Blog

A practical AI policy for universities in 2026


Most university AI policies were drafted in the first months after ChatGPT's release, when nobody knew quite what was happening and the instinct was to either ban the technology entirely or permit it with vague caveats. Three years on, many of those policies remain unchanged despite the landscape having shifted dramatically. Students are using AI whether it's permitted or not. Faculty are using it for research and administration while telling students not to use it for studying. The detection tools that were supposed to enforce bans have proven unreliable and have been abandoned by many institutions after flagging legitimate student work.

The result is a policy environment that satisfies nobody: students don't know what's acceptable, faculty interpret the rules differently across departments, and academic integrity officers are left to adjudicate cases without clear criteria.

This post proposes a framework that policy committees can adapt. It doesn't require adopting any specific tool. It does require making a distinction that most current policies fail to make: the difference between AI that generates work and AI that supports understanding.


The three-category framework

Category 1: Clearly inappropriate

AI that produces work the student submits as their own. This includes generating essay text, producing answers for take-home exams, creating code that the student presents as original, and any use where the AI does the cognitive work that the assessment was designed to develop in the student.

This category is already covered by most academic integrity policies, even those written before AI existed. The principle is the same one that prohibits buying an essay from a service or having someone else take your exam: the student must be the author of the work they submit. AI as ghostwriter falls squarely into existing frameworks around academic dishonesty.

Policy recommendation: Prohibit and enforce through existing academic integrity procedures. Be explicit that submitting AI-generated text, code, or analysis as one's own work constitutes academic misconduct.

Category 2: Clearly appropriate

AI that helps students understand the materials they've been assigned. This includes asking an AI to explain a concept from the assigned reading, generating practice questions for self-testing, finding connections between different parts of the curriculum, summarising lecture content for revision, and getting alternative explanations when the standard one doesn't make sense.

These are exactly the activities a student would undertake with a human tutor, a study group, or during office hours. The AI is not doing the student's work. It's helping them understand the material they need to engage with. The cognitive work of analysis, evaluation, and argumentation remains the student's responsibility.

An AI tutor grounded in the student's own course materials, which answers from the assigned readings and lecture transcripts rather than from generic training data, sits firmly in this category. The distinction from ChatGPT matters because the course-grounded tutor points students back to their sources rather than replacing them.

Policy recommendation: Explicitly permit. Students should know that using AI to understand their course materials is acceptable and encouraged, just as using a human tutor or study group is acceptable.

Category 3: Grey area requiring guidance

This is where most of the difficult cases sit, and it's where policies need to be most specific rather than most vague.

Research methodology. A student asks AI to help them design a research methodology for a dissertation. The AI suggests approaches, identifies potential pitfalls, and recommends readings. This is closer to what a supervisor does than what a ghostwriter does. Policy guidance: permitted, but the student should document the AI's contribution and the final methodology must reflect the student's understanding and judgment.

Structural feedback. A student asks AI to evaluate the structure of their essay outline and suggest improvements. The student wrote the outline; the AI provides feedback on its organisation. Policy guidance: permitted in the same way that showing a draft to a friend for structural feedback is permitted.

Grammar and style. A student uses AI to check grammar, improve sentence clarity, and suggest more precise vocabulary. Policy guidance: generally permitted, as this is functionally equivalent to using Grammarly or a proofreading service, but departments should be explicit about whether they permit it.

Data analysis assistance. A student asks AI to help interpret statistical results or suggest appropriate analytical methods. Policy guidance: permitted if the student demonstrates understanding of the methods used in their written work, prohibited if the student simply copies the AI's interpretation without understanding it.

Summarisation of external sources. A student asks AI to summarise a long article they found during research. Policy guidance: permitted for personal comprehension, but the student should read the original and cite the original rather than the AI summary in their submitted work.

Policy recommendation: Provide explicit guidance for each common use case within the grey area, acknowledging that reasonable people may disagree. Department-level specificity is better than institution-wide vagueness, because what's appropriate in a creative writing module is different from what's appropriate in a computer science module.


