# AI Dean's List — September 2026

- **AI system/product:** Grok (xAI)
- **Model name/version:** Grok; specific model version not identified in this session
- **Date:** September 24, 2026
- **Web research used:** Yes

## THE DEAN’S LIST

#1 — Governing AI Before It Scales
Why it matters: Campus AI use has outpaced strategy, policy, and oversight. Without clear rules for teaching, research, and operations, institutions risk integrity failures, privacy breaches, uneven student experiences, and costly vendor lock-in.

#2 — Cybersecurity as Everyone’s Job
Why it matters: Universities remain prime targets for ransomware, identity theft, and espionage, while AI and vendors widen exposure. Defense now depends on shared habits across campus, not on security teams alone.

#3 — Assessment That Still Measures Learning
Why it matters: Generative AI has broken many traditional assignments as proof of learning. Institutions that do not move to authentic, process-based assessment will struggle to defend what their credentials mean.

#4 — Data Leaders Can Trust
Why it matters: Useful AI, financial decisions, and student-privacy compliance all depend on governed data. Fragmented systems and unclear responsibilities for AI-processed records are now strategic liabilities.

#5 — Technology Spending Discipline
Why it matters: Costs are rising faster than revenue, and many AI investments have not yet shown clear returns. Leaders must decide what to fund, modernize, or stop before licenses and technical debt crowd out the mission.

#6 — The 2027 Accessibility Deadline
Why it matters: Public institutions serving larger populations must meet WCAG 2.1 AA for web content and apps by April 2027. The extension is a planning window, not a pause, and inaccessible learning widens equity gaps.

#7 — Campuswide AI Literacy
Why it matters: Students, faculty, and staff already use AI, often without shared standards or field-specific skill. Graduates and institutions that cannot use AI critically will lose ground with employers and in daily work.

## DEEPER ANALYSIS

These seven priorities are a judgment about what senior leaders—presidents, provosts, boards, and cabinet officers—most need to own over the next 12 to 24 months, not a reprint of any one association’s list. Technology leaders surveyed by EDUCAUSE for the 2026 Top 10 put collaborative cybersecurity first and spread artificial intelligence across several later items. That ranking is serious evidence. For institutional leaders, the sharper problem is that AI is already in daily use without a shared strategy, and that gap is reshaping learning, research, risk, and cost at once. Cybersecurity remains the failure mode that can stop an institution in a week. The order below reflects that distinction. Facts are attributed; ranking and implications are analysis.

### #1 — Governing AI Before It Scales

The issue is not whether colleges will use artificial intelligence. They already do. The issue is that use is personal, uneven, and lightly governed, while tools are moving from chat windows into advising, research, and administrative workflows that act with less human review.

Inside Higher Ed’s 2026 survey of 376 chief academic officers, fielded in July and August, found that roughly seven in ten provosts use AI at least weekly, but only one in ten reported a centralized institutional AI strategy. Value so far is mostly individual: 39 percent pointed to personal productivity and 36 percent to administrative efficiency, while 12 percent reported department-level workflow gains and 8 percent reported institution-wide operational transformation. Only about one in five agreed that their institution has a coherent vision for how AI will change what it teaches. Public doctoral provosts were more likely to say so (31 percent) than community college provosts (12 percent) or private baccalaureate provosts (11 percent). A May 2026 survey of campus technology officers found the same pattern from the IT side: generative AI is a high or essential investment priority for 49 percent, up from 34 percent a year earlier, and agentic AI for 35 percent, up from 28 percent—yet institution-wide transformation remains largely unrealized.

Large deployments show both the ambition and the strain. The New York Times reported that the California State University system anchored an AI initiative with a $16.9 million OpenAI arrangement covering hundreds of thousands of licenses, and that the rollout has produced conflict as well as experimentation. Policy is catching up in pieces, not as a national standard. The State University of New York set a December 31, 2026 deadline for campuses to adopt or update AI guidelines covering roles, training, procurement, bias, and student-data privacy. Florida has moved toward college-system rules on when AI may be used in instruction and grading; as of mid-September 2026 those rules were still in the proposal stage, with the state university system developing parallel expectations. In research, HHS’s Office of Research Integrity issued August 2026 guidance on generative AI under the revised Public Health Service misconduct regulations. The guidance is nonbinding, but it is operationally important: disclosure does not immunize a researcher, AI-detection tools are not sufficient evidence on their own, and institutions need verification and record-keeping practices.

