- Industry Alliance Targets Common Security Model for AI Agents — A 12-vendor coalition built on an Okta-developed blueprint is proposing a shared reference architecture for discovering, governing, monitoring and containing enterprise AI agents. The founding members — AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler — are tackling the reality that an agent can be built in one system, authenticated through another, reach tools and data in several more, and be monitored by yet another security platform. Members plan cross-vendor testing using several existing open standards.
📌 Key takeaways:
- Campus security teams running pilots of AI agents across multiple vendors should push for this kind of cross-vendor governance layer now, before agent sprawl makes inventory and revocation impossible.
- The architecture's four questions — where are my agents, what can they do, what are they doing, how do I respond — are a ready-made checklist for any institution writing its first agentic AI security policy.
- The scope explicitly covers MCP servers, tool registries, CI/CD and code assistants, meaning developer-platform teams are as affected as security teams.
🏛️ UCSD angle: The campus AI governance work and LiteLLM gateway already centralize model access for the TritonAI program; the Blueprint Alliance's agent-identity and scoped-permission model maps directly onto how the gateway's Developer API Program governs campus-built agents.
- California Community Colleges wants AI funded to tune of $195M — The largest system of higher education in the country is requesting $195 million in state funding for AI in its 2027-28 budget proposal, arguing that without a deliberate strategy colleges will adopt AI unevenly and widen disparities in access and student outcomes. The request includes $100 million in one-time funds to update technology systems across its 116 colleges, plus a competitive grant fund for district AI pilots and open-source applications built for systemwide replication. Another $40 million would fund AI professional development, a centralized learning portal, and frameworks for AI ethics and data governance.
📌 Key takeaways:
- This is a statewide-scale model for funding AI adoption: shared infrastructure and systemwide governance first, so individual colleges aren't each negotiating their own approach with vendors.
- For institutions drafting budget requests, CCC's structure — one-time modernization funds plus recurring professional development and grant funding — is a concrete template that connects equity arguments to line items.
- CCC explicitly ties the funding to financial-aid fraud defenses and says access to AI opportunity should not depend on which college a student attends — framing that resonates in any state with wide institutional variance.
🏛️ UCSD angle: The proposal lands as the UC system weighs consumption-based AI funding models; TritonAI's multi-tenant expansion is already proving out the "shared platform, systemwide replication" approach CCC is asking the state to fund.
- AI Platform Behind 12,000 E-mail Breaches Shut Down — Microsoft has disrupted EvilTokens, a cybercrime service that used an AI chatbot purpose-built for attackers to break into e-mail accounts, study their victims, and automate business e-mail compromise at scale. Since February the platform was tied to more than 12,000 compromised inboxes across over 10,000 organizations — including colleges and universities — before Microsoft and partners seized 50 websites and the UK's Metropolitan Police arrested two suspects. The attack chain started with device-code phishing that stole OAuth sessions, which meant password resets alone couldn't evict attackers; token revocation was required.
📌 Key takeaways:
- Campus security teams should treat OAuth token theft as the primary compromise vector in modern business e-mail compromise — incident response playbooks need token revocation and session invalidation, not just credential resets.
- The AI layer is the escalation: automated inbox analysis means BEC lures can now reference real invoices, real wire discussions and real organizational relationships, making user training and payment-verification controls more critical than ever.
- Higher education was among the named victim sectors; institutions with decentralized finance offices are especially exposed to impersonation of payment approvers.
🏛️ UCSD angle: With Microsoft 365 as the campus collaboration suite, UCSD's security operations already monitor for anomalous OAuth grants; the EvilTokens takedown is a useful case study for refreshing BEC response playbooks to include session-token revocation.
- 5 Questions To Ask To Manage Cloud Spending in Higher Ed — With the initial cloud migration push behind them, higher ed IT leaders are looking at the bill and asking whether they're paying too much. Veteran IT consultant Joel Snyder walks through five questions institutions should be asking, starting with where the money is actually going: breakdowns by application, service and project over the past several quarters, prioritizing the top spenders. He also presses on forecast accuracy — by now cloud costs should be predictable with minimal budget variance — and on whether the value received justifies each major line item.
📌 Key takeaways:
- FinOps discipline matters more as AI workloads land on cloud bills: AI inference and RAG workloads can spike costs in ways traditional application hosting never did, and institutions without per-project cost visibility will feel it first in the cloud line.
- The five-question framework is a practical starting point for any institution that has never run a formal cloud cost review — start with the top spenders, not a comprehensive audit.
- Forecast variance is the early warning sign: if cloud spend regularly misses budget, the governance conversation should happen before the next AI initiative lands on the same bill.
🏛️ UCSD angle: Cloud cost governance is live work at UCSD — the AI recharge model under design with Finance is aimed at exactly this problem, tying consumption-based pricing to per-unit visibility before AI spend scales.
- Towards safety cases for frontier AI training — OpenAI has published early guidelines for safety cases in frontier AI training, covering technical safeguards, operational practices, and how to investigate misalignment incidents. A safety case is a structured, evidence-backed argument that a training run is safe to proceed — an approach borrowed from safety-critical engineering industries — and the post is the company's first public template for what that argument should contain at the frontier-model scale.
📌 Key takeaways:
- Safety cases shift frontier-lab practice from "we ran the evals" to "here is a structured argument, with evidence, that this training run is safe" — a model that institutional AI governance boards can borrow when they require structured justifications for high-risk campus AI deployments.
- For research universities, the misalignment-incident investigation practices are directly relevant to IRB-adjacent review of AI research and to institutional policies on autonomous agent experiments.
- As major vendors adopt safety-case documentation, campus procurement teams should expect — and ask for — comparable assurance artifacts in RFPs for high-stakes AI services.