As AI tools become more integrated into higher education, they offer remarkable potential to enhance teaching, learning, and research. However, alongside these benefits comes the critical issue of data security. For faculty, staff, and students at a public four-year university, understanding the risks associated with data security in AI tools is essential to safeguard personal information and maintain the integrity of the academic environment.
When information is put into a public-facing AI tool, that data is collected, stored, and used to further train the model, putting student data at risk of misuse or unauthorized access. This risk is especially serious concerning student records, which are protected by the Family Educational Rights and Privacy Act (FERPA).
FERPA
Student records are protected by the Family Educational Rights and Privacy Act (FERPA). FERPA prohibits the unauthorized disclosure of a student’s educational records. More information about what constitutes student data and information is available on the FERPA webpage.
To ensure compliance with federal law and uphold the university’s ethical responsibilities, all student data used in conjunction with AI must be processed only on approved platforms, such as those secured by an enterprise license with the university.
Cybersecurity and AI
AI acts as a double-edged sword in cybersecurity. While it enables more sophisticated cyberattacks—such as highly convincing phishing attempts, malware, and deepfake impersonations—it also provides powerful tools for defense. Cybercriminals leverage AI to automate and scale attacks, making them harder to detect.
The integration of AI necessitates a shift in how higher education institutions approach security:
- Cultivating Digital Literacy: Developing a culture of skepticism and critical thinking is essential. Students and faculty must be trained to recognize the red flags of AI-enhanced scams and verify identities through established channels.
- Institutional Responsibility: Universities must implement clear data governance frameworks, ensuring that only approved platforms with enterprise-grade security and data-handling policies are used.
- Ongoing Adaptation: Because threats evolve rapidly, institutions must foster ongoing awareness and accountability, treating cybersecurity as an essential component of AI adoption rather than an afterthought.