This ranks first because the next 12 to 24 months will harden contracts, course norms, and research habits that are expensive to unwind. Agentic tools—systems that do not only answer but schedule, file, query, and recommend—will move from pilots into operations. State mandates will multiply. Institutions without a living governance model will either ban tools people already use or accept whatever a vendor’s default terms allow.

Implications differ by type. Research universities must connect academic AI policy to sponsor rules, research security, and misconduct procedures. Comprehensive publics and community colleges face the same integrity and privacy questions with thinner policy staff and more pressure to show workforce relevance quickly. Small privates are especially exposed to a single enterprise contract becoming the de facto strategy. System campuses cannot treat a system license as a substitute for local rules about teaching and student data.

Leaders should ask: Who owns AI governance, and does that body have authority over procurement, instruction, and research—not just a set of principles? Which data may never enter a general-purpose tool? What must be true before an AI system advises a student, scores work, or drafts a decision that affects employment or aid? How will we know whether a large license changed learning or only changed inboxes?

### #2 — Cybersecurity as Everyone’s Job

Cybersecurity is the acute operational risk. EDUCAUSE members ranked “collaborative cybersecurity”—a culture of shared responsibility, usable training, and security support built into daily work—as the top IT issue for 2026, ahead of any AI item. That framing matches how attacks actually start.

Sophos’s 2026 education ransomware study, based on institutions that had been hit, found that identity-based techniques—malicious email, phishing, compromised credentials, and brute force—initiated 85 percent of education ransomware attacks, above the cross-sector rate. In higher education, malicious email was the leading technical root cause (29 percent), and 77 percent of higher-education victims said the ransomware event was also their most significant identity attack. Average recovery costs across education reached $2.26 million, and education organizations recover more slowly than the cross-sector average. A separate incident tally from Comparitech found that, even as overall education-sector attack claims fell in the first half of 2026, claims against higher education rose by more than 8 percent from the prior half-year, with a higher median ransom demand. These sources measure different things—surveyed victims versus claimed incidents—and should not be blended into one rate. Together they support a narrower conclusion: identity compromise and costly recovery remain the practical problem.

Third parties multiply that problem. UpGuard reported in July 2026 that 28 percent of the 100 vendors most commonly used by universities had experienced a breach since 2024, that 95 percent of universities had at least one vendor with embedded AI exposure, and that 80 percent of institutions share the same 11 vendors. The spring 2026 ransomware incident affecting Instructure’s Canvas platform made the point concrete: a criminal actor exploited an issue tied to free teacher accounts, core systems were disrupted, and more than 950 EDUCAUSE community members joined an emergency discussion. Instructure said core course content and submissions were not compromised, while account and enrollment-related fields were involved, and validation was ongoing. One vendor incident became a sector incident.

This ranks second, not first, because senior leaders cannot treat security as an IT specialty and also cannot let AI strategy eclipse it. A governance failure degrades the mission over years. A breach can halt instruction, expose research, and trigger regulatory and insurance consequences in days. AI increases both the attack surface and the quality of phishing. The 2026 EDUCAUSE Horizon Report lists growing cybersecurity and privacy threats to student and faculty data among the technological trends most likely to shape teaching and learning.

Over the next two years, expect more identity-led attacks, more scrutiny of vendors that embed AI, and more pressure to adopt phishing-resistant authentication and centralized endpoint management. Research universities will also face tighter expectations around controlled unclassified information and research data. Regional and community colleges, with smaller security teams, will feel the same threat with less specialized staff. Medical and research campuses carry additional exposure through health and sponsored-project data.

