โ†
AI for Researchers
Visionary ยท M5 ยท lesson 5 of 16 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
๐Ÿ“–
in this lesson

2.1: Designing Institutional AI Research Policies

15 min

Overview

Lesson 2.1: Designing Institutional AI Research Policies

This lesson guides research leaders in developing institutional AI research policies covering publication, data governance, ethics, training, and compliance. You'll learn policy development processes that engage researchers authentically, design policies that are clear and feasible, establish governance mechanisms for oversight and adaptation, and communicate policies effectively to earn researcher buy-in.

Title

Lesson 2.1: Designing Institutional AI Research Policies

Purpose

This lesson guides research leaders in developing institutional AI research policies covering publication, data governance, ethics, training, and compliance. You'll learn policy development processes that engage researchers authentically, design policies that are clear and feasible, establish governance mechanisms for oversight and adaptation, and communicate policies effectively to earn researcher buy-in.


The Policy Gap Problem

Most research institutions in 2026 have three categories of existing policy that might appear to cover AI research: general IT policies (acceptable use, data security, cloud service approval), general research integrity policies (authorship, data management, research misconduct), and general data governance policies (data classification, privacy, sharing). The uncomfortable truth is that none of these policy categories adequately addresses the novel situations created by AI research. The intersection of AI capabilities and research norms produces scenarios that existing policy frameworks were simply not designed for.

Consider a few concrete examples. A postdoctoral researcher uploads a draft manuscript to an AI writing assistant to improve clarity. Your authorship policy probably doesn't address whether AI assistance in writing requires disclosure. Your IT acceptable use policy probably says nothing about uploading unpublished research to third-party services. Your data policy might restrict sharing confidential research data but doesn't define whether an AI API call constitutes 'sharing.' Each of these questions is genuinely ambiguous under most institutions' current policy frameworks, and yet researchers are making decisions about them every day, often without any formal guidance.

The policy gap is not just about missing rules. It is about the absence of a coherent framework for thinking about AI in the research context. When policies are absent, researchers default to individual judgment, which varies enormously. Some researchers are maximally cautious and avoid AI tools entirely even when they would be appropriate and beneficial. Others use AI tools in ways that create legal, ethical, or reputational risks without realizing it. Neither outcome serves the institution's research mission.

Developing AI-specific policies is urgent, but the approach matters as much as the content. Policies imposed top-down without faculty input will be ignored or actively resisted, academic culture prioritizes researcher autonomy, and faculty view research practice decisions as fundamentally their own. Policies that are technically correct but practically unworkable will produce compliance theater rather than real behavior change. The goal is policy that researchers understand, find reasonable, can actually follow, and that protects both them and the institution.

The Five-Domain Policy Architecture

Rather than attempting to write a single comprehensive 'AI policy,' research leaders should think in terms of five distinct policy domains that each need AI-specific provisions. These domains have different stakeholders, different technical requirements, and different enforcement mechanisms, a unified policy tends to be either so general it provides no real guidance or so long it goes unread.

Domain 1: AI Use in Research Workflows. This policy addresses what AI tools faculty, staff, and students can use for what purposes in the conduct of research. It covers: which tools have been vetted and approved for research use; what categories of research activities AI can and cannot support; data input restrictions (what data cannot be entered into AI tools); documentation and disclosure requirements when AI is used; and the scope of coverage (does this apply to all researchers at the institution, or only those conducting externally funded research?).

Domain 2: AI Attribution and Authorship. This policy addresses intellectual contribution and attribution when AI is involved in creating research outputs. It covers: disclosure requirements in manuscripts, presentations, and grant applications; the distinction between AI-assisted work (where the researcher directs and is responsible) and AI-generated content (which raises academic integrity questions); institutional position on AI authorship (most institutions now align with ICMJE guidance that AI cannot be listed as an author); and documentation requirements for reviewers and editors who ask about AI involvement.

