# Academic integrity and artificial intelligence: how to update institutional rules

> Update academic integrity rules for artificial intelligence with clear criteria for use, disclosure, assessment, privacy and responsibilities.

- Site: Genialoh (https://genialoh.org)
- Language: en
- Category: Governance
- Reading time: 15 min
- HTML version: https://genialoh.org/#/en/blog/academic-integrity-and-artificial-intelligence

---
Generative artificial intelligence is forcing universities to review their academic integrity rules.

Traditional policies tend to focus on plagiarism, cheating during assessments, impersonation and unauthorized use of materials. Those behaviors remain relevant, but AI introduces situations that are harder to classify.

A student can use a tool to generate ideas, improve the clarity of a text, translate a paragraph, review code, solve a problem, create references, summarize a source or write an entire submission.

Some of these practices can support learning. Others can hide a lack of understanding, break the instructions of an activity or present as one's own work that the student did not do.

That is why the institutional question can no longer be limited to: did the student use artificial intelligence? The university must answer more precise questions.

> **New institutional questions**
> 
> - Was the use allowed?
> - At what stage of the activity was it used?
> - What part of the result belongs to the student?
> - Was the support received disclosed?
> - Was the information verified?
> - Does the activity preserve evidence of learning?
> - Were protected data or materials shared?
> - Was there intent to deceive?
> - Were the instructor's instructions clear enough?
> - Is the consequence proportional to the behavior?

Updating the rules does not mean accepting any use of AI. It means defining understandable conditions so that students, faculty and authorities can act consistently.

UNESCO recommends that the incorporation of AI in education be based on a human-centered vision, with data protection, ethical validation, pedagogical design and capacity building. The OECD also identifies academic integrity, data protection, equity and reliability of generated content as central areas of adoption policy in higher education.

## What is academic integrity in the age of AI?

Academic integrity is the commitment to produce, evaluate and communicate academic work honestly, responsibly and transparently. It is not limited to avoiding plagiarism.

- Present authentic evidence of learning.
- Acknowledge external contributions.
- Respect the rules of each activity.
- Use sources responsibly.
- Verify information.
- Protect data and materials.
- Do not impersonate the work of others.
- Take responsibility for the content submitted.
- Respect assessment processes.
- Act fairly toward other students.

AI does not eliminate these principles. It changes the ways they can be met or breached. A generated text is not necessarily a violation: it depends on the activity's purpose, the instructions, the degree of the tool's intervention, the disclosure made and the evidence the student can present about their process.

## Why traditional rules are no longer enough

A policy that simply bans using artificial intelligence can be hard to enforce. AI is already embedded in search engines, word processors, design platforms, spell checkers, translators, coding tools and productivity systems. Students may not know which features are covered by the ban.

There are important differences between correcting spelling, asking for an explanation, generating an outline, rewriting a paragraph, solving an exercise, creating a bibliography, writing a full essay, making up data, using confidential information or presenting an answer without understanding it. A useful policy must distinguish between behaviors, not just list brands or applications.

## First change: define categories of use

The university can establish a common classification that each instructor adapts to their activities.

| Level | Description | Examples |
| --- | --- | --- |
| 1. Not allowed | The activity must be completed without generative AI support. | In-person exam, oral exam, supervised writing. |
| 2. Limited | AI can only be used in specific stages. | Generate study questions, review clarity, compare structures. |
| 3. Allowed with disclosure | The student may use AI but must document its participation. | Essays, projects, analyses with a disclosure statement. |
| 4. Required | The tool is part of the learning objective. | Compare answers, identify bias, design prompts, defend iterations. |

Every activity must indicate its level. The university can require all instructions to include a visible section that explains what is allowed, what is not and what evidence must be preserved. This practice prevents students from having to guess each instructor's expectations.

## Second change: define what authorship means

AI complicates the idea of authorship because it can generate content that the student selects, modifies and presents. The policy must clarify that submitting work implies taking responsibility for accuracy, source selection, arguments, data, references, compliance with instructions, disclosure of support and the originality of decisions.

A statement like "the AI did it" does not remove the student's responsibility. Whoever submits the work must be able to explain it, defend it, reproduce the key steps, justify their decisions, identify sources, acknowledge limitations and correct errors.

