The study’s findings point to a troubling reality: many schools are already under attack without realizing it. According to David Bader, Director of the Institute for Data Science at the New Jersey Institute of Technology, the 41 percent figure might understate the true scale of the problem.
“This number is concerning because it suggests nearly half of educational institutions are facing security challenges before establishing proper safeguards,” Bader explained. “Schools have historically been soft targets, given limited cybersecurity budgets and small IT teams. The sudden influx of AI tools has only widened that gap.”
The potential for underreporting is significant. Schools may be unaware that an AI-generated phishing email or a deepfake shared among students even qualifies as a cyber incident. As AI tools become more sophisticated, distinguishing legitimate educational uses from malicious ones becomes increasingly difficult.
James McQuiggan, CISO Advisor at KnowBe4, echoed that concern. “Schools are adopting AI rapidly, often without strong cybersecurity hygiene. This number could be conservative,” he said. “Many lack the resources and governance to manage AI safely, which increases the risk of data exposure and misuse.”
The 2025 Verizon Data Breach Investigations Report supports these findings, noting that 77 percent of education-sector breaches stem from phishing — a figure that underscores how generative AI can make even low-effort scams far more convincing.
AI Finds a Place in Every Classroom
Despite the risks, AI is now deeply embedded in daily education. The study found that 86 percent of institutions allow students to use AI tools, and 91 percent of faculty have integrated AI into their work. Only 2 percent have banned AI use outright.
Students primarily use AI for research (62 percent), brainstorming (60 percent), and language support (49 percent). More advanced uses, such as coding (30 percent) or completing assignments (27 percent), are more closely monitored.
For many educators, AI represents both opportunity and inevitability. “Schools have largely lost the ability to meaningfully prohibit AI use, even if they wanted to,” said Bader. “AI tools are freely available on personal devices, and students access them outside school networks regardless of policy. The question isn’t whether to allow AI, but how to use it responsibly.”
He added that banning AI outright would likely backfire, driving its use underground while depriving students of essential digital literacy. Instead, schools should lead with education, ethics, and oversight.
Responsible Use vs. Unrestricted Use
The difference between “using AI” and “using AI responsibly” is crucial. Sam Whitaker, Vice President of Social Impact and Strategic Initiatives at StudyFetch, warned that unrestricted use of general-purpose tools like ChatGPT can have long-term consequences for students’ creativity and critical thinking.
“Schools have both a choice and a responsibility to provide solutions built for learning, not cheating,” Whitaker said. “AI learning platforms designed for education can enhance comprehension and engagement, but tools that simply generate answers can stunt students’ intellectual growth.”
This highlights a deeper issue: the absence of clear, consistent policies for AI use across schools.
Policies Lag Behind Practice
While many institutions are building frameworks to guide AI use, implementation remains uneven. The report found that just 51 percent of schools have formal policies in place, and 53 percent rely on informal guidance. Even more concerning, fewer than 60 percent use AI detection tools or provide AI-focused education programs for students.
Despite more than 40 percent of schools already facing AI-related incidents, only 34 percent have dedicated budgets for AI safety, and 37 percent maintain incident response plans. This leaves many schools reacting to threats rather than preventing them.
“Relying on informal guidelines leaves students and faculty uncertain about what’s acceptable,” said Keeper’s Anne Cutler. “Policies help balance innovation with accountability by setting expectations, protecting sensitive data, and ensuring transparency about AI use.”
However, experts caution against one-size-fits-all policies. Elyse J. Thulin, Research Assistant Professor at the University of Michigan’s Institute for Firearm Injury Prevention, emphasized the need for tailored approaches.
“A baseline of guidance is important, but every organization must adapt its strategy to fit its infrastructure and community,” she explained. “With any new technology, there’s potential for both benefit and harm. That doesn’t make the technology itself bad — it just means we need to manage it wisely.”
The Path Forward: Education and Resilience
AI’s rapid evolution has outpaced traditional governance models, but that doesn’t mean schools are powerless. Experts agree that progress begins with three steps: education, investment, and transparency.
By training staff and students to recognize AI-generated threats, allocating funding for proper cybersecurity tools, and enforcing clear, adaptable policies, schools can better protect themselves while still embracing innovation.
As Thulin put it, “AI is developing at an extremely rapid pace, so continued research and policy support are absolutely critical. The more we study these patterns, the better we can safeguard students and build safer learning environments.”
In an era where the same technology that helps students learn can also be used to deceive, the responsibility falls on educators, policymakers, and tech leaders alike to strike the right balance between opportunity and oversight.


