Two-fifths of UK universities do not have a publicly accessible artificial intelligence policy, according to a new report that criticises the lack of a shared approach across the sector and warns that many existing policies "promise support but deliver surveillance".
The study, What UK University AI Policies Actually Do: A Study of 96 Institutions (HEPI Policy Note 71), was published on 21 May by the Higher Education Policy Institute and authored by Professor Sam Illingworth of Edinburgh Napier University. It examines AI policies across 96 UK degree-awarding institutions and reveals a significant gap between stated intentions and actual implementation.
41% with no accessible policy
The report found that 41 per cent of UK degree-awarding institutions have no AI policy that a student, parent or regulator can easily find online. Some policies sit behind login walls, others return broken URLs, and many cannot be found through a search engine at all.
Of the 163 institutions with degree-awarding powers analysed, only 96 had publicly accessible AI policies. The remaining 67 institutions either had no discoverable policy or one that was "locked behind authentication walls", for example on a university intranet that requires a login.
Education language, discipline reality
The paper argues that most of the 96 policies that are publicly accessible use the language of learning but actually operate as detection-and-discipline frameworks. A computational count of 77 keywords across all 96 policies suggested 86% of the policies were education-dominant. However, a close reading by the author of a subset of 19 policies found close to half had been misclassified, with educational vocabulary being used to dress detection-and-discipline architectures.
According to Times Higher Education, Professor Illingworth found that many policies emphasise a desire to "help students use artificial intelligence" but in practice "promise critical thinking but deliver audit trails" and "name support yet deliver surveillance".
The University of Southampton's policy, for example, promises to produce "critically digitally literate" graduates but actually serves as a "binary list of acceptable and unacceptable uses anchored by an early threat: 'We will take disciplinary action that may result in penalties on your marks'".
No shared approach across the sector
The report reveals that the sector has no shared approach. 163 institutions have 163 separate responses to the same challenge, with framing that ranges from "educative, not punitive" to language that treats non-declaration of AI use as evidence of concealment. A student transferring from one institution to another may find policies that differ in fundamental orientation, not only in detail.
The report also found that a policy's location predicts its function more accurately than the language used. Policies hosted within academic misconduct frameworks enforce. Policies hosted within learning and teaching frameworks educate. Vocabulary alone does not move the needle.
Notably, no policy in the sample states "we trust students". The dominant model is conditional trust: students are trusted only if they declare their use, retain evidence and submit to verification.
Professor Illingworth said: "Universities are supposed to develop critical thinkers. If an institution's own AI policy cannot model critical thinking about AI, if it resorts to compliance while claiming to educate, then the policy contradicts the mission. The deficit model does not require punitive language to reproduce itself. It requires only the assumption that students cannot be trusted to think".
Four exemplars identified
The report identifies four exemplars in the AI policies of Durham University, the University of Stirling, Canterbury Christ Church University and Arts University Plymouth. These span all four major institution types: Russell Group, other pre-92, post-92 and specialist.
They demonstrate that AI policy can extend trust, develop critical literacy and address risk through focusing on assessment design rather than detection.
At more than 9,000 words long, Durham's policy is said to allow "thinking out loud" and "distinguishes explicitly between academic misconduct and 'unwise or unethical' behaviour, and refuses to use the misconduct process to police the latter".
Nick Hillman OBE, Director of the Higher Education Policy Institute, said: "Every university in the world is wrestling with how to respond to AI. The technological developments of the last few years are causing huge changes for academics, students and managers".
"This report assesses the state of play on guidance for students, nearly all of whom now regularly use AI. It argues some universities still need to hone their response to AI into something that is pedagogically sound and genuinely helpful to students".
Five principles for student-centred AI policy
The report sets out five principles for a student-centred AI policy:
-
Location determines framing — policies hosted within misconduct frameworks enforce; policies hosted within learning frameworks educate
-
Trust should be the default — rather than conditional trust based on declaration and verification
-
Student voice should shape the policy — students should be involved in developing institutional approaches
-
Critical literacy should replace tool proficiency — focus on developing students' ability to think critically about AI rather than simply learning to use specific tools
-
Policies must be publicly accessible — not hidden behind login walls or buried on institutional websites
Context and implications
The findings come as the HEPI/Kortext Student Generative AI Survey 2026 found that 95% of UK undergraduates are using AI in at least one way, and 94% are incorporating it into assessed work — a sharp rise from just 3% in 2024.
The report's author suggests the "performative gap may well be unintentional" and a "structural consequence of producing educational guidance within regulatory architectures". "The response to AI has been absorbed into existing governance structures, and many of those structures were already organised around detection and punishment".
Professor Illingworth also found that all the policies appear to have been developed "in isolation", with universities "producing documents that range from genuine critical literacy resources to one-paragraph additions to misconduct procedures" and no sector body coordinating efforts.
The report serves as a wake-up call for UK higher education institutions, urging them to move beyond compliance-driven approaches and develop AI policies that genuinely support student learning in an era of near-universal AI adoption.
