Principles Without Capacity: The Limits of Ethical AI Governance in Higher Education

By Javier Surasky

ES: Versión en español

Researchers, professors, and students build an ethical bridge toward AI infrastructure guided by autonomy, transparency, privacy, equality, and human oversight.

Discussions of artificial intelligence in higher education are often organized around principles such as autonomy, transparency, equality, privacy, accountability, and human oversight. Necessary as these principles are, they leave one critical issue largely unexplored: the institutional conditions required to put them into practice, a part of AI digital governance.

UNESCO has warned that “the effective and ethical use of AI in education depends on various factors including, but not limited to, access to digital infrastructure, and to the internet in particular; availability of AI resources; regulations on data security and privacy; policy guidance and incentives; and professional development opportunities.” (Miao & Cukurova, 2024, p. 22).

Putting ethical principles into practice requires material, legal, organizational, and professional capacities that universities do not always possess. Transparency depends on having sufficient information about the systems being used. Privacy requires an understanding of what data are generated, how they are processed, and where they are stored. Human oversight presupposes that those responsible for exercising it have adequate knowledge, time, and authority. Equality requires accessible services, while accountability depends on identifiable authorities, oversight procedures, and accessible and secure complaint mechanisms.

Ethical AI governance in higher education, therefore, faces a gap between demanding normative principles and institutional capacities that are insufficient or unevenly distributed.

Principles in Context

Any institution, including a university, can't prohibit certain practices without developing the capacity needed to enforce those prohibitions.

An ethical framework for AI in higher education should establish which uses in research, teaching, and administration are acceptable. It should also specify the conditions, procedures, and oversight mechanisms under which those uses may take place. As Reimers et al. (2026, p. 157) observe, “The promise of AI in education cannot be understood in isolation, particularly in fragile systems where initial conditions, such as infrastructure, teacher capacity, and inequality, exert powerful influences”.

Every educational technology enters a preexisting structure of resources, skills, hierarchies, and inequalities that shapes how it is adopted and used. In the case of AI, outcomes are conditioned by differences in access, understanding, and the ability to respond when rules are breached or systems fail. A university with technical teams, legal counsel, its own infrastructure, and the ability to negotiate with vendors can integrate new technologies under very different conditions from one that relies on free versions, external services, and fragmented or poorly coordinated decision-making structures.

Applying the same principle uniformly to institutions with different capacities can produce unequal outcomes. Such differences arise not only between universities but also among faculties, campuses, and administrative units within the same institution.

Major AI systems are developed, maintained, and modified by actors outside universities. Their internal mechanisms are not necessarily transparent, and their terms of use, functions, and costs may change as a result of decisions over which educational institutions have no control.

This problem has been widely examined in other areas of technology governance, yet it remains insufficiently incorporated into university debates on AI. Universities are attempting to govern technologies over which they exercise only limited control. Several of those limitations deserve closer attention.

Infrastructure

The infrastructure required to work with AI includes Internet access and computers, but also processing capacity, secure storage, cloud services, stable networks, maintenance, specialized technical support, and cybersecurity safeguards.

These resources cannot be assessed solely in quantitative terms. Computing, storage, and connectivity needs vary across disciplines and intended uses. Indicators that appear equivalent may therefore conceal substantial differences in quality and adequacy, both between universities and among faculties within the same institution.

From this perspective, the recommendation to prioritize generative artificial intelligence tools “that are open access or low cost” (Sánchez Mendiola & Carbajal Degante, 2023, p. 80) may reduce barriers to entry, but it does not eliminate inequalities arising from differences between versions, computing capacity, technical support, security, and access to advanced features. Nor does it prevent new forms of stratification among institutions, faculty, and students.

Debates on ethics in higher education should therefore incorporate a dimension of strategic autonomy. This should not be understood as technological self-sufficiency, but as an institution’s capacity to evaluate systems, compare alternatives, negotiate terms, restrict uses, choose among providers, and replace technologies when they no longer meet the technical, legal, or ethical requirements established by the university.

Human Capacity as Infrastructure

Capacity building for AI should reach everyone who participates in university life: institutional authorities, administrative teams, faculty, professional and support staff, researchers, and students.

Training is part of the institutional infrastructure required to govern technology. It should not be limited to learning how to write effective prompts or use the features available in a particular application.

