5.1: Navigating Evolving AI Policies
Overview
AI policies in research, at the level of institutions, funding agencies, and journals, are changing rapidly, inconsistently, and often without the coordination that researchers need to maintain compliance across multiple policy environments simultaneously. A researcher submitting a paper to a journal, whose work is funded by a federal agency, and who is employed at an institution may face three different and potentially conflicting AI policy requirements at the same time. As of 2026, there is no unified standard: different journals have contradictory requirements, funding agencies are still developing their guidance, and institutional policies range from detailed to non-existent. The researchers who navigate this environment successfully are not the ones who have found the stable answer. There is no stable answer yet. They are the ones who have built adaptive compliance systems: habits and workflows that track policy environments, detect changes, and update practices accordingly. This lesson is about building those systems.
Title
Lesson 5.1: Navigating Evolving AI Policies
Purpose
This lesson teaches researchers how to navigate rapidly evolving AI policies across different institutions, funding agencies, and journals, each with different requirements, often changing frequently. You'll learn to build compliance systems that adapt as policies change rather than defaulting to assumption-based approaches.
The Current AI Policy Landscape for Researchers
To navigate the policy landscape, you first need to understand its structure. AI policies affecting researchers currently operate at four distinct levels, each with different authority and different rates of change.
Institutional policies govern what researchers at a given university, research institute, or funding body may do with AI tools in the work they conduct as employees or affiliates of that institution. Institutional policies may address: permissible AI tool use in research and teaching, data governance requirements for AI tool use (particularly regarding what data may be submitted to external AI services), research integrity standards for AI-assisted work, and IP ownership provisions for AI-assisted outputs. As of 2026, institutional policies range from detailed and comprehensive to non-existent. Many institutions adopted rapid interim policies in 2023-2024 that are now being revised; others have not yet addressed AI systematically.
Journal and publisher policies govern what researchers must disclose and what practices are permitted for research submitted for publication. Journal policies have been perhaps the most visible point of AI policy development for researchers, because they directly affect how research is published and what constitutes acceptable methodology. Current journal policies include requirements to disclose AI tool use, prohibitions on listing AI as an author, varying standards for how much AI assistance is permissible in writing, and evolving requirements for AI-assisted methods sections. Different publishers have adopted different standards; policies continue to evolve; and norms are still far from uniform across disciplines.
Funding agency policies govern what practices are permissible in grant-funded research and what disclosure requirements apply to grant applications and reports. Major funding agencies, NIH, NSF, UKRI, EU Horizon, have all developed AI-related guidance, but at different stages of specificity. Some agencies require disclosure of AI tool use in applications and reports; some have data governance requirements affecting what can be submitted to AI services; some are developing AI-specific elements in research integrity frameworks. Researchers working on funded projects must track the agency-specific requirements for each grant.
Disciplinary and professional society norms represent a fourth layer that operates below the level of formal policy but can shape practice expectations significantly. Professional societies have published guidelines on AI use in research and publishing that may not have binding force but influence editorial decisions, peer review standards, and community expectations. COPE (Committee on Publication Ethics) guidance, professional medical association standards, and disciplinary society recommendations all contribute to this normative layer.
Building a Policy Tracking System
The core problem with navigating AI policy is that policies change and there is no central registry. A researcher who checked her institution's policy twelve months ago may be working under requirements that have been substantially revised. A researcher who verified a journal's AI disclosure requirements when submitting a previous paper cannot assume those requirements apply to the next submission. Building a tracking system is not about achieving permanent compliance. It is about building habits that detect change before it catches you.
For institutional policy, identify who at your institution is responsible for research integrity, research computing, and data governance. These offices typically issue AI policy updates. Subscribe to any mailing lists or newsletters from these offices. Set a calendar reminder to check the institution's research integrity website quarterly, even if you have not received an active notification. When you start a new research project, verify the current policy at project initiation, not based on what you remember from the last project.
For journal policies, the key discipline is checking at submission time, not at writing time. AI policies are frequently updated between when you write a paper and when you submit it, so verifying the policy six months before submission and then relying on that knowledge may leave you non-compliant. Create a submission checklist that includes checking the journal's current AI policy as a standard step before every submission.
