Universities Fight Back Against AI Cheats

An agentic artificial intelligence tool called Einstein caused an uproar in higher education earlier this year. Einstein offered to log autonomously into the learning management system Canvas every day, watch lectures, write papers and submit homework on students’ behalf — without their professors knowing.
Exposing a Core Problem
Einstein exposed a core problem in higher education IT: There’s no reliable way to distinguish students from AI agents acting in their place on any major LMS. Josh Callahan, CISO for California State University, says “The Einstein tool was a big wake-up call.”
Callahan notes that Einstein echoes the fundamental challenge that all large language model-based AI tools have brought to higher ed: How do we assess student learning in a way that really captures their knowledge and their ability to apply that knowledge?
Assessing the Risk
While AI tools can enhance teaching and learning, they also pose a risk to human autonomy and creativity, potentially making important decisions or performing tasks that should contribute to student learning. Isaac Galvan, community program director of cybersecurity and privacy for EDUCAUSE, says higher ed needs “to ensure AI supports learning rather than replacing meaningful engagement in the educational experience.”
The attack surface extends beyond course management to student portals, registration systems, financial aid platforms and advising tools. Sandeep Kumbhat, vice president and global field CTO for Okta, says “AI is outpacing security, and higher ed IT teams are struggling without proper visibility into the tools being used.”
Higher ed leaders are realizing that the agentic AI problem is an identity security problem. Galvan says “Agentic AI creates an identity and access management challenge because it can blur the line between a human user and a technology acting on that user’s behalf.”
Mitigating the Issue
Educators can help address the issue, Callahan says, by requiring in-person essay writing and test taking, or video calls where students hold three fingers in front of their faces to reveal any facial overlay, known as the three-finger test.
Higher IT leaders can also help by treating agentic AI as the identity and access management challenge that it is. Callahan says “Viewing agentic AI through an identity lens is critical for long-term success.”
To mitigate AI impersonation, institutions should implement more stringent controls and verification processes to better validate users and their activities. Authentication controls can verify a student’s identity, confirming that the student who’s registered for a course is the same person doing the work.
Galvan advises that higher ed IT leaders need to strengthen identity security “by investing in identity and access management solutions that help verify genuine human presence.”
Understanding Agentic AI as an identity security problem can help institutions develop effective strategies to combat it. By recognizing the limitations of current security measures, educators and IT leaders can work together to create a more secure learning environment, focusing on security risks in higher education.
Building Effective Governance Frameworks
Higher ed institutions first need an effective AI governance framework.
Galvan says that institutions must take a collaborative governance approach that involves colleagues from across the organization in decision-making and oversight.
Kumbhat explains that such governance can involve certification campaigns timed to semester and enrollment cycles rather than annual reviews, least-privilege access scoped to specific tasks and continuous discovery to catch shadow agents acting outside central IT.
Galvan cautions, however, that higher ed should be wary of governance that’s too rigid. “Governance frameworks must strike a balance between caution and innovation,” he says.
Ultimately, finding a balance between security and innovation will be key to addressing the agentic AI cheating crisis in higher education. By working together and developing effective governance frameworks, educators and IT leaders can help ensure that AI supports learning, rather than undermining it, and institutions like SUNY are already taking steps in this direction.
Effective governance frameworks can also facilitate the development of teacher groups focused on AI readiness.
They are critical to the success of higher education institutions in the face of agentic AI.

Higher ed faces growing security risks
