The AI conversation in most Gulf universities started with cheating, and it never left.
Two years on, the institutional energy has gone into detection tools, revised assessment regulations, rewritten academic integrity policies, and a working group that meets twice a term. All of that work was necessary. None of it changed how the university runs.
Meanwhile admissions still reads applications by hand at intake. The prospectus still takes most of a term to produce. The accreditation self-study still eats a team for a semester. Student enquiries still queue. Course specifications still get rewritten from scratch every cycle by academics who would rather be doing almost anything else.
Here is the position most Gulf institutions are actually in: you have an AI policy for your students and no AI plan for your institution.
That is not an AI problem, and it is not a technology problem. It is an operating model problem, and it is the reason AI in higher education has produced a great deal of governance and almost no operational change.
This playbook sets out what an AI operating model is, the four dimensions that decide whether AI sticks in a university, the specific way each one fails in this sector, and a 90-day sequence you can start without a business case, a procurement round or a new hire.
What an AI operating model actually is
An AI experiment is one person doing one task faster. An AI operating model is the institution doing work differently, on purpose, at scale, in a way that survives that person moving on.
The two look identical for about a term and then diverge completely. The experiment produces a good anecdote for a conference paper. The operating model produces a change in cost, speed or quality that shows up in something you already report to your board or your accreditor.
An operating model answers four questions that experiments never have to:
Who owns the outcome? Not who owns the tool, and not which committee has the item on its agenda. Who is personally accountable for the thing AI is meant to improve, whether that is time to offer, applicant conversion, or the cost of producing a validated course.
What is the work, redesigned? Not the existing process with a faster step in the middle. The process rebuilt around what is now cheap. If your admissions cycle still has the same committee gates and the same manual re-keying it had three years ago, you have not redesigned anything.
Who can actually do it? Not the two enthusiasts in the computing department. The people who run the process every day, trained for their role rather than sent to a generic awareness session.
What is allowed? Which tools are sanctioned, what data can go in, what must stay out, and who decides. For an institution holding student records, applicant financials, disability and wellbeing disclosures and unpublished research, this is the question that decides whether staff use AI at all.
Miss any one and AI stays a hobby in your institution. Get all four working and it becomes infrastructure.
Only one of the four is really a technology question. The other three are leadership, capability and clarity. That is the whole point, and it explains why AI handed to IT as a systems rollout, or to a committee as a policy matter, so reliably goes quiet.
The four dimensions
The four dimensions below are the same ones our AI readiness assessment scores against, in the same order. Read each, be honest about where the institution sits, and take the 30-day action even if you do nothing else this term.
1. Leadership
What good looks like. The senior team, Vice Chancellor, Provost, COO, Registrar, deans, uses AI in their own work most weeks, visibly. AI is owned by a named leader with an outcome attached, not by a committee. And at least one of them has built something with it, an agent or a connected workflow, rather than only ever having a conversation with it.
How it fails in higher education. This sector has a failure mode that is different in kind, not just degree. In most industries AI arrives as an opportunity and gets under-resourced. In universities it arrived as a threat, through the academic integrity door, and it never got reframed. So it was handed to the body that handles threats: a working group, a policy committee, an academic standards sub-committee. That group is doing exactly the job it was set up to do, which is to contain a risk. Containment is therefore what you get.
Committees are where AI ownership goes to die, because nobody on a committee is accountable for an outcome. They are accountable for a paper going to the next meeting. Two years of that produces a very good policy and an unchanged institution.
The second failure is quieter. Universities have unusually high tolerance for parallel activity. Three departments running three uncoordinated AI pilots does not feel like a problem in an institution built on academic autonomy. It feels like healthy pluralism. It is not, at least not at the operational level, because none of it compounds.
Do this in the next 30 days. Take one operational outcome you already report, time from application to offer, applicant conversion, cost per enrolled student, prospectus cycle time, and put a named leader on it with AI as the lever and a term to show something. One owner, one number, one term. Not a committee. Then, personally, build something. Connect Claude to a report you hate producing and see where it breaks. Two hours of that will recalibrate what you ask for more than any vendor briefing.
