On this page

You are the provost, dean, governance lead, teaching center director or committee chair who has to produce or defend this policy, and to answer a colleague who calls it too strict or too vague. The direct bottom line: publishing a policy is the easy part, and a document alone changes nothing. Most institutions have already answered whether to have one by publishing one, and the resulting estate is broad but shallow — advisory rather than binding, clustered around academic integrity, and thin on the data, equity and capability problems that decide whether AI use goes well. What separates a defensible policy from a document that gathers dust is a named owner, a review calendar, a translation path into courses, and an assessment design that rewards the behavior you are asking for.

The short version

Write short on aspiration and explicit about obligation. Audit your draft for every "may" and "can" where you mean "must," and define plagiarism and prohibited uses in words a first-year student can apply. Name an executive owner and a review cycle before you publish. Say where FERPA, GDPR, HIPAA, IRB and research-integrity obligations live instead of folding them in — one document absorbing data protection, research ethics, clinical regulation and academic conduct will be long, unread and unenforceable. Fund staff capability and student access together, because they fail together. Ask how many courses actually operationalized the policy, and treat a low number as a support failure rather than a compliance problem. Build reflection on AI use into graded work at a level proportionate to the effort it takes, and attach an evaluation plan, because nobody can claim the policy improved anything until they measure it.

Decide first: what your document governs

Manikonda and Outlaw (2026) crawled AI policies from 149 R1 and R2 United States universities and verified 130 university-level policies spanning 34 states. The register is advisory rather than directive: 95% of policies carried a negative clarity-strength score, so weak language ("may," "can") dominates over directives ("must," "prohibited"). University-level policies prioritize data security, risk mitigation, procurement and legal compliance with little pedagogical guidance, while the school-level policies that exist focus on teaching and AI Literacy. Only eight business schools had a school-specific policy, and those differed from their host framework in six of eight cases. The authors' remedy is a layered structure: a university-wide risk-management layer, department-level policies, and inter-departmental committees with faculty and students.

That gives you a scope decision to state in writing: declare the document a risk-management instrument, and place operational detail at department level, which also answers the charge of vagueness.

Decide second: whether the provisions bind

Look at what institutions publish when nothing forces the question. Eldredge et al. (2026) scanned all 48 CAHIIM-accredited health informatics and health information management master's programs in the US. Forty programs (83%) published at least one AI-related document; of the analytic sample, 21 documents (53%) were guidelines, 9 (23%) informational and only 7 (18%) formal policies. Academic integrity was the most frequent keyword (n = 139), ahead of citation (59), Assessment (50) and plagiarism (38); disclosure of AI and contract cheating each appeared once; HIPAA appeared five times, FERPA eleven and electronic health records not at all. Equity vocabulary was near-absent — inclusion (n = 9), accessibility (n = 9), equitable access (n = 2). That is attention without commensurate binding commitment.

The lesson costs nothing: count your modal verbs and write a consequence where you mean one.

Decide third: who writes it, and who is bound

Two reviews place the weakness in capacity, not intent. Ashiq (2026) synthesized more than seventy UK sources and found that only a minority of institutions maintain official AI governance plans, that strategic planning gaps produce policy drift and performative compliance, that national guidance from the Office for Students and Jisc has been criticized for lacking specificity and enforcement power, and that staff AI-training and infrastructure investment concentrate in research-intensive institutions while teaching-led institutions face capacity constraints. Baroudi (2026) reviewed 19 sources and found that only 7% of institutions had created senior AI leadership roles despite 49% treating AI as a strategic priority, with a theory-implementation gap driven by weak policy frameworks and limited digital infrastructure, particularly in the Global South. Writing a policy is not the bottleneck; owning, resourcing and revising it is.

So decide who chairs this and who sits on it before you draft. Crompton et al. (2026) convened a Delphi panel from 22 countries and locations across six continents and produced a consensus framework with eight core areas — academic integrity, ethical and responsible use, privacy and protection, equitable access, GenAI literacy, integration strategy, human oversight and accountability, and institutional support and infrastructure — plus a six-part mechanism to keep policy current: a multidisciplinary governance committee (more than half the panel), scheduled review cycles (half the panel), professional development, communication with all Stakeholders, evaluation of effectiveness and monitoring of external developments. Use the framework as your coverage checklist and the mechanism as your operating model. Note where the consensus is lopsided, because your committee will drift the same way: ethical and responsible use was referenced by two-thirds of panelists and privacy by over half, but equitable access by only one-third — equity is what a consensus process under-weights first. Half the panel insisted significant GenAI outputs be reviewed by a human, and favored process-focused and oral assessment.

