Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

How Universities Are Updating Academic Integrity Policy for AI Writing Tools

Universities have largely moved from blanket AI bans toward tiered permission frameworks and disclosure requirements. This guide covers the policy shift, the AI Assessment Scale framework, and what research administrators should know.

Ask about How Universities Are Updating Academic Integrity Policy for AI Writing Tools

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Between 2023 and 2026, most universities moved through the same arc on generative AI: an initial instinct toward blanket prohibition, followed by a shift toward permission-based frameworks that specify when and how AI assistance is allowed rather than banning it outright. The policy language changed accordingly — from a single line added to an honor code (“use of AI tools is prohibited”) to layered systems that vary by course, assignment, and even assignment stage, paired with disclosure requirements borrowed from research-integrity practice. This guide describes that shift in aggregate and points to the frameworks and named institutional examples that are publicly documented, rather than asserting what every institution does, since policy specifics change on each institution’s own cycle and vary widely even within the same university.

From blanket bans to tiered permission

The earliest wave of institutional response to ChatGPT-class tools (late 2022 through 2023) leaned heavily on prohibition: many honor codes and syllabi simply extended existing plagiarism or unauthorized-assistance language to cover AI-generated text. That approach ran into two practical problems that have driven the subsequent policy shift. First, blanket bans proved difficult to enforce reliably — AI-detection tools produce false positives at rates that make them a poor sole basis for an integrity finding (CASRAI’s explainer on AI-detection false positives and guide to how AI-text detection actually works cover why). Second, blanket bans didn’t map onto how AI tools were actually being used across disciplines: grammar and citation assistance, literature summarization, code debugging, and full-draft generation are different activities with very different implications for academic integrity, and a single rule couldn’t distinguish between them.

What replaced the blanket ban, at the institutions with publicly documented policies, is some version of a tiered or conditional framework: permission is scoped to a specific tool, task, assignment, or course stage, rather than granted or denied globally. The common design elements, seen repeatedly across the examples below, are:

  • Tiering by task, not just tool. The same AI tool might be permitted for brainstorming or proofreading and prohibited for drafting graded submissions.
  • Disclosure as the default condition of permitted use. Where AI use is allowed, most policies require the student to say so — naming the tool, and often the version, the purpose it served, and sometimes the prompts used.
  • Instructor- or course-level authority over the specifics. Rather than a single university-wide rule, the institutional policy sets the outer boundary (e.g., “unauthorized AI use is academic misconduct”) and delegates the operational detail — what’s authorized, for which assignments — to the syllabus.
  • Data-handling restrictions layered on top of the integrity question. A growing number of policies address what happens to the text a student pastes into a public AI tool, separate from whether using the tool was permitted at all.

What a tiered policy actually looks like

Carnegie Mellon University’s Eberly Center for Teaching Excellence publishes a set of six example academic-integrity policy statements that instructors can adapt for their syllabus, and the set is a useful illustration of the range institutions are now working within: two examples prohibit AI use at any stage, including brainstorming; two permit AI use throughout coursework provided students cite the tool and disclose the specific version used, in some cases including the exact prompts and AI responses in an appendix; and two make permission conditional on the specific assignment, with one restricting AI to ungraded exercises like idea generation while prohibiting it on graded submissions. The Eberly Center frames these as a spectrum for instructors to choose from and adapt, not a single mandated university policy — which is itself representative of the broader trend: the most consequential AI-integrity decisions are increasingly made at the course level, inside a boundary set by the institution.

A commonly cited public description of university policies compiled in mid-2026 characterized several major institutions’ approaches along similar lines — for example, describing the University of Chicago as directing instructors to categorize their course AI policy into one of four tiers (prohibited, permitted with authorization, permitted with citation, or broadly allowed), and describing UCLA’s Academic Senate guidance as treating unauthorized AI use the same way it treats unauthorized help from another person. Individual course and department policies at any given institution change on their own schedule, so treat specific characterizations like these as illustrative of the pattern rather than as a current, official statement of any one university’s policy — always confirm against the institution’s own current policy page before relying on specifics.

The AI Assessment Scale: a shared reference framework

One reason policy language looks similar across otherwise unrelated institutions is that several have converged on the same published framework rather than each writing tiering language from scratch. The AI Assessment Scale (AIAS), developed by Leon Furze, Mike Perkins, and colleagues and published in the peer-reviewed Journal of University Teaching and Learning Practice (with an earlier version posted to arXiv in December 2023), defines five levels running from “no AI” through to “full AI,” each specifying what a student may and may not use AI assistance for at that level, and each intended to be attached to a specific assignment rather than applied blanket across a course. The AIAS was designed explicitly as an alternative to binary allow/ban language, and a revised version was published in 2024 refining the level definitions based on early classroom use. It functions less as a rule in itself and more as a shared vocabulary that lets an instructor communicate a specific, task-level permission quickly, rather than every course inventing its own terminology.

Disclosure requirements: what students are being asked to report

Where policies permit AI use, the disclosure requirement is doing much of the integrity work that a blanket ban used to attempt through prohibition. The requirements vary in specificity but recur across the same few elements: which tool was used, often including the version or model; what task it was used for; and, in the more detailed policies, the prompts submitted and the AI-generated output received, sometimes required as an appendix to the submitted work. This mirrors the disclosure structure that journal publishers converged on for manuscripts around 2023–2024 — CASRAI’s guide to publisher policy on generative AI in manuscripts and the position statements from COPE and ICMJE that it covers use a similar logic: AI cannot be an author or bear responsibility for the work, so a human author must disclose exactly how it was used and remains fully accountable for the resulting text. Universities extending this logic to coursework and theses are, in effect, applying a research-integrity disclosure norm one step earlier in a researcher’s career.

