Student records exposed by an AI access error. A legacy system felled by an untested AI fix. A campus chatbot that pulled from a data source no one approved it to touch.
These are all real risks of agentic AI adoption in higher education, even for tools explicitly greenlit by administrators. Most schools have responded with policies telling students, faculty, and staff what's fair game when it comes to AI use and what's off limits. But some go further, applying the principle of least privilege (PoLP) through specific controls that restrict what an AI tool can do. Whether that looks like disabling network access, blocking outside sharing, or cutting off functions at the platform level, the test is the same: could the tool do it anyway, no matter how it's prompted? A policy can't answer yes to that—but a control can.
The trouble is that most institutional AI governance treats these as one and the same, with a general AI use policy standing in for a control that was never built. This article examines which schools are currently on the right track, and why turning policy into control has been a challenge for the rest of higher ed.
Two schools getting it right (publicly, anyway)
Since not all schools publicly disclose their AI governance approach, it's impossible to know for sure who's doing what. Most AI governance is policy-driven, with only a handful of institutions publicly disclosing technical restrictions against agents in AI workspaces. Even policy alone is far from universal: a recent Inside Higher Ed survey found that an institution-wide policy for general AI use is only in place at 42% of colleges and universities, and nearly a third (31%) report no formal AI policy in any area at all.
Among that handful, two of the clearest examples are California State University, Chico and Michigan State University.
California State University, Chico
By March 2025, California State University, Chico—better known as Chico State—had documented administrator-level capability controls in its ChatGPT Edu workspace. The university's configuration limits sharing of custom GPTs to Chico State users and blocks external access through GPT Actions. By default, custom GPTs can’t access external APIs or domains unless Chico State approves a user’s support-ticket request. The workspace also permits code execution while disabling network access from that execution environment, so code can run without reaching external sites or services.
This isn’t a blanket ban: ChatGPT’s web search and deep research features are still available to Chico State users.The distinction is between user-facing web research and more autonomous or programmable connectivity, like custom GPT Actions and code capable of making network requests.
Note: Though Chico State is an individual campus within the larger California State University (CSU) system, that doesn't necessarily mean the rest of CSU takes the same AI governance approach. The limited public record may reflect uneven disclosure, uneven implementation, or both.
Michigan State University
Like Chico State, Michigan State University (MSU) disables third-party connectors in its ChatGPT Edu workspace by default, with exceptions reviewed case by case. Guidance published in February 2026 also states that ChatGPT's Atlas Web Browser is disabled to protect university data and maintain compliance with MSU's data governance policies.
Students, faculty, and staff who want to use a connector such as Google Drive or Zoho Cliq for coursework, research, or administrative work may submit a request to MSU IT, which reviews requests for data security and policy compliance. Custom GPTs remain available within the university workspace, but public sharing is allowed only when they use publicly available data and contain no institutional, confidential, or restricted information.
While Chico State and MSU show what least privilege AI governance looks like in practice, there isn't a whole lot of public evidence that other institutions have done the same. The reasons why suggest as much about higher ed's structure as they do about the technology itself.
Why the rest of higher ed hasn't caught up yet
Several obstacles keep institutions from turning AI governance policy into more enforceable technical permissions: fragmented data environments, fluid identities and roles, limited administrative control planes, and usability trade-offs that can drive users toward shadow AI.
Fragmented data environments
Universities commonly manage their student information, learning management, HR and payroll, research, advancement, library, health, and departmental data across siloed systems. Each system may have its own data owners, contracts, access rules, and identity integrations. Applying even just one consistent, task-specific AI access policy across all systems, then, is no small task.
Fluid identities and roles
College campuses exist in a state of perpetual flux. They include students whose enrollment status can change from one semester to the next; lucky faculty granted sabbatical; visiting scholars who come and go; and graduate teaching assistants who are at once both student and employees. And then of course there are grants, labs, and research collaborations that all run on their own timelines.
This makes it especially difficult to translate changing and overlapping roles into access profiles that meet users’ needs and are automatically revised or revoked when an affiliation ends. AI agents, then, need permissions that shift and expire just as often as the human roles they're tied to.
Limited administrative control planes
Vendor-managed products may offer useful configuration controls—enabling and disabling browser access, connectors, actions, sharing, or code-execution networking. But most of these controls are blunt instruments: they apply to an entire workspace or user group, not to a single agent performing a single task.
The gap here is significant. A university may restrict what systems a teaching assistant is allowed to log into, but an AI tutor built for one course doesn't need that same access. Instead, it needs something like this: "Read this course's repository for this term. Nothing else. Not other courses, not email, not a connector that could write or send." That's a permission scoped to the agent's one task, not to the user who deployed it, and not to the workspace it lives in.
Vendor consoles are generally built for the first kind of control, not the second. AI agent least privilege means checking permission each time an agent uses a tool, and authorizing only the access needed for that specific task, data source, and action.
The usability/shadow AI trade-off
Once IT begins restricting browsing, connectors, agents, or advanced models, unapproved personal AI tools can start looking awfully attractive next to their university-sanctioned counterparts. If approved paths are too constrained or too slow, users may turn to shadow AI, undermining the visibility and contractual protections that centralized governance is meant to create. However, that gap is less about willpower than it is about what stage of the process most campuses are still in.
The truth is, most campuses are still building the basics AI governance depends on: SSO, enterprise contracts, data-classification guidance, approved tools, and workspace-level feature controls. Task-specific agent permissions require a deeper layer of identity engineering, data classification, connector governance, policy enforcement, monitoring, and revocation—investments universities have historically concentrated in their most regulated environments, like health, finance, and high-risk research.
Universities don't typically have a single office that can mandate and enforce a standard AI architecture across faculty, central IT, medical centers, research organizations, colleges, libraries, and departmental technology purchases. Academic freedom, separate budgets, grant-funded research, and local technology ownership can make uniform enforcement difficult, even when a central AI office has sound policy.
How FERPA further complicates access governance
The Family Educational Rights and Privacy Act, or FERPA, requires institutions to use reasonable methods to ensure that school officials access only education records in which they have a legitimate educational interest. An AI agent with broad, standing access to student systems—or one that can move freely among course materials, advising records, email, and connected data sources—can obscure who is accessing which records, for what institutional purpose, and whether that access is limited to a legitimate educational interest.
FERPA doesn't prevent universities from using AI. But if institutions want to protect student records, AI workflows need to include clear purpose limitations, carefully scoped access, and controls that show what data an agent was authorized to use.
Key takeaways
The reason why PoLP is such an attractive solution for AI governance in higher ed is that universities are rich in high-stakes data, but poor in central control. It's the exact sort of environment where a policy telling a tool what it shouldn't do matters less than a control that makes sure it can't.
By disabling GPT Actions, cutting off the Atlas browser, and keeping a tight leash on third-party connectors, Chico State and MSU show what least privilege AI governance looks like in practice. But most institutions are still figuring out the basics of their IT infrastructure before agent-level permissions can even enter the conversation. That gap has real stakes for student records, research data, and any system an unchecked agent can reach. The question is whether universities can close that gap before their next breach.



