Agentic AI in the higher-education system (2026)¶
Source
Document: "Agentische KI im Hochschulsystem: Einsatzszenarien, Kompetenzverschiebungen und Steuerungsmöglichkeiten". Authors: Göllner, Ionica, Meier, Miram, Möller, Richter, Sexauer. Issuing body: Hochschulforum Digitalisierung / KI-Campus (Stifterverband). Date: May 2026 (reflecting discussion as of January 2026). Distilled: 2026-07-25. German-language public discussion paper. Quotations below are given verbatim in German with an English rendering.
Summary¶
A German-language discussion paper from a nine-month community of practice on how institutions handle AI agents in higher education. It sets out types (analytic, generative, agentic AI), works three use cases (administration, teaching, research), maps skills from AI literacy to "agentic professionalism", and looks at strategic governance. The governance part is why it is distilled here: because agents act, written policy no longer binds them, so steering has to move into guardrails, clear role accountability, set autonomy levels, and staged rollout. This reading takes the governance and research-workflow content and generalises it from universities to scientific institutions. Teaching didactics are cited as context, not distilled into practice. This is the main source for the governance practice here.
Hooks, with citations¶
1. Agentic AI reaches into all core functions, not one application area. The document: "Die Möglichkeiten, Folgen und Risiken agentischer KI betreffen damit nicht einzelne Anwendungsbereiche, sondern potenziell alle zentralen Funktions- und Entscheidungsprozesse" (§1, p. 1). Rendering: the possibilities, consequences and risks of agentic AI concern potentially all central functional and decision processes, not single application areas. Relevance: agents change how research is planned, performed and governed, so the topic passes the scope test. Audiences: governance, practitioners.
2. The research agent has concrete source and governance requirements. The document describes a "Lernender Research-Agent" that monitors a research field and produces periodic briefings, requiring "Zugriff auf qualitätsgesicherte Forschungsquellen (inkl. Metadaten, Zitierinformationen und Retraktionshinweisen)" and "Verlässliche Governance- und Transparenzregeln, die Autonomiegrade, menschliche Aufsicht, Quellen-Nachvollziehbarkeit sowie Datenschutz- und Lizenzkonformität sicherstellen" (§3.3, p. 8-9). Rendering: access to quality-assured research sources including metadata, citation information and retraction notices, and governance rules ensuring autonomy levels, human oversight, source traceability, and data-protection and licence conformity. Relevance: a concrete research workflow that grounds BP05 and BP07. Audiences: practitioners, providers.
3. Autonomy, intervention and accountability must be made explicit. The document: agentic AI requires the ability "Autonomiegrade, Eingriffspunkte und Verantwortungszuschreibungen in Mensch-Agent-Workflows bewusst zu entwerfen, situativ zu verhandeln und auditierbar zu dokumentieren" (§4.1, p. 9-10). Rendering: to consciously design, situationally negotiate and auditably document autonomy levels, intervention points and accountability in human-agent workflows. Relevance: grounds BP04 and BP09. Audiences: governance, practitioners.
4. Situated judgement is not automatable. The document, citing the European Commission Joint Research Centre (2025): "Situatives Urteil, Präferenzen und Wertentscheidungen sind nicht automatisierbar" (§4.1, p. 10). Rendering: situated judgement, preferences and value decisions are not automatable. Relevance: the epistemic core stays human; grounds BP04 and BP07, and matches the mission vision. Audiences: practitioners, providers, governance.
5. From guidelines to guardrails. The document, citing Kassorla et al. (2026): "From Guidelines to Guardrails. The autonomy of AI agents renders traditional governance models obsolete. A system based on written policies and human persuasion is ineffective for a machine that only understands architectural constraints. An agent cannot be persuaded to follow a rule; it can only be prevented from executing an action." (§5.2, footnote 13, p. 13). Relevance: the central governance insight behind BP04. Audiences: governance, providers.
6. Steer with dynamic guardrails and traceable decision records. The document: steering "sollte weniger über detaillierte Richtlinien als über dynamische Leitplanken erfolgen, die Handlungsspielräume begrenzen, kontinuierliche ... Prüfmechanismen vorsehen und Entscheidungs- wie Verhinderungsprozesse nachvollziehbar dokumentieren, auch wenn mehrere Agenten beteiligt sind." Governance becomes "ein iterativer Prozess fortlaufender Anpassung" (§5.1, p. 13). Rendering: use dynamic guardrails that bound the action space, provide continuous checks, and document decision and veto processes traceably even when several agents are involved; governance is an iterative process. Relevance: grounds BP04. Audiences: governance.
