October 4, 2026:


For the first time in the history of the EDUCAUSE Top 10 IT Issues list, artificial intelligence has claimed the top spot — a signal, organizers said Thursday in Denver, of urgency more than consensus, and of a sector navigating what the list’s theme calls an “age of perpetual change.” The 2026 EDUCAUSE Annual Conference is set to wrap up today, Friday, October 2, with a closing general session scheduled for 10:30 a.m. MT at the Colorado Convention Center, capping four days of sessions attended by more than 7,000 technology professionals.
The conference — run by the nonprofit association EDUCAUSE — brought together CIOs, cybersecurity leaders, instructional designers, data officers, and technology vendors to assess the challenges bearing down on campus IT in 2026 and plan for 2027. The week’s defining moment arrived Thursday evening when EDUCAUSE unveiled the 2027 Top 10 IT Issues list, revealing that AI had displaced cybersecurity from the top position it has historically occupied. The conference’s online component follows October 14–15.
The 2027 EDUCAUSE Top 10, themed around an “age of perpetual change,” signals that AI governance is no longer an aspirational priority for higher education IT leaders — it is existential. The shift matters beyond the symbolism: the list is compiled each year from member surveys, and this cycle drew 882 respondents, the largest voting pool on record. What those nearly 900 IT leaders voted for, at #1, was not “deploy more AI” but “determine where AI adds real value” — a framing that reflects the field’s anxiety about getting adoption wrong.
EDUCAUSE CEO and President John O’Brien set the stakes at Thursday’s reveal session: “How do we help our institutions move forward when none of us can say with any certainty exactly what the future will look like?” Senior Director of Research and Insights Mark McCormack, presenting the full list, put the AI finding in context: “This doesn’t signal consensus as much as it signals urgency.”
The full 2027 EDUCAUSE Top 10, in order:
To accompany the list, EDUCAUSE rolled out two new tools: a “What About Your Institution?” tab on the Top 10 website that filters priorities by institution size and classification, and an AI discussion guide built to be dropped into a large language model for an interactive guided conversation about the report.
Understanding why higher education put AI governance at #1 requires understanding what makes campus IT structurally different from a corporate environment. Higher education institutions operate on open-network architectures, where academic freedom and research collaboration demand a degree of access that is fundamentally incompatible with the closed, perimeter-based security models common in enterprise settings. Identity management is a perpetual challenge: student populations turn over every semester, creating massive authentication overhead. IT teams are dramatically understaffed relative to the scale of institutions they support — and dramatically underfunded relative to comparable commercial organizations.
AI compounds every one of these structural vulnerabilities. Deploying generative AI tools at scale requires trustworthy, de-siloed data (which most institutions do not yet have), clear governance on what data can be fed to which model (which most institutions are still building), and staff capable of evaluating AI outputs critically (which requires training most IT teams do not yet have resources to deliver). The 2027 Top 10’s emphasis on sandboxes, governance structures, and stakeholder-meeting is a pragmatic acknowledgment of where the sector actually is — not where product announcements claim it should be.
The EDUCAUSE Top 10 report puts it plainly: institutions need safe spaces to experiment with AI that are “untethered from the need for absolute certainty” while still protecting people and data from risk. For institutions without resources to build those structures independently, the Top 10 suggests consortia and shared resource networks as lower-cost paths.
Cybersecurity ranking third — rather than first, as it typically does — does not mean the threat has eased. The month of May 2026 delivered one of the most significant cyberattacks in the history of educational technology: ShinyHunters, a ransomware-as-a-service group, breached Instructure’s Canvas learning management system in two waves, first on April 29 and again on May 7 after Instructure claimed to have resolved the initial incident. Canvas is used by 41% of North American institutions, meaning a single vendor compromise reached into nearly half the sector simultaneously.
