What Should a University AI Policy Include? A Component Checklist for 2026

<![CDATA[

Short answer: nine components. Scope; a permission position set per assessment rather than institution-wide; a defined disclosure mechanism; a stated line between assistance and intellectual content; evidence and burden-of-proof rules; equity of access; staff capability; a review cadence; and an appeals route. Most policies we see cover three of the nine.

The failures are consistent enough to be predictable. Below is each component, why it fails when omitted, and what the obligation behind it actually is.

Why is one institution-wide rule the wrong design?

Because “may students use AI” has no single correct answer across a university. In a programming module a generative tool may be the object of instruction; in a language assessment testing unaided composition it defeats the construct; in a doctoral thesis the question is not permission but disclosure and authorship.

An institution-wide permitted-or-prohibited rule therefore fails in one of two directions. Set it permissive and you have authorised tool use in assessments designed to measure unaided ability. Set it restrictive and you have banned something half your curriculum now teaches — and you will not enforce it, which is worse than not having the rule.

The workable structure is a small number of named categories that assessments are assigned to, set by the module or programme owner and published to students with the assessment brief. Three categories are usually enough: no AI use permitted; AI permitted for defined support activities with disclosure; AI use expected and itself assessed. What matters is that a student can tell which one applies to the task in front of them, without interpretation.

The evidence that clarity is the binding constraint is reasonably direct. In the Higher Education Policy Institute’s Student Generative AI Survey 2026 — conducted by Savanta in December 2025 among 1,054 full-time UK undergraduates — students split almost evenly on whether their institution encourages AI use: 37% agreed and 36% disagreed. A population that cannot agree on what its institution’s stance is does not have a communicated policy, whatever the policy says.

What does the disclosure mechanism have to specify?

“Students must declare AI use” is not a mechanism. A mechanism answers four questions: where the declaration goes, what it must contain, when it is made, and what happens if it is absent.

A useful model already exists in most institutions, because the same problem was solved for editorial assistance long before generative AI. The University of Toronto’s School of Graduate Studies, addressing external copy editors, requires prior approval with a strong rationale, states that “the intellectual content of the thesis cannot be modified through the external editing process,” requires the student to “clearly identify the contributions of an external copy editor to their work in the thesis document,” and provides that students may be asked to supply the thesis before and after editing. The same page directs students to the School’s guidance on the appropriate use of generative artificial intelligence in graduate theses.

That structure transfers cleanly: approval where the stakes warrant it, an untouchable core of intellectual content, disclosure inside the document itself, and an evidential fallback. Institutions writing an AI policy from scratch are usually rewriting a rule they already have.

Administrators planning a policy at a whiteboard
Most of the components already exist somewhere in your regulations, written for a different technology.

Where is the line between assistance and intellectual content?

This is the component most policies gesture at and none define, and it is the one every appeal will turn on.

A workable formulation states the test rather than enumerating tools, because tools change and enumerations date within a term. The test that survives contact with cases is roughly: could the student account for this work — its claims, its structure, its sources — under questioning, as their own reasoning? Assistance that leaves that true is assistance. Assistance that makes it false is substitution, whether the helper was software, a friend, or a paid service.

Two specific rules are worth stating explicitly because they resolve most real cases:

  • Sources must be independently verified by the student. A reference the student has not opened may not exist. This single rule addresses the most common and most detectable failure mode, and it is technology-neutral.
  • Interpretation, argument and methodological choice are intellectual content. Language, formatting and structural scaffolding are generally not.

What must the policy say about evidence?

It must say who bears the burden and what will not discharge it. A policy silent on this hands the question to whichever panel hears the first contested case.

The specific provision to include: detector output is a trigger for inquiry, not a finding, and no allegation may rest on it alone. The reasoning — and the base-rate arithmetic that makes it unavoidable at institutional volume — is set out in our analysis of whether AI detection is reliable enough to base a case on. Writing it into the policy protects the institution as much as the student, because it prevents a panel from producing a decision that cannot survive appeal.

Does equity of access belong in an AI policy?

Yes, and it is the component most often missed. If an assessment expects AI use, the institution has made a tool a condition of participation, and any student without it is disadvantaged on grounds unrelated to their ability.