Those involved need at least a basic understanding of how AI systems work, what biases are, how they may arise, what privacy risks these systems create, and how they may affect teaching, assessment, research, and administration. They also need access to institutional channels for consultation, guidance, and training.

Training requirements should increase in proportion to a person’s institutional responsibilities and to the potential impact of the systems with which they work. Using a tool to organize study materials does not require the same capabilities as deciding whether to incorporate it into assessment, resource allocation, or the management of students’ academic trajectories.

Training must also be continuous and context-specific. AI systems change rapidly, add new features, and alter their terms of use. The needs of different disciplines and university activities also vary. Studying, teaching, conducting research, and managing institutions with AI require different skills.

Universities need to educate critical users, not merely certify instrumental competencies.

Transparency

In discussions of ethics in higher education, transparency is usually framed as an obligation imposed on students, researchers, and faculty. They may be required to disclose that they used an AI tool, explain the purpose for which it was used, or retain a record of the instructions given to the system. These measures are useful, but they address only part of the problem.

Transparency requirements should also apply to institutions and technology providers. A university seeking to make its ethical principles operational needs to know, at a minimum, what functions each system performs, what data it receives, how long it retains them, whether it reuses them, where it processes them, and what mechanisms it provides for deleting or retrieving information.

There is little value in imposing strict rules on users if the institution then accepts lengthy and difficult-to-understand contracts containing data reuse provisions that it does not fully understand.

Complete technical transparency is not possible in the field of AI. Even so, companies seeking to provide services to universities should supply the information requested by the institution. That information should then be assessed against the university’s ethical principles when contracts, purchases, or authorizations for use are being considered.

Institutions with greater capacity can review contracts, test systems, and negotiate specific clauses. Those without such resources are often compelled to accept standard terms.

Interuniversity cooperation may therefore be necessary to pool technical and legal expertise and reduce disparities in bargaining power.

Privacy

The educational use of AI involves continuous information flows. Students, faculty, researchers, and administrative teams may enter academic work, assessments, research data, personal records, and institutional information into AI systems.

A general warning not to upload sensitive information is insufficient, partly because there is not always a shared understanding of what should count as sensitive information.

Privacy thus reappears as a question of institutional capacity. It exposes the tension between the need to record interactions or preserve evidence and the potential expansion of surveillance over students and university employees that such records may enable.

This tension is intensified by the asymmetry inherent in educational relationships. When a platform is mandatory for taking a course, teaching, or being assessed, accepting its terms is not a genuinely free choice. The same applies when an institution requires its staff to use particular digital environments to perform their work.

Human Oversight

Chan and Colloton argue that “Adopting AI technologies into academic settings requires a structured approach to monitoring and evaluating AI implementation” (2024, p. 150).

Human oversight, or keeping a human in the loop, is often presented as a way to reinforce other principles and prevent decisions from being made entirely by machines. Under this model, a system may provide suggestions or assistance, while final responsibility remains with a human decision-maker.

That formula is insufficient unless institutions specify who is responsible for oversight, what must be reviewed, and what authority the reviewer has when a problem is identified.

Human responsibility also requires competence, time, information, and the authority to modify, challenge, or reject a system’s output. No one exercises meaningful control when they are limited to approving results they do not understand, or when the volume of decisions makes substantive review materially impossible.

It is also necessary to distinguish among levels of risk. Using AI to organize a bibliography is not equivalent to using it to decide whether a student may enroll in a course, allocate resources, or assess academic performance. The greater the potential impact on rights, academic trajectories, or resource distribution, the stronger the requirements for documentation, oversight, review, and training should be.

To prevent human oversight from becoming a passive review of results, it must be accompanied by clear and workable channels for reporting incidents and challenging decisions. Students, faculty, researchers, and university staff must know where to file a complaint, what procedure applies, and what remedies or corrective measures are available.

Efforts by Argentine Universities

Argentine universities have begun to develop internal instruments to guide the use of AI, although their scope and level of operational detail vary.

The National University of Cuyo adopted its Principles for the Responsible Use of Generative AI through University Council Resolution 262/2026. The document addresses human-centeredness, academic integrity, data protection, accessibility, technological sovereignty, traceability, and institutional evaluation. It also provides for support mechanisms for students, faculty, and staff, as well as auditing criteria.

