AI in Higher Education: When Practice Runs Ahead of the Rules
The first major national diagnostic shows that 89.7% of Portuguese institutions already have AI activity in at least one domain (in use or in development) — but only 14.7% have a policy in practice. The problem, says CNIPES, is no longer technological or ethical: it is institutional.
In April 2026, the National Council for Pedagogical Innovation in Higher Education (CNIPES) published the first rigorous portrait of what is really happening with Artificial Intelligence at Portuguese universities and polytechnics. The result is uncomfortable.
The number that sums it all up: 89.7% of the surveyed institutions now have AI activity in at least one domain (teaching, research, or administration) — counting both those that report actual use and those that are in development. But only 14.7% have a formal AI policy in practice. There is practice without governance. There is adoption without a framework. And, above all, there is a belief — mistaken, as we will see — that the central problem is still plagiarism.
It is not. The problem has changed.
The national portrait (and its central paradox)
The CNIPES diagnostic is described by its own authors as a "photograph of the Portuguese ecosystem," consolidated across 68 institutions after duplicate handling and conducted between 2025 and 2026. One methodological detail deserves emphasis, because it will matter later: the survey was directed at institutional leadership — rectorates, presidencies, governing bodies — not at faculty, students, or staff. In the report's language, this is a "structural diagnostic layer," indispensable but insufficient. That is precisely the gap that Phase 2 of the project will fill. For now, a few numbers are worth memorizing:
- 52.9% of institutions use AI in teaching (plus 25% in development)
- 42.6% use it in research
- Only 26.5% use it in management and administration
- Just 19.1% have reached what the report calls "full maturity" — AI simultaneously in teaching, research, and administration
There is a paradox here worth unpacking. Universities adopted AI first where one would expect the most caution — in the classroom — and hesitate where one would expect the most efficiency — in the back office. And yet, it is in assessment that adoption is "residual". In other words: Portuguese institutions are, quietly, being pragmatically cautious where the risk is greatest.
There is another surprising finding. Private institutions are more formalized than public ones in AI policy: 69% of private institutions have policies in practice or in development, versus 38.5% of public ones. The public sector — supposedly more regulated — lags behind the private sector on this issue.
The four imbalances of the system
CNIPES does not stop at the numbers. The report proposes a conceptual framework — four imbalances — that is worth understanding:
1. Mature principles vs. inconsistent procedures. Everyone talks about equity, transparency, accountability. The ethical vocabulary is consolidated. But the operational translation is uneven — regulation emerges "course by course," at the discretion of each faculty member, rather than as an integrated architecture. And the numbers confirm it: although there is already relevant activity in all three domains, "only a minority of institutions report policies already in practice."
2. Growing use vs. insufficient verification. Adoption grows faster than validation routines. The report identifies the exact inflection point: "when AI enters assessment, advising, decision-making, or evidence-production processes, the problem is no longer just use but validation of the result." As the authors synthesize it, "adoption grows; institutional validation routines have not yet grown at the same pace."
3. Abundant pilot projects vs. fragile longitudinal evidence. There is a lot of localized experimentation — in a single course, a chatbot, an R&D project — but little comparable accumulation. The Portuguese data are explicit: adoption occurs "mainly in individual courses, specific programs, R&D projects, assistants, and localized initiatives, rather than in structural, longitudinal programs." Pilots are not evaluated systematically, and so they do not generate transferable evidence.
4. Operational acceleration vs. risk of eroded judgment. This is the most uncomfortable one. The efficiency gain can coexist with a progressive erosion of judgment, authorship, and intellectual presence. The report describes it precisely: "the speed with which AI has entered academic work routines creates the temptation to shift onto the machine what previously required cognitive friction, comparison, justification, and interpretive delay." In the name of productivity, cognitive muscle is lost.
The authors' synthesis is surgical: "universities are running pilot projects faster than governance can keep up".