> **A warning sign, not conclusive proof**
> 
> A student's inability to explain the submitted content is a signal to review, but it should not automatically become conclusive proof of a violation.

## Third change: separate AI use, plagiarism and academic fraud

Not all unauthorized uses are identical. The policy can distinguish between categories with different responses.

| Category | What happened |
| --- | --- |
| Unauthorized use | The student used a tool in an activity that did not allow it. |
| Missing disclosure | Use was allowed, but was not reported as required. |
| Deceptive presentation | The student claimed to have done work substantially generated by a tool. |
| Fabrication of information | Nonexistent data, sources, interviews or citations were included without verification. |
| Learning impersonation | The tool did the central part that was supposed to demonstrate competence. |
| Improper use of information | Personal data, assessments or confidential materials were introduced into a tool. |
| Manipulation or evasion | The origin of the work was hidden or established controls were bypassed. |

## Fourth change: design assessments that preserve evidence of learning

Academic integrity cannot rely solely on detecting generated texts. TEQSA recommends that institutions review the integrity of their assessment systems and reform activity design in light of the opportunities and risks of generative AI.

- Partial submissions and drafts.
- Journals and in-class discussion.
- Oral defense and follow-up questions.
- Application to a local case.
- Data collected by the student.
- Reflection on decisions.
- Comparison of sources and error review.
- Supervised activities and combined individual/collaborative work.

### Redesign example

| Traditional activity | Redesigned activity |
| --- | --- |
| Write a 2,000-word essay on the effects of AI on employment. | Select a local sector and formulate a research question. |
|  | Use AI to generate two possible explanations and identify claims needing evidence. |
|  | Contrast with five sources and interview someone in the sector or analyze data. |
|  | Write your argument, attach a use disclosure and defend conclusions. |
|  | Explain which AI suggestions you rejected and why. |

AI can participate, but the student must research, verify, decide and argue.

## Fifth change: establish a use disclosure

A common disclosure enables transparency and prevents each instructor from inventing a different format.

> **Short disclosure template**
> 
> I used [tool] for [purpose] during [stage]. The main prompts were [description]. I reviewed or modified the result as follows: [explanation]. I verified the information through [sources]. I take responsibility for the content submitted.

| Field | Content |
| --- | --- |
| Tool | Name and version when possible. |
| Purpose | Explain what it was used for. |
| Stage | Planning, research, drafting, analysis, editing or other. |
| Intervention | What the tool generated or modified. |
| Verification | How claims, data or references were checked. |
| Student decisions | Which suggestions were accepted, modified or rejected. |
| Limitations | Errors or issues identified. |
| Responsibility | Confirmation of review and understanding of the final content. |

The disclosure should be proportional. A long record is not required for a minor correction if the activity's objective does not demand it.

## Sixth change: regulate generated sources and references

AI tools can produce nonexistent references, incorrect data or citations that do not match the original content. The policy should set clear rules.

- AI does not replace consulting the source.
- Every reference must be located and verified.
- Documents the student has not reviewed should not be cited.
- Data must be checked with reliable sources.
- Direct quotes must be contrasted with the original.
- Automatically generated bibliographies must be reviewed.
- Confidential or nonexistent sources cannot be presented as evidence.

Students must understand that a well-formatted reference list can still be false.

## Seventh change: protect data, assessments and materials

Academic integrity also means protecting information. UNESCO emphasizes the need to protect privacy and establish governance mechanisms before incorporating generative tools into education.

> **Do not enter into unauthorized tools**
> 
> - Full names, IDs and student records.
> - Individual grades.
> - Medical, financial or identifiable personal information.
> - Unpublished exams and confidential question banks.
> - Undisclosed research and partner-company data.
> - Contracts, proprietary materials and strategic institutional information.

The university must provide a list of authorized tools and a process to evaluate new solutions.