ShinyHunters claimed to have stolen 3.65 terabytes of data tied to approximately 275 million individuals across 8,809 institutions — including names, email addresses, student ID numbers, and private messages exchanged on the Canvas platform. The second attack exploited the same class of cross-site scripting (XSS) vulnerabilities that enabled the first — a security failure that drew sharp criticism and prompted Congress to investigate. The House Committee on Homeland Security requested Instructure’s CEO testify about the company’s cybersecurity practices. Instructure paid a ransom and received “shred logs” as claimed proof of data destruction — an assurance that cybersecurity experts note provides no guarantee the data is actually gone.
More than 950 EDUCAUSE community members joined an emergency QuickTalk webinar to discuss campus responses in the breach’s immediate aftermath. The Canvas incident was a case study in why #3 on the 2027 list emphasizes culture over control: no campus IT team controls the security practices of a vendor whose software sits at the center of its instructional infrastructure. Vendor risk management, not just perimeter defense, is the challenge.
The broader ransomware picture confirms the pressure. According to the Sophos 2026 ransomware education report, 85% of ransomware incidents targeting education now stem from identity-based attack techniques — above the cross-sector average of 79%. The median ransom demand sent to education institutions reached $775,200, and the average recovery cost — excluding ransom payment — climbed to $2.26 million.
For campus security teams, the architectural response gaining traction is zero-trust security — a framework that assumes no user, device, or system should be automatically trusted regardless of whether it is inside or outside the network perimeter. Every access request is continuously authenticated and validated before permission is granted. The challenge is that zero-trust is not a product to be purchased; it is an architectural journey that requires sustained investment and cultural change — two things in short supply at most institutions facing an enrollment cliff.
Thursday’s program ran from 7:30 a.m. to 5:00 p.m. with the conference exhibit floor open from 9:15 a.m. to 4:15 p.m.
Among the sessions anchoring Thursday’s slate was a panel on accelerating digital transformation using Higher Education Reference Models, presented by Washtenaw Community College and Ellucian’s EDUCAUSE 2026 sessions, which explored how institutions can connect technology priorities to institutional mission in a structured way. A separate session from Brooklyn Law School and Ellucian examined how executive sponsorship typically fades after a project’s launch announcement, leaving implementation teams to carry change alone, and presented a practical scorecard for sustaining sponsor visibility across a modernization project’s full lifecycle.
Wednesday opened the first full conference day with a general session at 8:00 a.m. followed by the EDUCAUSE Commons exhibit floor at 9:15 a.m.
An analysis of risk architecture across 91 US public higher education systems, presented by Ellucian Chief of Industry Transformation Dan Greenstein of Ellucian, introduced six institutional archetypes and a framework for identifying emerging risks and building financial sustainability. A separate midday session examined AI’s impact on higher education operations, drawing on Ellucian’s third annual AI survey and exploring which tasks AI should automate versus which require sustained human judgment.
At 3:30 p.m. Wednesday, Pathify CTO Chris Hagan joined LACCD Vice Chancellor and CIO Dan Watkins and MIT Sloan Managing Director and Deputy CIO Rajiv Shridhar for a session on AI governance readiness — exploring how institutions assess their organizational and technical capacity before committing to AI agent deployments.
Friday’s program runs from 7:30 to 11:30 a.m. MT. The morning opened with networking from 7:30 to 8:00 a.m., followed by open sessions from 8:00 to 10:00 a.m. MT. The closing general session is scheduled to begin at 10:30 a.m. MT and is expected to synthesize the week’s themes.
Among the morning sessions was a panel led by Pathify featuring leaders from four customer institutions: California Institute of the Arts VP for IT Allan Chen; LACCD Vice Chancellor Dan Watkins; Central Michigan University Director of Marketing Eric Hazen; and University of Utah Product Manager and Interim Associate Dean for Online Education Sarah Williams. The session focused on reducing technology sprawl through strategic system consolidation — the “art of the essential” in IT portfolio management.
This year’s conference featured three headline speakers. Future-of-work strategist Heather McGowan delivered a keynote on shifting institutions from fixed-knowledge models to continuous, agile learning frameworks — the workforce transformation argument for why “future-proofing students” ranks #2 on the 2027 list.
Paul LeBlanc, widely recognized for scaling Southern New Hampshire University into one of the largest digital education providers in the country, appeared in a new role: Board Chair of Human Systems, an AI and education company. His session explored the ethical limits of AI integration in learning environments and where human-centered education must hold its ground against automation pressure.