Principles for implementation

Make the distinction between Category 1 and Category 2 central. Most current policies treat all AI use as a single phenomenon, which is like having a library policy that treats reading a book and plagiarising from it as the same activity. The primary distinction in AI policy should be between AI as ghostwriter (Category 1) and AI as study tool (Category 2). Once this distinction is clear, most enforcement questions become manageable.

Be specific about acceptable uses. "Students may use AI responsibly" is not a policy. "Students may use AI to understand assigned readings, generate practice questions, and seek alternative explanations of course concepts. Students may not use AI to produce text, code, or analysis they submit as their own work" is a policy.

Acknowledge that detection is unreliable. AI detection tools produce false positives at rates that make them unsuitable as the primary enforcement mechanism. Policies should focus on clear expectations, student understanding, and assessment design rather than on detection technology.

Design assessments that are resilient to AI misuse. Open-book exams, in-class presentations, oral examinations, portfolio assessments with reflective components, and assessments that require engagement with specific course materials are all naturally resistant to AI ghostwriting. The long-term solution to AI in assessment is assessment design, not detection.

Provide faculty training. Many faculty members are uncertain about AI and making policy decisions based on incomplete understanding. Institutional AI policy should be accompanied by faculty development that covers what AI can and cannot do, how course-grounded AI tools differ from general-purpose chatbots, and how to design assessments that leverage AI as a learning tool rather than viewing it solely as a threat.

Review annually. The AI landscape is changing rapidly. A policy written in 2026 may need significant revision by 2027. Build a review cycle into the policy itself.


Why this framework benefits institutions

A clear, three-category AI policy has practical benefits beyond academic integrity.

Reduced ambiguity. Students know what's permitted. Faculty have a framework for making decisions. Academic integrity officers have criteria for adjudicating cases.

Better student outcomes. Students who are explicitly permitted and encouraged to use AI as a study tool will use it more effectively than students who use it covertly with uncertainty about whether they're doing something wrong. The permission to use AI openly leads to better learning practices than the grey market that exists when policy is unclear.

Institutional positioning. Universities that develop thoughtful, nuanced AI policies position themselves as forward-thinking rather than reactive. Prospective students and their families increasingly ask about AI support, and a clear policy that includes access to AI tutoring grounded in course materials is a genuine differentiator.

Reduced enforcement burden. Clear categories reduce the number of edge cases that academic integrity committees need to adjudicate. When the policy itself answers the question, fewer cases need to be escalated.


Frequently asked questions

How do we enforce the distinction between Category 1 and Category 2? Primarily through assessment design rather than detection. Assessments that require engagement with specific course materials, in-class components, oral examination, and reflective practice are naturally resistant to ghostwriting. The policy sets the expectation; the assessment design enforces it.

Should different departments have different policies? A universal institution-wide framework (the three categories) with department-level specificity for the grey area is the most practical approach. What's appropriate in creative writing differs from what's appropriate in engineering, and the policy should acknowledge this explicitly.

What if a student uses a course-grounded AI tutor and a general-purpose chatbot? Many will. The policy should address the distinction between tool types and use types. Using a course-grounded tutor to understand readings is Category 2 regardless of what other tools the student uses. Using ChatGPT to generate essay text is Category 1 regardless of what other tools the student uses. The two activities are assessed independently.

How should students disclose AI use? For Category 2 uses (understanding materials), disclosure should be optional, in the same way students don't disclose that they used a dictionary or visited the library. For Category 3 uses (grey area), disclosure should be expected and the specific use described. For Category 1 uses (generating submitted work), disclosure is irrelevant because the use itself is prohibited.


Related reading: AI tutoring vs ChatGPT, An AI that only answers from your course materials, Bloom's two sigma problem. Related pages: AI tutor, For students, Solutions: AI without the risk.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.