Everyone Published a Position on AI. Almost Nobody Scored on It.
- Jul 28
- 4 min read

Most public sector and higher ed organizations have now published something about AI. A statement of principles. A page on the IT site. A paragraph in the strategic plan about responsible use.
Almost none of them can evidence it.
In our Securance 11 Peer Benchmark — eight organizations assessed against the standard — Domain 11, Ethics and External Positioning, scored 0.0 out of 9 in state and local government and 3.0 out of 9 in higher education. The higher education figure comes from a single institution’s published position: one data point, not a trend.
Those numbers sit alongside a benchmark average of 11.8 out of 100 across all 11 domains, with five domains at a flat zero.
Ethics is not where organizations typically begin. It stands out for a different reason: it is the domain most visible from outside the organization, and the one where the distance between what you have published and what you can prove is measured in public.
The statement was written by people who don’t know what’s running
Here is the pattern. The AI principles were drafted by a committee — general counsel, communications, a policy office, maybe a faculty group. They are careful and sincere. They commit the organization to transparency, human review, and protection of sensitive data.
Meanwhile, the actual AI arrived through Domain 6, Build versus Buy versus Embed — switched on inside systems already under contract. A summarization feature in your ERP. Assistive grading in your LMS or SIS. A chatbot someone enabled in Microsoft 365 for the public-facing site. None of it went through the committee. Some of it touches student records, resident data, or payment data. Nobody has mapped it against the principles, because the principles and the inventory live in different buildings.
That is not a drafting problem. It is a governance problem that only becomes visible from outside.
Three ways the gap goes public
A records request. In government, a FOIA or AI-feature disclosure request asks which AI systems the agency uses and what decisions they inform. In higher education, the same question arrives through a student press inquiry or a faculty senate resolution. Either way, you must produce an inventory. If the inventory contradicts the published statement — or doesn’t exist at all — that becomes the story.
A reporter calls. Usually it is not an AI story at all. It is a reporter working on how the city screens applications for assistance, or how the university decides which students get flagged as at risk, and somewhere in the reporting they learn a model is involved. The question that follows is specific: is AI used in this decision? Organizations that can name the system, the human review step, and the appeal path answer in two sentences. Organizations that cannot end up reciting their principles instead — which reads as evasion, whether or not it is.
A public error. An AI-assisted output goes out wrong: a benefits determination, a grade, a public notice. The first question is never what the model did. It is what you told the public you were doing, and whether this matches.
What defensible external positioning looks like
Domain 11 does not ask whether your statement is well written. It asks four things:
Can you evidence every public claim? If the statement promises human review of AI-assisted decisions, there must be a documented review step with a named owner. If it promises that student, resident, or patient data is not used to train vendor models, there must be contract language that says so — FERPA, GLBA, CJIS, HIPAA, and PCI compliance all turn on that answer.
Is there a current inventory behind the statement? Not a policy — a list. What AI is running, where it touches people, and who approved it.
Is disclosure decided in advance? Where AI touches a member of the public — a student, a resident, an applicant — someone must have decided whether they are told, and that decision must be written down rather than improvised under pressure.
Is there one named spokesperson? When the question arrives, the organization must already know who answers it.
Write less, evidence more
The instinct after reading this is to rewrite the statement. That is backwards. Shorten it until every remaining sentence is one you can prove, then rebuild in the order the controls actually come online:
Build the inventory. Nothing else can be evidenced without it, and it is the fastest of the four to produce.
Name the spokesperson. One line in a job description. No budget, no project plan.
Decide disclosure in advance. Where AI touches the public, settle whether they are told — before someone asks.
Then add the claims back. Each one only when the control behind it exists and has an owner.
Three defensible sentences you can stand behind in front of a council, a board, or a reporter are worth more than a page of principles nobody has tested. Public trust is not built by the statement. It is built by the statement holding up the first time someone checks.
Where you stand
Domain 11 is one of 11 domains in The Securance 11, our AI governance standard for public sector and higher education.
Take The Securance 11 Index. 12 questions, about six minutes, and you will see your score across all 11 domains — plus get the full playbook, free.
If step one on that list — the inventory — is where you are stuck, book 20 minutes with Paul Ashe here: https://outlook.office.com/book/Securance11Meeting@securanceconsulting.com/. A free AI usage analysis of your environment follows the call.
.png)



Comments