Organizational psychologist and bestselling author Adam Grant will present at the online component of the conference, October 14–15, addressing topics spanning artificial intelligence, IT strategy, and digital transformation.
The EDUCAUSE Commons exhibit floor featured vendors ranging from legacy edtech platform providers to AI-focused startups. Carahsoft Technology Corp. was joined by more than 95 partners at the conference, with booth partners including Cisco Systems, Cloudflare, KnowBe4, SolarWinds, and Sophos showcasing a range of higher education security and IT solutions.
Ellucian, presenting eight sessions at the conference, showcased its SaaS student lifecycle platform at booth #821. “At EDUCAUSE 2026, we’re showing what becomes possible when AI is built around the way higher education actually works,” said Chief Product and Technology Officer Mike Wulff.
Pathify, a 2026 EDUCAUSE Strategic Partner, was selected as part of the inaugural EDUCAUSE Higher Ed Ready Program cohort — a designation recognizing vendors whose platforms meet specific interoperability and service standards for higher education environments. “EDUCAUSE is pleased to recognize Pathify as part of the first cohort to earn the Higher Ed Ready designation,” said EDUCAUSE President and CEO John O’Brien.
The in-person conference in Denver concludes today, but the program continues online October 14–15. In-person attendees gain access to the online sessions as part of their registration. The online event will include recorded sessions from Denver as well as new content, including Adam Grant’s general session, which was not part of the in-person program.
The EDUCAUSE Top 10 is compiled from member surveys across thousands of higher education institutions, and cybersecurity has historically held the top position. AI’s move to #1 in the 2027 list does not reflect a belief that AI is more important than security in an absolute sense — EDUCAUSE senior researcher Mark McCormack was explicit that the ranking “signals urgency more than consensus.” What it reflects is that AI governance is now a triage problem: institutions are deploying AI tools faster than they can evaluate them, govern them, or train their staff to use them responsibly. The shift to #1 is a sector-wide acknowledgment that getting AI adoption wrong is now one of the highest-consequence risks campus IT leaders face.
In late April and again in early May 2026, the ransomware group ShinyHunters breached Instructure’s Canvas learning management system — used by 41% of institutions — in two separate attacks exploiting cross-site scripting vulnerabilities. The group claimed to have stolen 3.65 terabytes of data affecting approximately 275 million individuals across more than 8,800 institutions, including student names, email addresses, ID numbers, and private platform messages. Instructure paid a ransom. If you attended or work at a college or university that uses Canvas, assume your name and email address were potentially exposed and monitor for phishing attempts. Congress has called Instructure’s CEO testify about the company’s security practices.
Three structural factors make campuses persistently high-value targets. First, open network architecture: universities must support research collaboration and academic freedom in ways that are fundamentally incompatible with locked-down enterprise security postures. Second, identity sprawl: student populations turn over every semester, making robust identity management technically demanding and resource-intensive. Third, resource constraints: campus IT teams are dramatically understaffed and underfunded relative to comparable organizations in other sectors. Add to this a vendor concentration problem — when a platform like Canvas is used by 41% of institutions, a single supply-chain breach reaches the majority of the sector simultaneously. The Sophos 2026 education ransomware report confirms that 85% of ransomware incidents in education now trace to identity-based attack techniques, which zero-trust architecture is specifically designed to address.
The enrollment cliff refers to the now-arriving decline in the US college-age population, caused by falling birth rates after the 2008 financial crash. Economist Nathan Grawe projected a roughly 15% decline in traditional college-age students between 2025 and 2029; that projection is now confirmed reality, particularly for smaller regional institutions and community colleges. For campus IT, the cliff means a budget squeeze arriving simultaneously with pressure to invest in AI infrastructure, cybersecurity upgrades, and digital accessibility compliance. The 2027 Top 10 items #6 (working creatively within constraints) and #8 (measuring enrollment shifts) both address this convergence directly. It is the structural context that makes the “age of perpetual change” framing feel urgent rather than rhetorical.