The AI Act takes the field
There is an additional reason governance cannot wait. The European regulatory framework referenced in the CNIPES report itself — the AI Act — explicitly classifies education as a "high-risk" domain, with emphasis on transparency and data privacy. This is not a minor regulatory detail: it means that higher education institutions are, or soon will be, subject to formal governance obligations that the overwhelming majority of them do not meet today. When only 14.7% have a policy in practice, the distance between what the law will soon require and what the institution delivers is itself the portrait of risk. The window to build those policies before they become enforceable is closing — and whoever lacks governance when it closes will be exposed.
The real problem: epistemic risk, not plagiarism
Here we arrive at the report's most original contribution. The public debate on AI in education has been dominated by the plagiarism question: students use ChatGPT to write papers; universities need detection tools; let's revise codes of conduct. All true. All secondary.
CNIPES shifts the framing. The central problem, it says, is not academic integrity (though that matters). It is epistemic risk. Large language models (LLMs) — ChatGPT, Claude, Gemini — are not knowledge engines. They are engines of linguistic plausibility.
One reads in the report, in a passage worth recording:
"LLMs automate language, not knowledge; they simulate reasoning without guaranteeing truth."
This is not a theoretical hypothesis. The BBC studied how AI assistants represent its own news: in 45% of cases, the answers contained serious errors. These were not small misunderstandings — they were factually wrong statements, delivered with the confidence of someone who knows. The model was not lying; it was doing what it was trained to do: produce statistically plausible language.
When this moves into a classroom, the effect is corrosive in a quiet way. A student who submits a paper "written" by an LLM is not cheating — often does not even know the result is wrong. The validating system is the faculty member; but if the faculty member also uses AI to grade, we lose the human verification bond. "Automation without interpretation is abdication," the report says.
Epistemic risk is harder to combat than plagiarism, because there is no detection tool that solves it. It demands literacy — knowing how to recognize what an LLM is and what it is not — and it demands deliberate human verification. Treating AI outputs as "fallible evidence requiring validation," not as answers.
What is already being done in Portugal
There is good news too. Several Portuguese institutions are building serious responses.
Instituto Superior Técnico published its Guide to the Responsible Use of Artificial Intelligence in November 2025, considered the first initiative of this kind among Portuguese university schools. The document results from internal reflection, defines guidelines for students, faculty, and researchers, and seeks to align practice with European legislative developments (the AI Act classifies education as a "high-risk" domain). Teresa Peña, one of the authors, synthesizes: "it is not enough to recognize that AI exists; it is necessary to use it more correctly and productively" — and that means cultivating its use to expand, not replace, "the unique capabilities of the human being: critical thinking, creativity, and emotional intelligence."
FCCN (the digital services unit of FCT) runs IAedu, an initiative dedicated to reflection and capacity-building for the responsible use of AI in education and research. FCCN's framing is useful because it broadens the debate: the integration of AI into the scientific system is not only technological or only pedagogical — it is strategic. It demands robust infrastructure, clear policies, community capacity-building, and a shared vision. The goal, they write, is for AI adoption to reinforce, not compromise, the principles of rigor, transparency, openness, and collaboration that sustain scientific production.
And some are already pushing the debate further. Joana Mata Pereira, Director of Learning Innovation at Católica-Lisbon SBE, argues that the discussion on academic integrity is necessary but insufficient. The right question is not "how to limit AI," but rather: what do we want students to learn? "Do we want them to keep up with every change, or to learn how to cope with change? To know the latest tool, or the foundations that let them find, evaluate, and use what they need at any given moment?". At a time when AI generates, summarizes, and synthesizes information at a speed exponentially greater than human speed, the value of higher education has ceased to lie in making knowledge available. It lies, increasingly, in teaching how to think about it.