Leaders should ask: Is multi-factor authentication, preferably phishing-resistant, actually universal for students, faculty, contractors, and alumni systems that still touch campus identity? When a major vendor is breached, who decides what we tell students and how quickly instruction continues? Are security practices designed into work, or added as annual training people click through? Which shared vendors, if compromised, would stop us?

### #3 — Assessment That Still Measures Learning

If credentials stop signaling learning, technology efficiency elsewhere will not save the institution’s value proposition. That is why assessment ranks above data platforms and spending rules.

The 2026 EDUCAUSE Horizon Report treats this as a present condition, not a forecast. AI is already reshaping teaching, instructional design, academic support, and the student–faculty relationship. Traditional assessments are a weak signal when a general-purpose model can produce the artifact. The report describes a shift toward authentic, process-based demonstrations of learning, and it warns that suspicion—faculty policing outputs, students hiding tool use—is damaging trust. An EDUCAUSE assessment study released in 2026 found faculty and staff warming to AI for creating assessments while also believing students use AI to complete them, and it stressed that students still lack clear rules for when use is allowed. Developing judgment about when not to use AI was described as essential.

The academic-leadership data show how unfinished the response is. In the Inside Higher Ed provost survey, only 8 percent described their institution’s AI approach as primarily defensive—focused on detecting cheating—while 13 percent said the focus was adapting current tests and 20 percent said the institution was actively rethinking what it assesses. Nearly half of provosts rated AI’s impact on higher education as neither positive nor negative. The New York Times reported in September 2026 on an MIT committee’s warning of “cognitive surrender”: students reaching for a bot at the first difficulty, gaining an illusion of learning, and pulling away from office hours and communal study—even as the same committee described immense potential to augment campus work. Detection tools are a poor foundation for academic discipline. ORI’s research guidance makes a parallel point: automated detection is a lead, not a verdict.

In my judgment this outranks operational AI uses because the next two years will set the norms students carry through a degree. Courses that keep take-home essays and problem sets unchanged will either inflate grades or spend the term in misconduct cases. Courses that ban tools students will use at work will teach evasion. The workable path is narrower and harder: assignments that show reasoning in progress, oral and in-class demonstration where that is the right evidence, explicit permission rules, and faculty time to redesign. That path costs more in faculty labor than a detector license.

Research universities can sometimes separate graduate research training from undergraduate general-education assessment; they should not assume one policy fits both. Community colleges and access-oriented publics have less room to add high-touch assessment without support, and equity suffers if only well-resourced programs can move to studios, practicums, and supervised work. Professional programs—nursing, teaching, engineering, law—face licensure and employer expectations that make “the essay was polished” an especially weak claim.

Leaders should ask: What evidence of learning would still be credible if every student had a capable model? Where have we replaced detection with redesigned assessment, and where have we only written a syllabus warning? Do promotion, workload, and teaching-evaluation systems reward faculty who rebuild courses? What will we tell accreditors, employers, and families our grades now mean?

### #4 — Data Leaders Can Trust

AI strategy, security, privacy, and financial control converge on data. EDUCAUSE’s 2026 list makes that plain: operational and financial analytics, a data-centric culture, knowledge management for safer AI, forward-looking scenario planning, and decision-maker data literacy occupy five of the ten issues. An EDUCAUSE Review analysis of the current AI landscape argued that broken data foundations—silos, legacy systems, and unresolved ownership—are the main barrier to meaningful AI, and that data governance is a board-level matter, not an IT backlog.

Privacy law has not caught up in statute, but it already applies. FERPA restricts disclosure of education records. AI tools that receive student work, advisor notes, or risk scores are processing those records, and the school-official exception holds only when the vendor is under the institution’s direct control and uses the data for the authorized purpose. A May 2026 AACRAO addendum to its long-standing FERPA guide treats AI-generated risk scores, adaptive pathways, and vendor-held cloud data as part of the current compliance environment. AACRAO’s discussion identifies artificial intelligence as the most urgent student-privacy challenge because adoption has outrun the frameworks meant to govern it. That is expert judgment, not a new federal rule, and it matches what campuses are experiencing.