Domain 3: Research Data and AI. This policy governs what data can and cannot be processed by AI tools. It integrates with existing data classification policies but adds AI-specific dimensions: which AI processing environments are approved for which data classes; requirements for on-premise processing of sensitive research data; data retention and deletion obligations when data is processed by AI systems; and the definition of 'processing by AI' that triggers policy application (is using a Word spell-checker covered? Is using a grammar AI? Is using an AI coding assistant that sees code but not data?).

Domain 4: AI Development Lifecycle. This policy governs the development, validation, and release of AI systems created as research outputs. It covers: documentation requirements for AI systems at each lifecycle stage; testing and validation requirements before deployment in studies involving human subjects; model card requirements for released AI systems; version control and reproducibility requirements; and open-source vs. proprietary release decisions.

Domain 5: AI Procurement. This policy governs the acquisition of AI tools for research use. It covers: the approval process for research AI tools (who reviews, what criteria); due diligence requirements for commercial AI vendors (data use agreements, privacy practices, security certifications); student and researcher data protections in procurement contracts; and the process for requesting institutional procurement of new AI tools.

Drafting the AI Use in Research Policy

The AI Use in Research Workflows policy is typically the highest-priority document to develop, because it has the broadest applicability and addresses the most frequent compliance questions. A well-designed AI use policy has five core components.

Scope definition answers: who is covered (all researchers affiliated with the institution, specific categories of researchers, only those on funded projects?), what activities are covered (only research activities, or also teaching and administrative work?), and what AI tools are covered (all AI tools, only generative AI, only AI APIs that process institutional data?). Scope decisions have significant implications for both coverage and enforceability, a policy that purports to cover all AI tool use by all affiliates for all purposes is likely unenforceable and will generate more confusion than clarity.

Permitted use cases should be specified affirmatively where possible. Rather than defining AI use purely through prohibitions, effective policies articulate the use cases that are clearly appropriate: literature review assistance, data coding and categorization, writing assistance for clarity and grammar, translation, code generation, data visualization. This positive framing helps researchers understand the policy intent and reduces the compliance burden of constantly asking 'is this allowed?'

Data input restrictions are the most technically complex component. Research data exists on a spectrum from fully public to highly restricted, and AI tools exist on a spectrum from fully on-premise institutional tools to commercial cloud APIs with opaque data retention practices. The policy needs to define: what data classification levels may be processed by what categories of AI tools; the specific restrictions on entering HIPAA-covered data, FERPA-covered data, export-controlled data, proprietary sponsor data, and unpublished research data into commercial AI services; and approved alternatives for processing restricted data (on-premise AI tools, privacy-preserving APIs with appropriate agreements).

Documentation requirements specify what researchers must record when they use AI tools in research. At minimum: which AI tool was used, for what purpose, with what inputs (categories of data, not necessarily the data itself), and what outputs were used in the research. This documentation supports research integrity, enables reproducibility, and provides evidence of policy compliance. Some institutions are implementing AI use logs as a component of research data management, the record of AI tool use becomes part of the research record.

Disclosure requirements specify when and how AI use must be disclosed externally: in manuscripts, in grant applications, in presentations, to research participants. These requirements should track (and ideally exceed) the requirements of major funders and journals, so that institutional compliance automatically satisfies external requirements.

AI Authorship and Attribution Policy

The authorship and attribution landscape for AI in research has evolved rapidly since 2023 and the policy landscape in 2026 is complex. Research leaders need to understand both what major journals and funders require and what their institutional policy should say.

Major journal policies in 2026 have largely converged on a few principles, though with significant variation in specifics. Nature Portfolio journals require that authors disclose any AI tools used in the preparation of manuscripts, specify the tools used, and state how they were used. AI cannot be listed as an author, and authors must be able to take responsibility for all content including AI-assisted portions. Science takes a similar position. Cell Press requires detailed disclosure in methods sections. IEEE and ACM have both issued guidance that AI cannot be listed as a co-author and that AI use must be disclosed in methods or acknowledgments. The Journal of the American Medical Association (JAMA) and other clinical journals follow ICMJE guidance, which similarly prohibits AI authorship and requires disclosure.

