Information Security Programme · Q2 2026

AI Governance

Building AI we can stand behind. APEI is increasing its capability to meet AI-accelerated threats while enabling responsible AI adoption across the institution, governed through the structures and policies already in place.

3of 5
AI Maturity Stage
19
Policies Identified
3
Active Vendor Tracks
Aug 2026
EU AI Act Deadline
Executive Summary

Governance that keeps pace with both the threat and the opportunity

AI is reshaping the threat landscape and APEI's own operations at the same time. The governance programme responds to both: strengthening defences against AI-accelerated attacks while giving the business a safe, consistent way to adopt AI.

The Threat
AI is lowering the barrier for sophisticated attacks. In Q2, APEI saw 550+ spear phishing emails delivered past Microsoft Defender and 203 student account takeovers across the quarter. Sector breaches at Canvas and GitHub show even major platforms are exposed.
The Approach
Rather than a separate AI rulebook, APEI is integrating AI controls into the existing governance structure. 19 policies already in the security library have been identified for AI-specific updates, building on the foundation of acceptable use, information security, and data privacy.
The Committee
The AI Governance Committee brings stakeholders together from across the business, not just technology. AI tool requests, vendors, and use cases are reviewed with the right input from across the organisation rather than decided in isolation by Information Security.
The Outcome
A culture of responsible AI adoption across APEI. The goal is not compliance for its own sake, but ensuring every function understands the risks, applies consistent standards, and makes better decisions about how AI is used.
Programme Status
Where the programme stands today
Committee Charter
Approved
Charter Complete - Team In Assembly
Policy Integration
19 Policies
Across 4 Phases
EU AI Act
Aug 2026
Deployer · On Track
AI Maturity Stage
3 of 5
Governance
AI Maturity Journey
From a running start to governed scale
APEI entered this work with established compliance infrastructure already in place, giving the programme a foundation to build on rather than starting from scratch.
Stages 1 & 2 — Complete
The foundation is set. AI tool inventory complete, NIST AI RMF adopted as the primary framework, and structured rollout delivered across engineering, academic support, and operations. 32 employees trained through the Overclock Accelerator.
Stage 3 — Current
Formalising governance now. Charter approved and committee assembling. Policy programme in Phase 1 scoping. Enhancing observability and response tooling is the active thread, with three vendor tracks in flight.
Stages 4 & 5 — Planned
AI embedded into development workflows, student services, and business processes, followed by continuous measurement and AI observability loops across the enterprise.
Awareness
Stage 1
Tool inventory and acceptable use established
Adoption
Stage 2
Structured rollout across teams
3
Governance
Current
Charter, policy, and review process
4
Integration
Planned
Embedded in workflows and services
5
Optimisation
Planned
Measurement and observability loops
Active Initiatives
What is in flight, grouped by track
Each initiative supports the same theme: increasing capability to meet AI-accelerated threats while enabling safe adoption.
01 Governance & Compliance
AI Governance Committee
Approved

Charter presented to the Board with no objection. The committee draws stakeholders from across the business so AI decisions are made with the right input, not in isolation.

View detail
Policy Integration
In Progress

19 existing policies identified for AI-specific updates, integrated into the current security library rather than written as a separate AI rulebook.

19
Policies
4
Phases
View detail
EU AI Act
On Track

Deployer classification confirmed. Obligations for use-case documentation, risk assessment, and human oversight feed directly into the policy programme.

View detail
02 Detection & Response
CrowdStrike
In Negotiation

A like-for-like MSSP replacement at reduced cost, moving to a more mature security operations platform. The capability uplift is the point: stronger detection and response against AI-driven threats.

99%
AI Detection*
<30m
Response*
*CrowdStrike platform capability
Abnormal Security
POC Active

Behavioural AI on M365 that catches what Defender misses. The POC quantified the gap: targeted attacks reaching executives and finance teams that traditional controls let through.

72
Attacks Found
M365
API-Native
View detail
03 Engineering & Acceleration
Claude in CI/CD — Anthropic
POC Active

Every critical pull request is auto-scanned for OWASP issues, secrets, and CVEs, with critical findings blocking merge automatically. Beyond scanning, Claude is reducing GRC cycle time on policy, risk assessment, and control review work.

