Short answer: a coursework policy assigns permission per assessment. A thesis has no assessment brief, no single submission point, and spans years of changing rules — then becomes a research output. Doctoral governance should therefore rest on accountability and disclosure, not permission, and the publishing world has already written the test.
Most institutional AI policies are written from the undergraduate assessment problem outward, then extended to research degrees with a sentence. That sentence is where graduate schools get into difficulty.
Why does the coursework model not transfer?
Because every assumption underneath it fails at doctoral level.
| Coursework | Doctoral thesis | |
|---|---|---|
| Unit of permission | The assessment, set by a module owner | No assessment brief exists |
| Duration | Weeks | Three to seven years, across several policy revisions |
| Submission | One deadline | Continuous drafting, supervision, revision, corrections |
| Who judges | The marker, against a rubric | Examiners, including at least one external to the institution |
| What it becomes | A grade | A public research output, often published in parts |
| Verification available | Usually none beyond the text | An oral examination, plus a supervision record |
The last two rows are the ones to build on. A doctorate is the one place in the institution where you have both a genuine authorship-verification instrument and a documented process trail — and where the consequences of getting authorship wrong extend past the degree into the literature.
The per-assessment permission structure that works elsewhere is set out in what a university AI policy should include. This piece is about the population that structure does not reach.

What governs a thesis that a coursework policy does not?
Publication-integrity norms, because a thesis is a research output and much of it will be submitted to journals — sometimes before the degree is awarded.
The International Committee of Medical Journal Editors sets out four authorship criteria, and all four must be met:
- Substantial contributions to the conception or design of the work, or the acquisition, analysis or interpretation of data;
- Drafting the work or reviewing it critically for important intellectual content;
- Final approval of the version to be published; and
- Agreement to be accountable for all aspects of the work, ensuring that questions related to the accuracy or integrity of any part of it are appropriately investigated and resolved.
Criterion four is the one your graduate regulations want. It is not a rule about tools; it is a standard about the person. A candidate who cannot investigate and resolve a question about the accuracy of chapter four has an authorship problem, and it makes no difference whether the gap was produced by a language model, an unacknowledged collaborator or a paid service. The test is technology-neutral, which is exactly why it will still be usable in three years.
Can an AI tool be a contributor?
No, and the reasoning is worth quoting because it is the cleanest available statement of why.
The ICMJE says chatbots “should not be listed as authors because they cannot be responsible for the accuracy, integrity, and originality of the work, and these responsibilities are required for authorship.” It follows that “humans are responsible for any submitted material that included the use of AI-assisted technologies,” and that authors “should not list AI and AI-assisted technologies as an author or co-author, nor cite AI as an author.”
Two further obligations in the same passage transfer directly into a thesis context. Authors “should carefully review and edit the result because AI can generate authoritative-sounding output that can be incorrect, incomplete, or biased.” And authors “should be able to assert that there is no plagiarism in their paper, including in text and images produced by the AI,” with appropriate attribution of all quoted material.
That second obligation is the one that catches candidates. Fabricated references are the most common and most detectable failure, and the rule that addresses it — sources must be independently verified by the author — costs nothing to state and requires no detection technology to enforce.
Where should disclosure go?
In two places rather than one, and again the publication convention is the model worth adopting.
The ICMJE directs that where AI was used for writing assistance, this is described in the acknowledgments; where it was used for data collection, analysis or figure generation, it is described in the methods. Disclosure is required both at submission and inside the work itself.
That split is better than a single declaration form for three reasons. It puts methodological use where examiners assess method, so it is evaluated rather than merely noted. It puts language assistance where other acknowledged help already sits, alongside proofreaders and translators, which normalises it. And it produces a document that remains correct when a chapter is extracted for publication, rather than one carrying an institutional form no journal will accept.
Specify the content, not just the location: which tools, at which stages, for what purpose. A declaration that says “AI was used for editing” tells an examiner nothing they can evaluate.

What does this mean for examiners?
It means they need instructions, and most currently do not get them.
An external examiner arrives from another institution with a different policy, or from industry with none, and forms a view about acceptable assistance based on their own discipline’s conventions. If two examiners hold different views, the candidate is judged against a standard nobody published. That is an appeal waiting to happen, and the institution loses it.
Three additions to the examiner brief resolve most of it:
- State the institution’s disclosure requirement and tell examiners where in the thesis to find the declaration.
- State that a disclosed, permitted use is not a defect and should not be treated as one. Without this, a conscientious candidate who discloses is penalised relative to one who does not — the precise inversion of the incentive you want.