One participation decision is worth making deliberately. Hingle and Johri (2026) had students co-design a GenAI course policy through guided inquiry; the priorities that emerged were training for students and instructors, standardized disclosure procedures, stronger institutional support rather than reliance on individual instructors, and a role in decisions about the rules governing their own learning — which argues for student membership on the committee rather than a consultation round. Baroudi found empowering and distributive leadership styles associated with higher faculty engagement and openness to change, and documented Change Management machinery (Valente's contagion model, Rieber and Welliver's five-stage framework) as the support for adoption. Leadership style, on this evidence, is part of the policy.

Tan et al. (2026) offer a six-dimension organizational framework whose propositions are explicitly left for future empirical validation. It is a checklist of what a policy should cover, not evidence of what works — useful for structure, over-claiming if cited as proof.

The gap in practice is between individual rules and institutional ones. The AAC&U/Elon survey of 1,057 US faculty (Watson and Rainie 2026) found 87% had created their own policies for students on generative AI use, while only 48% said their institution had written such guidelines and 35% said their department had. Structurally, 55% reported a task force or oversight group, 37% new AI-focused classes, 17% an AI major or minor, 16% new academic leadership offices, and only 13% had adopted AI literacy as a general education learning outcome. The sample is non-scientific and the authors say it is not generalisable, but the asymmetry is the point: the rules students actually meet are written by the instructor in front of them, which is why translation into courses matters more than publication. Coates, Croucher and Calderon (2025) supply the governance instrument for the opposite end — an academic integrity indicator framework built for institutional governors through research reviews, multi-institutional case studies, prototyping and expert confirmation, together with reforms to governance architectures, people and technologies.

Compliance with baseline law is not ethical data governance. Varadaraju and Vijayakumar (2026) argue that Learning Analytics governance in higher education has remained compliance-first, centered on meeting FERPA and GDPR, and propose the LEAGUE framework — Lawfulness, Equity, Agency, Governance, Utility and Ethics by Design — demonstrated against an early-alert case study. The Delphi panel independently put privacy and data protection as a critical theme for over half its members, and the OECD Digital Education Outlook (2026)'s third policy pillar is an enabling environment for trustworthy GenAI covering Privacy, safety, bias testing and transparency.

The lesson from the health informatics corpus is scope discipline: its AI documents barely mentioned HIPAA, FERPA or IRB guidance and never mentioned electronic health records, because those obligations live in broader compliance policy. Name where each obligation sits, and require students to encounter it in coursework.

Decide fifth: how the policy reaches the classroom

This is the decision most policies fail, and it is measurable. Ganguly et al. (2026) analyzed 116 institutional GenAI policies from 131 R1 universities alongside 98 computer-science course syllabi from 54 R1 institutions. Institutions mostly encouraged GenAI use (73, 63%) while 31 (27%) discouraged it; at course level, 90 syllabi (92%) gave explicit guidelines but 49 (50%) outright prohibited GenAI use, 40 (41%) permitted partial use, only 7 (7%) encouraged it. Only 47 of 131 institutions had both an institutional policy and detectable course-level translation. Governance, on this evidence, means translating policy into concrete instructor support, or instructors will improvise local rules that may not align with institutional guidance.

Ask your committee how many courses detectably translate the policy, and treat the answer as a support metric, not a compliance metric.

