# Scoring the Impact AI Is Having on Higher Education

**Published:** 2026-09-07  
**Author:** Kin Lane  
**Canonical:** https://apievangelist.com/2026/09/07/scoring-the-impact-ai-is-having-on-higher-education/

I spent the summer studying the impact AI is having on higher education with my intern Emily Barton. We each dug into how AI is being used on the campuses of universities relevant to our own worlds — Emily looked at her school and the wider California system, and I looked at NYU and Columbia. July produced two essays from each of us, and this represents the second essay from me. I've come out of the summer with a fresh understanding of APIs in higher education, but also of the different ways students, faculty, administrators, and even governments are responding to this moment.

## Courses, Programs, and Degrees — Vendors and Capacity (Kin)

As part of my ongoing university profiling work, I put NYU and Columbia side by side — two large private research universities in the same city, held constant in weight class so that what actually differs in their AI strategy comes into focus. What I found is that the research layer barely differentiates them at all: both run serious in-house GPU compute, both have deep cross-school AI faculty, and both landed on the same policy fundamentals around disclosure, academic integrity, and enterprise-privacy vendor tiers. The divergence lives entirely in the community-tools and curriculum layer — what each institution actually puts in the hands of students and staff, and whether the AI wave changed the degrees themselves. Columbia created a new MS in Artificial Intelligence and an AI minor, and concentrated ownership of "Columbia AI" in its Data Science Institute; NYU left its degree programs unchanged and split responsibility between central IT and the Provost's AI-in-Education office.

The sharpest fork is build versus buy. NYU buys and rebrands — its community-facing AI is vendor chat interfaces, almost entirely Google, provisioned through NYU identity, with no institution-controlled platform or developer surface beyond a not-yet-public pilot. Columbia buys and builds — it licenses all three major model vendors (OpenAI, Anthropic, Google) but wraps them in CHAT, its own self-hosted LibreChat platform, keeping the control plane and the data in-house, with documented custom agents and a platform underneath that supports MCP and OpenAPI Actions. Through the agent- and API-native lens this research applies to every school, that makes Columbia the "own your stack" model and NYU the "vendor passthrough" model — and Columbia clearly leads, because it built the control plane and agent-capable surface NYU still lacks, and changed its curriculum where NYU didn't. Neither posture is obviously wrong, but the single-owner org structure and multi-vendor hedge behind Columbia's tooling is a hypothesis I'll be testing against the schools still to come.

## Students, Faculty, and Administrators — Trust and Labor (Emily)

Emily's research anchors on Loyola Marymount University and then widens out to the California higher-education landscape, and the LMU portrait is a useful contrast to the big research universities: rather than building anything of its own, LMU provisions a long roster of vendor AI embedded in existing tools — Microsoft Copilot, Adobe Firefly, Zoom AI Companion, [Otter.ai](http://otter.ai/) for accessibility accommodations, Turnitin's AI detector, Respondus proctoring — while leaving actual classroom policy to individual instructors through the syllabus, with a default that AI use is prohibited absent explicit permission and that permitted use must be attributed or it counts as academic dishonesty. Her student-newspaper polling and faculty interviews capture where the culture actually sits: roughly half of students never use AI for coursework, a slim majority think using it is appropriate, and both students and faculty converge on the same line — AI as a tool for digesting and jump-starting material is legitimate, but submitting its output as your own work defeats the point of paying for an education. The Ai-DEAL training suite from LMU's iDEAL program shows the institution investing in AI literacy for educators and even parents, though Emily flags the right open question: whether anyone is required to take it, or does.

The California survey is where the structural findings emerge. Emily's comparison table across UC Irvine, the CSU system, Stanford, UCLA, USC, and UC Davis shows the same build-versus-buy fork from the NYU/Columbia work, with UC Irvine's ZotGPT as the standout "own your stack" case — a full proprietary ecosystem including ClassChat for course-trained bots, Creator for custom workflows, and most notably the ZotGPT Gateway, a genuine API platform with multi-model access, budget controls, and instant key management, which UCI now sells to other institutions. Around that she documents the friction the vendor-passthrough schools are generating: CSU faculty and students publicly contesting the ChatGPT Edu contract renewal (including an unfair practice charge from the faculty union), Stanford abandoning a 105-year-old honor code to allow proctored exams, and a Brown case study suggesting AI-permissive take-home exams correlate with worse outcomes and no financial incentive for faculty to police misuse. Two cross-cutting patterns she surfaces deserve to travel into the broader research: the P1–P4 data-classification tiers that govern what can legally touch these tools (FERPA, HIPAA, export-controlled data), and the striking consensus at Berkeley, Caltech, and USC against AI detectors — on accuracy, trust, and privacy grounds — in favor of pedagogical redesign, even as LMU still ships Turnitin's detector to every instructor.

