As Artificial Intelligence becomes increasingly embedded across higher education, universities must balance the opportunities it creates with new risks around data security, third-party services and cyber-resilience. Dr Fadi Alhaddadin, Director of MSc Information Technology (Business) Programme, School of Mathematical and Computer Sciences, Heriot-Watt University Dubai, tells us why secure AI adoption requires strong governance, resilient technology and a university-wide culture of cybersecurity.

Artificial intelligence is rapidly becoming part of university life. But as institutions accelerate AI adoption, they may also be creating a cybersecurity challenge, one that cannot be solved by technology alone.
Universities have unusual cybersecurity environments. They are simultaneous places of teaching, research, innovation and open collaboration. They manage sensitive student records, financial information, staff data, intellectual property and research, while operating large and diverse digital ecosystems involving students, academics, researchers, administrators and external partners.
Now, Artificial Intelligence is adding another layer of complexity.
Generative AI tools are increasingly being used in teaching, research, administration, software development and student services. While AI can improve productivity and create new opportunities, it also raises important questions: What data are staff and students putting into AI systems? Where is that data going? Who has access to AI-generated information? And what happens when AI becomes part of a critical university process?
The challenge is no longer simple to adopt AI. It is to adopt it securely.
Cybersecurity risks in higher education are not hypothetical. Universities are attractive targets because of the breadth and value of the information they hold, including student records, financial information, research data and intellectual property.
The growing dependence on cloud services means that a university’s security boundary is no longer limited to its campus network. Universities therefore cannot secure only the systems they own; they must also understand the security of the digital ecosystem on which they depend.
AI makes this ecosystem even more complicated. One of the simplest and easiest-to-overlook risks is the inappropriate sharing of sensitive information. An academic might copy student information into a public Generative AI service, a researcher might upload unpublished findings, or a staff member might paste an internal document into an AI assistant.
The intention may be legitimate, but the key cybersecurity question is: Was the data appropriate to share with that system?
AI governance cannot be separated from data governance. Universities need clear policies defining what information can be entered into AI systems, which tools are approved, how institutional data is protected, and when human review is required. Staff and students should understand that an AI tool is an information-processing environment, not simply a more sophisticated search engine.
This is particularly important because AI systems can introduce risks to confidentiality, integrity and availability, the three foundational objectives of information security. NIST’s AI Risk Management Framework identifies security and resilience as important characteristics of trustworthy AI and highlights risks involving AI systems, their underlying technology, and their data and outputs.
AI can also become the defender
There is, however, another side to the story. The same technology that creates new risks can also strengthen cybersecurity. AI can assist security teams by analysing large volumes of logs, identifying unusual behaviour, summarising security alerts and supporting incident investigations. EDUCAUSE has explored the use of AI in ransomware response and security operations in higher education.
This creates the AI paradox: AI can increase the attack surface while also improving an institution’s ability to defend it.
The answer is not to ban AI, but to develop the capability to use it responsibly. NIST’s Generative AI Profile supports this approach by framing risk management across the AI lifecycle and encouraging organisations to consider their objectives, resources, risk tolerance and applicable requirements. For universities, this means asking security questions before deploying an AI system, not after something goes wrong.
From cybersecurity to cyber-resilience
There is another lesson universities should take from the ransomware era: perfect prevention is unrealistic. A resilient university is not one that assumes it will never suffer a cyberattack; it is one that can continue operating, respond effectively and recover quickly when an attack occurs.
That requires more than firewalls and antivirus software. Universities need tested backups, strong identity and access management, multi-factor authentication, vulnerability management, network segmentation, monitoring and well-rehearsed incident-response procedures. CISA’s ransomware guidance emphasises preparation, prevention, detection, response and recovery rather than relying on a single defensive measure.
Most importantly, universities need to test their plans. A document sitting in a policy folder is not resilience. A tested recovery process is.
People remain part of the security system
Technology, however, is only part of the answer. Higher education is fundamentally a people-centered environment, where students and staff need to experiment, collaborate and share information. Excessively restrictive security controls can undermine that mission, while insufficient controls can expose institutions to unnecessary risk.
The goal should therefore be secure enablement rather than security by restriction. This means providing approved AI tools, clear guidance and practical training; explaining why certain information should not be shared; and involving academics, students, researchers, legal teams, IT professionals and senior leadership in discussions about institutional AI risk.
The key question for higher education is therefore not whether AI should be used. It is how universities can use AI without compromising the trust on which education and research depend.
This requires a shift from viewing cybersecurity as an IT responsibility to seeing it as an institutional capability. Every new AI deployment should raise questions about data, identity, access, third-party dependencies, security testing, human oversight and recovery. Major cyber-incidents should also become opportunities to strengthen institutional resilience.
Universities have spent decades building digital campuses, and AI is now helping to shape their next generation. The institutions that succeed will not necessarily be those that adopt AI fastest, but those that understand that innovation and security are not competing priorities, they are two sides of the same responsibility. The future of higher education will be increasingly intelligent. It must also be resilient.


