Skip to content
← Guides & helpTrust & verification8 min readBy The CiteDash team

How to read your university AI policy

Find every policy layer that applies to you, decode vague wording, and turn your university's AI rules into a checklist you can actually follow.

Most students read their university's AI policy for the first time after something has gone wrong: a flagged submission, a supervisor's raised eyebrow, a declaration form at submission asking about tools they never logged. By then the policy is a hazard. Read it early and it becomes the opposite: a written boundary you can rely on and, when needed, quote.

The difficulty is that the policy is rarely one document. It is a stack of documents written by different offices at different times, and the layer that actually governs your thesis may not be the one that appears when you search the university website. This guide shows you how to find every layer, what to extract from each, and what to do when the text is vague, silent, or out of date.

Reading policy sounds like a chore next to actual research, but the stakes are asymmetric. An hour of reading now is cheap insurance against a misconduct process later, and the notes you make double as raw material for the disclosure statement most universities now expect in the thesis itself.

Find every AI policy layer that applies to you

Work from the top down and collect the documents before you interpret any of them. In most universities the stack looks like this:

  • The university-level academic integrity code and any standalone generative AI policy or guidance page
  • Graduate school or doctoral college regulations, which often add thesis-specific rules on authorship and declarations
  • Faculty or department guidance, where disciplines translate the central policy into local practice
  • Your program or module handbook, which can restrict further for specific assessments
  • The assessment brief or thesis submission requirements themselves, including any declaration forms
  • Your supervisor's expectations, which are informal but operationally binding
  • External rules if you will publish or are funded: journals and funders increasingly have their own AI provisions

When policy layers conflict

Two rules of thumb. The most specific and most restrictive layer usually controls the piece of work in front of you: a module handbook that bans AI for one assessment overrides a permissive university page for that assessment. And when two layers genuinely conflict, do not resolve the conflict yourself: ask the program office in writing and keep the answer.

Date every document as you collect it. AI guidance is being rewritten constantly, and a printout or saved PDF with a date is the difference between arguing about what the rules said and showing what they said.

The six questions your AI policy needs to answer

As you read, you are hunting for answers to six questions. If you finish reading without an answer to any of them, that gap is itself important information.

Write your answers down with a citation to the exact clause that gives each one. You are building a personal compliance sheet, and the clause references are what make it useful in a disagreement: an answer you can point to beats an answer you remember.

  • Which uses of AI are permitted, restricted, or prohibited, and for which kinds of work?
  • Is disclosure required, and if so in what form and where in the document?
  • Does the university run AI detection on submissions, and what process follows a flag?
  • What are you allowed to upload to external tools, given confidentiality, data protection, and unpublished results?
  • What can be delegated and what cannot, while you remain the author of your thesis?
  • Do the rules change between coursework, the thesis, and examinations?

The three common shapes of university AI policy

Reading many policies, three archetypes recur. Prohibition-first policies ban generative AI by default and carve out exceptions per assessment; under these, silence means no, and you need explicit permission in writing before using anything. Permission-with-disclosure policies allow AI use in principle and make honesty the load-bearing wall; under these, the disclosure requirement is the rule most likely to catch you out, because a permitted use becomes misconduct the moment it goes undisclosed.

The third shape is the tiered or traffic-light policy, where each assessment carries a designation running from no AI at all through AI-assisted to AI-integral. These are the clearest to operate under and the easiest to trip over, because the designation lives in the assessment brief rather than the policy, and it can differ between two pieces of work you submit in the same term. Identify which shape your university uses and you will know where its sharp edges are.

None of the three shapes is inherently stricter in practice. A prohibition policy with generous carve-outs can allow more than a permissive policy with a heavy disclosure burden. What changes is where the risk concentrates: in getting permission, in disclosing fully, or in reading every assessment brief.

Decoding vague policy language

AI policies lean on adjectives that nobody defines. Editorial assistance is usually fine and substantive generation usually is not, but the line between them passes somewhere through the middle of a paragraph rewrite, and the policy will not tell you where. The same goes for proofreading versus rewriting, assistance versus authorship, and checking versus producing.

