TraceYield

AI Coding Policies for HBO-ICT: What Should Lecturers Actually Require?

A practical assignment-level policy checklist for HBO-ICT lecturers covering permitted tools, disclosure, privacy, verification, attribution, and explanation.

TY

TraceYield Insights

11 min read · Updated August 25, 2026

TraceYield

AI engineering evidence

AI Coding Policies for HBO-ICT: What Should Lecturers Actually Require?

A broad institutional policy is not enough

Students need to know what they may do in this assignment, not only that their institution has a general AI policy. A course team should translate institutional principles into a short, visible set of requirements tied to the learning outcomes and the technology students will encounter.

The policy should not become a legal document. It should answer practical questions: which tools are permitted, which activities are allowed, what must be disclosed, what must be verified, what data may not be shared, and what happens when a student is unsure.

State the permitted use by task

Separate explanation, brainstorming, code generation, debugging, testing, refactoring, and agentic changes. A course may allow an assistant to explain an error while requiring students to write a core algorithm themselves. Another may permit a coding agent because evaluating and supervising one is part of the outcome.

Avoid vague labels such as “AI allowed” when the assessment carries different expectations. A small table with allowed, disclose, verify, and not allowed columns is often clearer than several paragraphs.

Require material disclosure

Ask students to name the tool category, purpose, material contribution, important modification, and verification. Do not require every trivial interaction. The disclosure should help the assessor understand the work and should be short enough to complete honestly.

Explain that disclosure does not automatically reduce a mark. What matters is whether use was within the rules and whether the student can demonstrate the required learning.

Include privacy and data handling

Students should know whether code, course material, client information, credentials, or personal data may be entered into an external tool. The policy should point to the institutional data classification and give a safe alternative for sensitive work. Lecturer-provided repositories and workplace projects may have additional obligations.

This is a teaching opportunity. Responsible programming includes recognizing that a convenient prompt can disclose information to a service with terms and retention behavior the student has not evaluated.

Define verification and accountability

Generated code is not exempt from normal engineering responsibility. Require students to run relevant tests, inspect assumptions, check dependencies, review security and privacy implications, and explain what the evidence does not prove. Make the level proportionate to the task risk.

The student remains accountable for submitted work even when a tool produced part of it. That does not mean the student must be able to explain every library implementation; it means the student must understand and defend the relevant choices at the level assessed.

Give lecturers a fair response path

If a suspected breach arises, the course team should have a process for clarification, evidence review, and referral under institutional rules. A detector score should not replace that process. Students should know how questions will be handled before they submit.

Policies are most credible when they are understandable, applied consistently, and reviewed after real assignments. The purpose is not to make lecturers police every tool. It is to make the assessment conditions clear enough for learning and fair enough for judgment.

A one-page policy structure

Use these headings: purpose and learning outcomes; permitted tools and uses; prohibited data; material disclosure; verification and testing; attribution and collaboration; explanation or demonstration; uncertainty and questions; and response to suspected breaches. Link to institutional privacy and assessment rules rather than repeating them inaccurately.

The policy should be readable on the assignment page. Students should not have to search several documents to discover whether an agent may edit a repository.

Keep consequences connected to the rule

Students need to know what happens when use falls outside the permitted range. Consequences should follow institutional procedure and distinguish an honest misunderstanding from deliberate misrepresentation. Do not make a disclosure mistake equivalent to every form of academic misconduct.

Clear escalation routes protect students and lecturers alike.

Distinguish course rules from legal advice

An assignment policy can explain educational expectations, but it should not pretend to resolve every privacy, copyright, employment, or data-protection question. Link to institutional policy and direct students to the appropriate contact for cases involving client material, personal data, or a regulated project.

This keeps the document useful without making claims the course team is not qualified to make.

Review policy after real assignments

Collect the questions students asked, the disclosure notes lecturers found useful, and the situations where the permitted range was unclear. Use those examples to rewrite the next version. A policy is a teaching artifact that should improve through use.

Shared examples across HBO-ICT courses can reduce contradictory expectations while still leaving room for different learning outcomes.

Policy examples should include edge cases

Explain what happens when a student asks an agent to debug a prohibited task, when a group shares a generated component, when client code contains confidential material, or when a student cannot verify an answer. Edge cases are where broad wording becomes confusing.

A policy that answers those questions briefly will be more useful than one that repeats general statements about responsible AI.

Agent completion does not always mean engineering completion.

TraceYield engineering note

References

Pilot Program

Understand the WHY behind your engineering AI usage.

TraceYield evaluates trajectory evidence instead of stopping at spend totals. Join the private pilot to review AI coding usage with engineering context, security controls, and developer trust.

Join the TraceYield private pilot