TFIS · AI Ethics in Education · Course
Developing Institutional
Guidelines — Part 1
Ethical AI Use in Teaching and Learning · Diagnose
Session 6 · Wednesday 2 September 2026 · 8.00–10.00 pm
Re-entry · from craft to constitution
SAY
"This afternoon you fixed a course. Tonight we ask why you had to. A lecturer redesigning
assessments alone is heroism; heroism is what institutions run on when governance is absent.
The Index number from Monday: only 6% of teachers say their school's AI policies are clear. Not 6%
say policies are good — 6% say they're clear. Clarity is the whole product tonight.
Axiom seven: policy is a product. It ships with a version number, it has users, and it dies
without maintenance. You are now product teams."
Exercise · Institutional maturity scan · 20 min · teams
Score your institution. Honestly.
- 10 items, 0–4 each (instrument in your pack). Policy findable? Context-specific? Student-facing? Evidence standards? Data rules? Funded staff development? Equity of access? Named owner? Student voice?
- If central policy is absent, score your faculty — the absence is itself a datum.
- Team totals harvested on the board. Typical Malaysian HE in 2026: L1–L2.
SAY
"Nobody in this room caused this score, and everybody in this room can move it. Only about half of
schools have AI policies at all — your institution having a score puts it mid-pack. Wednesday it moves."
Policy anatomy · the drafting skeleton for tomorrow
A complete guideline answers seven questions
| # | Component | The move |
| 1 | Scope & definitions | Most policy fights are secretly definition fights — settle them here. |
| 2 | Principles | The five from Session 2, localized. Principles survive model churn; rules get versioned. |
| 3 | Permission architecture | Three-lane vocabulary institutionalized: every course declares lanes per assessment. One unenforceable blanket rule → a thousand enforceable local ones. |
| 4 | Disclosure standard | One canonical format, used by students and staff. Symmetry is credibility. |
| 4b | Instructor AI-use disclosure | Parallel to student disclosure. Instructors disclose their own AI use in teaching materials, feedback, and grading. The double standard (faculty use AI; ban students) erodes trust. Mirror test required. |
| 5 | Integrity procedure | Process evidence primary; detector explicitly demoted to at-most-screening — with the Patterns citation attached. Policies with footnotes get challenged less. |
| 6 | Data & privacy rules | The PDPA floor: which data, which tools, what agreements. Institutional accounts over personal. Add platform governance: AI-platform logging, auditing, anonymization, and mental-health flag protocols (§3.3.8–9 of MIT report). |
| 7 | Ownership & review | Named owner, version, review date ≤12 months, student representation. Include monitoring metrics: AI-use surveys, campus engagement data, post-graduation feedback sources. A policy without an owner and data is a wish. |
| 8 | Roles, infrastructure & funding | Who is responsible for AI leadership (AI Lead / committee), implementation support (AI Fellows / training), and resources (Pilot Fund). Without infrastructure, the policy is a poster on a wall. |
You are not inventing this alone
Malaysia is building the same thing, one scale up
The proposed national AI Governance Bill (NAIO consultation fact sheets):
- Principle-based, not rule-based — rigid rules go stale; principles get operationalized by lighter instruments. "Regulate and forget" → "adapt and learn."
- A Central Authority with a named mandate — set principles, ensure safety, investigate incidents, build capacity.
- Obligations proportional to risk. Phased implementation: socialize first, codify later.
SAY
"Your guideline is the proposed AI Bill scaled to a faculty: same logic, smaller jurisdiction.
You're not writing a house rule. You're practicing national governance."
