Guide and template

AI policy template for universities (2026): staff, students and research

A university AI policy has to work for three audiences at once: students who want to know what is allowed in an assignment, researchers who need to know what they may upload and disclose, and the staff who approve tools and answer to the DPO. This guide sets out what the policy should cover on 7 October 2026, under the GDPR and the EU AI Act as amended by Regulation (EU) 2026/1744, shows how six European universities structure theirs, and gives example clauses you can adapt. The full policy is available as an editable Word template.

Published 7 October 2026 · Sources checked 7 October 2026

The short answer

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers an AI assistant for research work with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

1. How six European universities structure their AI policies

We read the public AI policy pages of six universities on 7 October 2026. They take different shapes, from a single charter to a framework with separate guidance per audience, but the same building blocks recur.

UniversityFormHow it is organisedNotable rule
Utrecht University (Netherlands)Institutional AI policy hubSeparate sections for students, teachers, researchers and employees; an ethical code of conduct, a responsibility matrix and a model AI disclosure statement [17]A request process for AI tools used in education, run through a questionnaire called AI Veritas, with three outcomes: approved, approved with conditions or disapproved [18]
KU Leuven (Belgium)Central GenAI page with five principlesPrinciples plus guidelines per target group: students, teaching staff, researchers and administrative staff [19]For confidential and strictly confidential data, only Copilot signed in with a KU Leuven account [19]
Ghent University (Belgium)University-wide frameworkSix fundamental principles, from accountability to privacy and exemplary behaviour; divisions such as education and research write their own detailed guidelines on top [21]The framework links explicitly to the ALLEA Code, the GDPR, the information security policy and the data classification guidelines [21]
University of Helsinki (Finland)Guidelines on AI in teaching, adopted by the Academic Affairs Council; faculty-level thesis guidelinesUniversity-wide rules for teaching and learning; faculties add detail, for example the Faculty of Medicine's guidelines on AI use in theses [22][23]Students must disclose use or non-use of AI in written work; assessment must not be entirely outsourced to AI [22]
Université Paris Cité (France)Single charter on generative AI (PDF, June 2026)Preamble, how generative AI works, six principles of use, then specific rules for teaching, research and administration [24]Generative AI is forbidden in written exams unless the exam paper allows it; undeclared use is treated as fraud [24]
University of Edinburgh (UK)Staff and student guidance attached to the university's own AI platform, ELMGuidance for staff and separate guidelines for students, with the platform as the recommended tool [25]No identifiable patient, clinical or research participant data in ELM [25]

Three patterns stand out. First, every one of the six separates audiences: what a student may do in an essay is not written in the same place as what a researcher may upload. Second, the central document is short and principle-based, and the operational detail (tool lists, data classes, assessment levels) sits in linked pages that can change without a full policy revision. Ghent says so directly: the framework is a starting point that divisions elaborate [21]. Third, tool rules lean on existing policies: KU Leuven ties tool choice to its three information classes [19], and Ghent lists the data classification guidelines among the rules its framework builds on [21].

For the tools these and 29 other universities provide, see our survey of 35 European universities.

2. Scope, definitions and principles

Utrecht's policy covers "all AI systems and tools referred to in the EU AI Act" plus impactful algorithms with potentially risky effects [17]: tie the definition to the AI Act, then add what matters locally. The scope should cover staff, students and contractors acting for the university, and every AI system used for university purposes: licensed centrally, bought by a department, free of charge, built in-house, or switched on as a feature inside software the university already uses. The last group is easy to miss because it arrives without any new procurement.

Use the AI Act's definitions so that the policy stays aligned with the law. A university is normally a deployer: a body using an AI system under its authority (Article 3(4)). It becomes a provider if it develops a system and puts it into service under its own name, and Article 25(1)(c) can make a deployer the provider of a high-risk system if it changes the intended purpose of a general tool so that it becomes high-risk [11]. Our AI Act guide for universities explains the roles in more detail.

Principles cover the cases the rules do not foresee. The six universities converge on human responsibility for output, critical checking, transparency, careful data use, fairness and, at Ghent and Paris Cité, sustainability [21][24].

Example clause (scope). This policy covers every AI system used for University purposes, whether licensed centrally, bought by a unit, offered free of charge, built in-house or embedded as a feature in other software. Private use outside University activities is not covered, except that University data may not be entered into such tools.

3. Approved tools and how tools get approved

A list of tool names does not answer the question users ask: "may I paste this?". Each approval should name the plan (an enterprise licence is a different service from the consumer version of the same brand) and the highest information class the tool may receive.

