Data Governance Maturity, AI Integration, and Equity in Colorado K-12 Public Schools
Colorado's 179 K-12 public school districts operate as autonomous governance units, each responsible for securing and managing student data assets that span health, financial, residential, and academic records. The accelerating integration of artificial intelligence (AI) and machine learning (ML) tools into administrative workflows, productivity software, and instructional platforms has fundamentally altered the risk landscape for student data, yet governance frameworks at the state, district, and school levels have not kept pace. This dissertation investigates whether Colorado's decentralized educational governance structure is institutionally capable of producing equitable, secure, and sustainable data governance outcomes in the AI era. Drawing on Institutional Theory (DiMaggio & Powell, 1983) as the primary explanatory lens, Deming’s (1986) Systems of Profound Knowledge as the operational evaluation framework, and Transformative Leadership theory (Shields, 2010, 2018) as the educational leadership framework, this study advances the argument that governance failure in Colorado’s K-12 system is not a technical problem but an institutional one. Decentralized structures, the absence of standardized equity metrics, and compliance-driven rather than outcome-driven policy cultures combine to produce a self-reinforcing cycle that systematically disadvantages rural districts and vulnerable student populations. This cycle is conceptualized as the Governance-Equity Deficit Model (GEDM), which constitutes the original theoretical contribution of this dissertation. Chapter 1 establishes the problem statement, defines the scope of the study, and presents a single integrated research question addressed through three sequential analytical phases. Chapter 2 synthesizes existing literature through the lens of the GEDM, encompassing the historical evolution of information security paradigms, Colorado state law applicable to student data governance, equity and algorithmic accountability scholarship, and modern AI risk management frameworks including the NIST AI Risk Management Framework (AI RMF; National Institute of Standards and Technology [NIST], 2023), ISO/IEC 42001 (International Organization for Standardization & International Electrotechnical Commission [ISO/IEC], 2023), and related international standards. Chapter 3 presents a systematic policy document analysis methodology grounded in the Deming framework and augmented by a structured AI-assisted screening protocol with transparent human oversight and inter-rater validation. The study focuses exclusively on publicly available policy, legislative, and governance documents. The findings are intended to inform the Colorado Department of Education (CDE), state legislative bodies, and district technology leadership with actionable, evidence-based recommendations for centralized coordination mechanisms, standardized equity metrics, and pathways to improve governance maturity across Colorado's diverse district landscape.