The HEPI 2026 survey found that only 38% of students say they are provided with AI tools by their institution, while 95% report using AI in at least one way. The gap is being filled by consumer products at students’ own expense, with the predictable consequence that capability tracks ability to pay. A policy that requires or rewards AI use without provisioning it has quietly introduced a paywall into assessment.

What does the policy owe staff?

Capability, and in some jurisdictions this is now a legal duty rather than good practice.

Article 4 of the EU AI Act — Regulation (EU) 2024/1689 — provides that “providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf,” taking account of their technical knowledge, experience, education and training, the context of use, and the persons on whom the systems are used.

A university that adopts an AI system is a deployer. For institutions in the EU, staff AI literacy is therefore not a training aspiration to be funded when budget allows; it sits in the regulation. Institutions outside the EU should still note the standard, because it is the direction of travel and because multinational vendors will build to it.

The student-side evidence points the same way. HEPI 2026 found 68% of students believe AI skills are essential to thrive, while fewer than half (48%) feel their teaching staff are helping them develop those skills — with arts and humanities students particularly likely to feel unsupported.

The nine components, as a checklist

# Component Failure mode if omitted
1 Scope — which activities, levels and awards Endless argument about whether the policy applies
2 Per-assessment permission categories A rule that is either unenforceable or pedagogically wrong
3 Disclosure mechanism — where, what, when, and consequence Declarations that are unusable as evidence
4 The assistance / intellectual content test Every case decided on the panel’s instinct
5 Evidence and burden of proof Findings that fall on appeal
6 Equity of access and provisioning Capability that tracks ability to pay
7 Staff capability and AI literacy Inconsistent enforcement; in the EU, a regulatory gap
8 Review cadence with a named owner A policy that ages out within one product cycle
9 Appeals route and published outcomes No feedback loop; the same dispute recurs

How often should it be reviewed?

Annually at minimum, with a named owner and a fixed date. The reason is empirical rather than theoretical: the proportion of students directly including AI-generated text in assessed work moved from 3% to 8% to 12% across the three HEPI surveys. A policy calibrated to any one of those years is miscalibrated for the next.

Attach the review to the assessment cycle rather than the governance calendar, so revisions reach module briefs before the teaching period they govern.

If you would like to discuss how an institutional platform supports disclosure and process visibility rather than after-the-fact detection, request an institutional evaluation and we will work through it against your own policy.

Frequently asked questions

Should our policy ban AI outright?

An institution-wide ban is unenforceable in most curricula and conflicts with programmes that now teach these tools. Set permission at the assessment level instead.

Does the EU AI Act apply to universities?

A university using an AI system is a deployer, and Article 4 of Regulation (EU) 2024/1689 places an AI literacy duty on providers and deployers in respect of staff and others operating systems on their behalf.

What is the AI literacy obligation exactly?

To take measures ensuring, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on the organisation’s behalf, proportionate to their background and the context of use.

Who should own the policy?

A named academic officer with authority over assessment regulations, supported by data protection and IT. Ownership split across committees is the most common reason a policy is never updated.

How specific should the disclosure statement be?

Specific enough to be evidence: which tools, at which stages, for what purpose. Vague declarations protect no one.

Should we publish permitted-use categories to students?

Yes, with the assessment brief. A rule a student cannot locate at the moment of writing is not operative.

Do we need to provide tools if we permit them?

If an assessment expects or rewards their use, yes — otherwise attainment reflects purchasing power. Only 38% of students report being provided with AI tools by their institution.

How do we handle doctoral work differently?

Through disclosure and authorship rules rather than permission categories, following the model institutions already use for external editing of theses.

What data should we collect to review the policy?

Case volumes and outcomes, appeal rates, and a periodic student survey with a stable instrument so year-on-year comparison means something — the measurement problem covered in our piece on what student AI statistics actually measure.

Should the policy name specific products?

Avoid it in the policy itself. Name categories in the policy and maintain an approved-tools list separately, so a product change does not require a governance cycle.

How do we test a policy before adopting it institution-wide?

Run it in one department first with agreed success criteria, as described in our guide to running a departmental pilot.

]]>

Bring Tesify to your institution

Scope a departmental pilot: one cohort, one term, and your own measures of what worked.

Request an evaluation We reply within 2 business days

Categories