Faculty use AI to grade essays. Students upload assignments to AI writing tools. Administrators paste student records into chatbots. Your LMS audit log sees none of it. A DNS log audit does.
Open campus networks, BYOD policies and a culture of academic freedom create the perfect environment for uncontrolled AI adoption. FERPA and state student-privacy laws add regulatory teeth.
Faculty paste student submissions into AI tools for feedback generation, plagiarism analysis and rubric-based scoring. Each paste sends student work and identifiers to a third-party server.
Students use AI writing assistants, code generators and research tools on the campus network. Usage patterns reveal which departments and courses have the highest adoption.
Admissions, financial aid and registrar staff paste student records into AI tools for letter drafting, report generation and data analysis. FERPA-protected data flows to unvetted vendors.
Faculty upload research datasets containing human-subjects data to AI analysis platforms. IRB approvals do not account for AI tool data handling, creating compliance gaps.
Faculty use AI to generate lecture materials, quiz questions and course outlines. While lower risk, it creates dependency on tools the institution has not vetted or licensed.
Academic advisors and counsellors use AI chatbots for student communication drafts. Messages contain grades, disciplinary records and accommodation details protected under FERPA.
Shadow AI creates compliance gaps across federal and state student privacy frameworks.
| Requirement | Source | Shadow AI Risk | What the Audit Produces |
|---|---|---|---|
| Education Records Protection | FERPA 99.3 | Student records shared with AI vendors without consent | AI tools accessed by admin staff with data-handling policies |
| Directory Information Controls | FERPA 99.37 | Student names/IDs in AI tool prompts | Usage patterns by department for risk assessment |
| School Official Exception | FERPA 99.31(a)(1) | AI vendors do not meet school official criteria | Vendor assessment with legitimate educational interest analysis |
| Student Data Privacy | State laws (SOPIPA, etc.) | AI tools collecting student data without contracts | Complete AI vendor list for state compliance review |
| Data Minimisation | State student privacy acts | Excessive data shared in AI prompts | Tool-by-tool risk classification for policy decisions |
| Research Compliance | IRB / Common Rule | Human-subjects data in AI analysis tools | Research-related AI tools identified by faculty usage patterns |
Sample excerpt from a shadow AI audit of a mid-sized university (18,000 students).
An admissions officer pastes applicant essays and recommendation letters into ChatGPT to generate evaluation summaries. Each prompt contains the applicant's name, school, GPA and personal statement. The AI vendor stores and may train on this FERPA-protected data.
A psychology professor uploads survey responses containing participant demographics and health indicators to an AI analysis tool. The IRB approval does not mention this tool. The vendor's terms permit training on uploaded data, violating informed consent.
A financial aid counsellor uses an AI writing tool to draft award letters and appeal responses. Each letter contains the student's name, family income, EFC and award amounts. The AI tool has no student data privacy agreement with the institution.
A department adopts an AI-powered proctoring tool that monitors students via webcam during exams. The tool uses facial recognition and behaviour analysis. The institution has no data processing agreement, and students were not informed their biometric data would be processed by a third party.
Upload your campus DNS logs and get a FERPA-mapped shadow AI inventory with department-level usage patterns.
Start Your Free Audit