Industries

AI Governance for UK Universities: Closing the Gap

DATS is the AI consulting system from DILR.AI that places governance where student AI use has outrun university policy. This guide sets out a five-part framework for UK universities: a register, assessment rules per module, sanctioned tools, retained evidence and a termly review, recording decisions for OfS conditions B2 and B4 in England.

AI Governance for UK Universities: Closing the Gap DATS · EDUCATION AI Governance for UK Universities: Closing the Gap 38 % of UK undergraduates say they are provided with AI tools Source: HEPI, Student Generative AI Survey 2026 dilr.ai/blog

UK undergraduates have already decided how they will use AI. Many of their universities are still deciding. In the HEPI Student Generative AI Survey 2026, fielded by Savanta in December 2025 across 1,054 full-time UK undergraduates, 95% report using AI in at least one way and 94% use generative AI to help with assessed work. Only 38% say their institution provides them with AI tools. That gap between what students do and what the institution provides and supports is the governance problem this post is about.

It is not a technology shortage. Across organisations generally, McKinsey's State of AI reports that 88% of organisations already use AI in at least one function. What universities often lack is a standing system that tells a registrar, a quality office and a data protection officer which uses are permitted, which assessments still test what they claim to test, and where the evidence sits when a regulator or an appeals panel asks. Our enterprise AI consulting guide covers AI governance for regulated sectors in general; this post applies the question to a university.

The scope is deliberate. We write for the Director of Innovation and the university COO who owns governance sign-off, and we anchor the regulatory duties to England, where the Office for Students (OfS) regulates registered providers. We cede three neighbouring questions to posts that already answer them: schools, multi-academy trusts and the DfE product safety standards sit in our AI tutor safeguarding guide for schools and trusts; the cross-line map of where AI pays across education sits in our education sector hub; and the choice of a tutoring or teaching platform sits in our AI teacher buyer's guide.

This guide is shipped by the team behind DATS, the five-stage AI consulting system from DILR.AI, delivered by senior practitioners who ship code, not decks. Or see our AI operating model work, which sets governance, RACI and lifecycle so the result is audit-ready by design.

Why is university AI governance behind student adoption?

University AI governance is behind student adoption because students adopted generative AI individually and immediately, while institutions must agree policy across faculties, assessment boards, data protection and procurement before they act. In HEPI's 2026 student survey, 95% of UK undergraduates use AI, yet only 38% are provided with AI tools, and opinion on whether institutions encourage AI use splits almost evenly, at 37% agreeing and 36% disagreeing.

HEPI describes that even split as a polarised landscape, and the detail matters for anyone designing a policy. Students at Russell Group institutions are the most likely to say their institution encourages AI use, at 39%, up from 26% a year earlier, a rise of 13 points between two editions of the survey. In the same HEPI survey, 68% of students believe AI skills are essential, while fewer than half, 48%, feel their teaching staff are helping them develop those skills. The demand for direction is explicit.

Staff are in the same position. Jisc's Digital Experience Insights survey of higher education professional services staff for 2024/25 found that 39% used AI in their roles, up from 25% the previous year, but only 30% reported being provided with AI systems by their organisation. Use is running ahead of provision, which is the university version of shadow AI, a pattern our shadow AI governance guide describes for enterprise voice agents.

The money makes the delay harder to fix. The OfS report on the financial sustainability of higher education providers in England 2026, published on 14 May 2026, records that 100 providers, 35.8% of the sector, reported deficits in 2024-25, and that forecasts show 119 providers, 42.7%, in deficit in 2025-26. The same report notes that 2024-25 came in better than providers had forecast, but a governance programme still competes with every other call on a constrained budget. That is a reason to build on the committees and records a university already keeps, and it is the approach this post describes.

UK undergraduates: AI use against institutional support
95%Use AI94%Use for assessed work68%AI skills essential48%Staff help build skills38%Given AI tools
Share of 1,054 full-time UK undergraduates, surveyed by Savanta for HEPI in December 2025. Source: HEPI, Student Generative AI Survey 2026

What does OfS condition B4 require when students use generative AI?

OfS condition B4 requires a registered provider in England to ensure students are assessed effectively, that each assessment is valid and reliable, and that awards are credible. The OfS defines effective assessment to include assessments designed to minimise opportunities for academic misconduct and to help detect it. Condition B4 does not mention generative AI by name, so each university must decide what valid assessment means once AI is everywhere.