This ranks fourth because governance and assessment redesign fail in practice without data the institution can explain, secure, and stand behind. It is not first because a perfect warehouse will not, by itself, decide what learning is or who is accountable when a model is wrong. Over the next two years, more student-success and administrative tools will request cross-system data—aid, advising, learning-management activity, card swipes, even help-seeking chats. Early-alert and “digital twin” projects already illustrate the direction: Austin Community College, for example, has described an effort to combine real-time student data so staff can intervene before a student stops out. Those uses can help. They also create records students may have a right to see, and they can encode bias if the underlying data reflect uneven advising or policing of some students more than others.

Research universities must reconcile student-record rules, human-subjects rules, sponsor data rules, and health-privacy rules when the same person is a student and a research participant. Community colleges often have the greatest need for proactive support analytics and the least capacity to integrate legacy systems. Institutions under enrollment stress will be tempted to buy prediction without asking what action the prediction is allowed to trigger.

Leaders should ask: What are our authoritative data for enrollment, cost, and student progress, and who may challenge them? Which AI vendors are school officials under a contract that forbids training on our records and limits subprocessors? If a student asks what an algorithm said about them, can we answer? Are financial and academic leaders trained to use the data, or only to receive dashboards?

### #5 — Technology Spending Discipline

The sector is adopting new tools into a worsening cost structure. Higher Ed Dive, summarizing rating-agency outlooks, reported that Moody’s 2026 higher-education outlook estimated sector revenue growth of about 3.5 percent against cost growth of about 4.4 percent, with other agencies similarly cautious. Inside Higher Ed’s provost survey found that half of chief academic officers said federal funding to their institution had declined, including about four in five at public doctoral universities. Technology budgets sit inside that squeeze. In the May 2026 technology-officer survey, only 29 percent said AI spending had met or exceeded return expectations; a quarter said it fell short and 27 percent were unsure. Nearly half said the pace of technology change is unsustainable without new resources. Looking toward 2030, the most common worries were IT talent (62 percent), a critical breach (59 percent), and unsustainable costs (56 percent). Almost all expected IT costs to rise.

EDUCAUSE’s sixth issue for 2026 is measured investment: clearer cost, return, and legacy-system assessments, including the choice not to buy. Gartner’s higher-education technology outlook for 2026 similarly points CIOs toward targeted AI outcomes, data and analytics investment, and technical debt. The debt is not abstract. Aging student, finance, and identity systems raise security risk, block data integration, and make each new AI feature more expensive to connect. Adding a model on top of a broken process, as former Southern New Hampshire University president Paul LeBlanc told Inside Higher Ed, produces limited impact; rethinking the work is what changes outcomes, and few institutions are doing that.

This ranks fifth because money will decide which of the higher priorities are real. It is not higher because a savings program that ignores learning, security, and privacy will cut the wrong things. Over the next two years, more cabinets will face renewal decisions on learning platforms, enterprise resource systems, and AI licenses at the same time as deferred facilities needs and possible enrollment softness. Research universities may see research-computing and research-administration IT squeezed by shifts in federal support even when undergraduate systems look stable. Tuition-dependent regional universities and small privates have the least slack and the most danger of a multi-year license becoming a fixed cost they cannot exit. Community colleges may gain from shared state services if those services are governed well, and lose flexibility if they are not.

Leaders should ask: Which technology costs are contractual, which are staffing workarounds for old systems, and which are bets? What would we stop funding to pay for a secure, governed AI environment? Do AI proposals name a baseline, a decision owner, and a date to continue or cancel? Is technical-debt reduction a funded program, or a speech?

### #6 — The 2027 Accessibility Deadline

On April 20, 2026, the Justice Department extended compliance dates under its 2024 Title II rule on web and mobile-app accessibility. Public entities serving a population of 50,000 or more—covering most public colleges and universities—now have until April 26, 2027. Smaller public entities and special districts have until April 26, 2028. The technical standard did not change: WCAG 2.1 Level AA for web content and mobile apps, with implications for digital course materials and public programs, not only the marketing site. The department said it had overestimated institutions’ capacity and the ability of tools, including generative AI, to remediate inaccessible content at scale.

