← All educational resources
Leadership

The Institutional AI Governance Charter Worksheet

A free resource for higher ed & EdTech leaders · Fillable PDF included

Most institutions have an AI committee. Far fewer have a charter. A committee meets, debates, and produces minutes. A charter says who decides what, which uses are allowed, what has to be disclosed, and who is accountable when a system gets a decision wrong. This worksheet is how you write one — and how you find out which AI is already running on your campus.

Prefer a printable, fill-in version? Download AI Governance Charter Worksheet as a branded PDF — ready to print and complete by hand or on screen.

Download the fillable PDF →

Ask a provost or a district superintendent who approves a new AI tool and you will usually get a pause, then a name, then a qualification: "well, it depends what kind of tool." That pause is the governance gap. It isn't a shortage of policy — most institutions have written something about generative AI in the last two years — it's that the policy speaks to students and instructors about coursework, while the systems that actually make consequential decisions about people (admissions screening, early-alert risk scoring, automated grading, integrity monitoring) were procured and deployed by different offices under no shared rule at all.

Governance is a decision-rights problem before it is a technology problem

The useful mental model here comes from the NIST AI Risk Management Framework, which organizes AI risk work into four functions — Govern, Map, Measure, and Manage. The ordering matters. Govern is the one that spans the whole organization and makes the other three repeatable; without it you get well-intentioned one-off reviews that don't survive a staffing change. In practice, "govern" means writing down four things: what counts as an in-scope AI system, who has authority to approve one, what conditions attach to approval, and who is accountable for outcomes. Everything else in this worksheet is downstream of those four answers.

The regulatory clock moved — but only the clock

Institutions with any European footprint (branch campuses, EU-resident online students, EdTech vendors selling into the EU) should know exactly where the EU AI Act now stands, because the dates changed this summer and a lot of internal planning is running on the old ones. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the main obligations for stand-alone high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027; high-risk AI embedded in regulated products under Annex I moves to 2 August 2028. What did not move: the Article 50 transparency rules began to apply on 2 August 2026, and enforcement started then for general-purpose AI models, the prohibitions, transparency, and AI literacy.

Education is one of the eight sensitive areas in Annex III, and it is worth reading the four sub-points literally, because they map onto systems many institutions already run: 3(a) determining access or admission or assigning people to institutions; 3(b) evaluating learning outcomes; 3(c) assessing the appropriate level of education a person will receive; and 3(d) monitoring and detecting prohibited behaviour of students during tests. That last one is proctoring. If you use automated monitoring in assessment, you are looking at a named high-risk category with a fixed date — and sixteen extra months is a planning window, not a reprieve. The substantive requirements did not change; only the date on which non-compliance begins to matter did.

How to use this worksheet

Work it in order. Start with the charter pre-flight checklist — if you can't check an item, that's not a failure, it's the agenda for your next governance meeting. Then build the use case register, and be deliberately generous about what you include: the free pilot in one department, the vendor feature that quietly turned on in an existing platform, and the spreadsheet macro someone replaced with a model all belong on the list. Most institutions are surprised by the length of their own register the first time they build it honestly. The decision rights matrix is where the charter earns its keep — assign a single accountable owner per decision type rather than a committee, because committees deliberate and individuals decide. Finish with the readiness calendar so the work is dated and owned rather than aspirational.

If assessment and integrity systems are on your register, our accreditation readiness scorecard pairs well with this — accreditors increasingly ask how you validate the tools that touch student evaluation. For help standing up a governance charter, running the use case inventory, or reviewing vendor AI terms at scale, see our advisory services or get in touch.

The worksheet

Use the template below on this page, or grab the fillable PDF to print and share with your team.

1 — Charter pre-flight

Your charter is ready to circulate when every item below can be checked. Anything you can't check is the agenda for the next meeting — mark it and assign it.

  • We have a written definition of what counts as an in-scope "AI system" for governance purposes, and it does not depend on a vendor calling it AI.
  • The charter names a single accountable executive owner for institutional AI risk — a person, not a committee.
  • Decision rights are written down: who may approve a pilot, who must approve a production deployment, and what escalates to the cabinet or board.
  • We have defined risk tiers and stated what changes at each tier (review depth, human oversight, documentation, approval level).
  • Any system that influences a consequential decision about a person — admission, placement, progression, grading, integrity findings — is explicitly tiered as high risk regardless of jurisdiction.
  • Human oversight is specified operationally: who reviews, what they can see, what authority they have to override, and how the override is recorded.
  • We have a disclosure standard: when students and staff are told an AI system is involved, and in what words.
  • There is a stated appeal route for a person affected by an AI-influenced decision, and someone is resourced to handle appeals.
  • Procurement is bound to the charter — contracts must address training on institutional data, model changes, subprocessors, logging, and evaluation evidence.
  • The charter names what we will not do with AI, not only what we will.
  • A review cadence and a sunset/renewal date are set for the charter itself.
2 — AI use case register

One row per system actually in use or piloting. Include free tiers, features switched on inside platforms you already own, and departmental experiments. Under the EU AI Act's Annex III, education use cases include 3(a) access/admission, 3(b) evaluating learning outcomes, 3(c) assessing appropriate level of education, and 3(d) monitoring prohibited behaviour during tests — mark which, if any, applies.

System / vendorOwning unitWhat decision it influencesWho is affectedAnnex III point (3a-3d / none)Human review in place?Risk tierApproved by / dateNext review
Early-alert risk scoring in the SISStudent successWhich students get outreach and advising holdsUndergraduatesNone — advising, not placementAdvisor reviews before any holdHighProvost — Mar 2026Mar 2027
         
         
         
         
         
         
         
         
         
         
3 — Decision rights matrix

Fill one row per decision type. Name individuals in the accountable column, not committees — the point of the charter is that someone can be asked why.

Decision typeWho proposesWho reviewsWho approves (accountable individual)Who must be consultedWho is informedStanding conditions on approval
Production deployment of AI touching student evaluationSponsoring deanAI governance group + IT securityProvostRegistrar, general counsel, accessibility officeFaculty senateAnnual bias/accuracy evaluation; documented human override path
       
       
       
       
       
       
       
       
4 — Readiness calendar

Governance decays when it isn't dated. Assign an owner and a target month to each item. If you have EU exposure, anchor the schedule to 2 December 2027, when the main Annex III high-risk obligations begin to apply.

Readiness milestoneOwnerTarget monthEvidence producedStatus
Complete first full AI use case register across all unitsCIOOctober 2026Signed register + gap memo to cabinet
     
     
     
     
     
     
     
     
     

Sources & further reading

  1. AI Omnibus enters into force — extended timelines (Annex III high-risk rules apply from 2 December 2027; Annex I from 2 August 2028) — European Commission, Shaping Europe's digital future
  2. Timeline for the Implementation of the EU AI Act (Article 50 transparency rules apply from 2 August 2026) — European Commission, AI Act Service Desk
  3. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689 — Official Journal of the European Union, EUR-Lex
  4. High-risk classification: Education and vocational training — Annex III points 3(a)-3(d) — European Commission, AI Act Service Desk
  5. AI Risk Management Framework (AI RMF 1.0) Core — Govern, Map, Measure, Manage — National Institute of Standards and Technology (NIST), U.S. Department of Commerce

Want the fillable PDF version?

Download AI Governance Charter Worksheet (PDF)
Work with EdTechXperts More resources