## July's AI Assessment

Coming out of our research in July, I took what I learned, compared it with what I know outside of academia, and [wrote about how, when you strip out the university, this really becomes a template that any enterprise organization can apply](https://apievangelist.com/2026/08/03/strip-out-the-university-and-this-is-a-template/) — I feel the lessons are universal. Emily emphasized the tensions between administrators, faculty, and students, highlighting [how professors became the AI police in this moment](https://apievangelist.com/2026/07/31/professors-became-the-ai-police/). I am very much coming at this from a technical perspective, while Emily wrestled with the labor, ethics, and realities of AI on campus, and how it is shaping the professor–student relationship, with or without the guidance of administrators. For me, the big lesson came out of Emily's work on the UC system and ZotGPT, [which provides a glimpse of what it looks like when a university owns its AI infrastructure](https://apievangelist.com/2026/07/28/zotgpt-what-it-looks-like-when-a-university-owns-its-ai-infrastructure/).

## August's Research Widened the Lens

After talking through each of our essays, we agreed that we wanted to widen the scope of our research and get out of the United States. I chose the UK, India, and South Korea, and Emily looked at Europe in general. The work helped us both get out of our comfort zones, think about the bigger picture, and challenge our American views of AI and education. There are definitely similarities in how international universities are approaching AI in this moment, but there are also new tactics and strategies being employed that speak to the different cultures and societal norms that shaped each of our stories.

## Governance, Benefactors, and Vendors — Policy and Money (Kin)

I spread my research across three universities — the Open University, Yonsei, and BITS Pilani — chosen to test whether the NYU/Columbia findings held outside the American private-research archetype, and they broke or inverted most of them. Each answered the AI wave with a different instrument entirely. The OU wrote the most formal governance found anywhere in this research — a versioned, board-approved Responsible AI Policy scoped against the EU AI Act, owned by risk and compliance rather than a provost, with exactly one sanctioned tool — while also operating the only real institution-controlled API in the study: CORE, a keyed public API over 400M+ open-access works, built by its Knowledge Media Institute out of the open-scholarship function, not any AI strategy. Yonsei reorganized a college — three AI degree programs since 2019 and a college renamed "AI Convergence" in Korean — yet provides no generative AI at all, licensing only detection tools, and in October 2025 watched a 600-student online midterm get defeated by ChatGPT under exactly the proctoring its own guideline prescribed. BITS Pilani is pouring concrete: a ₹1,000 crore AI+ campus at Amaravati inside a reported ₹2,200 crore programme, agentic AI taught as named modules in degrees priced and sold to working professionals — and no findable institutional AI policy at all.

The trio reframed the study's axes. Buy-versus-build, the question that structured the NYU/Columbia comparison, turns out to be a local anomaly of well-endowed American universities — three of the five institutions now profiled provide either no generative AI or a single narrowly-scoped tool, and the five together offer five incomparable instruments: vendor seats, a platform, a policy, a curriculum, a campus. Two findings sharpened rather than broke. Agent- and API-readiness remains the strongest discriminator and remains mostly a story of absence — no api. or developer. host resolves at Yonsei or BITS — and the one real agent surface came from the library tradition, not the AI office. And governance ownership predicts tool posture, but with the sign flipped: concentrating AI in a compliance function narrows the stack rather than enriching it, regulatory gravity (the EU AI Act) produces the policy document where India's delegated regime produces none, and Yonsei demonstrates that publishing a policy is not the same as having one that survives contact with reality.

## Discourse, Disclosure, and Oversight — Culture and Sovereignty (Emily)

The EU and the UK have answered the same question we have — what does AI governance in higher education look like? — with opposite instruments. The EU's is statutory: the AI Act binds every member state, classifies educational AI in admissions, assessment, and proctoring as "high-risk," bans emotion-recognition and biometric categorization in classrooms outright under Article 5, and reaches any provider serving EU students regardless of where they're based, with full compliance for grading and trajectory tools mandated by August 2026. The UK's is discretionary by design: a "pro-innovation" government posture leaves universities as autonomous bodies, coordinated only by principles-based frameworks — the Russell Group's five principles for its 24 universities, Jisc's guidance for further education — that emphasize AI literacy, pedagogical adaptation, and institutional autonomy over prescriptive mandates. Neither model is comfortable on the ground. The UK recorded nearly 7,000 proven cases of AI-assisted cheating in 2023–24 (rising from 5.1 to 7.5 cases per 1,000 students) while HEPI found 88% of students using AI for assessments; and on both sides of the Channel, AI detection is losing institutional confidence — Waterloo dropped Turnitin as unreliable and biased against ESL students, MIT concluded detectors don't work, and the emerging consensus response is assessment redesign: in-person exams, oral defenses, staged submissions, and process-based evaluation rather than surveillance.

