Gradescope — AI-assisted grading and feedback for higher education
United States of America
AI platform grouping similar student responses for batch grading; 3.2M students at 2,600+ universities. A peer-reviewed ACM 2017 study found …
United States of America · Salt Lake City · See the United States of America profile · See the Salt Lake City profile
Top 100% 7/100 · Ask Evidence Copilot about this practice
Hackers exploited Canvas's unverified "free for teacher" signup to exfiltrate ~275 million records from ~8,800 schools and universities; Instructure reportedly paid a ransom, exposing gaps in an LMS that embeds OpenAI-powered grading tools.
In late April 2026 the extortion group ShinyHunters gained access to Instructure's Canvas learning management system by exploiting its "free for teacher" account program, which allowed educators to self-register without institutional verification. The group claimed to have exfiltrated roughly 3.65 terabytes of data -- an estimated 275 million records covering names, email addresses, student ID numbers and private in-platform messages -- affecting approximately 8,800 universities, ministries of education and schools worldwide. Instructure has stated it found no evidence that passwords, birth dates, government IDs or financial data were taken.
The breach is notable for the AI-in-education catalogue because Canvas is not a passive record store: Instructure has spent 2025-2026 embedding generative and agentic AI directly into the platform, including an OpenAI partnership, an "IgniteAI" grading assistant and an agentic "IgniteAI Agent" that can create course modules and adjust due dates on an educator's behalf. Those AI features run on the same student and course data that was exposed, which is what elevates this from a generic IT incident to a governance case study for AI-integrated ed-tech specifically: the data pipeline feeding automated grading and course-management AI at thousands of institutions had a verification gap that let an external actor walk in.
On or around May 11, 2026 -- one day before the attackers' leak deadline -- Instructure reportedly reached a financial settlement with the intruders (unconfirmed reporting puts the figure near USD 10 million) and stated the compromised data had been destroyed, a claim that cannot be independently verified. The incident disrupted final examinations at some institutions and triggered legal and regulatory review under FERPA and COPPA given the volume of minors' data involved. It is included here as a cautionary case, not a model practice: the evidence is strong and well corroborated, but what it demonstrates is a governance and vendor-verification failure, not a learning-impact success.
Read the full analysis: https://www.law.berkeley.edu/research/bclt/bclt-legal-analysis/instructure-canvas-breach/
Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.
Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.
Where this practice's information was retrieved from, and when.
United States of America
AI platform grouping similar student responses for batch grading; 3.2M students at 2,600+ universities. A peer-reviewed ACM 2017 study found …
Portugal
Portugal's FCCN runs IAedu, a free, GDPR-compliant national platform giving university staff, researchers and students unified access to multiple LLMs. …
Holy See
The Vatican's Pontifical Academy for Life launched the Rome Call for AI Ethics in 2020; a 2023 Global University Summit …
Guyana
Guyana's national university requires students to disclose generative-AI use, grades AI-assisted and unassisted work on different rubrics, and flags its …
Open full copilot Grounded in cited practices — always check the sources.