The departmental policy self-audit
Last reviewed: 2026-07-18. Benchmarks reflect institutional policies collected 2024 and 2025; they age.
An hour with this checklist tells a chair three things: what the institution above you already provides, what your department covers on its own, and what nobody covers yet. Gather your institution’s AI guidance, your department’s own statements, and a couple of representative syllabi, then work through the six sections, writing I, D, or G inside each box: the institution covers it, the department covers it, or it is a gap. The output is not a score. It is your gap list, and the departmental adoption kit in this folder is built to close most of the department-level entries on it.
Two research snapshots make the benchmarks. A 2026 study in Educational Policy mapped the published AI policies of all fifty US flagship public universities (LaFrance 2026); its frequencies appear beside items below as “how common is this among institutions that publish policy.” A 2026 webinar study of the twenty-five US universities with the top-ranked computer science programs (Papadimitriou, unpublished presentation) supplies this audit’s five governing dimensions and its sharpest warning: most policies assign responsibility to faculty and students without building the support that would let them carry it. That warning is the test running through section four.
1. Purpose and ethics
The dimension: does the policy say what AI is for here, not only what is forbidden?
- A statement exists saying AI use should serve learning, with honesty about how it was used.
- Acceptable and prohibited uses are named in categories a student could apply, not left as “use responsibly.”
- Academic integrity language names AI explicitly. Benchmark: only 34 percent of flagship integrity codes do; most institutions lean on older unauthorized-assistance language. A frequent gap.
- Students are told to ask before using AI when a course’s rules are unclear, and asking is treated as normal rather than suspicious.
- Somewhere in the curriculum, AI literacy is named as a learning outcome, not only as a compliance topic.
2. Data protection
The dimension: does anyone say what may not go into these systems, plainly enough to act on?
- A no-upload rule exists and is short enough to live in a syllabus: private information about people, unpublished research data, secure exam materials, confidential documents.
- An approved-tool list exists, with approved uses. Benchmark: 92 percent of flagships publish data and tool governance; 78 percent recommend approved tools; 14 percent mandate them for defined uses.
- Someone is named who can approve a new tool, so approval is a request rather than a mystery.
- If courses collect students’ AI conversation threads, retention and access rules for those threads exist and mirror the protections on other student work.
- The privacy floor is referenced: FERPA in the United States, or the equivalent where you are.
3. Fairness, equity, and access
The dimension: does the policy create advantages it does not acknowledge?
- No course requires AI without providing an approved tool at no cost or an equivalent alternative. No hidden paywall around the grade.
- Accommodation decisions stay human and follow disability-services procedures; an accommodation is neither end-run by AI nor blocked by it.
- Detector limits are stated: automated detection scores are never the sole or primary evidence in an integrity case.
- Procurement-created inequity has been checked: students in different sections or colleges are not working with materially different tool tiers because of licensing, and no pilot can expire mid-semester and strand the students inside it.
- Equity is addressed explicitly somewhere, not assumed. Benchmark: only 38 percent of flagship guidance references equity and access. One of the two most common gaps.
4. Responsibility, with the support to carry it
The dimension, and the audit’s core test: for every duty the policy assigns, name the support that makes it dischargeable. A duty without support is a liability transfer, not a policy.
- Students are told to verify AI output, and a course, module, or guide teaches them how.
- Students are told to disclose AI use, and a disclosure format is provided rather than left to invention.
- Faculty are expected to set course AI policy, and sample syllabus language exists. Benchmark: 88 percent of flagships supply sample statements; if yours does not, the department writes its own.
- Faculty are expected to redesign assessments, and templates, worked examples, and training exist with named owners.
- Where TAs grade process evidence, calibration happens, on purpose, at least once a term.
- Instructors own integrity judgments, and the procedure they follow, with its evidence standards, is written down.
- The support units are named: who at the library, writing center, tutoring center, and teaching center carries which piece.
5. Transparency and disclosure
The dimension: can a student discover the rules, and does honest disclosure have a form?
- A disclosure standard exists and says when disclosure attaches: use that shapes substance, structure, or analysis, not spellcheck. Benchmark: 30 percent of flagships mandate disclosure, 68 percent recommend it. Either stance works; silence does not.
