In a research group of eight, one PhD student pastes non-anonymised interview transcripts into a generative AI assistant to summarise them. Another uses AI to rewrite the discussion of a joint paper without telling anyone. A third avoids AI entirely because she does not know whether the group leader allows it. When the paper is accepted and the journal asks for an AI disclosure, nobody can say exactly what the group used, or where. Nobody set out to break a rule; there simply was no rule.
University and journal policies set the outer frame, but they cannot answer a group’s specific questions: which of our data may go into which tools, who decides, and how we disclose on joint papers. A one-page group policy fills exactly that gap.
Why a group-level policy
- Shared responsibility: every co-author is accountable for the whole paper. One person’s misuse lands on everyone.
- Shared data: project data usually belongs to the institution or is bound by ethics approvals, not owned by individuals.
- Fairness: those who use AI and those who do not need to know they are judged by the same standard.
- Training: new students need to know from day one what is encouraged and what is not.
Part 1: classify your data
This is the most important part, because most risk lies in putting data into external tools. A simple three-level scheme:
| Level | Examples | May go into |
|---|---|---|
| Public | Published papers, open datasets, routine admin email drafts | Any tool the group has approved |
| Internal | Unsubmitted manuscripts, proposals, analysis code, anonymised data | Only institution-licensed tools or those committed not to train on your data; manuscripts need co-author agreement |
| Restricted | Identifiable participant data, health data, partner data under contract, manuscripts received for review | No external AI tools; locally run tools only if ethics approval permits |
Part 2: allowed, ask first, not allowed
| Allowed | Ask the group leader or co-authors first | Not allowed |
|---|---|---|
| Asking questions to understand concepts and methods | AI help writing code for a paper’s main analysis | Putting restricted data into external tools |
| Checking spelling and grammar in your own drafts | AI translation or editing of a joint manuscript | Having AI write content and presenting it as your own |
| Drafting emails and meeting notes | Using AI to label data that becomes a research variable | Citing AI-suggested references without reading the original |
| Suggesting search terms for the literature | AI-generated images in papers or posters | Using AI on manuscripts received for peer review |
The middle column is where a policy earns its keep: it does not forbid anything, but it ensures a conversation happens first. Say a student wants AI to label 3,000 survey comments: a five-minute chat with the group leader leads to the question “what gold standard will you validate against?”, and that question can save the paper from a painful round of review.
Part 3: which tools
List the tools the group has checked the terms for, how to log in (institutional or personal account), and which data level each may handle. Keep it short; two or three well-vetted tools beat ten whose terms nobody has read.
Part 4: records and disclosure
- Each project keeps an AI use log: date, person, tool, purpose and which part of the work was affected.
- Before submission, the manuscript lead compiles the log into a disclosure statement in the journal’s required format.
- Every co-author approves the disclosure, just as they approve their contribution statement.
Updating the log takes seconds each time and saves hours when a journal or committee asks.
Part 5: students and assessment
If your group includes master’s or PhD students, say clearly which skills you want them to practise themselves (first drafts, choosing analyses) and how supervisors will check independent capability: oral discussion, code walkthroughs, draft history. This protects students more than it restricts them.
A one-page template
- Purpose: one sentence on why the policy exists.
- Data classes: the three-level table.
- Allowed, ask first, not allowed: the three-column table.
- Approved tools: names, login route, permitted data level.
- Records and disclosure: where the log lives and who owns it.
- Students: skills to practise and how they are checked.
- When unsure: whom to ask and how.
- Review: the date of the next update.
Writing and maintaining it
Do not leave it to the group leader alone. Spend a 45-minute meeting on it: each person describes what they currently use AI for, the group sorts those uses into the three columns, and one person drafts the text. Link to your institution’s and target journals’ policies rather than copying them. Review it every term, because tools and rules change quickly. When someone joins, spend ten minutes of their induction reading the policy together.
The simplest way to start: put “what is everyone using AI for?” on the agenda of your next group meeting. The list of answers is the first draft of your policy.
Câu hỏi thường gặp
Does a research group need its own AI policy?
It helps, because university and journal rules do not answer specific questions such as which group data may go into which tools, who decides and how to disclose on joint papers. One page is enough.
What should a research group AI policy include?
Data classification, lists of allowed, ask-first and prohibited uses, approved tools, record-keeping and disclosure, expectations for students, a contact for questions and a review date.
What data should never go into an AI assistant?
Identifiable participant data, health data, partner data under contract and manuscripts received for review should generally stay out of external tools. Unsubmitted manuscripts should only go into licensed tools with co-author agreement.
How do we write an accurate AI disclosure for a multi-author paper?
Keep an AI use log for each project, have the manuscript lead compile it into a disclosure before submission, and have every co-author approve it.
How often should a group AI policy be updated?
At least once a term, since tools and institutional and journal rules change quickly, and whenever the group adopts a new tool or takes on a project with special data restrictions.