversight of AI tool requests, vendor deployments, and use cases before they reach production. It has been presented to the Board with no objection. The committee deliberately draws stakeholders from across the business so AI decisions reflect legal, academic, operational, and risk perspectives, not just security.
Rather than a standalone AI rulebook, AI controls are being integrated into the existing security library. 19 policies have been identified for AI-specific updates, sequenced across four phases by risk priority. Establishing the foundation first lets AI controls align with current security, privacy, and risk processes.
APEI has confirmed its classification as an AI deployer under the EU AI Act, with the August 2026 deadline on track. As a deployer, obligations centre on use-case documentation, risk assessments, and human oversight, feeding directly into the RMF Map and Govern functions and the policy programme.
CrowdStrike is under negotiation as a like-for-like replacement for the current MSSP, Compuquip, at reduced cost. The move consolidates SIEM, MDR, IVM, and EDR onto a single, more mature platform. The 99% AI detection and sub-30-minute response figures are CrowdStrike platform capabilities, representing the uplift APEI gains on transition.
A proof of value on M365 targeting the protection gap beyond Microsoft Defender. The POC identified 72 targeted attacks during the assessment period, with executives and finance teams the primary targets, consistent with attackers focusing on users with sensitive access or decision-making authority.
Claude is deployed in the CI/CD pipeline, scanning every critical pull request for OWASP issues, secrets, and CVEs, with critical findings blocking merge automatically. Beyond security scanning, it is compressing GRC cycle time on policy, risk assessment, and control review work from weeks to hours.