2. People and skills
What good looks like. Capability sits broadly rather than in a handful of enthusiasts. People have had structured, role-specific training built around what they actually do. And enablement is ongoing, because the tools move every quarter.
How it fails in higher education. The split here is not head office versus frontline. It is faculty versus professional services, and it breaks in both directions.
On the faculty side, capability is wildly uneven and academic autonomy makes mandated training a non-starter. You cannot compel a professor onto a course, and if you try, you will get attendance and no change. Anyone planning a rollout that depends on mandatory faculty training has planned a rollout that will not happen.
On the professional services side, the problem is the opposite. Admissions officers, registry, student services, marketing, finance and research administration can be trained, and mostly have not been, because the entire AI conversation in the institution was about teaching and assessment. The people running your highest-volume repeatable processes were never in scope, and they are where the operational return actually is.
Do this in the next 30 days. Pick one professional services function, and at intake that is almost always admissions, and build one role-specific prompt library for it. Ten prompts, written for that role, tested against your actual processes and your actual regulations. Train the people who do that job on those ten prompts, not on AI in general. Measure the cycle time before and after.
For faculty, do not mandate anything. Make it opt-in and make it genuinely useful, then publish what worked and who did it. A department that watches a colleague halve their marking preparation will opt in without a memo. That is the only mechanism that works in an institution built on autonomy, and it is slower to start and considerably faster to spread.
3. Process and workflow
What good looks like. AI shows up in real workflows rather than ad-hoc chats, ideally across several core processes, and at least one process has been genuinely redesigned rather than merely accelerated, running in production rather than sitting in a pilot report.
How it fails in higher education. Task acceleration mistaken for transformation. An admissions officer now drafts an offer letter in three minutes instead of ten. Real, and a rounding error, because the application still waits eleven days for credential verification, three days for a committee that meets weekly, and a manual re-key into the student information system. You optimised the three-minute step in a three-week process.
Then there is the document pile, which in a university is enormous and almost entirely untouched. Accreditation self-studies. Programme validation documents. Course specifications. Student appeals. Scholarship assessment. Research grant administration. Timetabling constraints. Committee papers, of which there are many. These are close to the ideal AI workload: high volume, structured, rule-governed, deadline-bound, and currently consuming expensive people who were hired to do something else.
Admissions at intake is the clearest example. It is the highest-volume, most repeatable, most deadline-compressed process in the institution, and in most Gulf universities it is still substantially manual.
This is where the two layers earn their keep. Canva is the creative and communications layer, where the prospectus, the open day campaign, the faculty-produced comms and the student-facing assets get produced on-brand at volume. Claude is the reasoning, workflow and agent layer, where the application gets read, the credential gets checked against the rule, the data gets pulled and the draft gets written. Prompt to presentation. The value is not in either layer alone. It is in connecting them to a process that actually runs the institution.
Do this in the next 30 days. Map one process on one page. Not a review, not a working group. One page, one hour. Enquiry to offer, or module proposal to validated course, or appeal received to appeal resolved. Mark every handoff, every wait and every re-key. Do not mark where AI could help. Mark where the time actually goes. It will be waiting and re-keying, not typing, and that tells you what to build first.
4. Governance and data
What good looks like. Staff have sanctioned tools and clear guidance rather than being left to work it out. There are real rules about what data goes in and what does not. And leadership is confident, not hopeful, that staff can use AI without exposing the institution.
How it fails in higher education. You wrote the wrong policy. Two years of institutional effort went into rules about what students may not do with AI, and not one line went into what your admissions team may put into it. The student-facing policy is mature. The staff-facing policy does not exist.
That gap has a specific cost. Because AI was introduced to the institution as a form of misconduct, staff reasonably infer that all AI use is suspect. Your registry officer is not going to volunteer that she has been using ChatGPT to summarise appeals, because the only institutional signal she has ever received about AI is that it is something people get disciplined for. So the cautious majority do nothing, and the confident minority do it quietly and unsanctioned, with student data.