This is a technology, academic, and legal issue at once. Content is created by faculty, vendors, and contractors, then published through platforms the institution does not fully control. A one-time audit will not hold. Private institutions are not covered by this Title II deadline; they remain exposed under Title III, state law, and student expectations, and many already aim at the same technical standard.

It ranks sixth because the date falls inside the planning window and the equity stakes are direct: students with disabilities cannot use what others are assigned. It is not higher because the obligation is defined and schedulable, whereas AI governance and assessment are still being invented. Waiting until early 2027 will turn a manageable program into emergency remediation, especially for course materials, archived PDFs, and third-party tools. AI can assist captioning and alt text; the department’s own rationale for the delay is that it does not yet do this reliably enough to carry compliance.

Large public research universities have more content and more decentralized publishers. Community colleges often have fewer accessibility specialists and a higher share of students who depend on mobile access and borrowed devices. Small publics in smaller jurisdictions may have the later 2028 date and should not treat that as permission to start later if their course platforms are shared with larger partners.

Leaders should ask: Do we know which sites, apps, and course-content systems are in scope, including third-party tools we require students to use? Is accessibility built into procurement and faculty development, or assigned to a small office after publication? What will we have finished by December 2026, not by the week of the deadline? How will new AI tools be tested for accessibility before campus rollout?

### #7 — Campuswide AI Literacy

Literacy is the human layer under every item above. EDUCAUSE framed two 2026 issues in these terms: the “human edge of AI,” meaning students, faculty, and staff who can use tools critically, creatively, and safely, and discipline-specific technology literacy for the workforce students are entering. The Horizon Report’s teaching-and-learning panel reached the same conclusion from the classroom side: AI literacy, including when not to use the tools, is now part of instructional design, not an optional workshop.

Practice is ahead of preparation. Provosts and technology officers both name skills and staff capacity as a top limit on institutional AI impact—51 percent of provosts and 55 percent of technology officers in the 2026 Inside Higher Ed surveys. Half of provosts also cited faculty and staff resistance. Some institutions are treating fluency as a graduation expectation. The New York Times reported that Ohio State is integrating AI into every major so that students can use it, and know when not to, in their field. That is a different project from a one-hour orientation module.

This ranks seventh not because it is optional, but because it is how the first six priorities get done. A policy no one understands will be ignored. An assessment redesign without faculty development will stall. A security culture without practical training will fail at the inbox, which is where Sophos found the leading entry point. Over the next two years, employers will keep treating AI fluency as a baseline skill while also asking for judgment, communication, and supervision of automated work. Institutions that teach only tool tricks will underprepare students. Institutions that teach only refusal will do the same.

Community colleges and regional comprehensives are closest to employers who want job-ready AI use in health, trades, business, and public service, and they often have the least faculty-development capacity. Research universities must add research-integrity literacy for graduate students and postdocs, not only undergraduate writing guidance. Professional schools need field-specific rules that match licensure and client confidentiality. Across types, staff literacy matters as much as student literacy: advisors, financial-aid officers, and researchers are already pasting sensitive material into consumer tools.

Leaders should ask: What must every graduate be able to do with AI in their field, and what must they be able to do without it? Who is responsible for faculty and staff development, and is that work funded in workload, not only in optional workshops? Are we teaching verification, citation, data care, and the limits of automation—or only prompt technique? How will we support students who use general-purpose chatbots for advising and emotional questions outside any institutional safeguard?

### Cross-Cutting Observations

The tools are ahead of the institutions. Personal productivity is widespread. Enterprise transformation, coherent curriculum vision, and clear student rules are not. Leaders who count licenses or pilot projects will overestimate readiness.

Shared responsibility is the operating model, not a slogan. EDUCAUSE’s 2026 framing—collective will plus individual capability—fits security, data, accessibility, and AI use equally. Central offices can set standards and buy platforms. They cannot click the phish, redesign the assignment, or caption the lecture for everyone else.