The template uses a default matrix: any approved tool for public information; tools marked "internal" for internal information; only tools with a data processing agreement and, where needed, a DPIA for confidential information and personal data; and either no AI tools or a named university-hosted platform for strictly confidential information, special category data and identifiable research participant data.

The approval route

Utrecht's process for AI tools in education is a good reference point. Only teachers or educational support staff may submit a request; the tool is assessed through a questionnaire that takes about 30 minutes; the outcome is approved, approved with conditions or disapproved; and the process covers single-task tools rather than general-purpose chatbots, which the university handles separately [18]. It also draws one firm line: "Requests for AI tools for quantitative assessment (automatic grading) will not be approved." [18]

The template's route has the same shape: a short request (use, users, data classes, plan, local owner), assessment against the checklist in Annex A with the DPO and information security consulted, and a recorded decision with reasons.

Example clause (approval). The outcome of a request is one of: approved, approved with conditions (for example limited to named information classes or user groups) or not approved. Reasons are recorded and the AI tool register is updated. Approvals are reviewed at least every 12 months and whenever the vendor changes its terms, subprocessors, data location or the AI functions of the product.

4. Personal data and confidential information

The AI Act does not affect the GDPR (Article 2(7)) [12], so the data rules in an AI policy are GDPR rules applied to a new kind of tool. The policy should require, for every use involving personal data, a tool approved for that class of data, a legal basis and compatible purpose, and data minimisation. Where a vendor processes personal data for the university, a processor agreement under Article 28 GDPR must be in place first, and transfers outside the EEA need a transfer mechanism.

A DPIA is required where processing is likely to result in a high risk. The EDPB lists criteria such as evaluation or scoring, systematic monitoring, sensitive data, vulnerable data subjects and innovative technology, and says that in most cases two criteria should trigger a DPIA [16]. AI tools used on students, applicants or research participants often meet two. Our DPIA screening tool gives a first answer.

There is also a question that sits upstream of the university. In Opinion 28/2024 the EDPB said that controllers deploying an AI model should carry out an appropriate assessment of whether the model was developed lawfully, as part of their own accountability [15]. In practice that means asking vendors about training data and documentation during procurement (section 11).

Name the data that must never go into AI tools. Tartu, Helsinki and Edinburgh all publish such rules (see our tools survey). Edinburgh's staff guidance says: "Do not use ELM with identifiable patient/clinical data or any identifiable research participant data." [25]

Example clause (data). Users must not enter into any AI tool: passwords or access credentials; national identity numbers; unpublished examination papers; or students' submitted work for grading, except in tools approved for that purpose. Special category data and identifiable research participant data may be entered only into tools listed for strictly confidential information, with the approval of the data owner and the DPO.

5. Teaching, assessment and academic integrity

Choose a default and let courses decide

The universities we read pick one of two defaults. Helsinki's guidelines, revised by its Academic Affairs Council on 28 May 2026, start from permission: "As a rule, AI use is permitted in teaching and in support of learning." Course coordinators decide on AI use in their courses and instruct students at the start [22]. KU Leuven also permits use unless a teacher, programme or faculty decides not to allow a particular use [20]. Paris Cité starts from the other side for exams: in written examinations, generative AI is forbidden unless the exam paper says otherwise, because without an indication no material is allowed [24].

Either default works if every assessment states which of the template's four levels of AI use applies (no AI, support only, assisted, integrated).

Disclosure

Disclosure rules need to be concrete. Helsinki requires students to disclose their use or non-use of AI in written work, even where a course does not ask for it [22]. Its Faculty of Medicine asks for a section titled "AI use in the thesis" above the reference list, describing the stage AI supported, the tool and how validity was ensured, and says supervisors may request log data or prompts [23]. Paris Cité asks students who use AI to add an "IAgraphie" section to the bibliography, naming the tool, version and maker, and to keep their prompt history [24]. KU Leuven's principle is shorter: "Communicate where and how you have used GenAI." [19]

AI in marking, and detection tools

The policy should also bind staff. Helsinki states: "Assessment must not be entirely outsourced to AI." It adds that AI's role must be supportive with the teacher making grading decisions, and that teachers may not enter students' answers into services outside the university that do not necessarily comply with the GDPR [22]. Helsinki's guidelines also say it is currently impossible to reliably determine whether answers were produced by AI or by students [22]. In our view, a policy should therefore not let a detection score stand as the only evidence of misconduct.

Paris Cité adds two rules worth copying: teachers may not require students to use an AI system that needs a personal account, and undeclared use is treated as fraud before the disciplinary board [24]. KU Leuven links unauthorised use to the irregularity articles of its Education and Examination Regulations [20].

