An AI governance framework for a university sets out which body approves AI use, which uses are barred, what evidence must exist before a system goes live, and how students can contest a decision AI influenced. It works when the governing body owns the assurance, the academic board owns the standards, and the executive owns the operation, with one register connecting all three.
Most universities already have AI inside admissions sifting, marking support, learning analytics, wellbeing triage and clearing. Very few have a governing-body framework that names those uses, records who approved them, and shows the safeguards working. This is the higher-education version of a general UK AI governance framework, and it is close in structure to the AI policy template for schools and colleges, with one important difference: a university has two decision-making bodies, and the framework fails if it does not say which one decides what.
Key takeaways
- The framework needs three layers: assurance held by council or the board of governors, academic standards held by senate or the academic board, and operation held by the executive. One register links them.
- Bar the uses first. A framework that lists only good practice gives no one a reason to stop.
- Significant decisions about applicants and students taken without meaningful human involvement fall under Articles 22A to 22D of the UK GDPR, which replaced Article 22 in February 2026. The safeguards they require, including a route to human intervention, are legal controls.
- Fair access and marking support both engage the public sector equality duty, so an equality analysis has to exist and be dated before deployment.
- The Office for Students regulates the registered provider, not its suppliers. The conditions of registration stay with the institution however a system was built or bought, so vendor assurance is evidence rather than a defence.
Who this applies to
This is written for councils, boards of governors, courts and audit committees at English higher education providers. It matters most where AI already touches an applicant's chance of a place, a student's mark, a wellbeing flag, a visa compliance record, or a decision about academic misconduct.
The regulatory anchor in England is the OfS regulatory framework. Its conditions of registration on quality, standards and governance attach to the registered provider. Its public interest governance principles expect the governing body to receive and test assurance that academic governance is adequate and effective, through explicit protocols with the senate or academic board. The UK Quality Code is the sector reference point for academic standards across the UK, although in England it is not a regulatory requirement for most providers. Neither document is an AI rulebook. Both make the governing body answerable for outcomes AI can quietly change.
The framework transfers to Scottish, Welsh and Northern Irish institutions with a few substitutions. The regulator and funding body differ in each nation, the Quality Code applies across the UK, and the UK GDPR applies everywhere. The public sector equality duty in section 149 applies in England, Wales and Scotland; Northern Ireland has its own duty under section 75 of the Northern Ireland Act 1998. Large further education corporations can use the same structure with the corporation board in place of council.
The framework in three layers
The common failure is a single AI working group that reports nowhere in particular. Split the work by what each body can actually decide.
| Layer | Body | Owns | Cannot delegate |
|---|---|---|---|
| Assurance | Council, board of governors or court | Risk appetite, barred uses, approval thresholds, the annual statement that the boundary held | Accepting residual risk on behalf of the institution |
| Academic standards | Senate or academic board | Rules on generative AI in assessment, marking support, detection tools and misconduct procedure | Whether a qualification's integrity is protected |
| Operation | Vice-chancellor's executive group | The AI register, DPIAs, equality analyses, supplier due diligence, incident response | Naming an accountable executive for each live system |
Under this split, council does not review individual tools. It approves the boundary, then asks for evidence that the boundary held. Senate does not run procurement. It decides what AI may and may not do inside assessment. This is the same division the OfS governance principles already expect between governing body and senate, applied to one new class of system. If your institution has a single committee doing all three, write the terms of reference properly before you write anything else.
The policy skeleton you can copy
This is the document council approves. Ten sections, each short enough to be read.
1. Purpose and scope. Say what the policy covers: AI built in-house, AI bought as a product, AI embedded in a system you already license, and staff or student use of public tools. Example wording: "This policy applies to any system that produces an output used to inform a decision about an applicant, student or member of staff, however that system was acquired."
2. Barred uses. The section that does the work. Suggested clauses:
- No rejection of an application, at any stage of admissions or clearing, without a member of staff who has considered the case and can change the outcome.
- No AI-generated mark released to a student without a marker who has read the work and can change the mark.
- No accusation of academic misconduct founded on an AI detection score alone.
- No sensitive student data, including health, disability, ethnicity, religion, safeguarding records and immigration status, entering a tool that has not been through a data protection impact assessment.
- No AI system deciding the withdrawal of a student, the outcome of a complaint, or a fitness-to-practise referral.
3. Uses that need approval. Name the threshold rather than the tool. Any system that scores, ranks, flags or predicts anything about a named person needs approval by the nominated committee before pilot, not after.
4. Human review. State that the reviewer must have the authority and the time to reach a different answer, and that overturned outcomes are logged. Example wording: "A review is meaningful only where the reviewer can access the underlying evidence, is not measured on agreement rate, and records the reasons for confirming or changing the outcome."
5. Assessment and academic integrity. Cross-refer to the senate rules rather than restating them, and require a single published statement to students about where AI is permitted in their work.
6. Student rights. Set out how a student is told AI was involved, how they ask for an explanation, and how they contest an outcome. The ICO guidance on automated decision-making safeguards sets the floor: information about the decision, a way to make representations, human intervention and a route to contest. That guidance is still in draft following the 2025 Act, so date your reliance on it.
