By
Sean O’Brien - Associate Vice President, NET+, Internet2
Estimated reading time: 5 minutes
What higher education’s cloud journey teaches us about governing generative AI before complexity hardens into debt
Higher education needs the institutional capacity to choose and change models while maintaining visibility. In this piece you will discover:
- How to leverage lessons from cloud adoption for generative AI
- The fix isn’t picking the right model, but building the control plane around all of them.
- Five cloud-era lessons you can apply to AI governance immediately.
- What a gateway-first approach looks like in practice.
- Five questions to determine whether your institution is ready.
Cloud adoption in higher education did not begin with a clean enterprise architecture. It often began with a departmental account, or a researcher putting a service on a purchasing card. Those choices created value quickly. They also left institutions years of cleanup: consolidating accounts, standardizing security controls, and building mature FinOps practices.
That history matters now. Generative AI is following the same path, only faster. Faculty, staff, researchers, and students are already moving among consumer subscriptions, licensed assistants, embedded AI features, and direct APIs. Each choice may be rational in isolation. Together, they can become an operating model that no one intentionally designed.
Earlier this year, in Campus Technology’s 2026 outlook, I described this as a narrowing window: “Waiting too long to plan for multiple services creates governance, cost, and visibility challenges that are difficult to unwind later.” The window is still open, but it will not stay that way.
Prepare for Multiple Models
A multi-model strategy does not mean buying every model or maintaining redundant contracts for their own sake. It means acknowledging that models differ by task, cost, and data access, and preserving the ability to adopt a better one without redesigning the entire environment. That flexibility matters because model leadership is increasingly temporary: new proprietary and open models are arriving rapidly, with some delivering comparable performance at significantly lower cost.
This is already visible in everyday work. One model may be strongest for coding, another for voice, another for deep analysis, and another because it is integrated with the productivity platform an institution already uses. The durable institutional asset is not a particular model. It is the control plane around the models: identity, policy, and cost.
Five Cloud Lessons to Apply Today
- Build the inventory before you need the cleanup. Know which AI services are in use, who owns them, what data they touch, and how they are paid for. Discovery should include sanctioned tools, departmental purchases, and embedded AI features. NIST’s AI Risk Management Framework calls for exactly this: inventory AI systems, monitor third-party, and pre-trained model risk.
- Design identity and policy once. Cloud teams learned the cost of inconsistent account structures and access controls. For AI, institutions should establish reusable patterns for authentication, role-based access, data classification, retention, logging, and acceptable use across providers—not rebuild them, model by model.
- Put an abstraction layer between applications and models. Where practical, use common APIs, gateways, and portable integration patterns so every application does not become permanently coupled to one provider. This enables routing, fallback, consistent guardrails, and easier model evaluation as capabilities change.
- Start AI FinOps while the spend is still understandable. Tokens matter, but cost per token is not enough. Leaders need cost by use case, owner, and outcome, backed by real budgets and chargeback. The FinOps Foundation guidance for AI treats AI as its own cost category because spending is granular and scattered across providers and clouds. That is precisely why visibility and ownership must come before optimization.
- Preserve experimentation through governed paths. Central governance should not become a single-model mandate. The goal is to make the safe path the easy path: give faculty and students room to experiment, with clear data boundaries and real oversight.
Access Before Answers
These lessons shaped our priorities in Internet2 NET+. As we began evaluating AI services with our members, an AI gateway was among the earliest needs we addressed. That was deliberate. Before choosing winners in a fast-moving model market, institutions need a way to manage access, apply guardrails, observe usage, control budgets, and steer work across providers. Cloud platforms such as Amazon Bedrock and Google Cloud’s Vertex AI Model Garden can provide a governed path to multiple proprietary and open models within their ecosystems, while an independent gateway can extend consistent access, policy, and observability across clouds and providers.
An independent gateway provides a unified interface for multiple models with role-based access, budget controls, prompt filtering, logging, and flexible deployment. The broader point is not that every campus must use the same gateway. Gateway capabilities and the governance model around them should be shared institutional infrastructure, not something added after sprawl occurs.
What Leaders Should Do Before Fall
Before the semester starts, get five people in a room: CIO, security, procurement, research, and academic leadership, and answer these out loud:
- Which AI services and models are already in use, and who is accountable for them?
- Which data may be used with which services, under what identity and retention controls?
- Where can a gateway or common integration pattern reduce duplicated controls and lock-in?
- Can we see usage, cost, and value by owner and use case across providers?
- How will we evaluate, add, route among, and retire models as the market changes?
If your team cannot answer all five with confidence, that’s your starting point. The institutions that answer those questions now will not eliminate complexity. They will make complexity manageable and help you manage complex, technology-provider-driven environments.
The Lesson: Readiness, Not Standardization
Cloud taught higher education that decentralized adoption can unlock innovation, but unmanaged decentralization eventually becomes expensive. Generative AI is giving us the opportunity to apply that lesson earlier.
We should not freeze today’s model landscape into tomorrow’s architecture, nor let endless experimentation substitute for institutional capability. We should build the identity, governance, observability, cost management, and portability practices that let our communities evolve as technology does.
The cloud learning curve was costly. We do not have to pay for it twice.
Subscribe and Stay Connected
Cloud Compass is the quarterly column inside of our Catching Up on the Cloud newsletter. Four times a year, we look at where the cloud is taking higher education, and what your institution should be doing to navigate that change.
The newsletter includes updates, resources, and events for cloud practitioners and decision makers at all levels. To subscribe — or to learn more about resources and program developments related to the Cloud or NET+ — email netplus@internet2.edu to connect with the NET+ team.
About the Author(s)
Sean O’Brien leads Internet2’s NET+ cloud service program working with institutions on the collaborative development, evaluation, and management of cloud services for the research and education community. He has worked in a variety of roles in higher education and the private sector focusing on cloud enablement, institutional research, and project management.