Universities adopting generative AI risk owning failures, an arXiv study says

An arXiv preprint analyzing 366 higher-education papers finds AI is routinely described as an actor but never made explicitly responsible when things go wrong.

Hannah Vogel ·

In an arXiv preprint (version 1) posted in September 2026, “Who Acts, Who Knows, Who Answers? A Corpus-Assisted Discourse Analysis of Agency, Epistemic Responsibility, and Accountability in Generative AI Higher Education Research,” the authors examine how 366 English-language titles and abstracts published between November 2022 and 14 August 2026 talk about responsibility in generative AI for higher education. The paper reports that “AI” is the most frequently named actor, appearing 2,050 times and entering 447 predicate associations, most involving action. Students are more often linked to knowing, judging and verifying. Yet, across 91,405 tokens in the final corpus, the study says no sentence makes AI explicitly responsible; responsibility is assigned to educators, institutions and policy—or disappears into passives and nominalisations. No one in the reported packet is on the record; this is a single-source academic preprint without independent verification or peer review at the time of posting.

A preprint finds AI framed as an actor but never as the responsible party

The study’s method mixes frequency counts, five-word collocations, actor–predicate associations, obligation-clause coding, and heuristic analysis of passives and reporting metonymies, applied to a corpus winnowed from 8,734 unique records after deduplication. Its headline finding is not that “responsible AI” is absent—phrases like “responsible AI” and “responsible use” appear frequently—but that they rarely specify who is responsible for what. In the dataset, AI “does” a lot; students and educators “know,” “evaluate,” or “verify,” while institutions and policy “must” act. Accountability is gestured at as a system attribute rather than assigned to a named actor with an obligation and a consequence. The authors say that even common formulations such as “ensure responsible use of AI” typically lack an explicit subject empowered to answer when outputs cause harm or breach rules.

The limits are material. This is a discourse analysis of titles and abstracts—front-of-house text—rather than a full audit of power, policy or practice in classrooms or procurement. It is English-only, and it stops at 14 August 2026. Titles and abstracts compress nuance and may not represent what the papers actually implement or recommend. Still, they are the part most widely read and repeated, and they influence how committees write RFPs, how vendors market “responsible AI,” and how administrators articulate risk.

Why this linguistic gap matters for procurement and contract risk

If AI “acts” but no one is named as “answerable,” the default in enterprise contracts is that the buyer inherits responsibility unless the agreement assigns it to the vendor. In higher education, that translates into faculty policies and IT use standards that place a duty of care on staff and students, while vendor terms often disclaim liability for model outputs. In the absence of a named accountable party in the discourse, procurement becomes the place where responsibility is concretized—through indemnities, auditability clauses, data-handling terms, human-in-the-loop requirements, evaluation provenance, and termination rights tied to safety incidents.

That changes the software sale. Legal and procurement will ask not just “does it work?” but “who answers when it doesn’t?” Marketing copy that leans on “responsible AI” without specifying the accountable actor invites contracts that shift the exposure to the institution: more buyer-side signoffs, stricter acceptable-use policies, and internal monitoring costs borne by the customer. Vendors that explicitly assume obligations—e.g., content-source logging, downstream review hooks, incident reporting SLAs, and limited but real indemnities—gain purchasing leverage because they move some risk off the buyer’s operating line.

The marketing problem: “responsible AI” claims without an accountable who

The preprint underscores how often responsibility is expressed as a property (“responsible use,” “responsible AI”) rather than as a relationship (“the vendor is responsible for X outcomes under Y conditions”). For go-to-market teams, that matters. When the semantics of responsibility blur between actor and attribute, the buyer fills the gap with extra process: human reviewers, pre-deployment pilots, and governance boards. In a budget, that looks like internal labor to supervise the model, parallel shadow workflows to validate outputs, and cross-charges for legal review—costs that lengthen cycles and depress realized ROI.

Sales and marketing leaders have a choice. Either they keep “responsible AI” as an umbrella slogan and accept longer, risk-priced cycles, or they operationalize it: name the specific obligations the vendor assumes (with limits), disclose evaluation traceability, and state the human or function that signs for incidents. The latter approach is harder copy but an easier sale to committees that increasingly include compliance, academic integrity officers, and data governance. Without it, “AI will help” headlines in higher education get rebutted by “who pays when it hallucinates?” on the procurement call.

Expect longer sales cycles and legal-created buying committees

If the research discourse reflects how institutions will frame their decisions, two practical shifts follow. First, buying committees grow to include roles that align with the study’s assignment of responsibility to educators and institutions—teaching and learning executives, registrars, integrity offices, and policy teams—alongside IT and faculty. That raises the bar for evidence: logging of prompts and outputs, chain-of-custody for evaluative decisions, and alignment with institutional policy language. Second, legal will sharpen redlines around use cases where “AI acts” versus “AI assists,” because the study shows the actor/knower split maps to who is expected to answer. Where AI acts—autonomous grading, automated conduct decisions, content filtering—expect buyers to demand vendor-side accountability mechanisms, not just AI literacy training for staff.

For vendors, this is a segmentation exercise. Offers pitched as “collaboration” get buyer-side guardrails and training budgets; offers pitched as “autonomous action” must carry vendor-side guarantees and operational logs. Those who fail to name the accountable party will find their tools reclassified as “assistive,” even when they aspire to automate, because only the “assistive” label fits the buyer’s risk appetite without vendor guarantees. That is not a purely semantic downgrade—it changes price realizeability, attach of services, and renewal prospects.

The skeptic’s view: research talk is not contract law

There is an obvious objection: titles and abstracts are not procurement documents. Corporate and university legal teams already insist on data-protection addenda, limitation-of-liability, and, increasingly, AI-specific terms. Many edtech and enterprise vendors have published responsible AI policies and model cards. The preprint’s sample is academic discourse, not contracts; it may overstate the governance gap in practice.

That counterpoint is fair and is part of why this finding bears watching rather than treating as verdict. The study is single-source and unaudited. It does, however, name the shape of the risk in the room: when influential narratives assign action to AI and accountability to “the institution” or to abstractions like “policy,” it is the buyer who ends up writing procedures and absorbing blame. The test in the next two quarters is whether public-sector RFPs and contract templates in higher education start naming vendor-side obligations for specific AI outputs, instead of extending buyer-side duty of care.

What would prove this wrong in the next two quarters

We should see one of two patterns in the coming six months. Either procurement language shifts toward explicit vendor accountability for AI-generated outputs—through named incident contacts, audit logs, evaluation provenance, and narrow indemnities—or buyer policies expand to make staff responsible for supervising and verifying anything the model does, with vendors disclaiming responsibility beyond uptime and data security. If it is the former, then the accountability gap the preprint highlights is closing in practice despite the discourse. If it is the latter, the linguistic pattern has purchase, and vendors will continue to sell “AI as actor” while institutions pay for the supervision.

The preprint’s core contribution is to force a more precise conversation: if AI is a tool, collaborator, evaluator, proxy, or infrastructure, who signs when it misfires? Until that line is written into contracts and policies with a named role and a consequence, the cost of “responsible AI” will sit with the buyer, not with the seller.

More stories