NAIO AI Governance Bill consultation fact sheets (proposed — verify current status at delivery)
The crosswalk · Bill principles ↔ your Session 2 lens
| Bill principle (proposed) | Course principle (S2) | Feeds component |
| 1 · Human Dignity, Agency & Rights | Autonomy (+ beneficence) | 2 · Principles; 3 · Lanes |
| 2 · Transparency & Explainability | Explicability | 4 · Disclosure |
| 3 · Accountability & Redress | Responsibility triad; justice | 5 · Integrity; 7 · Ownership |
| 4 · Safety, Security & Robustness | Non-maleficence | 3 · Lanes; assessment design |
| 5 · Responsible Data Stewardship | Justice + privacy | 6 · Data rules (PDPA) |
You aren't adopting a foreign framework. The national direction and the classroom ethics converge on the same five ideas.
The Bill's risk framework → your permission architecture
| Bill tier (proposed) | Obligations | Course-level equivalent |
| Tier 1 · Unacceptable | Prohibited | Uses that corrupt the credential itself — 🔴 plus procedural bar |
| Tier 2 · High risk | Risk assessment · documentation · traceability · human oversight · testing · monitoring · incident notification | Anything touching grades, references, admissions, records: human decision, AI second-reader at most, records kept, disclosure mandatory |
| Tier 3 · Low risk | Baseline duties + "due regard" | Ordinary coursework — 🟡 with disclosure; 🟢 where fluency is the outcome |
Notice: the Tier-2 obligation list is your S4 verification-log habit at institutional scale. You've been rehearsing compliance since this morning.
What good looks like · extract the moves, not the text
- Devolved-but-scaffolded (the Stanford/Harvard/MIT pattern): a short university-level floor — privacy, disclosure, defaults — with explicit instructor authority to set course rules provided they state them in writing. Adopt this shape.
- Default rules matter more than ideal rules. The best policies state what applies when a syllabus is silent — because most will be. Decide tonight: silence = 🟡 permitted-with-disclosure is the honest choice; silence = 🔴 is the common but fictional one.
- The teachable-policy test: if it can't be taught to first-years in ten minutes, it will not govern anything. Length is a bug.
- [LOCAL] layer: MQA terminology, current MOHE guidance, PDPA 2010 mapping for component 6 — slots marked in the S7 template, filled by whoever owns component 7.
Exercise · Gap analysis + mirror test · 40 min · teams · P12
Three gaps, evidenced — plus a mirror moment
Gap analysis (25 min): Take your scan results + the new 8-component skeleton. For each of your three lowest-scoring areas, one page total:
- Current state — evidence, one line
- Target state — which component fixes it
- Cost of inaction — one concrete scenario from this course's evidence
Mirror test (15 min): Before you draft policy for students, audit yourself.
- Open your own AI chat history from this week.
- For each use: did you disclose it in the output that reached students?
- Would your draft policy allow you what you just did?
- If the double standard gap (G3) is ≥2 levels wide, add a staff-disclosure component to your drafting brief.
Gate · drafting brief · 15 min · entry ticket to S7
No brief, no draft
Each team submits before leaving:
- Three gaps, ranked
- Default rule chosen (what silence means)
- Disclosure format sketched (from your P05 work — include instructor-disclosure parallel)
- Components selected: 4b (instructor disclosure) and 8 (infrastructure) — optional or required?
- [LOCAL] owner nominated
Close
SAY
"Tomorrow morning you write version 0.1. Not the perfect policy — the shippable one.
Perfect is what institutions say while shipping nothing. You have nine component slots — use what
your context needs. The 8-component skeleton and the mirror test you just ran are your insurance
against the two biggest policy mistakes: no infrastructure and a double standard. Tidur — the sprint starts at 8.30."
Appendix · facilitator only
Notes
- Longest lecture block tonight: policy anatomy + national frame ≈ 12 min each side of the scan. Everything else is teamwork.
- Bill status language: always "proposed" / "consultation" — verify current status the week of delivery.
- Reference: sources/malaysia-ai-governance-note.md + sources/AI_Governance_Bill_Fact_Sheet.md
- New this delivery: Component 4b (instructor disclosure), Component 8 (infrastructure), mirror-test exercise. The MIT report (§3.2.3, §3.3.1–4) provides the evidence base. Direct participants to aiandeducation.mit.edu/report/ for further reading.