Trust is the asset under pressure. Students and faculty are negotiating suspicion in the classroom. Families and employers are asking what a grade means. Privacy rules written for files now cover model outputs. A breach or a biased advising model spends trust that recruitment budgets cannot easily buy back.

Money will sort strategy from announcement. Rising costs, uncertain federal research support, and unclear AI returns mean every yes needs a no. Institutions that modernize core systems and govern data will be able to use AI. Institutions that stack licenses on legacy processes will pay more for the same work.

Capacity gaps will widen by institution type. Research universities face research-integrity, security, and infrastructure demands at once. Access-oriented and smaller institutions face the same student and employer expectations with fewer specialists. Shared services can close that gap or export one vendor’s failure to an entire system. Leadership attention has to follow that difference, not a single national playbook.

### What Might Be Underestimated

Vendor concentration as a sector risk. Institutional security programs still tend to imagine “our” network. UpGuard’s finding that most universities share a small set of vendors, and the Canvas disruption, show a different failure mode: one supplier incident can stall teaching at hundreds of campuses the same week. AI features inside those products add a data path leaders may not have reviewed. Monitoring third-party AI terms and practicing academic continuity without the primary learning platform deserve more cabinet time than they usually get.

Energy, facilities, and the physical cost of digital ambition. The 2026 Horizon Report flags growing awareness of AI’s environmental cost as an early teaching-and-learning trend. Most campuses will not build frontier data centers. They will still face utility costs, research-computing demand, and questions from students and trustees about whether local AI use matches climate commitments. Facilities backlogs and digital strategy are usually planned apart. They will collide when power, cooling, and cloud spend show up in the same budget.

Alternative credentials and the unbundling of information delivery. Brookings has argued that AI makes expert explanation cheap outside university walls, pushing institutions toward faster competency credentials, AI-embedded instruction, lower-stakes assessment, or more intensive human formation—and that each path gives up part of the traditional bundle. That is not only a technology issue, which is why it sits outside the seven. It is consequential: if employers accept shorter, cheaper demonstrations of skill, spending discipline and assessment redesign become competitive strategy, not internal improvement. Research-security rules for controlled data, including defense-related work, are a parallel watch item for universities with federal contracts. They will not dominate the sector, but a failed audit can shut off funding that regional peers never had.

