Key AI risks
▹Shadow AI operating outside data governance
▹Data breaches and model/data leakage through commercial tools
▹Insecure or unreviewed AI-generated code
▹Surveillance overreach in smart-campus deployments
Governed through the RMF Playbook
Each function pairs the outcome to reach for this domain (the Playbook's About) with the Playbook's suggested actions.
Govern
Set the rules for institutional data, security, and how AI-enabled systems are built and operated on institutional infrastructure.
Playbook · suggested actions
Set data-governance, shadow-AI, and records-retention policies.
Map
Know what AI exists across the environment, what data it touches, and where unsanctioned use is hiding.
Playbook · suggested actions
Classify data, inventory AI systems, and run discovery scans for unsanctioned use.
Measure
Assess the security, integrity, and privacy posture of AI systems and the code and data behind them.
Playbook · suggested actions
Assess security posture, logging, and the safety of AI-generated code.
Manage
Contain and remediate exposure, provision safe alternatives, and respond to incidents.
Playbook · suggested actions
Remediate exposure, provision safe tools, and run incident response.
Worked case studies · the RMF Playbook applied
10 scenarios
Each step is a Playbook suggested action for that function; the evidence line is the transparency & documentation you keep.
Shadow AI on departmental Zoom calls
IT Security · shadow-AI discovery
A department has quietly adopted a free AI note-taker that joins Zoom meetings containing FERPA-protected student data.
Govern
Apply the shadow-AI risk-management and data-governance policies.
Map
A discovery scan finds the tool; classify the data it touched and add it to the inventory.
Measure
Run a security risk assessment and review the vendor’s data-use terms and logging.
Manage
Disable the tool, migrate to an approved contained option, and run an incident review.
Outcome — The exposure is contained and an approved, governed alternative is provisioned for the team.
Evidence: Inventory entry + incident report + vendor data-use agreement
An AI coding assistant on institutional repos
IT Development · engineering team
Developers want to use an AI coding assistant that can read private institutional repositories.
Govern
The AI-assisted development standard sets acceptable use and data-exposure rules.
Map
Identify which repositories and secrets the assistant could reach.
Measure
Review AI-generated code security and test for leaked credentials.
Manage
Scope the assistant to safe repos and require code review before merge.
Outcome — Developers gain speed without exposing secrets or shipping insecure code.
Evidence: AI-dev standard sign-off + code-review policy
A custom RAG chatbot on institutional data
IT · custom application
A team builds a retrieval chatbot over institutional documents that include sensitive records.
Govern
The model-selection and deployment standard governs custom AI builds.
Map
Classify the source data and register the system in the inventory.
Measure
Test retrieval for data leakage and run access and logging checks.
Manage
Enforce access controls, log queries, and stage before production.
Outcome — The chatbot serves users without leaking sensitive records.
Evidence: Inventory entry + leakage test + access-control config
Smart-building HVAC optimization
Facilities · operational AI
Facilities deploys AI to optimize HVAC and energy use across campus buildings.
Govern
The campus-operations AI standard governs smart-building systems.
Map
Scope what the system controls and what occupancy data it uses.
Measure
Assess reliability, data retention, and any privacy implications.
Manage
Keep human override and monitor performance and access.
Outcome — Energy use drops with reliable, privacy-respecting operation.
Evidence: Operational-AI standard + data-retention record
Campus camera analytics
Public Safety · security AI
Public Safety proposes AI analytics on campus cameras, including behavioral monitoring.
Govern
The surveillance standard requires privacy and civil-liberties protections.
Map
Classify the data and identify affected community members; trigger Domain 6 review.
Measure
Assess accuracy, bias, and retention before any deployment.
Manage
Require community consultation and strict access and retention limits.
Outcome — Deployment proceeds only with community input and civil-liberties safeguards.
Evidence: Community-consultation record + impact assessment
Low-code AI automation by a department
Administrative unit · citizen development
A department builds a low-code AI workflow that moves student data between systems.
Govern
The low-code / no-code AI platform standard applies.
Map
Identify the data the workflow touches and register it.
Measure
Review the automation for data exposure and error handling.
Manage
Approve within guardrails and monitor the workflow.
Outcome — The unit automates safely without creating an ungoverned data pipe.
Evidence: Inventory entry + low-code review checklist
Data classification for a vendor integration
Data Governance · integration review
A new AI vendor integration will pull records from the student information system.
Govern
The AI data-governance policy sets classification and data-use rules.
Map
Classify the records the integration will access.
Measure
Assess the vendor’s data handling against the classification.
Manage
Approve the minimum necessary data flow and enforce it in contract.
Outcome — The integration moves only the minimum necessary, classified data.
Evidence: Data classification matrix + integration approval
An agentic script with SIS access
IT Development · agentic system
A developer proposes an agent that can take actions in the student information system.
Govern
The agentic-development standard sets human-in-the-loop and action boundaries.
Map
Define what actions the agent can take and what it can reach.
Measure
Test action boundaries, logging, and failure handling.
Manage
Require human approval for consequential actions and a kill-switch.
Outcome — The agent operates within hard boundaries and full logging.
Evidence: Action-boundary spec + agentic review record
AI in the IT help desk
IT Service Management
The help desk adds an AI assistant that reads tickets containing personal data.
Govern
Data-governance and acceptable-use policies cover the assistant.
Map
Identify the personal data in tickets the assistant processes.
Measure
Review data handling, retention, and logging.
Manage
Restrict data, mask where possible, and monitor use.
Outcome — The assistant speeds support without over-exposing personal data.
Evidence: Data-handling review + retention config
Model/data leakage via a browser extension
IT Security · endpoint risk
Staff install an AI browser extension that sends page content — including records — to a third party.
Govern
The shadow-AI policy covers unsanctioned extensions.
Map
Discover the extension and classify the data it exfiltrates.
Measure
Assess the exposure and the vendor’s data practices.
Manage
Block or restrict the extension and offer a safe alternative.
Outcome — The leak is closed and staff get a governed alternative.
Evidence: Discovery finding + endpoint-policy update
Risk-tier examples
Assistive
AI code completion with no access to production data.
Operational
AI-assisted scheduling and space-optimization in campus operations.
Consequential
AI-enabled surveillance and security systems with behavioral monitoring.
Tools & artifacts
AI system inventory
Shadow-AI discovery scan
Security risk assessment
Data classification matrix
Incident-response runbook
Key controls & instruments
AI data governance policy
Shadow AI risk management policy
AI-generated code review & security standards
Audit-trail & logging standards