Do not resolve ambiguity in your own favour by default; panels tend to resolve it the other way. When a use you care about sits in the grey zone, describe it concretely in an email to your program director or supervisor: the tool, the input, what the output was, what you did with it. A one-line written confirmation converts a grey zone into a boundary you can stand on.

While you wait for an answer, a workable conservative rule: if the tool contributed words, structure, or claims that survive into the submitted text, treat the use as substantive and act as though disclosure and permission are required. If the tool only checked or critiqued work you had already produced, you are more plausibly in editorial territory. This is a posture, not an interpretation; the written confirmation is still the thing to get.

The clause that matters most: you are responsible for all output

Nearly every AI policy contains some version of the same sentence: the student remains fully responsible for the accuracy and integrity of all submitted work, however it was produced. This clause is not boilerplate. It means a fabricated reference is your fabrication even though a tool produced it, and a misrepresented source is your misrepresentation even though you never opened the paper.

Operationally, the clause obliges you to verify everything an AI touches: every citation must resolve to a real paper you have read, and every claim must actually be supported by its source. This is the obligation CiteDash automates: citations are database objects that resolve to real papers, and the Fact Checker verifies each AI-assisted claim against the held full text before it reaches your draft. For the background on why models invent references in the first place, see why AI makes up citations.

Disclosure requirements: what universities usually ask for

Where disclosure is required, the common shapes are a statement in the thesis front matter, a section on the declarations page, or an appendix listing tools, versions, and purposes. Some departments also want prompts for any AI text that appears in the document, and some ask your supervisor to countersign.

Read the requirement for its granularity: a bare sentence saying you used AI tools will not satisfy a policy that asks which tools, for what, and at which stage. Our guide to the AI use disclosure statement walks through wording and placement, and CiteDash can generate a disclosure from your actual usage on the platform, which beats reconstructing months of work from memory the week before submission.

Data privacy: what you are allowed to upload

The policy layer students most often miss is not about integrity but about data. Uploading draft chapters, unpublished results, participant data, or anything covered by an ethics approval or an industry agreement into a consumer AI tool can breach confidentiality rules that exist entirely apart from the AI policy. Some universities restrict which tools may receive university work at all.

Check three places: the AI policy's own terms-of-use language, your ethics approval's data-handling commitments, and any collaboration or funding agreements. If you use CiteDash, the security page describes how documents are handled; whatever platform you use, you should be able to answer where your unpublished work goes when you press upload.

When the policy is silent, vague, or outdated

Many policy pages still carry rules written for an earlier generation of tools. Check the date on everything you read, and if the policy predates the tools you are using, do not assume either permission or prohibition: ask. An emailed question to the program office costs nothing and produces a written answer.

Keep the reply with your compliance notes. If the policy changes mid-degree, the record of what was permitted when you did the work is your protection, and universities generally judge conduct against the rules in force at the time. A dated folder of policy versions and clarification emails takes minutes to maintain and is exactly the artifact you want if the goalposts move.

Turn the policy into a working checklist

A policy you read once and shelve does not protect you. Turn your reading into a one-page sheet you actually consult, and keep it with your research notes where you will see it, not in a downloads folder. The test of a good compliance sheet is that you check it at the moment of decision, when you are about to paste something into a tool, not afterwards. It needs six entries:

  • Permitted uses, with clause references, for each kind of work you submit
  • Prohibited uses, stated bluntly enough that you cannot rationalise around them
  • The disclosure format your university expects, and where it goes in the thesis
  • Your logging habit: where you record AI use as it happens, not retrospectively
  • What you may not upload anywhere, ever
  • The written clarifications you have collected, with dates

The bottom line on reading your university's AI policy

Your university's AI policy is a stack, not a page. Collect every layer, answer the six questions, and put the answers where you will see them. Interpret grey zones in writing rather than in your head, verify everything an AI touches because responsibility clauses put every error on you, and keep a dated record of rules and permissions. Revisit the sheet each term and before submission: policies drift, assessments differ, and none of this takes long. All of it is easier than reconstructing your compliance after a question you did not expect.

Ready to try it on your own thesis?

Get Started Free

Do this in CiteDash

More guides