Example clause (marking). AI may support marking and feedback only in tools approved for that purpose and only in a supporting role: the examiner makes and is responsible for every grading decision. Output from AI detection software alone is not sufficient evidence of academic misconduct.

6. Research use and disclosure

Research needs its own section: unpublished results, participant data and peer review confidentiality raise different risks. Two European texts supply most of the content.

The ALLEA Code. The European Code of Conduct for Research Integrity (revised edition 2023) says researchers report their results and methods, "including the use of external services or AI and automated tools", in a way that facilitates verification [14]. Among unacceptable practices it lists "Hiding the use of AI or automated tools in the creation of content or drafting of publications." [14] It also asks that reviewing and assessment disclose the use of AI and automated tools [14]. Ghent's framework and Paris Cité's charter both refer to the Code directly [21][24].

The Commission's Living guidelines. The ERA Forum's Living guidelines on the responsible use of generative AI in research reached their third version in May 2026 [13]. For researchers they recommend, in summary:

Research organisations are asked to provide training, track how generative AI is used, integrate the guidelines into their research-practice rules and, where possible, offer tools they govern themselves [13].

The AI Act's research exclusion is narrow. Article 2(6) excludes systems specifically developed and put into service for the sole purpose of scientific research, and Article 2(8) covers research and testing before a system is placed on the market or put into service [12]. A licensed chatbot or transcription tool used by a research group is not excluded. Paris Cité adds a practical rule: confidentiality of projects and manuscripts rules out generative AI systems not secured by the university in evaluation activities such as peer review [24].

Example clause (research disclosure). Researchers disclose substantive use of generative AI, for example in data analysis, literature review, identifying research gaps or formulating hypotheses, in the methods section or equivalent, naming the tool, version, date and how the output was verified, in line with the requirements of the journal, publisher or funder.

The data side of research use (legal bases, participant information, transfers) is covered in our guide to GDPR and AI tools in research.

7. AI literacy measures under amended Article 4

Article 4 has applied since 2 February 2025. The AI Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026 [7], changed its wording. Providers and deployers must now "take measures to support the development of AI literacy" of their staff and other persons dealing with AI systems on their behalf, taking into account their knowledge, experience, the context of use and the people affected. The amended text adds that the obligation "does not require providers or deployers to guarantee any specific level of AI literacy of any individual" [1].

The Commission's AI literacy Q&A, updated after the amendment, adds the practical detail [2]:

Article 4 covers staff and others acting on the university's behalf. Students using a tool for their own studies are generally not in that group, although students acting for the university, such as teaching assistants who grade, are for that role. Universities can still offer students AI courses: Ghent lists a university-wide elective on AI essentials [21].

Validemic's analysis A proportionate programme has layers: a short general module for all staff who use AI; role-specific guidance for examiners, admissions, HR, IT, procurement and researchers handling personal data; training for anyone who will oversee a high-risk system from December 2027; and a dated record of what was offered to whom.

8. Prohibited practices (Article 5)

The prohibitions have applied since 2 February 2025 [6]. One is aimed squarely at universities: Article 5(1)(f) prohibits AI systems that infer emotions of a natural person in workplaces and education institutions, except for medical or safety reasons [3]. A university is both, so the ban protects staff and students. The Commission's guidelines on prohibited practices give education examples: emotion recognition to infer students' interest or attention is prohibited, as is its use during admissions tests, and exam software that also detects emotions such as anxiety falls within the ban [4].

The policy should also list biometric categorisation that infers sensitive traits such as race, political opinions or sexual orientation (Article 5(1)(g)), social scoring (Article 5(1)(c)) and manipulative techniques or exploitation of vulnerabilities (Article 5(1)(a) and (b)) [3]. From 2 December 2026, AI that generates non-consensual intimate imagery or child sexual abuse material is also prohibited under new points in Article 5(1) [3][6]. A university policy can simply ban that use now.

Example clause (prohibition). No AI system may be used to infer the emotions of students, applicants or staff in teaching, examinations, admissions or the workplace, except where the system is intended for medical or safety reasons.

9. High-risk uses: Annex III point 3 and the December 2027 date

Annex III point 3 lists four education uses as high-risk: determining access or admission; evaluating learning outcomes, including when used to steer the learning process; assessing the level of education a person will receive or can access; and monitoring and detecting prohibited behaviour of students during tests [5]. Point 4 adds recruitment and decisions on employment relationships, which matters for HR. An Annex III system is not high-risk if the conditions of Article 6(3) are met, for example a narrow procedural task, but never where it profiles natural persons [26].