The institutional policy challenge is that researchers submit to dozens of different journals with slightly different requirements, and keeping track of journal-specific requirements is not realistic. The institutional policy should therefore establish a floor that satisfies all major journal requirements, any disclosure that meets the institutional standard should automatically satisfy journal requirements, even if some journals have looser standards.

A critical distinction that institutional policy must address clearly is the difference between AI-assisted and AI-generated content. AI-assisted research is where a human researcher uses AI as a tool to improve or enhance their own work: using AI for grammar checking, for brainstorming ideas that the researcher then evaluates and selects from, for generating code that the researcher reviews and validates. AI-generated content is where AI produces substantive research contributions, analysis, synthesis, conclusions, with limited human intellectual contribution. Most institutional policies and journal policies accept AI-assisted work with disclosure but treat AI-generated content in research (particularly in peer review, grant applications, and core research findings) as academically problematic.

The policy should also address the specific case of peer review. Using AI to assist in preparing peer reviews raises confidentiality concerns (the manuscript is confidential), accuracy concerns (AI may not have current knowledge in specialized fields), and quality concerns (AI reviews may be superficial). Many major publishers now explicitly prohibit or restrict AI use in peer review, and institutional policy should address researcher obligations in this context.

For grant applications, funding agencies are establishing their own requirements. NIH, as of 2024, expects that AI tools used in preparing grant applications be disclosed in the application, and peer reviewers are prohibited from using AI to prepare reviews. NSF and other federal agencies have similar emerging requirements. The institutional policy should address grant application AI use explicitly so that researchers have clear guidance before submission.

Research Data and AI Policy

Research data falls into multiple regulatory categories that each create distinct restrictions on AI processing. The Research Data and AI policy must map these restrictions onto practical guidance for researchers.

Protected Health Information (PHI) under HIPAA may not be entered into commercial AI APIs without a Business Associate Agreement (BAA) that meets HIPAA requirements. Many major AI providers (Microsoft Azure OpenAI, Google Cloud Healthcare, AWS for Health) offer BAA-eligible configurations, but the default consumer or standard commercial versions of these services do not qualify. Research institutions must identify which AI processing environments are HIPAA-compliant and communicate this clearly. It is not intuitive to researchers that the same AI service might be BAA-eligible in an enterprise configuration but not in a standard API subscription.

FERPA-covered student data similarly cannot be processed by commercial AI services without appropriate contractual protections. Educational AI tools must function as 'school officials' with legitimate educational interest in the data: a legal standard that requires specific contractual terms about the vendor's data use, retention, and security practices. Educational AI research that uses student records must work through the institution's FERPA compliance framework.

Export-controlled research data (under ITAR or EAR) has some of the most stringent restrictions on AI processing. Data subject to export controls cannot be processed by systems accessible to non-US persons without an export license. Many commercial cloud AI services involve data routing through international data centers and are managed by internationally diverse engineering teams, both of which create potential export control compliance issues. Institutions with significant export-controlled research programs should maintain on-premise AI processing capability specifically for this use case.

Confidential sponsor data, data provided by industrial sponsors, government agencies, or other partners under confidentiality agreements, may have specific restrictions on processing methods defined in the research agreement. Research administration staff reviewing sponsored research agreements should be trained to identify and flag AI processing restrictions, which may not use the word 'AI' but may restrict 'processing by third-party services' or 'data sharing with vendors.'

Unpublished research data, even if not subject to any of the above regulatory restrictions, warrants special consideration when processed by commercial AI tools that may retain inputs for training or improve their models using submitted data. Researchers are often not aware that some AI API configurations retain submitted data for model improvement purposes. The policy should require researchers to review vendor data use terms before submitting unpublished research data, and the institution should negotiate enterprise agreements with major AI providers that include opt-out from training data use.

Approved processing environments should be specified in a registry maintained by the compliance or IT office: fully public data can use any approved AI tool; institutional-sensitive data can use approved enterprise tools with appropriate agreements; regulated data (HIPAA, FERPA, export-controlled) must use specifically approved compliant environments; and classified research must use air-gapped, approved secure processing systems.