7. Data protection. Require a completed DPIA before go-live for any system processing student, applicant or staff data, per the ICO's DPIA guidance, with the DPO's advice recorded and the residual risk decision named.
8. Equality. Require a dated equality analysis for any system touching admissions, progression, attainment or support, and require the analysis to be repeated when the model changes.
9. Suppliers. State the minimum contractual position: disclosure of model changes, restrictions on training with your data, audit rights, security assurance, and an exit route that returns or deletes data. Our AI vendor due diligence questions give procurement a starting list.
10. Reporting and review. Say what council receives, how often, and what triggers an out-of-cycle review: a new system, a model change, an incident, a regulatory update, or an adverse assurance finding.
Ten sections, roughly six pages. If the draft is longer than that, it has drifted into a manual and the governing body will not read it.
Mapping to UK duties
The framework earns its place when each clause maps to a duty someone can be held to.
| Duty or source | What it requires | Where it lands in the framework |
|---|---|---|
| OfS regulatory framework | Conditions of registration on quality, standards and governance that sit with the registered provider; the governing body receives and tests assurance on academic governance | The assurance layer, the annual statement to council and the barred-use list |
| UK Quality Code | A UK-wide reference point for academic standards and quality, not a regulatory requirement in England | Senate rules on generative AI in assessment and marking |
| Articles 22A to 22D, UK GDPR | Safeguards for significant decisions taken without meaningful human involvement, and tighter limits where special category data is used | Barred uses and the human review clause. See our note on Articles 22A to 22D for boards |
| ICO AI accountability guidance | The organisation must comply and be able to show it has; most AI use of personal data will need a DPIA | The DPIA requirement and the register. Our DPIA guide for AI covers the process |
| Section 149, Equality Act 2010 | Due regard to eliminating discrimination, advancing equality of opportunity and fostering good relations; English university governing bodies are listed public authorities | The dated equality analysis, repeated on model change |
| DfE guidance on generative AI in education | Written for schools and colleges in England rather than universities; safety first, close supervision of pupils, and no personal data in generative tools | Safeguarding clauses where the institution teaches under-18s or further education courses |
| NCSC secure AI development guidelines | Security across design, development, deployment and operation, including supply chain | Supplier clauses and the security assessment before go-live |
| ISO/IEC 42001 and the NIST AI RMF | A management system and a voluntary risk process, rather than a one-off policy | The review triggers and the annual cycle |
Most English universities are exempt charities with the OfS as principal regulator, so charitable duties sit behind this rather than beside it. Governing-body members are charity trustees in law even though the institution is not registered with the Charity Commission, which is one more reason the assurance layer cannot be delegated to the executive.
Evidence the governing body should ask for
A framework is real when a member can ask one question and get a dated artefact.
| Question | Evidence | Owner |
|---|---|---|
| What AI is live here? | A register with system, purpose, data, supplier, decision type and approval date | Chief operating officer |
| Who approved the admissions tool? | Committee minute, with the barred-use test applied | Committee chair |
| Does human review change anything? | Review log showing confirmed, amended and overturned outcomes | Director of admissions or registry |
| Is the detection tool reliable enough to accuse a student? | Validation record, error rates and the misconduct procedure that references it | Academic registrar |
| Have we assessed the equality impact? | Dated equality analysis with named author and review date | Director of equality, diversity and inclusion |
| What happens when it goes wrong? | Incident log, escalation route and the last exercised test | Chief information officer |
If the answer to any of these is a supplier's brochure, the control does not exist yet.
Common mistakes
Writing the policy before taking the inventory. Departments adopt tools faster than committees meet. Start with what is already running.
Letting senate and council both own assessment. Two owners means no owner. Senate sets the academic rule; council asks whether the rule is being followed.
Treating detection tools as evidence. Detection scores carry error rates that fall unevenly across student groups. One Stanford study found detectors consistently misclassified essays by non-native English writers as AI-generated. A score can start an investigation. It cannot finish one.
Approving the pilot and forgetting the scale-up. Most risk arrives when a pilot in one faculty becomes a process for all applicants. Make scale-up a fresh approval.
Assuming the supplier's assurance is yours. The conditions of registration sit with the registered provider. A contract can allocate cost. It cannot transfer accountability to the OfS.
Next steps
Take an inventory first: every system that scores, ranks, flags or predicts something about a person, with the faculty or directorate that owns it. Then draft the barred-use list and take it to council before the full policy, because that is the conversation that surfaces disagreement.
For a first draft you can edit, our AI policy generator produces a structured starting document, and the Board AI Scorecard gives the governing body a short baseline before the paper is written. If the gap is wider than one policy, our work on AI governance for universities and colleges covers the framework, the committee design and the first year of assurance.
Last reviewed: 3 September 2026.
Sources: OfS regulatory framework; OfS public interest governance principles (Annex B); QAA UK Quality Code; ICO: what does the UK GDPR say about ADM; ICO automated decision-making safeguards; ICO DPIA guidance; ICO AI accountability guidance; Equality Act 2010 section 149; Charity Commission guidance on exempt charities (CC23); DfE generative AI in education; NCSC guidelines for secure AI system development; ISO/IEC 42001; NIST AI Risk Management Framework; Liang et al., GPT detectors are biased against non-native English writers.