These rules were due on 2 August 2026. The AI Omnibus moved the date for Annex III systems to 2 December 2027 (Article 113 as amended) [6]. This is adopted law, not a proposal. From that date a university deploying such a system must, among other things, use it according to the instructions for use, assign competent human oversight, keep logs for at least six months, inform workers before workplace use, inform people subject to decisions and, if it is a public authority, register its use (Article 26) [9]. Bodies governed by public law and private entities providing public services must also carry out a fundamental rights impact assessment before first use (Article 27) [10].

Validemic's analysis Do not wait for 2027. Requiring prior approval for any high-risk use now builds the inventory you will need. Watch the quiet route into Annex III: a teacher using a general chatbot to propose grades that count towards a final mark. The template treats that as a high-risk use. Our AI Act education checker runs through the questions.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

10. Transparency under Article 50

Article 50 has applied since 2 August 2026 [6]. For a university the relevant duties are [8]:

The machine-readable marking of synthetic content in Article 50(2) is a duty for vendors as providers; our AI Act guide covers it.

11. Procurement and vendor assessment

Most of the evidence an approval needs comes from the vendor: the data processing agreement, subprocessors, data location, training use of inputs on the plan you will license, retention, security reports and, for the AI Act, the provider's classification and instructions for use. The policy should require these before signature, and stop units accepting click-through terms for tools that will receive more than public information.

Contracts should add what the law and the policy need: Article 28 GDPR processor terms; a commitment not to use university data to train models without consent; notice of changes to subprocessors and to AI functions; and, for high-risk uses, the information the university needs for its deployer duties under Articles 26 and 27. The last point matters for contracts that will run past 2 December 2027. New AI features added to existing software should be assessed before they are switched on.

Our vendor assessment guide sets out the questions to send, and the DPA checker covers the processor agreement clauses. Annex A of the template turns both into a checklist of about 35 questions across six areas.

12. Governance, roles and review

The universities we read all give the policy an owner and a body that keeps it current. Ghent has an AI task force with contact points for business operations, research and education [21]. Utrecht publishes a responsibility matrix that clarifies who is responsible for implementation, daily use and compliance in education [17], and its policy is endorsed by the Executive Board and the University Council [17]. Paris Cité's charter states it follows the recommendations of the university's ethics and research integrity committee and will be revised regularly [24].

The template proposes an AI governance group (IT, information security, the DPO, legal, procurement, library, education, research, HR and a student representative) that maintains the tool register, decides on approvals and coordinates AI literacy measures.

Plan the review now. On 7 October 2026 the Commission's guidelines on high-risk classification were still in draft, and the AI Office template for the fundamental rights impact assessment and the AI Board's recommendations on AI literacy were still to come [1][10]. An annual review with a list of pending items keeps the policy current.

13. What is in the Word template

Download the AI policy template for universities (Word, editable). Placeholders in [square brackets] are highlighted. The 19 sections follow the structure of this guide, from scope and definitions to procurement, incidents and review, with two default options for assessed work. Three annexes make it usable on day one: Annex A, an AI tool approval checklist covering the request, data protection, information security, the AI Act, education and research, and contract and exit; Annex B, an AI use statement for assessed work; and Annex C, four levels of AI use in assessment.

The template reflects the law and guidance we read on 7 October 2026. It is a starting point, not legal advice. Adapt it to your national law, your institution's legal status and your existing policies, and have it reviewed by your legal office and DPO.

Sources

All sources retrieved 7 October 2026.