For funding agency policies, track requirements at the grant level, not generically. An NIH R01 may have different requirements than an NIH R21; NSF policies differ by directorate; international grants operated under EU Horizon have their own framework. When you receive a new grant, read the data management plan requirements, the research integrity requirements, and any AI-specific clauses in the terms and conditions, and record what they require. When submitting progress reports or renewals, verify whether policy has been updated since the original award.
For collaborative research, policy complexity multiplies. Each collaborating institution may have different requirements; multi-site studies may have IRB or data governance requirements from multiple institutions; international collaborations may involve grant agency requirements from multiple countries. Assign explicit responsibility for policy tracking across the collaboration, do not assume a collaborator is tracking the policies that apply to their component.
Understanding and Implementing AI Disclosure Requirements
Disclosure is the most commonly required AI compliance practice, but what disclosure means varies significantly across policy environments. Understanding the variation, and implementing disclosure that satisfies the most stringent applicable requirement, is the practical compliance approach for researchers working across multiple policy environments simultaneously.
Most journal policies now require some form of AI use disclosure. The minimum standard across most policies is acknowledging that AI tools were used, identifying which tools, and describing the tasks they were used for. Many policies specifically require that AI use be disclosed in the methods section rather than merely acknowledged in a footnote. Some policies require that AI use in writing be distinguished from AI use in analysis. A small but growing number of policies require quantitative or qualitative characterization of how much AI assistance was involved.
Funding agency disclosure requirements have evolved beyond tool identification. Some agencies now require disclosure in grant applications of AI tools intended to be used in the proposed research, in progress reports of AI tools actually used, and in research outputs of AI-assisted methods. NIH's 2024-2025 guidance on AI in biomedical research introduced specific disclosure language for publications arising from NIH-funded studies. NSF has developed discipline-specific guidance that is being updated across directorates.
The challenge for researchers working across environments is avoiding both under-disclosure (missing a required element) and inconsistency (disclosing AI use differently in the paper versus the grant report versus the institutional record). Maintain a consistent disclosure record for each project: what AI tools were used, for what tasks, in what workflow stages. Use this record as the basis for disclosures in all venues, ensuring consistency rather than reconstructing disclosure from memory for each submission.
For methods sections in publications, the minimum adequate disclosure, satisfying most current journal policies, includes: identifying the specific AI tool and version, describing the task it was used for, noting the prompting approach or prompt structure, and characterizing how outputs were reviewed and verified. When policies are unclear about what level of detail is required, err toward more detail. The trend across all policy environments is toward more disclosure, not less, what is optional today may be required tomorrow.
Managing Conflicting Policy Requirements
The most practically difficult scenario in AI policy navigation is when different applicable policies conflict or make incompatible demands. A journal may permit extensive AI writing assistance while an institutional policy requires prior approval for such use; a funding agency may require specific data governance practices for AI tool use that conflict with a collaborating institution's policies; a professional society may recommend practices that differ from what the target journal requires.
When you identify a potential policy conflict, the first step is verifying that the conflict is real and not a misreading of one of the policies. Many apparent conflicts dissolve when policies are read carefully, what looks like a prohibition may be a disclosure requirement; what looks like a conflict between standards may be compatible at the level of actual practice. Read both policies specifically and assess whether there is a genuine incompatibility at the level of what you actually plan to do.
If the conflict is real, the general principle is to satisfy the most stringent requirement across all applicable policies, where that is possible. If one journal requires AI use disclosure and your institutional policy requires a specific disclosure format, use the format required by your institution, which will also satisfy the journal's disclosure requirement. This 'highest common standard' approach avoids compliance gaps in either direction when policies differ in stringency.
When policies are genuinely incompatible, when doing what one requires would violate what another prohibits, escalation is necessary. Contact the relevant research integrity office at your institution to seek guidance. For grant-related conflicts, contact the program officer. For journal conflicts, contact the editor before submission to clarify which interpretation applies. Seeking guidance before acting is always preferable to acting on your own interpretation and discovering after submission that you were non-compliant.
