Skip to main content
AI Education

Write an Institutional AI Policy People Follow

Produce a policy short enough to be read, specific enough to act on, and structured so a teacher can answer a student's question without escalating.

Advanced16 minBy ToolDix Editorial

Learning objectives

  • Scope a policy so it answers the questions people actually have
  • Assign the decisions that belong at course level rather than centrally
  • Write enforcement that is proportionate and appealable
  • Set a review cadence that keeps the policy current

ToolDix original visual

AI Education practice loop
1

Frame

Name the outcome and constraints.

2

Build

Try one bounded workflow.

3

Review

Keep evidence, revise, and share.

Institutional AI policies fail in two recognisable ways. The blanket ban is ignored within a month, teaches concealment, and leaves staff with no guidance for the cases that matter. The forty-page document with a governance framework is never read past the summary, and the teacher facing a student's question at eleven at night is exactly as unsupported as before.

A policy that works is short, answers real questions, and pushes the task-level decisions to the people who understand the task.

Scope it around the questions people ask

ToolDix original diagram
Six questions beat forty pages
Can students use AI for this assignment?
Per assignment, by the instructor, within a framework the policy supplies.
What must be disclosed?
Centrally, because students should not track five conventions.
What may staff use it for?
Grading, feedback, references, admissions -- each needs an explicit position.
Which tools are approved?
Centrally. It depends on contracts and data review individuals cannot perform.
What happens after a breach?
A graduated, appealable process.
Who decides unclear cases?
A named role. Unanswered questions default to whoever is least equipped.
Write against the questions that arrive, not around a topic taxonomy. Two pages that get read beat forty that do not.

Write the policy against the questions that actually arrive, not around a topic taxonomy.

"Can students use AI for this assignment?" — answered per assignment by the instructor, within a framework the policy provides.

"What must be disclosed?" — answered centrally, because consistency matters and students should not track five conventions.

"What can staff use it for?" — grading, feedback, reference writing, and admissions each need an explicit position, and staff use is where the highest-stakes decisions live.

"Which tools are approved?" — answered centrally, because it depends on contracts and data review that individuals cannot do.

"What happens when someone breaches the policy?" — a process, with proportion and an appeal.

"Who decides the unclear cases?" — a named role, because unanswered questions default to whoever is least equipped to answer them.

Two pages covering these beats forty pages covering everything.

Put each decision where the knowledge is

ToolDix original diagram
Each decision at the level that can make it
Central
  • Tool approval and data agreements
  • The disclosure standard
  • Staff use in consequential decisions
  • Breach process and detector position
Department
  • What is appropriate for this discipline
  • Programming, writing, and clinical differ genuinely
  • Discipline-specific examples
Instructor
  • The per-assignment rule
  • Which skill is being assessed
  • Pick a level from a short menu
  • One line in the brief
Give instructors three or four named levels rather than a principle. Adoption of a menu is far higher than adoption of a philosophy.

Centrally: tool approval and data agreements, the disclosure standard, staff use of AI in consequential decisions, the breach process, and the position on detection tools. These require contracts, legal input, and consistency.

At department level: what AI use is appropriate for this discipline. The answer differs genuinely between a programming course, a creative writing course, and a clinical placement, and pretending otherwise produces a policy that is wrong for most of them.

At instructor level: the per-assignment rule, because only the instructor knows which skill is being assessed. This is the decision that must be delegated — a central rule cannot know whether drafting is the target skill or a shortcut around it.

With the student: disclosing what they used, within the standard.

Give instructors a short menu rather than a blank page. Three or four named levels — no AI use; AI permitted for specified support tasks with disclosure; AI permitted throughout with disclosure and a defence of the work; AI use required and evaluated — let an instructor pick a level per assignment and paste one line into the brief. Adoption of a menu is far higher than adoption of a principle.

Make enforcement proportionate and appealable

Two commitments belong in the policy in writing.

Detector output is not evidence. State it explicitly. These tools are unreliable, their false positives fall disproportionately on non-native writers, and a student cannot disprove a probability. A policy that permits acting on a score will produce an injustice, and it will be one the institution cannot defend.

The process is graduated. A first ambiguous case is a conversation, not a disciplinary matter. Escalation should require evidence of the kind the policy names — inconsistency with prior work, inability to discuss the submission, admission — and every stage should be appealable.

Also state what happens to a student who discloses use that turned out to be outside the rule. If disclosure is punished as severely as concealment, the policy has just taught concealment.

Set a review cadence and name an owner

ToolDix original diagram
A policy without an owner silently becomes wrong
1
Name an owner
One role, accountable for the document being current.
2
Set the cadence
Annual review at minimum, a lighter check each term.
3
Define early triggers
New regulation, a capability shift, a vendor incident, a pattern of unanticipated cases.
4
Track a few signals
Menu levels in use, breach cases and outcomes, and which questions keep escalating.
Repeated escalation of the same question is a gap in the policy, not a failure of the people asking. Publish the version and date on the document.

A policy written this year will be wrong next year: capabilities move, regulation moves, and the practices students arrive with move.

Name an owner, set a review interval short enough to matter — annually at minimum, with a lighter check each term — and define the triggers that force an early review: a new regulatory obligation, a significant capability shift, a vendor incident, or a pattern of cases the policy did not anticipate.

Track a small number of signals rather than assuming compliance: how many instructors are using each level of the menu, how many breach cases arose and how they resolved, and what questions keep escalating. Repeated escalations of the same question are a gap in the policy, not a failure of the people asking.

Publish the version and the date on the document itself. An undated policy is one nobody can tell whether to trust.

Practice

Write the two-page version first, before any consultation. Constrain yourself to the six questions above.

Then test it: give it to three people — an instructor, a student, and someone in a support role — and ask each to answer a realistic scenario using only the document. Where they cannot, or where they disagree, the policy is incomplete at exactly that point.

Fix those points and only then circulate more widely. A policy tested against real scenarios by three people is better than one reviewed by thirty.

Common mistakes

The blanket ban. Ignored, teaches concealment, and useless as guidance.

Centralising the per-assignment decision. Only the instructor knows which skill is being assessed.

Permitting action on detector scores. It produces indefensible outcomes and damages trust everywhere else.

No owner and no review date. The policy silently becomes wrong, and nobody is responsible for noticing.

Sources and license context

These references informed the lesson. ToolDix adds its own explanation, workflow, and practice rather than reproducing source material. Every link below leaves ToolDix and opens the publisher's own site in a new tab.

Keep going

Read these next on ToolDix.

Original lessons that build on what you just read.