Data privacy is now a separate axis from academic integrity

A newer element of institutional policy, distinct from the “was this authorized” integrity question, concerns what happens to the content a student or researcher enters into a public AI tool. Several institutions’ policies now classify data by sensitivity and restrict entering anything above a low-risk classification — unpublished research data, personally identifiable student information, material covered by FERPA or HIPAA, or export-controlled content — into consumer-facing AI tools whose data-handling terms the institution doesn’t control. The practical response at a number of universities has been to stand up an institutionally licensed or hosted AI tool (sometimes built on the same underlying models as the public consumer versions) that comes with a data-processing agreement the institution has actually reviewed, and to steer sensitive use toward that tool rather than prohibiting AI assistance outright. This is a separate compliance question from academic integrity, but the two are increasingly addressed in the same policy document, since both turn on the same underlying question of what a student or researcher is doing with institutional or research data outside institutional systems.

Where AI detection fits — and its limits

Even as policies have moved toward permission-and-disclosure models, AI-text detection tools remain part of the enforcement picture for undisclosed use. But institutional caution about relying on detector output as standalone evidence has grown alongside the policy shift, for the same reason blanket bans proved hard to operationalize: detector tools have a documented false-positive problem, particularly for non-native English writers and certain formulaic academic prose styles. CASRAI covers the mechanics and limitations of these tools in more depth in How to Detect AI-Generated Text in Academic Writing and Why Does My Paper Say “AI Detected”?, including why a detector flag alone is not proof of an integrity violation and what steps a flagged researcher or student typically has available to respond. Policy language at a number of institutions has begun explicitly reflecting this limitation — treating a detector result as one input to an investigation rather than conclusive evidence on its own, and requiring corroborating evidence (such as a request for the student’s drafting history or a discussion of the work) before a finding is made.

What this means for research administrators and faculty

For research-administration staff and faculty drafting or updating policy language, the direction of travel across the publicly documented examples suggests a few practical takeaways:

  • A single institution-wide rule is increasingly the exception, not the norm. Expect to set an outer boundary at the institutional or honor-code level (what counts as a violation) and delegate the operational specifics to the course, department, or supervisor level.
  • Disclosure language should specify what “disclosure” means concretely — naming the tool and version at minimum, with prompt/output records as an optional stronger requirement for higher-stakes work like theses or grant narratives.
  • Separate the data-privacy question from the integrity question explicitly. A student or researcher can be fully authorized to use an AI tool for a task and still be in violation of a data-handling policy if they enter sensitive material into a public tool — these are two different rules and read confusingly if merged into one sentence.
  • Don’t lean on detection as the sole enforcement mechanism. Given documented false-positive rates, policy that treats a detector flag as conclusive proof creates real due-process exposure; corroborating evidence matters.

For the parallel question of what publishers require for AI disclosure in submitted manuscripts — a related but distinct policy layer that researchers encounter downstream of their institution’s own rules — see CASRAI’s AI & Digital Writing Tools for Research hub, which indexes the cluster’s guides on detection, disclosure, and publisher policy together.

Frequently asked questions

Have universities moved away from banning AI writing tools outright?

At the institutions with publicly documented policies, yes — the trend since around 2023–2024 has been away from blanket prohibition and toward tiered, task-specific, or course-level permission frameworks paired with disclosure requirements, though some contexts (many high-stakes exams, some early-stage graduate coursework) still prohibit AI use entirely. Policy varies by institution and even by department within the same institution, so this is a directional trend, not a universal rule.

What is a “tiered” AI permission framework?

A structure that specifies different levels of allowed AI assistance depending on the task or assignment, rather than a single allow/ban rule for the whole course. The AI Assessment Scale (AIAS) published by Perkins and Furze is the most widely cited published example, running from “no AI” to “full AI” across five levels.

What do universities typically require students to disclose about AI use?

Where disclosure is required, the recurring elements are: which tool was used (often including version), what task it was used for, and in more detailed policies, the actual prompts and AI outputs, sometimes as an appendix. Requirements vary by institution and by assignment type.

Is AI-detection software considered reliable enough to be the sole basis for an academic integrity finding?

Institutional caution here has grown: detector tools have a documented false-positive problem, and a number of institutions’ current guidance treats a detector result as one input requiring corroboration rather than standalone proof. See CASRAI’s guides on how AI-text detection works and why false positives occur for more detail.

How does academic-integrity AI policy relate to publisher AI-disclosure policy?

They apply at different stages and to different accountable parties, but share a common logic: a human remains fully responsible for the work and must disclose how AI was used, because the AI tool itself cannot bear that responsibility. CASRAI’s guide to the publisher policy landscape for generative AI in manuscripts and the legal landscape for AI disclosure cover the downstream, publication-facing version of this same question.

Note on sourcing: named institutional examples in this guide are drawn from each institution’s own publicly available guidance where cited directly (Carnegie Mellon’s Eberly Center), from the peer-reviewed literature describing the AI Assessment Scale, and from a mid-2026 third-party compilation of institutional policies for the remaining comparative examples. Individual course, department, and university policies are revised on their own schedules; confirm current requirements against an institution’s own official policy page rather than relying on a secondary summary.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →