<
Where is the line between assistance and intellectual content?
This is the component most policies gesture at and none define, and it is the one every appeal will turn on.
A workable formulation states the test rather than enumerating tools, because tools change and enumerations date within a term. The test that survives contact with cases is roughly: could the student account for this work — its claims, its structure, its sources — under questioning, as their own reasoning? Assistance that leaves that true is assistance. Assistance that makes it false is substitution, whether the helper was software, a friend, or a paid service.
Two specific rules are worth stating explicitly because they resolve most real cases:
- Sources must be independently verified by the student. A reference the student has not opened may not exist. This single rule addresses the most common and most detectable failure mode, and it is technology-neutral.
- Interpretation, argument and methodological choice are intellectual content. Language, formatting and structural scaffolding are generally not.
What must the policy say about evidence?
It must say who bears the burden and what will not discharge it. A policy silent on this hands the question to whichever panel hears the first contested case.
The specific provision to include: detector output is a trigger for inquiry, not a finding, and no allegation may rest on it alone. The reasoning — and the base-rate arithmetic that makes it unavoidable at institutional volume — is set out in our analysis of whether AI detection is reliable enough to base a case on. Writing it into the policy protects the institution as much as the student, because it prevents a panel from producing a decision that cannot survive appeal.
Does equity of access belong in an AI policy?
Yes, and it is the component most often missed. If an assessment expects AI use, the institution has made a tool a condition of participation, and any student without it is disadvantaged on grounds unrelated to their ability.
The HEPI 2026 survey found that only 38% of students say they are provided with AI tools by their institution, while 95% report using AI in at least one way. The gap is being filled by consumer products at students’ own expense, with the predictable consequence that capability tracks ability to pay. A policy that requires or rewards AI use without provisioning it has quietly introduced a paywall into assessment.
What does the policy owe staff?
Capability, and in some jurisdictions this is now a legal duty rather than good practice.
Article 4 of the EU AI Act — Regulation (EU) 2024/1689 — provides that “providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf,” taking account of their technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used.
A university that adopts an AI system is a deployer. For institutions in the EU, staff AI literacy is therefore not a training aspiration to be funded when budget allows; it sits in the regulation. Institutions outside the EU should still note the standard, because it is the direction of travel and because multinational vendors will build to it.
The student-side evidence points the same way. HEPI 2026 found 68% of students believe AI skills are essential to thrive, while fewer than half (48%) feel their teaching staff are helping them develop those skills — with arts and humanities students particularly likely to feel unsupported.
The nine components, as a checklist
| # | Component | Failure mode if omitted |
|---|---|---|
| 1 | Scope — which activities, levels and awards | Endless argument about whether the policy applies |
| 2 | Per-assessment permission categories | A rule that is either unenforceable or pedagogically wrong |
| 3 | Disclosure mechanism — where, what, when, and consequence | Declarations that are unusable as evidence |
| 4 | The assistance / intellectual content test | Every case decided on the panel’s instinct |
| 5 | Evidence and burden of proof | Findings that fall on appeal |
| 6 | Equity of access and provisioning | Capability that tracks ability to pay |
| 7 | Staff capability and AI literacy | Inconsistent enforcement; in the EU, a regulatory gap |
| 8 | Review cadence with a named owner | A policy that ages out within one product cycle |
| 9 | Appeals route and published outcomes | No feedback loop; the same dispute recurs |
How often should it be reviewed?
Annually at minimum, with a named owner and a fixed date. The reason is empirical rather than theoretical: the proportion of students directly including AI-generated text in assessed work moved from 3% to 8% to 12% across the three HEPI surveys. A policy calibrated to any one of those years is miscalibrated for the next.
Attach the review to the assessment cycle rather than the governance calendar, so revisions reach module briefs before the teaching period they govern.
If you would like to discuss how an institutional platform supports disclosure and process visibility rather than after-the-fact detection, request an institutional evaluation and we will work through it against your own policy.
Frequently asked questions
Should our policy ban AI outright?
An institution-wide ban is unenforceable in most curricula and conflicts with programmes that now teach these tools. Set permission at the assessment level instead.
Does the EU AI Act apply to universities?
A university using an AI system is a deployer, and Article 4 of Regulation (EU) 2024/1689 places an AI literacy duty on providers and deployers in respect of staff and others operating systems on their behalf.
What is the AI literacy obligation exactly?
To take measures ensuring, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on the organisation’s behalf, proportionate to their background and the context of use.
Who should own the policy?
A named academic officer with authority over assessment regulations, supported by data protection and IT. Ownership split across committees is the most common reason a policy is never updated.
How specific should the disclosure statement be?
Specific enough to be evidence: which tools, at which stages, for what purpose. Vague declarations protect no one.
Should we publish permitted-use categories to students?
Yes, with the assessment brief. A rule a student cannot locate at the moment of writing is not operative.
Do we need to provide tools if we permit them?
If an assessment expects or rewards their use, yes — otherwise attainment reflects purchasing power. Only 38% of students report being provided with AI tools by their institution.
How do we handle doctoral work differently?
Through disclosure and authorship rules rather than permission categories, following the model institutions already use for external editing of theses.
What data should we collect to review the policy?
Case volumes and outcomes, appeal rates, and a periodic student survey with a stable instrument so year-on-year comparison means something — the measurement problem covered in our piece on what student AI statistics actually measure.
Should the policy name specific products?
Avoid it in the policy itself. Name categories in the policy and maintain an approved-tools list separately, so a product change does not require a governance cycle.
How do we test a policy before adopting it institution-wide?
Run it in one department first with agreed success criteria, as described in our guide to running a departmental pilot.
]]>