- Every syllabus answers the basics: what AI use is allowed, which assignments allow what, what must be done without AI, how to disclose, what may never be uploaded.
- Assignment-level labels are in use, so the rules travel with the task instead of living only on page nine of the syllabus.
- The policy itself is findable: one page, linked where students and faculty actually look, not buried in a committee archive.
- Students hear the rules said out loud early in the term, because a policy nobody mentions is a policy nobody follows.
6. Currency and ownership
The dimension: is this a living policy or a document that was true once?
- The policy carries a date. Benchmark: 11 of the 25 top-CS-university policies carried none. An undated policy in a field moving this fast is an expired one.
- A review cadence exists and the next review is on a calendar, not an intention.
- An owner is named: a body or a person who maintains the policy, so updates have a home.
- A feedback channel exists, and what confused students last term reaches whoever revises the text.
- The department knows its own posture, chosen rather than drifted into. Benchmark: among flagships, 64 percent read as balanced or guidance-oriented, 20 percent as innovation-oriented, 16 percent as restrictive.
Before you pilot a tool
A compact test for any new adoption, drawn from a 2025 governance webinar (Shapiro, University of Lethbridge). Five questions, asked before the pilot starts: Can every affected student access it? Can the institution afford it at full scale, not just at pilot scale? Has anyone checked its failure modes and bias for your student population? Have the privacy and data-retention terms actually been read? And what workload does it add for the faculty who must supervise it? A pilot that cannot answer all five is not ready to touch a grade.
Reading your results
Gaps marked G at the institution level are not your failure, and they will not wait for the institution either. The department fills them locally, using the kit, and hands the working version upward when institutional policy finally convenes. That is the department-to-institution path, and departments that arrive with a tested answer shape the outcome.
Gaps at the department level map directly onto the kit’s one-semester rollout: the vocabulary and categories close most of section one, the syllabus practice closes most of section five, and the calibration and sample work closes section four. Section six closes itself the day you date the policy and calendar the review.
Items touching regulation, anything involving proctoring, monitoring, admissions screening, or automated grading, get a second pass with the regulatory landscape note in this folder, and then a conversation with counsel.
Run the audit again when the review date comes around. The benchmarks above describe institutions in 2024 and 2025; the useful comparison after that is not against them but against your own last run.
Auditing your adoption of the book’s commitments
The six dimensions above audit a tool. This section audits an implementation: the book’s ten commitments (the one-page adoption summary, Section 17.6.8), each paired with the artifact that would satisfy a skeptical auditor. A commitment without an artifact is a belief, not a practice.
- Teach students to use AI without surrendering their own thinking. Artifact: a named place in the curriculum where the habits of Part I are taught, not a link in a syllabus.
- Require every course to state its AI-use rules. Artifact: the category declared in every syllabus, checkable by reading them.
- Preserve meaningful assessment of independent competence. Artifact: the no-AI components named in each course’s assessment plan, with their grade weight.
- Treat AI literacy as an educational outcome. Artifact: the outcome stated in a course description, workshop, or orientation a student can point to.
- Require verification of AI-assisted work. Artifact: the verification step written into assignment instructions or rubrics, not assumed.
- Normalize brief, factual disclosure by students and faculty. Artifact: the disclosure template in use, and a faculty example on file.
- Protect privacy, access, and equity. Artifact: the approved-tool list with its data terms, and a no-cost route to every tool recommended for coursework.
- Never treat detector output as sole or primary evidence. Artifact: the integrity procedure’s written evidentiary standard, not a practice claim.
- Support faculty with templates, training, and TA calibration. Artifact: the templates in the shared drive, the training on the calendar, the calibration session on the term schedule.
- Review policies regularly as tools and practices change. Artifact: the review’s calendar entry and the dated policy version it produced.
Part of the companion repository for Learning with AI: A Framework for Students, Instructors, and Universities (James M. Hyman, SIAM Books). Benchmarks: J. LaFrance, “Governing Generative Artificial Intelligence,” Educational Policy (2026); A. Papadimitriou, webinar presentation, Global Higher Ed Webinars (2026); S. Shapiro, teachonline webinar (2025). These materials are free to use and adapt with attribution.