### Sources

- Inside Higher Ed, “From AI Use to Funding Cuts: How Provosts Are Navigating 2026,” September 23, 2026. https://www.insidehighered.com/news/governance/executive-leadership/2026/09/23/ai-use-funding-cuts-how-provosts-navigate-2026
- Inside Higher Ed, “Half of Campus Tech Leaders Question AI’s ROI,” May 12, 2026. https://www.insidehighered.com/news/tech-innovation/artificial-intelligence/2026/05/12/half-campus-tech-leaders-question-ais-roi
- Inside Higher Ed, “Survey: CTOs on Cybersecurity, AI, the LMS and More,” May 12, 2026. https://www.insidehighered.com/news/quick-takes/2026/05/12/survey-ctos-cybersecurity-ai-lms-and-more
- EDUCAUSE Review, “2026 EDUCAUSE Top 10: Making Connections,” Mark McCormack and the 2025–2026 EDUCAUSE Top 10 Panel, October 29, 2025. https://er.educause.edu/articles/2025/10/2026-educause-top-10-making-connections
- EDUCAUSE, “2026 EDUCAUSE Horizon Report | Teaching and Learning Edition,” May 18, 2026. https://library.educause.edu/resources/2026/5/2026-educause-horizon-report-teaching-and-learning-edition
- EDUCAUSE, “The Impact of AI on Learning Assessment,” June 2026. https://library.educause.edu/resources/2026/6/2026-educause-the-impact-of-ai-on-learning-assessment-report
- EDUCAUSE Review, “The Current State of Play: AI in Higher Education and the Road Ahead,” June 16, 2026. https://er.educause.edu/articles/2026/6/the-current-state-of-play-ai-in-higher-education-and-the-road-ahead
- EDUCAUSE Review, “How Higher Education Is Responding to the Canvas LMS Incident and Preparing for What’s Next,” May 11, 2026. https://er.educause.edu/articles/2026/5/how-higher-education-is-responding-to-the-canvas-lms-incident-and-preparing-for-whats-next
- The New York Times, “An M.I.T. Report Warns A.I. Is Causing ‘Cognitive Surrender.’ Universities Are in a Bind,” September 15, 2026. https://www.nytimes.com/2026/09/15/us/universities-ai-warnings-enthusiasm.html
- The New York Times, “A University System Went All In on A.I. Now It’s Tearing Itself Apart,” June 1, 2026. https://www.nytimes.com/2026/06/01/magazine/ai-university-college-california.html
- U.S. Department of Health and Human Services, Office of Research Integrity, “Guidance on Generative Artificial Intelligence,” August 2026. https://ori.hhs.gov/blog/oris-guidance-generative-artificial-intelligence-released
- Federal Register, “Extension of Compliance Dates for Nondiscrimination on the Basis of Disability; Accessibility of Web Information and Services of State and Local Government Entities,” April 20, 2026. https://www.federalregister.gov/documents/2026/04/20/2026-07663/extension-of-compliance-dates-for-nondiscrimination-on-the-basis-of-disability-accessibility-of-web
- NPR, “DOJ delays disability online access rule for schools,” April 22, 2026. https://www.npr.org/2026/04/22/nx-s1-5791680/doj-disability-web-access-delay-schools
- Sophos, “Identity-Based Attacks Are Responsible for 85% of Ransomware in Education, Sophos Report Finds,” August 27, 2026. https://www.sophos.com/en-us/press/press-releases/2026/08/identity-based-attacks-are-responsible-for-85-of-ransomware-in-education
- Comparitech, “Education Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches,” July 22, 2026. https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
- UpGuard, “New UpGuard Report: Nearly 1 in 3 Top Higher Education Vendors Had a Security Breach Since 2024,” July 1, 2026. https://www.prnewswire.com/news-releases/new-upguard-report-nearly-1-in-3-top-higher-education-vendors-had-a-security-breach-since-2024-302815221.html
- EdTech Magazine, “What SUNY’s Systemwide AI Policy Means for Public University IT Leaders,” June 26, 2026. https://edtechmagazine.com/higher/article/2026/06/suny-ai-policy-higher-ed-it-governance-perfcon
- The EDU Ledger, “Florida Moves to Enact AI Rules Across K-12 and Higher Education,” 2026. https://www.theeduledger.com/ai/article/15833671/florida-moves-to-enact-ai-rules-across-k12-and-higher-education
- AACRAO, “New Addendum Builds on the Trusted AACRAO 2012 FERPA Guide,” May 12, 2026. https://www.aacrao.org/news/new-addendum-builds-on-the-trusted-aacrao-2012-ferpa-guide/
- Higher Ed Dive, “6 higher education trends to watch in 2026,” 2026. https://www.highereddive.com/news/6-higher-education-trends-to-watch-in-2026/809045/
- EdTech Magazine, “Higher Ed IT Budgets Face a Dual Threat: Federal Research Cuts and State Funding Pressure,” August 6, 2026. https://edtechmagazine.com/higher/article/2026/08/higher-ed-it-budgets-face-dual-threat-federal-research-cuts-and-state-funding-pressure-perfcon
- Inside Higher Ed, “5 Ways AI Is Reshaping Student Success,” September 22, 2026. https://www.insidehighered.com/news/student-success/college-experience/2026/09/22/5-ways-ai-reshaping-student-success
- Brookings Institution, Michael J. Ahn, “How universities are affected by AI moving knowledge outside their walls,” September 18, 2026. https://www.brookings.edu/articles/how-universities-are-affected-by-ai-moving-knowledge-outside-their-walls/
- Gartner, “Top Technology Trends in Higher Education for 2026,” January 16, 2026. https://www.gartner.com/en/documents/7344730
