Writing
What the CPR Summit taught me about AI and compliance
I opened with a simple question: “How many of you have used an AI tool in the past week?”
About 20% of the room raised their hands.
This was the CPR Summit. Compliance, policy, and risk professionals from universities across Colorado. The people whose job it is to govern how institutions use technology. And only one in five had touched an AI tool in the past week.
I don’t say that to judge. It makes sense from a risk perspective. These are people trained to be cautious. But it also doesn’t quite make sense, because of how much of their work is built on the written word. Policy drafting. Contract review. Risk assessments. Audit preparation. Compliance communications. Every one of those is a task AI can help with. Every one of them is currently done mostly by hand.
The risk conversation is everywhere
The room talked about lawsuits constantly. Third-party litigation financing. Social inflation. “Nuclear verdicts.” That phrase came up more than once. The difference between proactive and reactive risk management was basically the theme of the day.
One of the simplest examples I heard was from a speaker talking about physical risk: “proactively put cones around the cracked pavement before someone trips.” It was about slip-and-fall liability, but the same logic applies to AI governance. Don’t wait for the incident to happen.
Not everything in that room is meant for AI. Insider threat analysis, threat assessment, and physical security are human judgment domains where a model adds less than it risks. But the gap between what AI can already do and what’s actually being used is enormous. The people in that room are the ones who have to close it.
The engaged ones were really engaged
The people who were interested asked probing questions. About Claude licensing and whether enterprise agreements cover what they think they cover. About whether we could form a Colorado-wide AI knowledge sharing group across universities. About the difference between AI guidance and formal policy, which is a question I’ve been wrestling with myself.
People took notes. Notes on how they could use AI in their own work starting Monday. They shared the same struggles we’ve had at CSU: choosing between guidance and policy as the right instrument for a given situation, integrating AI across research, teaching and learning, and administrative uses, and dealing with the reality that everyone is moving at different speeds.
What I’m taking away
The CPR Summit reminded me that the AI adoption problem is an organizational problem, not a technology one. The people who need to govern AI are the least likely to have used it, and the people who are using it are the least likely to know what governance looks like. Bridging that gap is most of the work.
The audience taught me something I had not planned to learn. The most useful thing I can do for a compliance professional is show them what AI does for someone in their exact role, doing their exact kind of work. Policy drafting. Contract review. Risk assessment templates. Not how the model works. What it produces. That may end up leading them to understanding how and why governance is necessary.
If your institution is working through the same questions about guidance versus policy, shadow AI, or federated governance, I would like to compare notes. Find me on the about page.