humanflow

How should a university write an AI policy?

Name behaviours rather than technologies, state explicitly what a detection score may and may not be used for, and put the operative rule at course level where the assignment is actually set — those three decisions determine whether a policy is usable.

Last reviewed 15 August 2026 · The HumanFlow team

Policies written around named tools age badly and cover the wrong things. A rule about ChatGPT does not address the next product, and a rule about "AI tools" arguably prohibits a spellchecker. The rules that survive describe what a student may do — generate prose for submission, translate, correct grammar, outline — because those are the acts an assessor can actually adjudicate, and they remain meaningful when the software changes.

The second decision is the one that generates appeals when it is left implicit. If a detection score can trigger an enquiry but cannot found a finding on its own, say so in the regulations. Detector vendors themselves present these scores as indicators for review rather than as determinations, and a policy that is silent leaves individual panels to invent an evidential standard case by case. Several institutions have gone further and disabled detection entirely, publishing their reasoning — those documents are the most useful prior art available, and they are public.

The third is placement. The rule students are judged against is the one attached to the assignment, so a well-drafted institutional policy sets the floor and requires every module to state its own position — permitted, permitted with disclosure, permitted for named tasks, or prohibited. Silence at course level is the single largest source of genuine confusion, and it is the institution's ambiguity rather than the student's.

Two things follow that are easy to get wrong. Disclosure requirements need a specified format and a place to put it, or students write "AI was used in the preparation of this work", which discloses nothing. And any policy resting weight on detection has to confront the measured disparity in false positives across student populations, because a rule that lands hardest on international students is a rule with an equality problem regardless of intent.

When this answer changes

Assessment design changes the question. Where work is produced under supervision or examined orally, the policy has far less to carry, which is why institutions rethinking assessment have needed less detection rather than better detection.

Sector guidance and regulator expectations move, and a policy written before them may be out of step even where it was well drafted.

Disciplines differ legitimately. A computing department permitting AI for code and prohibiting it for prose is being precise rather than inconsistent, and a policy allowing that variation is stronger than one imposing a single rule everywhere.

Where to go next

Sources

One of our direct answers.