## Eighth change: train faculty and students

A policy published on the institutional site does not automatically change practice.

| Faculty need to | Students need to |
| --- | --- |
| Communicate rules and design assessments. | Understand levels of use. |
| Recognize acceptable uses. | Disclose support received. |
| Analyze possible violations without accusing on suspicion. | Verify results and recognize errors. |
| Protect information and use institutional tools. | Protect personal data. |
| Document evidence and apply proportional consequences. | Preserve evidence of their process. |
| Guide students. | Cite correctly and take responsibility. |

UNESCO's teacher competency framework organizes preparation across five dimensions: human-centered approach, ethics, foundations and applications, pedagogy and professional development.

## Ninth change: do not rely solely on AI detectors

A detector can produce a score, but that score does not explain who produced the work, which tool was used, or whether a violation occurred. A university should not sanction a student based solely on an automated tool.

> **The review should consider**
> 
> - Activity instructions and disclosure of use.
> - Drafts and version history when available.
> - Sources used and ability to explain the work.
> - Comparison with previous submissions.
> - Conversation with the student and process evidence.
> - Possible alternative circumstances.

## Tenth change: apply proportional consequences

Not every violation requires the same response. The policy can consider severity, intent, impact, academic level, clarity of instructions, recurrence, amount of work affected, presence of deceit, use of protected data and cooperation during review.

| Response type | When it applies | Examples |
| --- | --- | --- |
| Educational | Initial or lower-severity cases. | Guidance, redo, corrected disclosure, workshop, written reflection, grade adjustment. |
| Disciplinary | Deliberate fraud, impersonation, recurrence or serious fabrication. | Sanctions aligned with the institutional code, reviewed by academic and legal areas. |

## Eleventh change: build a fair process for possible violations

- How suspicion is reported and what evidence must be presented.
- Who performs the first review.
- How the student is informed and what opportunity they have to respond.
- How the decision is documented and what consequences may apply.
- How to appeal and how confidentiality is protected.
- How the case is used to improve instructions or training.

The procedure should avoid both impunity and automatic accusations.

## Twelfth change: separate institutional rules from course rules

The university must provide common principles (honesty, transparency, responsibility, data protection, verification, disclosure, review procedure and general consequences). Each instructor must define the specific conditions of their activities.

> **Template for activity instructions**
> 
> - Use of AI: not allowed / limited / allowed with disclosure / required.
> - Authorized and unauthorized uses.
> - Required disclosure (format and length).
> - Process evidence: drafts, journal, sources, history or oral defense.
> - Verification: how to check data, citations or results.
> - Information protection: what content cannot be shared.
> - Assessment criteria and applicable consequences.

## Thirteenth change: include rules for faculty

Academic integrity is not solely the student's obligation. Faculty must communicate clear instructions, apply rules consistently, verify generated materials, avoid entering identifiable work into unauthorized tools, review AI-created questions and rubrics, retain responsibility over grades, disclose when AI participates significantly, avoid accusations based solely on detectors and participate in training.

## Fourteenth change: integrate AI into existing regulations

It is not always necessary to create a completely separate regulation. The university can update the integrity code, student regulations, assessment policy, faculty manual, privacy policy, research guidelines, security policy, course formats, disciplinary procedures and platform terms. A general AI policy can connect these documents and provide common criteria.

## Fifteenth change: review the policy regularly

Tools change quickly. A policy based on brands, specific features or detection techniques can become outdated.

- Policy owner.
- Approval and review dates.
- Channel to propose changes.
- Version history.
- Urgent update procedure.
- Faculty and student participation.
- Change communication.

A semiannual or annual review can be complemented by updates when new risks or use patterns appear.

## Summary institutional policy example

> **Summary policy**
> 
> The university promotes responsible, transparent and pedagogically justified use of artificial intelligence. Each activity will indicate whether its use is prohibited, limited, allowed with disclosure or required. Students retain responsibility for any work submitted. It is prohibited to enter sensitive personal data, records, grades, confidential assessments or unauthorized institutional materials into external tools. Possible violations will be reviewed considering instructions, evidence, disclosure, opportunity to respond and proportionality. No disciplinary decision will be based solely on an automated detector.