The National Technological University adopted a more narrowly focused instrument. Resolution 279/2026 establishes guidelines for the use of generative AI in postgraduate courses and thesis writing. It includes requirements for human oversight and control, differentiated responsibilities for faculty, students, thesis supervisors, and evaluators, and a review of the contractual terms governing the tools in use in order to prevent risks to intellectual property.

The National University of the Northeast followed a different approach. Resolution 9323/2025 approved regulations governing the implementation and use of its institutional “IA UNNE” system. The instrument links principles of transparency, explainability, data protection, bias mitigation, and accountability to mechanisms for informed consent, human validation, traceability, auditing, and system updates.

At larger and more decentralized universities, such as the University of Buenos Aires and the National University of La Plata, responses are distributed between central authorities and individual faculties.

At the University of Buenos Aires, the Faculty of Economics adopted its own rules governing the academic use of AI, while the Faculty of Law developed a pilot program focused on AI literacy and the strategic and responsible use of generative AI in legal practice. There is, however, no single university-wide policy covering all faculties.

At the National University of La Plata, an Artificial Intelligence Working Group was established with representatives from the central administration, faculty, researchers, and professional and support staff from different academic units. Individual faculties have also adopted their own documents, including a practical guide for faculty developed by the Faculty of Law and Social Sciences. The university likewise has no general regulation applicable to all functions and academic units.

These cases reveal a range of responses: guiding principles, mandatory guidelines, regulations for institutional systems, coordinating bodies, and sector-specific recommendations. They represent meaningful progress, but the capacity to implement them effectively, monitor compliance, and review them periodically remains an open question.

Basic First Steps

In light of these developments and limitations, universities need to move from general declarations to concrete mechanisms for gathering information, making decisions, and exercising oversight.

The first step should be to map the systems currently in use and the functions they perform, the data they process and the contractual terms that apply, the existing risks and safeguards, and the distribution of capacities and responsibilities across the institution. Without this baseline information, ethical principles risk remaining disconnected from actual practice.

Based on that assessment, each university can review its existing policies, address previously unanticipated uses, identify gaps, and set priorities according to factors such as the potential for harm, the scale of a system’s use, and its possible effects on rights and academic trajectories.

The rapid pace of technological change requires flexible institutional structures capable of responding effectively. University policies should therefore provide for periodic evaluation involving all affected groups, accessible complaint mechanisms, and the authority to suspend uses when sufficient safeguards are not in place.

This work also requires coordination across faculties, especially at large and decentralized universities. Bodies such as the Artificial Intelligence Working Group created by the National University of La Plata, which brings together representatives from across the university, can perform this function if they are given clear responsibilities, adequate resources, and an operational mandate.

Conclusion

Ethical AI governance in higher education depends on the capacity to translate declaratory principles into decisions, procedures, and oversight mechanisms. Doing so requires information, infrastructure, human capacity, technical and legal expertise, clearly assigned responsibilities, and accessible channels for complaints and review.

It also requires distinctions among the different areas of university activity. Administration, research, and teaching involve different risks, actors, and oversight needs. A general policy may establish a shared set of core principles, but its implementation must account for these differences.

Developing such capacities requires staff time, dedicated teams, training programs, and sustained investment. This point must be stated clearly: without adequate funding, universities will find it difficult to give AI governance the priority it requires.

Without resources, clearly assigned responsibilities, professional capacity, and effective oversight procedures, ethical principles will remain institutional declarations rather than functioning as meaningful standards for governing AI.

Educating professionals and citizens for a world that is already digital requires universities to address this issue seriously and urgently. Only then can they fulfill their responsibility to prepare graduates to respond to the needs of the societies in which they live and work.


References

Chan, C. K. Y., & Colloton, T. (2024). Generative AI in higher education: The ChatGPT effect. Routledge. https://doi.org/10.4324/9781003459026

Miao, F., & Cukurova, M. (2024). AI competency framework for teachers. UNESCO. https://unesdoc.unesco.org/ark:/48223/pf0000391104

Reimers, F., Azim, Z., Palomo, M.R., & Thony, C. (2026). Artificial intelligence and education in the Global South: A systems perspective. Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-11449-5

Sánchez Mendiola, M., & Carbajal Degante, E. (2023). La inteligencia artificial generativa y la educación universitaria: ¿Salió el genio de la lámpara? Perfiles Educativos, 45(special edition), 70-86. https://doi.org/10.22201/iisue.24486167e.2023.Especial.