7. Anchor accountability to defined roles, not to the institution in the abstract. The document distinguishes "eine strategische Verantwortung", "eine fachliche Prozessverantwortung ... und menschliche Entscheidungshoheit" and "eine technische Betriebsverantwortung", which "müssen ineinandergreifen und dokumentierte Eskalations- und Abschaltprozesse vorsehen" (§5.2, p. 13-14). Rendering: strategic responsibility, professional process responsibility with human decision authority, and technical operational responsibility must interlock and provide documented escalation and shutdown processes. Relevance: grounds BP04. Audiences: governance.
8. Adapting an agent can turn a deployer into a provider. The document: institutions are often deployers "können jedoch gerade beim Einsatz agentischer KI durch Anpassung, Feintuning oder Zweckänderung selbst zu Anbietern werden, mit entsprechend erweiterten Pflichten"; classifying agents into a risk class is "eine Governance-Entscheidung mit strukturellen Folgen" (§5.2 footnote 14, §5.3, p. 13-15). Rendering: through adaptation, fine-tuning or repurposing an institution can itself become a provider with expanded obligations; risk-class assignment is a governance decision with structural consequences. Relevance: grounds BP03 and BP04. Audiences: governance, providers.
9. Infrastructure is an instrument of governance. The document: control over model inference and over interfaces to core systems become critical governance points, and which agent frameworks may connect and under what conditions is "keine rein technische, sondern eine strategische Entscheidung über Zugriff, Reichweite und Risiko" (§5.3, p. 15). Rendering: not a purely technical question but a strategic decision about access, reach and risk. Relevance: grounds BP03 and BP04. Audiences: governance, providers.
10. Ungoverned personal agents create a new shadow IT. The document: personal agents with broad access to mail, calendar and file structures form a "'Schatten-IT' [die] sich institutioneller Steuerung entzieht und birgt Risiken für Datensicherheit und Integrität"; proactive governance must address institutional and individual use alike (§5, p. 12). Rendering: a shadow IT that escapes institutional steering and creates data-security and integrity risks. Relevance: grounds BP04. Audiences: governance.
11. Pilot low-risk first, define transition criteria, inventory and review. The document recommends starting "mit klar abgegrenzten, risikoarmen Anwendungsfällen", defining success criteria and the conditions for moving to production, defining "zulässige Autonomiegrade und akzeptierte Risikogrenzen", establishing control and escalation mechanisms, and to "inventarisieren Sie KI-Agenten systematisch und überprüfen Sie regelmäßig ihre Arbeitsweise und Ergebnisse" (§6, p. 17-18). Rendering: staged adoption from bounded low-risk cases, explicit success and transition criteria, defined autonomy levels and risk boundaries, control and escalation mechanisms, and systematic inventory and regular review of agents. Relevance: grounds BP04 and BP09. Audiences: governance, providers.
12. The question is what an organisation is willing to grant. The document: "Die Frage ist nicht nur, was Agenten dürfen (und können) – sondern was eine Organisation ihnen kulturell zuzugestehen bereit ist" (§5.4, p. 16). Rendering: the question is not only what agents may do and can do, but what an organisation is culturally prepared to grant them. Relevance: the governance-culture dimension of BP04. Audiences: governance.
Mapping to practices¶
| Hook | Supports | In tension with |
|---|---|---|
| 1 | (scope confirmation) | |
| 2 | BP05, BP07 | |
| 3, 5, 6, 7, 9, 10, 12 | BP04 | |
| 4 | BP04, BP07 | |
| 8 | BP03, BP04 | |
| 11 | BP04, BP09 |
No direct tensions. The teaching and examination use cases (§3.2) change how teaching is run rather than how science is done, and are cited as context.
Proposed changes to practices¶
- [x] Create BP04 as a new governance-facing practice, grounded primarily in this document (hooks 3, 5, 6, 7, 9, 10, 11, 12).
- [x] Add this document as grounding to BP03 (hooks 8, 9), BP05 (hook 2), BP07 (hooks 2, 4), and BP09 (hooks 3, 11).
Cautions and gaps¶
- The framing is German higher education. Teaching and examination didactics are cited as context and not distilled into practice.
- A discussion paper described by its authors as work in progress, not peer-reviewed.
All derived practices are
draft. - EU AI Act specifics (provider versus deployer duties, risk classes) are jurisdiction-bound. The record uses the underlying pattern as a general governance idea, not as legal advice.