The duty binds the registered provider, not the student, not the AI vendor and not the student union. The OfS sets it out in its quality and standards conditions of registration, and the guidance attached to condition B4 gives illustrative examples of what would likely concern the regulator. One of them is general, but it applies plainly to work produced with generative AI:

"Assessments designed in a way that allows students to gain marks for work that is not their own would likely be of concern." Office for Students, quality and standards conditions of registration, guidance to condition B4

The same guidance adds that a provider not taking reasonable steps to detect and prevent plagiarism, essay mills or other academic misconduct would likely be of concern. Under condition B2, the support a provider must take all reasonable steps to ensure includes support relating to understanding, avoiding and reporting academic misconduct. Read together, the two conditions put the burden on assessment design, detection and support at once. Detection on its own is not enough: a university also needs assessments that still test the student, and HEPI's recommendation of clear, assessment-specific guidance is the practical way to show students what was permitted.

That is why HEPI's numbers matter to a quality office. The share of students who directly include AI-generated text in assessed work rose to 12% in 2026, from 8% in 2025 and 3% in 2024, and 65% of students say assessment has changed significantly in response to AI. Some students report anxiety about false accusations of misconduct. An institution whose rules differ module by module, with no record of what each module allowed, is exposed on both sides: to work that is not the student's own, and to misconduct findings that are hard to explain when a student disputes them.

The OfS is also researching the sector's response. Its artificial intelligence in higher education page, published on 27 May 2026, describes a research project with Advance HE on how universities and colleges are responding to AI, with roundtables concluded and findings planned for later this year. The OfS says the findings are meant to help institutions consider how to use AI tools, develop policies to mitigate risks and strengthen their AI capabilities, so they are worth reading against any governance built now.

What should a university AI governance system actually contain?

A university AI governance system should contain five working parts: a register of every AI use across teaching, research and professional services; assessment rules set per module and recorded centrally; sanctioned tools that students and staff can actually reach; retained evidence of each decision; and a termly review. The register and the sanctioned tools are usually new work; the other three can build on things a university already runs, such as its module catalogue, records schedule and committee cycle.

A university AI governance evidence system
01Register every useTeaching, research and professional services02Set assessment rulesPer module, recorded centrally03Provide sanctioned toolsEqual access for every student04Retain the evidenceDecisions, briefs and assessed work05Review each termThrough the existing committee cycle
Our five-part governance framework, separate from the DATS engagement stages.

The register. Start with what is already in use, not with a policy draft. Professional services teams, faculties and research groups each hold tools the centre has never seen. The register records the tool, the owner, the data it touches and the decision it informs. Our guide to building an AI tool inventory for UK regulators sets out the columns that matter; a university adds the module or service each tool supports.

Assessment rules per module. HEPI recommends that providers publish clear, accessible and assessment-specific guidance on AI use. The operative word is assessment-specific. A single institutional statement cannot tell a student whether a reflective essay in nursing and a coding assignment in computer science allow the same tools. The rule belongs in the assessment brief, and a copy belongs in a central record so that an appeals panel can see what the student was told.

Sanctioned tools. HEPI also recommends ensuring that the AI tools necessary or advantageous for a course are accessible to all students. Equal access is a fairness point the Russell Group principles on generative AI, published on 3 July 2023, raised when they warned that generative AI tools may sit behind paywalls. Providing a sanctioned tool also gives the university one place to assess how student and staff data are handled.

Retained evidence. The OfS asks providers to retain appropriate records of assessed work for five years after the end date of a course, and to document how they decided what to retain. Add the assessment brief and its AI rule to that record and the university can show, years later, what each cohort was permitted to do.

Termly review. A policy written once and left alone drifts away from the tools students and staff actually use. A short review each term, run through the existing learning and teaching committee, keeps the register and the rules current without creating a new body to fund.

Where a university wants this run inside the institution, our AI execution office is embedded delivery, with production placements the institution owns.

Who owns AI governance inside a university?

AI governance in a university should be owned by one named senior officer, for example the COO or a Pro Vice-Chancellor, with defined roles for the academic registrar, the quality office, the data protection officer, IT and each faculty. Ownership matters because the OfS conditions bind the provider as a whole, so no single faculty or professional service can carry the risk alone, and a split decision becomes nobody's decision.

The decision rights split along existing lines, which is what makes the model affordable. The conditions bind the provider, so this allocation is a design choice rather than a rule. In our framework the academic registrar and the quality office own the assessment rules and the misconduct process, because they usually run assessment regulations already. The data protection officer advises on which personal data may enter which tool, while the decision stays with the institution as controller. IT owns the sanctioned tool estate and its access controls. Each faculty owns the module-level rule, because, as the Russell Group principles note, appropriate uses are likely to differ between academic disciplines. The senior owner arbitrates when those positions conflict and signs the termly review.