Decide sixth: capability, access and the review you promised

Two frequently omitted provisions are staff development and equitable access. The Delphi panel placed institutional support and infrastructure as the foundational enabler; Baroudi found senior AI roles rare and emphasized AI literacy and hands-on training for faculty and staff. Ashiq found staff AI-training concentrated in research-intensive institutions, widening a Digital Divide. Adarkwah et al. (2026) analyzed 159 documents from 30 highly ranked universities in the ten countries best placed on the IMF AI Preparedness Index, scored against UNESCO's eight-component GenAI framework. Four universities were excluded for lacking publicly accessible policies, leaving 26, and no public policies were found for German universities or Tallinn University of Technology. Core ethical and governance principles were widely adopted while inclusion, equity, internet access, gender parity and environmental impact were frequently overlooked, and many provisions remained declarative rather than operationally assured — the same pattern the health informatics corpus found, where equity vocabulary was near-absent. The OECD's fourth pillar is equitable digital infrastructure, including offline small language models for low-connectivity settings. Tan et al. extend the competency dimension past AI Literacy to data literacy, digital ethics, strategic thinking, change leadership and lifelong learning.

Budget these together and name an owner: a policy that mandates AI use without funding devices, connectivity, accommodations or training has assigned an obligation it cannot support.

Two recent policy studies give you an audit instrument and a warning about support. Gutowski and Hurley (2025) scored institutional policies on five dimensions with explicit rubrics — prohibitiveness, permissiveness, educational integration, transparency and accountability, and depth — and found most institutions in their sector taking generally prohibitive positions while reserving discretion to individual instructors, no single accepted approach, and clarity itself treated as the precondition for defensible enforcement. Their recommendation is deliberately procedural: comprehensive guidelines whatever your stance, stakeholders involved in drafting, proactive training, governance designed to be flexible, and review cycles, on the view that policy generation is not a one-time event. Qian (2026) reaches the same structural point from the support side: what distinguishes institutions is not the rule alone but the support ecosystem published alongside it — faculty development, student guidance, assessment support and governance structures that make the policy operational. Read your draft as a support commitment with rules attached, not the reverse.

Four objections you will hear

"We already have an academic integrity policy."

It is necessary and not sufficient, and the corpus shows why: integrity is the easiest provision to write, which is why it dominates the keyword counts while equity vocabulary, access and data obligations sit near-absent. What the evidence supports is division of labor, not merger — conduct rules stay where the academic-integrity process can enforce them, and the AI policy carries what an integrity code cannot reach: procurement and data security, disclosure procedure, accessibility and access, staff training, and the assessment conditions under which integrity is achievable. The Delphi panel's insistence on human review of significant GenAI outputs, and its preference for process-focused and oral assessment, has no home in an integrity code.

"Faculty will ignore it."

Some will, and it is rarely about will. Ashiq's evidence is capacity: governance plans are uncommon, planning gaps produce policy drift and performative compliance, and training and infrastructure investment concentrate in research-intensive institutions while teaching-led ones face constraints. Baroudi's is structure — 7% of institutions had created senior AI leadership roles against 49% treating AI as a strategic priority. Ganguly et al.'s is translation: only 47 of 131 institutions had both a policy and detectable course-level implementation. Faculty are not ignoring the policy so much as being left alone with it. The counter-measure is professional development, worked examples and distributive leadership, which Baroudi associates with higher faculty engagement and openness to change.

"Students will not read it."

They will respond to it anyway, which is the more useful fact. Braun and Khafizov (2026) surveyed 1,809 students, 250 faculty and 62 administrative staff at one teacher-education university and found students reporting higher AI-use intensity and usefulness while faculty and staff reported stronger integrity concerns. In their pooled model, perceived usefulness had the strongest standardized association with Trust (β = 0.402) and institutional policy clarity was positive but weaker (β = 0.223); students reported higher perceived policy clarity than faculty did. These are cross-sectional, self-reported associations, but the ordering warns against treating a well-written policy as a trust-building instrument on its own. Ogbo et al. (2026) model student AI use as a coordination problem in which cohort norms, not stated rules, govern behavior, and show threshold-driven transitions: reflective assessment must be rewarded above a critical level before responsible use displaces opportunistic practice, the reward must be proportionate to the effort reflection demands, and peer sensitivity determines cascade speed. Students respond to assessment structures rather than pronouncements, which supports pedagogy-led governance over surveillance. The OECD adds that general-purpose chatbots improve output quality but that advantage disappears and sometimes reverses in exams when AI access is removed, with metacognitive engagement dropping as work is offloaded. Put the requirement in the graded assessment.