The data itself is not forgiving. Student records, applicant financial information, disability and wellbeing disclosures, safeguarding notes, unpublished research. Data protection obligations vary across GCC jurisdictions, and international accreditors are increasingly asking how AI is used in assessment and administration. On top of that sits the brand and content problem: universities are federated by design, so faculties and departments produce their own comms, and AI makes producing off-brand, off-message material effortless. That is the same dynamic we wrote about in the cost of off-brand content nobody is measuring.
Do this in the next 30 days. Write a one-page staff AI usage policy. One page, not a project, and explicitly separate from the student academic integrity policy. That separation is the entire point, because it is the signal that AI is a tool the institution uses and not only a risk the institution polices. Three sections: which tools are sanctioned, which data categories never go into an unsanctioned tool (student records, applicant financials, disability and wellbeing disclosures, unpublished research), and who to ask when it is unclear. Publish it with the Vice Chancellor’s name on it.
Governance is not the brake here. It is the permission. Staff move when they know where the edges are, and right now yours have been told only where the cliff is.
The journey: five steps, scoped one at a time
Once you know where you stand, sequence matters more than ambition. One path, five steps, each scoped and bought on its own.
Step 1. Assess. A free self-serve assessment across the four dimensions. Three minutes of honesty before anyone builds a business case.
Step 2. Blueprint. The plan, the licence case, and a date. The institution scanned for where AI actually pays, prioritised into a heatmap, then one function taken deep: every valued task mapped to a specific recommendation, blockers named honestly, a right-sized licence plan, adoption targets set before deployment, and a business case that survives your finance committee. In higher education the first function is almost always admissions and student recruitment, or the document-heavy end of registry. Three to four weeks. One function deep beats twenty shallow, because depth is what makes a plan executable, and the heatmap shows where the rest sits.
Step 3. Enable. The go-live. Deployment and configuration, the project run properly, a change campaign, role-based training built around real workflows, prompt libraries per team, named champions in each function, and adoption tracked against the targets already set. Most deployments fail quietly. Licences get bought, a pilot impresses, usage fades within a term. A proper launch is how you avoid being one of them. In a university this is also where the faculty question gets answered honestly, with opt-in enablement that earns its own spread rather than a mandate that produces attendance.
Step 4. Govern. Risk and spend under control as usage scales. A usage baseline covering every AI tool in the institution, sanctioned or not, and in a federated organisation that number is always higher than leadership expects. A data exposure inventory. A spend baseline and cost guardrails. A governance workshop with leadership, IT and legal. A staff usage policy written to your jurisdiction and your accreditation context. A board-ready readout with a remediation plan.
Govern is the hardest and most valuable step in this sector, and it is where most institutions should honestly start. You already have the committee, the scrutiny and the regulatory exposure. What you do not have is a baseline of what is actually happening, or a policy that tells staff what they may do rather than what students may not. Many organisations start here, usually after a board question or a regulatory prompt, and a governed estate is a faster estate to deploy into.
Step 5. Build. Agents in production, function by function, off the heatmap. The application processing, the appeals triage, the accreditation documentation, the connected pipeline from enquiry to offer to enrolment. Built, tested, deployed to real users, with a runbook and a handover. Eight to twelve weeks per function. This is where the numbers are, and where money burns if you arrive without capability or guardrails.
Executive coaching runs alongside any of it, for the leader the board is asking. Five sessions, on Claude personally, building your own agents around how you actually work. It is the fastest way to fix a Leadership score, and a low Leadership score caps everything else.
Why one step at a time: each has to earn the next. Buy the lot up front and you have committed to a plan built on untested assumptions, in an institution that will remember. Buy them in sequence and you get four decision points where you can stop, redirect or accelerate on the strength of something real.
You can read more about how the journey works in practice.
The 90-day starting sequence
Universities have two real start dates, September and January, and everything works backwards from them. That is a constraint worth using rather than resenting, because it gives you a natural deadline and a natural reporting moment. Pick the next one and count back.
Days 1 to 30. Get honest and get an owner. Score the institution across the four dimensions. Take the weakest, not the most interesting, because the weakest is your ceiling. Name a leader with one operational outcome and one number. Write and publish the one-page staff AI policy, separate from the student policy. Have one leader build one thing personally. Baseline the numbers now, before anything changes, because you cannot report a result you never measured.
Days 31 to 60. Prove one process, properly. Take the process you mapped and rebuild it rather than accelerate it. Build the role-specific prompt library for the people in it. Train those people on their actual work. Keep the scope small enough to finish. One process running properly beats five pilots running vaguely, and it beats a strategy document by a distance.
Days 61 to 90. Show the number and pick the next one. Report before and after using a number you already reported before AI arrived, not an AI-specific vanity metric. Show what broke, because something will have, and in an institution full of sceptics the honest failure is what buys you the second engagement. Then pick the next process off the same map.
The point is not the 90 days. It is that at the end you have an owner, a policy, a trained team, a proven case and a repeatable motion. That is an operating model. Everything after it is scale.
The same four dimensions play out differently by sector. In real estate, the constraint is a distributed frontline with no training and no rules. In franchise and multi-site operators, it is that you do not employ the people producing the brand. The pattern holds; only the failure modes change. Underneath all three sits the same operating model for the content itself: the four tiers and five control points set out in the AI Content Supply Chain.
Where to start
You probably already know which of the four is your weak spot. Most leaders do. But a rough sense is not a straight answer, and a straight answer is what you need before this becomes a paper for a committee.
So we built a way to get one.
Nine questions, three minutes. An honest score of where your institution stands and the single next step that will move you fastest. It scores across the same four dimensions this playbook is built on, names your biggest gap, and tells you the fastest way to close it.
It is not a quiz that tells everyone they are doing brilliantly. Some of the results are uncomfortable. That is deliberate, because an uncomfortable accurate number is worth considerably more than a flattering vague one, and it is a great deal easier to take to a board.
Take the AI Readiness Assessment
Whatever you score, you will know where you stand and what to do next. Which, given where most AI work in this sector has ended up, already puts you ahead.
Frequently asked questions
What is an AI operating model in a university?
An AI operating model is the way an institution runs its work with AI on purpose and at scale, rather than individuals using AI ad hoc. It answers four questions: who owns the outcome, how the process is redesigned rather than just accelerated, who is capable of doing the work, and what is allowed with which data. An AI experiment makes one person faster. An operating model changes something the institution already reports.
Where should a university start with AI?
Start with your highest-volume repeatable operational process rather than with teaching and assessment. In most Gulf institutions that is admissions and student recruitment at intake, or a document-heavy registry process such as appeals or course validation. Map the process on one page, mark where the time actually goes (usually waiting and re-keying rather than typing), rebuild that, and put a named leader on one measurable outcome.
Is an AI policy for students the same as an AI policy for staff?
No, and conflating them is the most common governance error in the sector. A student academic integrity policy tells students what they may not do. A staff usage policy tells employees which tools are sanctioned, which data categories must never be entered into an unsanctioned tool, and who decides in unclear cases. Most institutions have written the first and not the second, which leaves cautious staff doing nothing and confident staff doing it unsanctioned.
How do you train faculty on AI when training cannot be mandated?
You do not mandate it. Academic autonomy means a compulsory programme produces attendance and no change. Make faculty enablement opt-in and genuinely useful, start with the people who already want it, and publish what worked and who did it. Meanwhile train professional services staff properly, since admissions, registry, marketing and research administration run the highest-volume processes and can be trained on a role-specific basis.
How long before AI delivers anything real in a university?
One process rebuilt, one team trained and a measurable before-and-after is achievable inside 90 days without a large programme. Scale takes longer, and it depends on whether a named leader owns an outcome, whether capability extends past a few enthusiasts, and whether staff know what is allowed. Those three, rather than the technology, set the timeline. The academic calendar gives you two natural start points a year, so work back from September or January.