## A 30-day update plan

| Days | Phase | Actions |
| --- | --- | --- |
| 1-5 | Diagnosis | Gather current policies, identify conflicts, consult community, review tools, document cases. |
| 6-10 | Design | Define categories, create disclosure, set responsibilities, address data, design procedure and proportionality. |
| 11-15 | Consultation | Academic leadership, technology, legal, faculty; test instructions in different disciplines. |
| 16-20 | Adaptation | Incorporate changes, create examples, prepare templates, define FAQs, align disciplinary rules. |
| 21-25 | Training | Train faculty, prepare student materials, practice case analysis, present authorized tools. |
| 26-30 | Publication | Publish current version, communicate application, open a question channel, log incidents, measure understanding. |

## Indicators to evaluate the new rules

- Courses that state the AI use level and trained faculty.
- Students who know the rules and disclosures submitted.
- Questions received, cases reviewed and resolution time.
- Types of violations, recurrence and appeals.
- Redesigned activities and authorized tools.
- Privacy incidents and training needs.

The goal should not be to increase the number of sanctions. It should be to improve clarity, prevent problematic behavior and preserve valid evidence of learning.

## Common mistakes when updating the policy

| Mistake | Risk |
| --- | --- |
| Banning all AI without distinguishing uses. | Hard to enforce; includes tools students do not recognize as AI. |
| Allowing everything without conditions. | Weakens assessment and increases privacy risks. |
| Relying on detectors. | A score does not by itself prove a violation. |
| Not training faculty. | Inconsistent interpretation. |
| Not listening to students. | Practical confusions go unaddressed. |
| Overly technical language. | The rule is not understandable across the community. |
| Not updating assessments. | Activities without sufficient learning evidence. |
| Same consequence for all cases. | Ignores severity, intent, impact and recurrence. |
| Publishing without examples. | Users do not understand how it applies. |
| Not naming who resolves questions. | Improvised decisions. |

## Frequently asked questions

### Is using artificial intelligence always plagiarism?

No. It depends on the instructions, the purpose, how it was used and whether it was disclosed. There can be authorized use, unauthorized use, missing disclosure, fabrication of information or other different behaviors.

### Should students cite ChatGPT or other tools?

The university must define a form of disclosure or attribution. In addition, academic claims must be supported by verifiable sources, not just a generated response.

### Can a student be sanctioned based on a detector score?

A decision should not be based solely on an automated detector. Instructions, process, sources, drafts, the student's explanation and other evidence must be reviewed.

### Can AI be allowed in some activities and prohibited in others?

Yes. Permission should relate to the learning objective and the evidence the instructor needs to observe.

### Who should update the rules?

Academic leadership, integrity committees, legal, technology, data protection, faculty and student representatives should participate according to institutional structure.

### Is it necessary to modify every course?

All should state clear rules, but redesign can prioritize high-impact assessments or activities that can be easily delegated.

### What data should not be entered?

Names, IDs, records, individual grades, medical or financial information, confidential assessments and unauthorized institutional materials.

### Does the university need an institutional platform?

A dedicated platform can help provide identity, academic context, program tutors, common guidelines, training, implementation, support and analytics. It does not eliminate the need for policy and pedagogical design.

### How is the new policy communicated?

Through regulations, faculty manual, course syllabi, induction sessions, training, FAQs and visible messages within the platforms used.

### How often should it be reviewed?

A periodic review and an extraordinary procedure should be established to respond to relevant changes in tools, regulations or academic practice.

## From prohibition to institutional responsibility

AI does not eliminate academic integrity. It forces us to define it with greater precision. A university needs rules that distinguish between support, collaboration, delegation, deceit and improper use of information. It also needs assessments that preserve evidence of learning, trained faculty, authorized tools and fair procedures.

> **Genialoh for your institution**
> 
> - Institutional name, logo and colors.
> - Values, methodology and context based on plans and programs.
> - Tutors configured around degrees or programs.
> - Academic guidelines present in the experience.
> - AI support for faculty and institutional analytics.
> - Training, implementation, support and adoption tracking.

Book a first 30-minute meeting. If the institution decides to move forward, it will select two degrees or programs and provide the required authorized documentation. Genialoh will prepare a functional demo with the institution's identity and academic context in less than 14 days from receiving the complete documentation. After the presentation, up to five authorized people can explore it for 30 calendar days.
