Businesses are writing AI policies, creating approved-tool lists, and adding AI questions to compliance reviews. But a policy is not yet an operating control unless the organization can say what counts as AI use, what counts as a violation, and how either event will be recorded.
Without those definitions, an increase in reported AI incidents can be difficult to interpret. It might indicate more prohibited use. It might also reflect better detection, clearer rules, new reporting requirements, or a change in how incidents are categorized.
Maryland’s public universities provide a useful case study.
The Baltimore Banner recently requested records of AI-related academic-misconduct violations from Maryland’s 12 public campuses. Six reported more violations in 2025–26 than in 2023–24. At the University of Maryland, College Park, the number rose from 120 to 208.
That sounds like a clean trend, but the underlying records are not clean enough to support a simple conclusion.
College Park said its total number of academic-misconduct referrals remained about the same. Three campuses could not readily provide AI-specific records, and another had not tracked the category throughout the period. One College Park professor told The Banner that she had caught several students using AI but handled those cases herself instead of referring them to student conduct.
The numbers are real. What they measure is less certain.
An increase in recorded AI violations could reflect more prohibited use. It could also reflect better detection, clearer rules, different reporting practices, a new database category, or instructors becoming more likely to escalate cases they once handled informally.
Those possibilities are not interchangeable. Distinguishing among them is the work of governance.
A Policy Needs an Observable Event
If an organization wants to govern AI use, it first needs to define the event it is trying to control. “Used AI” is usually too broad.
A person might use an AI system to:
- Find or organize sources
- Brainstorm possible approaches
- Summarize background material
- Rewrite existing prose
- Generate a first draft
- Answer a question directly
- Check grammar or clarity
- Translate content
- Produce code or images
- Recommend an action for human review
These activities carry different risks and have different relationships to the work being evaluated. A useful policy therefore needs a task-specific taxonomy of permitted, restricted, and prohibited uses.
The University of Maryland’s current guidance illustrates the importance of that context. It encourages instructors to establish course-specific policies and tells students to assume that AI use on assignments is prohibited unless the syllabus or assignment says otherwise. It also recognizes permitted learning uses and calls for disclosure and attribution when AI is used.
The rule is not simply “AI is allowed” or “AI is banned.” The boundary depends on the task, the instructor’s policy, and what the student does with the system.
If those distinctions are unclear, enforcement becomes an impression followed by paperwork.
Disclosure Is Part of the Control
Many permitted uses of AI cannot be inferred reliably from the finished work. If a policy allows some uses and prohibits others, people need a practical way to describe what they did.
A short disclosure might record the tool used, the task supported, the output incorporated, and the human review performed.
In a classroom, that could appear at the end of an assignment. In a company, the same information could become part of a change record, content workflow, model-use log, or approval step.
Disclosure is not bureaucratic decoration. It makes the governed activity visible enough to review. It also gives the organization evidence that is more useful than attempting to reconstruct an entire process from the final output.
Enforcement Data Needs a Common Schema
The Maryland records show what happens when institutions try to compare events that were not recorded consistently.
If one instructor reports every suspected violation, another handles cases privately, and a third institution records AI misuse under a broader plagiarism category, their totals are not directly comparable without substantial caveats.
Organizations create this problem when they publish a policy before checking whether their incident systems can answer basic questions:
- What rule was allegedly violated?
- What AI capability was used?
- What task was the person performing?
- Was that use permitted, restricted, or prohibited?
- Was the use disclosed?
- What evidence supported the finding?
- Who reviewed the case?
- What corrective action occurred?
- Was the decision appealed?
- Did unclear guidance contribute to the incident?
Without common fields and definitions, the organization has enforcement anecdotes rather than governance data.
Detection Is Not Evidence
AI detection introduces another source of uncertainty. A tool can flag a document without establishing what happened or whether a policy was violated.
UMD’s guidance advises instructors to treat AI-detection results as possible indicators of misconduct, not definitive proof or the sole basis for grading decisions. That distinction should travel well beyond education.
A governance process must document its evidence standard separately from its detection methods. It must also identify who is authorized to evaluate that evidence and what recourse exists when the evidence is incomplete or disputed.
Otherwise, the operative standard quietly becomes whatever the detector says today.
The Measurement Problem Is the Governance Problem
It is tempting to ask whether AI cheating is rising across Maryland’s public universities. The available data supports a narrower conclusion: reported AI-related violations increased at several campuses.
That is useful information. It is not the same as measuring the prevalence of prohibited AI use.
The distinction matters anywhere an organization wants to govern AI-assisted work. A serious policy needs more than a principle such as “use AI responsibly” or “disclose when appropriate.” It needs an operating chain:
- Scope
- Permitted uses
- Prohibited uses
- Disclosure
- Evidence standard
- Recording schema
- Reviewer
- Corrective action
- Appeal
- Trend analysis
If those pieces are missing, the organization may have a rule. It does not yet have an operating control.
Sources: The Baltimore Banner’s reporting on Maryland campuses and the University of Maryland’s Guidelines for the Use of Generative AI.