"We cannot police it."

You cannot, and the evidence says you do not have to. Ogbo et al. offer the one formal result in this corpus — policy pronouncements alone leave opportunistic practice intact when assessment incentives are misaligned — so the lever is design, not detection. Braun and Khafizov's strongest measured driver is perceived usefulness, not policy clarity, so a policy that makes responsible use useful to students travels further than one that threatens detection. Where you do enforce, keep it narrow and procedural: defined prohibited uses, disclosure rules students can follow, and the human-review and oral-assessment practices half the Delphi panel endorsed. Your real exposure is the translation gap, not student evasion — 92% of syllabi gave explicit guidelines while 50% prohibited GenAI outright, against 63% of institutional policies that encouraged it. The inconsistency students meet is between your policy and your own courses.

Where enforcement fails, it is more often an evidence problem than a detection one, and that is where institutional exposure sits. Munoz et al. (2026) documenting real allegation files found the evidentiary base thinner than policy implies: system-recorded traces exist only in supervised assessment, process evidence (drafts, supervision meetings, presentations) exists only where those practices were already required, and natural justice requires the student to be told the allegation and given a chance to respond before any determination. Detector output cannot substitute for that: Hadra et al. (2026) measured accuracy of 0.69 and 0.61 for two widely used commercial tools, both failing on hybrid human-AI text and with a borderline misclassification risk for EFL student writing, and Bassett et al. show no threshold resolves the tradeoff between flagging honest work and missing concealed use. A finding that rests on a score nobody can interrogate is the case that generates the appeal, the complaint and occasionally the claim. Write the evidence standard into the policy, ban standalone detector evidence, and link the procedure to the obligations on Legal Issues and Risks.

What the evidence cannot yet tell you

This corpus contains no study measuring whether an institution's AI policy changed student behavior, staff practice or learning outcomes. What exists is descriptive: Manikonda and Outlaw find policy language weak and misaligned; Ashiq documents policy drift; Baroudi names the absence of longitudinal and causal evidence as a gap. Eldredge et al. caution that analyzing public documents only creates a visibility bias, so the absence of privacy or equity language is a finding about published guidance rather than practice. Tran, Liu and Nguyen (2026) reviewed 65 peer-reviewed papers on AI and social-emotional learning and found nearly three-quarters mentioned no policy implications at all, and that the minority which did mostly lacked the actor-specific detail — who should act, on what, why, when and how — that real policymaking needs. Treat the gap as a reason to instrument your own policy, not to wait.

The defensible stance is that the policy is not the deliverable; the mechanism is. Publish binding provisions where you mean them, give the document a named owner and a scheduled review, translate it into course-level support, put the compliance obligations where students will meet them, fund staff capability and access together, and attach an evaluation plan — nobody can claim the policy improved anything until they measure it.

What to do this week

  • Count your modal verbs. Search the draft for "may" and "can," rewrite each instance where you mean "must" or "prohibited," and define plagiarism and prohibited uses explicitly.
  • Name one owner and one date. A standing governance committee, a scheduled review cycle, a named executive sponsor, and a line assigning responsibility for monitoring external developments.
  • Book the layering conversation. Convene department-level leads and a committee with faculty and student members, and decide which provisions are university-wide and which the department writes.
  • Write the missing provisions. Accommodations, accessibility, device and connectivity assumptions and language coverage belong with the rule that requires AI use; then name where FERPA, GDPR, HIPAA, IRB and research-integrity obligations live.
  • Ask for the translation number. Treat a weak answer as a support failure and pair restrictions with worked examples.
  • Change one assessment and one evaluation question. Build reflection on AI use into graded work at a level proportionate to the effort it takes, then state what you will measure, when, and who owns the finding.

For the course-level counterpart of this work, see writing a course AI policy and communicating it to students. The research base sits in institutional governance research, the global Delphi framework and program-level policy audits; see Administrators and Change Management for the leadership and implementation dimensions. Educational AI Policy collects the sector-wide literature, and AI Governance covers how authority and accountability are distributed.

Embed this page

Copy the code below to embed a chromeless version of this page in a learning management system or other website. The embedded view hides the site header, navigation, and footer.