- State what to do with a concern. Examiners should raise authorship questions through the oral examination and the report, not resolve them privately or ignore them.
How does the oral examination fit?
It is the strongest authorship instrument any part of the university has, and it works without any technology at all.
A candidate who wrote the thesis can explain why this method rather than an alternative, where a source came from, what a paragraph means, and what they would do differently. A candidate who cannot do that across the whole document has an authorship problem that a viva surfaces reliably and a classifier does not. The reasons a detector score cannot carry that weight are set out in whether AI detection is reliable enough to base a case on.
Two design points. Make the examination cover the whole thesis rather than the contribution alone, so no chapter is out of scope. And record that authorship verification is a standing purpose of the examination rather than something invoked when there is suspicion — an instrument used only under suspicion is an accusation, while an instrument used always is a standard.
What about the years in between?
This is the operational problem, and it is the one a policy document cannot solve on its own.
A candidate who started in 2023 has been supervised under at least two revisions of your rules. Three provisions keep that manageable:
- Name the version that applies. Either the rules at submission or the rules at registration — pick one, publish it, and be consistent. Ambiguity here is resolved against the institution.
- Put AI use on the annual review agenda. A standing question in the progress review turns a single end-of-candidature declaration into an ongoing record, and it lets a supervisor correct a practice in year one rather than discover it in year four.
- Treat the supervision record as process evidence. Drafts, comments and revision history establish how a document came to exist, which is the evidence an authorship question actually needs and the thing a finished PDF cannot supply.
That third point is where institutional tooling either helps or does not. A supervision relationship conducted through emailed attachments leaves no usable trail; one conducted where the writing happens leaves a complete one as a by-product. It is also the workload argument, since supervisors currently spend review time on formatting rather than argument — the problem described in what your supervisors are actually reviewing.
Six provisions to add to your graduate regulations
- An accountability standard for the candidate, expressed as the ability to account for every part of the thesis under examination.
- A disclosure requirement split between acknowledgments and methods, specifying tool, stage and purpose.
- An express statement that AI cannot be named as an author or contributor.
- A source-verification rule: no reference enters the thesis unless the candidate has read it.
- An examiner brief covering the disclosure requirement, the treatment of disclosed use, and the route for a concern.
- A named applicable-version rule, plus AI use as a standing item at annual review.
Every one of these is technology-neutral, which means none of them expires when the products change.
If you would like to see how process evidence of this kind is generated as a by-product of supervision rather than as an additional reporting burden, request an institutional evaluation and we will work through it against your own regulations.
Frequently asked questions
Why do permission categories fail for doctoral work?
Because there is no assessment brief to attach them to, no single submission point, and a candidature long enough to span several revisions of the policy itself.
What should the operative test be instead?
Accountability. The ICMJE requires final approval of the version and agreement to be accountable for all aspects of the work, including that questions about accuracy or integrity are investigated and resolved.
Can an AI tool be listed as a contributor?
No. The ICMJE states chatbots cannot be responsible for the accuracy, integrity and originality of the work, and that AI should not be listed as an author or co-author, nor cited as an author.
Where should the candidate disclose AI use?
Writing assistance in the acknowledgments; data collection, analysis or figure generation in the methods. Naming the tool, the stage and the purpose in each case.
Should a disclosed use count against a candidate at examination?
No, and the examiner brief should say so explicitly. Otherwise disclosure is penalised and concealment is rewarded.
What about fabricated references?
Address them with a source-verification rule rather than detection. The ICMJE requires authors to be able to assert there is no plagiarism, including in AI-produced text and images, with full attribution of quoted material.
Do external examiners need separate guidance?
Yes. They come from institutions with different policies and will otherwise apply their own discipline’s conventions, which produces inconsistent standards and appealable outcomes.
Which policy version applies to a continuing candidate?
Whichever you name — the rules at registration or the rules at submission. What matters is that it is stated, because ambiguity is resolved against the institution.
Is the oral examination sufficient to establish authorship?
It is the strongest instrument available and far more reliable than a classifier, particularly when it covers the whole thesis rather than the contribution alone.
Should AI use be reviewed before final submission?
Yes, as a standing item at annual review. A practice corrected in year one is a conversation; the same practice discovered in year four is a case.
What if a chapter has already been published?
The journal’s disclosure rules already applied to it. Requiring the thesis declaration to be consistent with what was disclosed at publication prevents two incompatible accounts of the same chapter.
Does this require new technology?
No. All six provisions are regulation changes. Tooling helps by generating the supervision record as a by-product, but the standard does not depend on it.