View detail
Policy Integration Matrix
19 policies, sequenced by risk priority
Phased across four releases, with Phase 1 targeting the highest-exposure gaps from the Q2 threat assessment.
Phase 1 — Q3 2026
5 Critical policies
Progress
Scoping
PolicyGap SummaryOwnerStatus
AI Acceptable UseNo current policy covering AI tool usage by staff and facultyCISONot Started
AI Risk Assessment FrameworkNo formal risk tier classification for AI systemsInfoSecNot Started
Data Classification for AIExisting classification does not address AI training or inference dataInfoSecNot Started
AI Incident ResponseExisting IR playbook has no AI-specific scenariosInfoSecNot Started
Security Awareness for AINo AI-specific guidance in current awareness programmeInfoSecNot Started
Phase 2 — Q4 2026
8 High priority policies
Progress
Not Started
PolicyGap SummaryOwnerStatus
Identity & Access for AINo RBAC requirements specific to AI system accessIT / InfoSecNot Started
Vulnerability ManagementProcess not updated for AI system and model vulnerabilitiesInfoSecNot Started
IR PlaybooksNo AI-augmented threat scenarios in current playbooksInfoSecNot Started
Email SecurityPolicy does not reflect AI-crafted phishing patternsInfoSecNot Started
Generative AI UsageNo institutional position on GenAI for coursework or productivityAcademic Affairs / CISONot Started
AI Model GovernanceNo lifecycle management policy for AI models in productionIT / InfoSecNot Started
AI Ethics ReviewNo ethics review process prior to AI deploymentCISO / LegalNot Started
AI Audit & LoggingNo requirement for audit trails on AI-assisted decisionsInfoSec / ComplianceNot Started
Phase 3 — H1 2027
5 Medium priority policies
Progress
Not Started
PolicyGap SummaryOwnerStatus
Student Data & AIFERPA obligations not explicitly mapped to AI data flowsLegal / RegistrarNot Started
AI Third-Party RiskSupply chain risk not assessed for the AI vendor stackProcurement / InfoSecNot Started
AI Continuity & ResilienceBCP/DR does not address AI system dependenciesIT / InfoSecNot Started
AI Change ManagementProcess not updated for model updates or retrainingITNot Started
AI in HR ProcessesNo guidance on AI use in hiring or workforce decisionsHR / LegalNot Started
Phase 4 — H2 2027
1 Longer-horizon policy
Progress
Not Started
PolicyGap SummaryOwnerStatus
AI SustainabilityNo policy addressing the environmental impact of AI compute usageFacilities / ITNot Started
Vendor & Initiative Coverage
Capability investments, mapped to the RMF
The active investments map across all four NIST AI RMF functions. Map is the least covered today, addressed through the policy programme rather than a vendor tool.
In Negotiation
CrowdStrike
Falcon Platform · Detection & Response
99%
AI Detection
<30m
Response
RMF Coverage
MS — MeasureMG — Manage
Detection and response capability uplift
CrowdStrike is under negotiation as a like-for-like replacement for the current MSSP, at reduced cost. The platform capability figures shown are what APEI gains on transition, central to the goal of meeting AI-accelerated threats with a more mature operating model.
Scope
SIEM, MDR, IVM, and EDR consolidated onto a single platform, replacing Compuquip
H2 Roadmap
Charlotte AI for autonomous SOC triage and Falcon AIDR for visibility across AI agent identities and workloads
Next Steps
Contract finalisation, with cost reduction confirmed against current MSSP spend
POC Active
Abnormal Security
M365 Email Protection
72
Attacks Found
0
MX Changes
RMF Coverage
MS — MeasureMG — Manage
Closing the email protection gap
Behavioural AI detects the targeted attacks that signature-based tools miss. The POC quantified the delta beyond Microsoft Defender, identifying 72 targeted attacks during the assessment period, with executives and finance teams the primary targets.
Capabilities
Stops payload-less BEC, spear phishing, and account takeover. Graymail reduction cuts inbox noise so genuine threats stand out
Deployment
API-native on M365 with zero MX record changes required
Next Steps
POC results review and decision on full M365 deployment, including model tuning phase
POC Active
Anthropic / Claude
AI Engineering & Governance
Every
Critical PR
Hours
GRC Cycle
RMF Coverage
GV — GovernMS — Measure
AI in the SDLC and GRC acceleration
Claude scans every critical pull request for OWASP issues, secrets, and CVEs, blocking merge on critical findings with no human intervention. It also compresses GRC work, taking policy, risk assessment, and control review from weeks to hours.
Capabilities
Automatic PR security scanning, merge blocking on critical findings, full SDLC oversight for responsible AI usage
H2 Roadmap
Expanded repository coverage, AI observability consolidation, and organisation-wide integration under review
Next Steps
Refine prompts for consistent output and reduce token waste across pipelines
Regulatory Alignment
Frameworks the programme aligns to
NIST AI RMF 1.0

Primary governance framework. Structures risk management across the Govern, Map, Measure, and Manage functions.

FERPA

Student data compliance. AI data flows touching student records must preserve FERPA obligations.

CMMC / 800-171

Defence-adjacent use cases. Controls applied where AI systems touch CUI or federal programmes.

EU AI Act

Deployer classification confirmed. August 2026 compliance deadline on track.

GV — Govern
Committee charter, acceptable use, ethics review, and cross-functional AI risk ownership.
MP — Map
AI system inventory and use-case risk classification. Addressed through the policy programme.
MS — Measure
Vendor assessments, EU AI Act and CMMC tracking, and AI audit logging.
MG — Manage
Incident response, change management for model updates, and continuous risk treatment.
Horizon Initiatives
What comes next
Q3 / Q4 2026
AI Visibility & Response
Once CrowdStrike is operational, expanding AI observability across the environment: understanding how AI tools are used, what data is shared, and which services are accessed, with controls on prompt types and PII submission to external platforms. The goal is to enable AI safely, not to block it.
Q3 / Q4 2026
AI Data Security Controls
Data loss prevention and classification controls specific to AI ingestion and output, protecting sensitive student and financial data from AI-enabled extraction. Aligned to the data classification gaps identified in Phase 1 of the policy programme.
Q3 / Q4 2026
AI Threat Preparedness
Tabletop exercises and response playbooks for AI-augmented threat scenarios, with updated IR playbooks integrated into the new MSSP. Directly addresses the Q2 finding that AI is actively lowering attack barriers.

Items under consideration for Q3 and Q4 2026. No commitments implied.