What is missing — and what comes next
CNIPES proposes three pillars for the integration of AI in higher education, and they are worth knowing because they will likely shape Portuguese policy in the coming years:
- Knowing about AI — conceptual, ethical, epistemic, and affective literacies
- Doing with AI — pedagogical and creative application (operational, interpretive, reflective, creative)
- Being without AI — critical restraint and self-regulation; "the wisdom to recognize when not to use AI"
This last pillar is the most interesting — and the most counter-current. Public discussion forces us to be either for (adoption) or against (ban). CNIPES's position is more sophisticated: to use AI well, one must know when not to use it. It is also the hardest pillar to teach and the hardest to assess — there is no rubric for "the wisdom of not opening ChatGPT."
What is missing, in empirical terms, is Phase 2 of the diagnostic, which CNIPES already has under way. The second survey targets faculty, students, and staff — not leadership — and is complemented by three inter-institutional focus groups. The stated goal is "to move from a structural portrait of the system to a finer understanding of practices, perceptions, limits, and needs." We will finally know how many Portuguese students use AI, how often, and for what. The international figure — 88% of UK university students regularly use generative AI, but fewer than half have received formal training (Goodier, 2025, referenced by CNIPES) — suggests we will find similar numbers here.
A note on institutional metacognition
There is a detail in this report that deserves more attention than it has received. Right on page 7, the authors state, in an "AI Transparency" section, that the report itself was written with AI assistance — ChatGPT 5, Gemini, Elicit, and SciSpace, in an "assistive, not substitutive" role.
This is neither an accident nor a hidden Technical Note. It is a deliberate methodological choice, and a practical example of what the report advocates: using AI while declaring its use, treating its outputs as raw material to verify, keeping human interpretation at the center. The institutions that take AI governance seriously are not the ones that ban it — they are the ones that practice it transparently.
Conclusion: automation without interpretation is abdication
The Portuguese portrait is not that of a backward country. It is that of a country where practice has run ahead of governance — and where that distance is becoming the main risk. When 89.7% of institutions have AI in circulation and only 14.7% govern it, the problem lies neither in the technology nor in ethics. It lies in the institution.
The next twelve months will be decisive. CNIPES's Phase 2 will reveal the true scale of use — and will likely surprise those who still think of AI as a marginal issue. The European AI Act is entering phases of application that directly affect education. Institutions that, by then, lack even a minimally functional policy will be exposed.
But the good news is that the question is no longer difficult. It is no longer about deciding whether AI exists, or whether it should be adopted. It already exists; it has already been adopted. The question is different: will we keep running pilots without evaluating them, or will we start building evidence? Will we keep letting each faculty member invent their own yardstick, or will we create comparable institutional frameworks? Will we keep treating AI as a shortcut for appearing intelligent — that British student: "It helps me look smart, but I don't feel like myself" — or will we use it to be better?
The choice is ours. And, as the report closes, "the next stage requires moving from principles to implementation, from experimentation to evaluation, from individual efforts to collective governance."
Automation without interpretation is abdication. And abdication is not an option.
References
- CNIPES (April 2026). Inteligência Artificial no Ensino Superior em Portugal — Diagnóstico nacional para governação institucional. DOI: 10.5281/zenodo.19555760. wwwcdn.dges.gov.pt
- FCCN (February 2026). Inteligência Artificial no Ensino Superior: desafios à identidade e aos valores da ciência. fccn.pt
- Mata Pereira, Joana (Católica-Lisbon SBE). Inteligência Artificial e Ensino Superior: o que muda afinal? clsbe.lisboa.ucp.pt
- Instituto Superior Técnico (November 2025). Técnico apresenta Guia para a utilização responsável da Inteligência Artificial. tecnico.ulisboa.pt
Ollama: the complete guide to running AI locally with privacy
How to run LLMs like Llama 3, Gemma 2, or Mistral on your own machine — with no internet, no API costs, and full privacy. Installation, models, REST API, and use cases.
Ler artigo →How do I get started with Artificial Intelligence in my business?
A practical guide to taking your first steps with AI — no advanced technical training required.
Ler artigo →Is Artificial Intelligence accessible to businesses of all sizes?
AI for everyone: how SMBs can adopt artificial intelligence without million-dollar budgets. Tools, real costs, use cases, and ROI — from open-source to SaaS.
Ler artigo →