The second-order effect of the EU's regulatory gravity is a build-out, not just a rulebook: because dependence on American commercial platforms sits awkwardly with the AI Act, GDPR, and European linguistic diversity, the sovereignty answer is increasingly coming from universities themselves. ETH Zurich and EPFL's Apertus — an open-weights LLM trained on 15 trillion tokens of openly available data, roughly 40% non-English, using the "goldfish objective" to prevent verbatim memorization of training text — and OpenTela, a peer-to-peer serving mesh that has handled 13 million requests across 142 models for over 1,000 researchers, are the flagship cases, alongside UvA's GDPR-compliant wrapper around commercial models, Bocconi's LUIGI playground, and PSL's planned archive-trained model under France 2030. The periphery is testing the edges of the model: Estonia is putting ChatGPT Edu into its national secondary system ("think of it like a calculator"), Finland's locally-running, GDPR-compliant Generation AI literacy tools won the EU's 2026 Digital Skills Award, and the EU–Morocco digital dialogue extends the sovereignty framework toward Africa. Even the commercial market is bending to the framework — Anthropic now watermarks all Claude output worldwide to meet Article 50 transparency rules — though an Exeter-published study warns the deeper tension remains unresolved: comprehensive, anticipatory guardrails may simply be unable to absorb the pace of the technology they regulate, compared with the reactive, sector-by-sector American approach.

## The Kin Score - University Assessment

July's work by Emily and me reinforced what I had been working on all summer to help quantify the programmability of enterprise organizations outside of academia. The blueprint provided by ZotGPT echoed the composite portion of what I dubbed the Kin Score this summer. It is a scoring system I had been developing in one form or another since 2014, but I began formalizing it in June to help me assess the footprint of enterprise API programs — work that ZotGPT and other university API programs helped validate. The composite score of the Kin Score measures the following surface area of any enterprise, including higher-education institutions:

- Contract Quality — Technical depth and richness of the API contract artifacts: OpenAPI, AsyncAPI, JSON Schema, JSON-LD, and other machine-readable artifacts.
- Developer Ergonomics — How easy is it to get started? SDKs, CLI, portal, getting-started, documentation, sandbox/console, MCP server, and authentication clarity.
- Access Clarity — What it costs, what you are permitted to do, and how you get in: plans, pricing, sign-up, terms of service, privacy, FinOps mapping, compliance/trust.
- Operational Transparency — Does the provider expose how the API behaves operationally? Rate limits, status, changelog, deprecation, security disclosure.
- Contract Governance — Artifacts that describe and constrain the contract: rulesets, vocabulary, declared conformance, overlays.
- Discoverability — Can the API be found and understood from machine-readable metadata alone? Driven by apis.yml completeness, tagging, and identity signals.
- Regulatory Posture — Does the API publish the consent, security, legal, and standards-conformance posture its regime demands?
- Open-Source Surface — Does the repository publish the maintainership surface a consumer needs in order to depend on it?

These facets measure the foundation of what is needed to support web, mobile, device, and AI applications, but also the interoperability required to operate online today. Our research this summer into AI adoption at higher-education institutions helped push me to add four optional facets that apply when applying the Kin Score to university operations:

- Governance & Accountability — Is there a versioned policy with a named owner, a senior accountable officer, a standing body, and a mandatory assessment before deployment?
- Programmatic & Agent Surface — Is there an institution-operated model gateway with keys, budgets, and usage visibility? An OpenAPI on a domain the institution owns? A scholarly API that answers a query, not just returns 200?
- Provided Surface & Equity of Access — What is sanctioned, who is eligible, and do distance and online cohorts get the same access as residential? Is compute capacity disclosed and reachable by anyone beyond research faculty?
- Curriculum, Integrity & Disclosure — Did the degrees change? Is agentic AI taught? Was the integrity control tested and revised after it failed? Are vendors named with their data terms?

These facets are meant to quantify the characteristics of AI adoption, but also the API foundation required to do AI effectively as an enterprise. I consider these facets essential if you are going to invest in your internal capacity as an institution or enterprise, but when it comes to investing in the future workforce of any country or region, they are fundamental. This is how we make sure we are properly equipping students, but also professionals, with what they need to effectively use AI, rather than be used by AI. This is how we ensure we aren't just outsourcing everything we know to a handful of vendors, and are investing in the institutional and enterprise capacity required to be competitive in today's market.

I learned a lot this summer working with Emily. Her perspective on the University of California system, and her assessment of AI adoption in Europe, helped shape how I will continue assessing higher-education institutions. I've already begun applying my new rating system to 250+ universities around the world, and by the end of September I should have an informed view of the programmability of these institutions and how they are being impacted by artificial intelligence. I don't anticipate these findings will immediately frame the impact AI is having on universities for me, but they will provide me with a baseline I can use to fire up conversations with administrators, faculty, students, and the vendors selling to universities. Then I can learn more, and iterate upon the educational facets of my Kin Score over time. As I write this, New York and Los Angeles have imposed restrictions on the usage of AI at the K–12 level — something I think will send shockwaves through the industry. I look forward to continuing to tune into the impact AI is having on higher education, and I'm thankful Emily came to work with me this summer. While I do still worry about her future in an AI-fueled workforce, I'm confident she will find her way forward.

---

*Emily Barton's companion essay from this same research, on how the EU and UK are answering the sovereignty question inside their universities, is here: [Personalities of Sovereign AI](/2026/09/07/personalities-of-sovereign-ai/). You can connect with her on [LinkedIn](https://www.linkedin.com/in/emily-i-barton/).*