The Policy Development Process

The process by which institutional AI research policies are developed matters enormously for their ultimate effectiveness. Policies that emerge from a top-down administrative process, drafted by legal counsel, approved by the provost, distributed to faculty, will face skepticism and resistance in academic cultures that value researcher autonomy. Policies that emerge from genuine faculty engagement, with iterative feedback and transparent decision-making, earn buy-in that makes compliance real rather than performative.

Faculty Senate engagement is the single most important element of a successful policy development process. The Faculty Senate (or equivalent shared governance body) represents faculty interests in institutional decision-making, and faculty policy that bypasses shared governance will be perceived as illegitimate. The practical approach: brief the Faculty Senate Academic Affairs or Research Committee early in the process, share a policy framework (not a draft text) for comment, incorporate feedback into the drafting process, share draft text for committee review before broader consultation, and seek Faculty Senate endorsement before implementation.

Subject matter consultation should include at minimum: the IRB (which needs to align AI research review criteria with institutional policy), the Library (which has significant expertise in research integrity, data management, and scholarly communication), the Graduate School (because graduate students are heavily affected and have distinct compliance needs as both researchers and students under faculty supervision), Legal Counsel (for regulatory compliance review), the Office of Research Security (for export control implications), and the research compliance office.

The approval pathway varies by institution but typically flows through: a faculty-led policy committee (Faculty Senate committee or Joint Governance Committee), the Provost's Office or Vice Provost for Research (for academic policy approval), the Vice President for Research (for research-specific policies), and the Board of Trustees or Regents (if the policy involves significant institutional liability or fundamental changes to academic standards). Understanding your institution's specific approval pathway before beginning the development process will save significant time, getting a policy back from board-level review because it should have gone through faculty governance first is a frustrating and costly delay.

Timeline expectations: a well-developed institutional AI research policy typically takes 9-18 months from initiation to full implementation, including stakeholder consultation, drafting, review, approval, and implementation. Research leaders should resist pressure to shortcut this process, because policies that skip genuine consultation are policies that will be re-opened within two years when faculty resistance forces revision. A phased approach, interim guidance while the full policy is developed, allows the institution to provide clear direction immediately while the permanent framework is built properly.

Policy Implementation: Training, Attestation, and Technical Controls

A policy that exists on paper but is not implemented in practice provides no real protection for the institution or its researchers. Implementation has three components: training programs, attestation requirements, and technical controls, and the most effective implementations use all three.

Training programs for AI research policies must reach multiple audiences at the right depth. Faculty and principal investigators need: conceptual understanding of why the policies exist (regulatory context, protection rationale), practical guidance on what actions the policies require in their specific research contexts, clear examples of compliant and non-compliant behavior, and an efficient path to ask questions when situations are ambiguous. Graduate students and postdocs need similar content but often with greater emphasis on the practical how-to. They are the ones most frequently using AI tools in day-to-day research. Research administration staff need training on the policies' implications for their specific functions: IRB coordinators need to know how to review AI components in protocols; sponsored research staff need to know what contract provisions to watch for; export control staff need to understand AI-specific export considerations.

Training delivery options include: online modules (scalable, trackable, but low engagement), in-person workshops (high engagement, not scalable), department or lab-level training (effective for reaching specific research communities with relevant examples), and integration into existing required research training (reaches researchers who might otherwise not engage with standalone AI training). The most effective institutional approaches combine an online module for baseline certification with targeted in-person workshops for high-AI-use departments.

Attestation requirements formalize researcher acknowledgment that they have read, understood, and agree to comply with the policy. For research-specific policies, attestation can be built into: the human subjects research training certification (renewal period); sponsored research agreement routing (researchers sign off on AI use policies as part of grant acceptance); graduate student onboarding (entering students acknowledge AI research policies as part of their matriculation); and annual research compliance attestations where institutions maintain them.

Technical controls are the most powerful implementation mechanism because they make compliant behavior the default path, but they are also the hardest to implement. Can you block researchers from uploading data to unapproved AI services? In practice, this is technically difficult and would create significant researcher friction if implemented broadly. Targeted technical controls are more feasible: requiring institutional authentication for approved AI service access (creating an audit trail), configuring enterprise AI service accounts that automatically exclude training data use, and implementing data loss prevention (DLP) rules that flag potential AI-related data exfiltration. Technical controls work best when combined with training and attestation, researchers who understand why restrictions exist are more likely to comply even when technical enforcement is imperfect.