Write this down as a RACI, not a committee terms of reference. Our delivery team RACI for voice AI shows the format for one AI system; a university runs the same table across its register. An AI operating model is the engagement that sets those decision rights, governance and lifecycle so the record is audit-ready by design rather than reconstructed after a complaint.

Staff capability belongs in the same table. HEPI's recommendation that staff get access to AI training and the time to use it lines up with Jisc's finding that fewer than a quarter of professional services staff had time to explore new tools. For learner and staff training as a product, see Dilr Academy, which the education sector treats as a separate decision.

How should a university evidence AI decisions for the OfS and the ICO?

A university should evidence AI decisions by keeping, for every registered use, the decision, its owner, the data it touches, the assessment rule students were given and the date it was last reviewed. For the OfS, that record supports the case that assessment rules were designed and communicated. For data protection, it shows the institution, as controller, assessed personal data risk before deployment rather than after an incident.

The ICO side needs care in 2026. The ICO's guidance on AI and data protection carries a notice that it is under review because of changes made by the Data (Use and Access) Act, and that it may be subject to change. Its accountability chapter still covers what to consider in a data protection impact assessment. The practical reading is to keep the DPIA as the record of each high-risk use and to check the guidance for updates at each termly review rather than waiting for a final version.

Most of the evidence already exists in pieces. Module catalogues often hold assessment briefs. Records teams already handle retained assessed work. Procurement holds the contracts for sanctioned tools. What is usually missing is the join between them: a single view that answers which modules permitted which tool, under which rule, at which date. Building that join is a knowledge system problem, close to the enterprise knowledge retrieval solution listed among our enterprise AI solutions.

Do not let the evidence system make decisions it should only record. An AI system that drafts an assessment brief, summarises a misconduct file or flags a gap in the register is assisting a named human. A system that decided a misconduct case or graded assessed work would be taking a decision the provider should keep with accountable staff. Keep the line visible in the register itself, with a column that names the human who decides.

The engagement itself follows the DATS five-stage methodology: Discover and Diagnose, Prioritise and Place, Operating Model, Pilot to Production, Scale and Run.

What is the best approach to university AI governance in 2026?

The best approach to university AI governance in 2026, for most English providers, is a light evidence system run through existing committees: a central register, assessment rules per module, sanctioned tools, retained records and a termly review. We prefer it to a standalone AI policy because it leaves a record that can be shown when conditions B2 and B4 are tested. It is not always the right answer, and three alternatives win in specific circumstances.

When an in-house team wins. A university with an established digital education unit, an academic integrity office that already logs module-level assessment rules and records that retain them may need nothing external. The register and the termly review are the only additions, and its own staff know the committee cycle better than any outsider.

When an audit firm wins. Where the question is assurance rather than build, such as a governing body that wants an independent opinion on AI risk for its audit committee, an assurance provider such as the internal auditor is the better fit, and the large audit firms, Deloitte, PwC and KPMG among them, offer assurance work. An assurance review is a different product from an operating system that staff run every term.

When a specialist consultancy fits. Where the register does not exist, faculties disagree and the evidence sits in systems that do not talk to each other, a consultancy that builds alongside staff can help. That is the work DATS does: a four to six week placement diagnostic that produces a ranked roadmap of where AI belongs and where it does not, an operating model that sets governance, RACI and lifecycle, and embedded delivery with placements the university owns. Other AI consultancies, Faculty among them, work in the same market; compare scope, handover and who runs the system after the engagement ends.

Whichever route a university takes, judge it on four criteria: does it produce evidence an OfS assessor could read; does it give students assessment-specific rules before they submit; does it give equal access to sanctioned tools; and does it survive the departure of the person who built it. For how a university's enquiry and admissions lines fit alongside this, see our AI voice guide for higher education admissions, and for why we embed rather than deliver projects, read about the embedded AI delivery team model.

Frequently asked questions

Does OfS condition B4 ban students from using generative AI?

OfS condition B4 does not ban students from using generative AI. It requires registered providers in England to assess students effectively, with valid and reliable assessments and credible awards. A university may permit, require or restrict AI in a given assessment, provided the design still tests the student's own achievement; HEPI recommends making the rule clear in assessment-specific guidance. HEPI notes many students will be encouraged or required to use AI.

That is why the rule belongs in the assessment brief rather than in a single institutional policy. Our enterprise AI consulting guide covers how the same principle, rules set where the work happens, applies in other regulated sectors.