  1. AI Act (as amended), Article 4: AI literacy, AI Act Service Desk explorer.
  2. European Commission, AI Literacy: Questions & Answers.
  3. AI Act (as amended), Article 5: Prohibited AI practices.
  4. European Commission, Guidelines on prohibited AI practices, C(2025) 5052 final.
  5. AI Act, Annex III: High-risk AI systems referred to in Article 6(2).
  6. AI Act (as amended), Article 113: Entry into force and application; Regulation (EU) 2026/1744 on EUR-Lex.
  7. European Commission, AI Omnibus enters into force, 27 July 2026.
  8. AI Act (as amended), Article 50: Transparency obligations.
  9. AI Act, Article 26: Obligations of deployers of high-risk AI systems.
  10. AI Act (as amended), Article 27: Fundamental rights impact assessment.
  11. AI Act (as amended), Article 25: Responsibilities along the AI value chain; Article 3: Definitions.
  12. AI Act (as amended), Article 2: Scope; Recital 25.
  13. European Commission, Directorate-General for Research and Innovation, Living guidelines on the responsible use of generative AI in research, ERA Forum stakeholders' document, third version, May 2026.
  14. ALLEA, The European Code of Conduct for Research Integrity, revised edition 2023 (PDF), sections 2.3, 2.8 and 3.1.
  15. European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 18 December 2024.
  16. European Data Protection Board, Data protection guide for small business: Be compliant (section on DPIAs).
  17. Utrecht University, AI policy; AI responsibility matrix.
  18. Utrecht University, Allow listing process.
  19. KU Leuven, Generative AI at KU Leuven.
  20. KU Leuven, Responsible use of generative artificial intelligence (students).
  21. Ghent University, University-wide framework for responsible use of generative AI at Ghent University (PDF); GenAI at Ghent University.
  22. University of Helsinki, Instructions for teaching: Artificial intelligence in teaching (guidelines revised by the Academic Affairs Council, 28 May 2026).
  23. University of Helsinki, Faculty of Medicine: Guidelines on AI use in theses at the Faculty of Medicine (PDF, dated 12/2025).
  24. Université Paris Cité, Charte d'usage des systèmes d'intelligence artificielle générative (French, PDF, file dated 16 June 2026).
  25. University of Edinburgh, Information Services: Using generative AI in your work: guidance for staff.
  26. AI Act (as amended), Article 6: Classification rules for high-risk AI systems.

About this page

Written by Validemic and checked on 7 October 2026. We read the amended AI Act articles in the European Commission's AI Act Service Desk explorer, the Commission's AI literacy Q&A, the third version of the Living guidelines (May 2026), the ALLEA Code (2023) and the EDPB documents listed above, and the public AI policy pages of six universities on that date. Short quotations are verbatim; the Paris Cité charter is in French and is paraphrased in English. We only read public pages, so guidance behind university intranets is not covered, and a missing detail means it was not on the page we read. Commission guidelines are non-binding, and this page and the template are not legal advice.

If you work at one of these universities and your policy has changed, or we have described it inaccurately, or you spot an error in the law summary, please contact us and we will correct it and note the change here.

Frequently asked questions

Is a university legally required to have an AI policy?

No law requires a document called an AI policy. But the AI Act requires deployers to take measures to support the AI literacy of staff (Article 4), bans certain practices such as emotion recognition in education (Article 5), and sets duties for high-risk uses from 2 December 2027. The GDPR requires a legal basis, processor agreements and, where needed, a DPIA for every tool that processes personal data. A written policy is the usual way to show how the university meets these duties.

Does AI literacy under Article 4 mean every member of staff must be certified?

No. As amended by Regulation (EU) 2026/1744, Article 4 requires measures to support AI literacy and says it does not require any specific level of literacy for any individual. The Commission's Q&A says no certificate is needed and an internal record of training and guidance is enough.

Should students be allowed to use generative AI in assessed work?

Most universities in our sample let the course decide. Helsinki permits AI use in teaching as a rule, with course coordinators deciding per course; KU Leuven permits it unless a teacher, programme or faculty decides otherwise; Université Paris Cité forbids it in written exams unless the exam paper allows it. Whatever the default, the policy should require a clear statement per assessment and a disclosure format.

Can teachers use AI to grade student work?

Only with care. Evaluating learning outcomes is a high-risk use under Annex III point 3(b) of the AI Act, with obligations applying from 2 December 2027. Helsinki's guidelines say assessment must not be entirely outsourced to AI, and Utrecht will not approve tools for automatic grading. Students' work is also personal data, so it may only go into tools approved for that class of data.

Do researchers have to disclose that they used ChatGPT or similar tools?

The European Code of Conduct for Research Integrity lists hiding the use of AI or automated tools in creating content or drafting publications as an unacceptable practice. The Commission's Living guidelines ask researchers to disclose substantial use, for example in data analysis or literature review, and treat basic editorial help as not substantial. Journals and funders may set stricter rules.

Does the AI Act's research exemption cover AI tools used by researchers?

No. Article 2(6) excludes AI systems developed and put into service for the sole purpose of scientific research, and Article 2(8) covers research and testing before a system is placed on the market. Recital 25 says other AI systems used in research remain subject to the Regulation, so licensed tools used by researchers fall under the normal rules.

How often should a university AI policy be reviewed?

At least once a year is a common choice, and sooner when the law changes. Several items were still pending on 7 October 2026, including the Commission's guidelines on high-risk classification and the AI Office template for fundamental rights impact assessments.