Enforcement and Academic Integrity

AI policy enforcement raises genuinely difficult questions that research leaders must think through carefully before adopting policies that cannot be enforced consistently or fairly.

Defining violations requires clarity about what the policy actually prohibits, as distinct from what it requires. Violations typically fall into categories: prohibited data handling (entering restricted data into non-approved AI tools), failure to disclose AI use in publications or grant applications, misrepresentation of the nature of AI involvement, and procedural non-compliance (failing to document AI use, failing to obtain required approvals). The policy should be specific enough that a reasonable researcher can know in advance whether a particular action constitutes a violation.

The investigation process for alleged AI policy violations should follow your institution's existing research misconduct procedures, with modifications specific to AI: who receives and assesses allegations, what constitutes sufficient evidence to proceed to formal investigation, what the formal investigation process looks like, and what sanctions are available. Importantly, many AI policy questions will arise as good-faith interpretation disputes rather than intentional misconduct, a researcher who genuinely didn't know that entering unpublished data into an AI tool was prohibited is in a very different position than a researcher who knowingly submitted AI-generated text as their own analysis. The enforcement framework should distinguish between these situations.

The proof problem is real and should not be minimized. After the fact, proving that AI was used to generate specific content is technically challenging and contextually dependent. AI detection tools are unreliable. They produce significant false positives and false negatives, and their outputs are not suitable as sole evidence in academic integrity proceedings. The better enforcement approach focuses on process: did the researcher follow required procedures (documentation, disclosure, approvals) rather than trying to prove AI involvement through content analysis.

Sanctioning frameworks for AI violations should be proportionate to the severity of the violation and the nature of intent. Procedural violations by researchers who didn't know the policy (especially in early implementation phases) warrant remediation and training, not formal sanctions. Repeated violations or deliberate misrepresentation warrant the same range of sanctions available for other research integrity violations: reprimand, additional oversight requirements, suspension of research privileges, termination. Violations that harm research subjects or misuse protected data may also trigger regulatory reporting obligations.

Policy Lifecycle Management

AI research policies that are written once and filed are not adequate for a field evolving as rapidly as AI. Policy lifecycle management, systematic processes for review, update, and communication of policy changes, is as important as the initial policy development.

Trigger-based review ensures that policies are revisited when circumstances change materially. Three categories of triggers should automatically initiate policy review: major technology changes (a new AI capability that significantly expands what researchers can do with AI, or a significant incident involving an AI system), regulatory changes (new legislation, agency guidance, or enforcement action that creates new compliance obligations or changes the risk landscape), and significant incidents (a research misconduct finding, a data breach involving AI-processed data, or a harmful AI output that reaches public attention). Each of these triggers should have a defined review process and timeline: not just 'we will review the policy,' but 'within 90 days of the triggering event, the AI Policy Committee will complete its review.'

Annual review cycle ensures that policies are periodically assessed even in the absence of specific triggers. An annual review should: compare current policy language against the current regulatory landscape, assess whether the policy is achieving its intended behavioral effects (this requires feedback from researchers), identify emerging AI use cases that the current policy doesn't clearly address, and update any regulatory or technical references that have become outdated. Annual review doesn't necessarily mean annual revision, if the policy is working and the landscape hasn't changed substantially, the review can confirm that no changes are needed.

Version control and communication are critical when policies change. Policy updates should be versioned with clear effective dates and a summary of what changed and why. Communication of changes must reach all affected researchers, email alone is not sufficient for policy changes that affect research behavior. Effective change communication includes: direct notification to research compliance staff who field policy questions, updates to training materials and online resources, briefings to department chairs and graduate program directors, and updates to the FAQ resources that researchers consult. The most common failure in policy lifecycle management is updating the policy document without ensuring that the people who implement and comply with it know it has changed.