Does this apply to universities in Scotland, Wales and Northern Ireland?

The OfS conditions described here apply to registered higher education providers in England only. Universities in Scotland, Wales and Northern Ireland sit outside the OfS conditions, and this post does not cover the arrangements that apply to them. The HEPI survey sampled full-time UK undergraduates, and the five-part evidence system does not depend on any one regulator, but the regulatory anchor changes.

UK GDPR and the ICO apply across the whole UK, so the data protection side of the register is the same in every nation. For the cross-line view of education, including where Dilr Voice and Cognibl, from DILR.AI, fit for admissions and operations desks, see the education sector hub. For more posts in this category, browse our industry guides.

Want to see this in production? Start with DATS AI consulting, read the AI teacher platform buyer's guide, see Cognibl for operations desks, or explore Dilr Voice for admissions lines.

Service
AI Placement Diagnostic
Service
AI Operating Model
Service
AI Execution Office
Talk to the operators

Turn AI rules into evidence your university can show.

30-min scoping call · No deck · Confidential. We will tell you whether DATS fits, and which register, rules and records to build first.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

ai governance uk universitieseducationhigher education ai policy ukuniversity ai assessment rulesai governance universities redditbest university ai governance approach 2026ai consulting education sector ukdats

Questions this article answers

Why is university AI governance behind student adoption?

University AI governance is behind student adoption because students adopted generative AI individually and immediately, while institutions must agree policy across faculties, assessment boards, data protection and procurement before they act. In HEPI's 2026 student survey, 95% of UK undergraduates use AI, yet only 38% are provided with AI tools, and opinion on whether institutions encourage AI use splits almost evenly, at 37% agreeing and 36% disagreeing.

What does OfS condition B4 require when students use generative AI?

OfS condition B4 requires a registered provider in England to ensure students are assessed effectively, that each assessment is valid and reliable, and that awards are credible. The OfS defines effective assessment to include assessments designed to minimise opportunities for academic misconduct and to help detect it. Condition B4 does not mention generative AI by name, so each university must decide what valid assessment means once AI is everywhere.

What should a university AI governance system actually contain?

A university AI governance system should contain five working parts: a register of every AI use across teaching, research and professional services; assessment rules set per module and recorded centrally; sanctioned tools that students and staff can actually reach; retained evidence of each decision; and a termly review. The register and the sanctioned tools are usually new work; the other three can build on things a university already runs, such as its module catalogue, records schedule and committee cycle.

Who owns AI governance inside a university?

AI governance in a university should be owned by one named senior officer, for example the COO or a Pro Vice-Chancellor, with defined roles for the academic registrar, the quality office, the data protection officer, IT and each faculty. Ownership matters because the OfS conditions bind the provider as a whole, so no single faculty or professional service can carry the risk alone, and a split decision becomes nobody's decision.

How should a university evidence AI decisions for the OfS and the ICO?

A university should evidence AI decisions by keeping, for every registered use, the decision, its owner, the data it touches, the assessment rule students were given and the date it was last reviewed. For the OfS, that record supports the case that assessment rules were designed and communicated. For data protection, it shows the institution, as controller, assessed personal data risk before deployment rather than after an incident.

What is the best approach to university AI governance in 2026?

The best approach to university AI governance in 2026, for most English providers, is a light evidence system run through existing committees: a central register, assessment rules per module, sanctioned tools, retained records and a termly review. We prefer it to a standalone AI policy because it leaves a record that can be shown when conditions B2 and B4 are tested. It is not always the right answer, and three alternatives win in specific circumstances.

Does OfS condition B4 ban students from using generative AI?

OfS condition B4 does not ban students from using generative AI. It requires registered providers in England to assess students effectively, with valid and reliable assessments and credible awards. A university may permit, require or restrict AI in a given assessment, provided the design still tests the student's own achievement; HEPI recommends making the rule clear in assessment-specific guidance. HEPI notes many students will be encouraged or required to use AI.

Does this apply to universities in Scotland, Wales and Northern Ireland?

The OfS conditions described here apply to registered higher education providers in England only. Universities in Scotland, Wales and Northern Ireland sit outside the OfS conditions, and this post does not cover the arrangements that apply to them. The HEPI survey sampled full-time UK undergraduates, and the five-part evidence system does not depend on any one regulator, but the regulatory anchor changes.

Dilr Voice

Voice AI built for your sector

Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.

Related articles

← Previous
Writer.com Alternative UK: A Brand Team Switching Guide

One email, once a month. No hype. Just what we learned shipping.