For recurring policy environments, journals you publish in regularly, agencies you apply to repeatedly, establish direct lines of communication with policy staff or editors who can provide timely guidance when policies are ambiguous or evolving. Policy uncertainty that affects a single researcher is likely affecting others in the community; engaging policy staff creates shared clarity.
Future-Proofing AI Research Practices
Given that AI policies are still in early stages of development and will continue to evolve, the most resilient practice is not optimizing for current requirements but building practices that are likely to remain compliant as requirements strengthen.
The consistent direction of policy development across all environments is toward more documentation, more disclosure, and more transparency. Policies that currently recommend disclosure are likely to require it; policies that currently require minimal disclosure are likely to require more detail; policies that do not yet address AI are likely to develop requirements. Practices that exceed current minimum requirements are investments in future compliance.
Concretely, this means: maintain a project-level AI use log that records all AI tool use throughout a research project, not just what you disclose at publication, but what you actually did. Include tool names, versions, dates of access, tasks performed, data submitted, and outputs received. This log becomes the basis for any disclosure format that might be required in the future, rather than requiring reconstruction from memory.
It also means using AI tool practices that are auditable. API-based access with logged API calls provides better documentation than consumer interface use; version-pinned model calls provide better reproducibility documentation than floating model versions; prompt libraries stored in version control provide better documentation than prompts reconstructed from memory. These practices satisfy not just current disclosure requirements but the more detailed documentation requirements likely to come.
For research programs with commercial implications, maintain cleaner separation between AI tool use that is fully documented and auditable, and any exploratory AI use that is informal. Mixing these can create retroactive compliance problems if the research later proves commercially significant and requires IP or regulatory documentation of how it was conducted.
Finally, engage with policy development. Researchers who participate in professional society working groups, respond to funding agency requests for comment on AI policy, or provide feedback to journal editors contribute to the development of policies that are grounded in actual research practice. The policies being developed now will shape research norms for years; researcher engagement in their development makes those policies more workable.
Building Institutional and Lab-Level AI Policy Knowledge
Individual policy tracking is necessary but insufficient for labs and research groups. When AI policy knowledge is concentrated in a single PI or administrator, it creates fragility, the knowledge is lost when people leave, and junior researchers make policy assumptions they cannot verify. Building institutional and lab-level knowledge systems distributes the responsibility and reduces compliance risk.
At the lab or research group level, create a shared AI policy reference document that records: the current AI-related policies of your institution, the AI policies of funding agencies currently supporting the lab's research, AI policies of journals the lab regularly submits to, and the last date each policy was verified. Assign a specific person, typically a lab manager, a designated graduate student, or the PI themselves, to update this document on a regular schedule and before each major submission or grant application.
Onboarding is the most important moment for communicating AI policy to new lab members. Graduate students, postdocs, and research staff who join the lab and begin using AI tools without understanding applicable policies create compliance risks. Build a brief AI policy orientation into the lab's standard onboarding process: this is what our institution allows, this is what our current funders require, this is where you look up journal-specific requirements before submitting.
For labs that operate across multiple institutions or collaborate internationally, the policy reference needs to track the intersection of multiple institutional requirements. Identify the most restrictive applicable requirement on each dimension, data governance, disclosure, tool permissions, and train all lab members to that standard, so that compliance across the collaboration does not require member-specific tracking of which requirements apply to them.
Connect your lab's AI policy practices to your research integrity training program. Many institutions require periodic research integrity training for all lab members. AI policy compliance is a natural component of this training, and integrating it ensures coverage without requiring standalone AI-policy-only sessions. Professional development events, lab meetings, journal clubs, group retreats, can include short updates on AI policy changes as a standing agenda item.
The goal of these lab-level systems is not bureaucratic compliance for its own sake. It is ensuring that AI tool use in the lab is deliberate, documented, and defensible, that any member of the lab can explain what AI was used for, under what terms, and in compliance with which policies. That kind of institutional knowledge is what allows a research group to use AI tools confidently and productively, without the compliance uncertainty that makes some researchers avoid AI tools entirely.
Skill.re