Peer Review With AI Assistance: Confidentiality Comes First
4 min read · updated August 3, 2026
Most discussion of AI in peer review argues about whether the reviews are any good. That is the second question. The first one is that a manuscript under review is somebody else’s confidential unpublished work, and pasting it into a service is a disclosure you were not entitled to make.
The argument that comes first
When you accept a review invitation you accept a confidentiality undertaking. The manuscript is unpublished, it usually contains results the authors have not yet established priority on, and in the case of grant review it contains an unfunded research plan — arguably the most commercially and academically sensitive document in the whole system. You agreed not to share it.
Sending it to a third-party service is sharing it. That is true whether or not the provider trains on it, whether or not it is retained, and whether or not anyone ever reads it. The undertaking was not “do not let this be trained on”; it was “do not disclose this”, and transmission to a party the authors never agreed to is disclosure. Retention and training policies affect how bad the breach is, not whether one occurred.
Notice what this argument does not depend on. Not model quality, not hallucination, not bias. It would apply identically to a perfect system, which is why it is the argument that has actually driven policy, and why it will not be resolved by better models. It can only be resolved by changing where the computation happens — a model running on infrastructure already covered by the confidentiality arrangement raises a different question from a consumer chat interface, and any serious policy will distinguish them.
The second argument: accountability
A review is a named expert’s judgement. Its value to an editor is not the prose; it is that a person who knows the field read the paper and formed a view they are willing to stand behind. Generated text can simulate the prose and cannot supply the judgement.
Editors describe the resulting artefact recognisably: fluent, correctly structured, superficially thorough, and engaging with nothing specific — no view on whether the control was appropriate, no reaction to the surprising number in table 3, no knowledge of the two other groups working on this. It is a review-shaped object. Worse, it is confidently reasonable, so an editor without domain expertise cannot easily tell it apart from a good review, and its errors carry the reviewer’s name.
Where it has been prohibited
Several major funders have moved first and moved hardest, because grant applications are the most sensitive documents in the system. The United States National Institutes of Health prohibited peer reviewers from using generative AI tools in analysing and formulating critiques of grant applications, on confidentiality grounds. Other national funders have issued comparable prohibitions for the same reason.
Journal and conference policy is more varied and is still moving: some publishers prohibit uploading manuscripts to external tools while permitting limited assistance with the reviewer’s own writing, some require disclosure, some are silent. There is no single rule to quote, and the practical consequence for a reviewer is unavoidable — read the policy of the specific venue before you accept, because the obligations differ and the confidentiality undertaking you signed is theirs, not a general one.
Uses that raise neither objection
- Improving your own review text. Once you have written the review, working on its clarity and tone involves your words, not the manuscript. Tone in particular is a real problem in peer review and this is a legitimate use.
- Checking your own manuscript before submission. Your own unpublished work is yours to share, subject to your collaborators’ agreement and any institutional or funder rules about where data may go. Running a hostile pre-review on your own paper is one of the more useful applications available.
- Editorial screening by the publisher. Scope checks, format compliance, statistical reporting checks and reference verification, performed by the party that already holds the manuscript legitimately, raise no confidentiality problem. This is also where the effort is best spent, because it is mechanical work that reviewers currently do badly.
- Reference verification. Checking that every citation resolves and supports the claim made of it, as described in the integrity checks. Note this needs the reference list, not the manuscript.
What a usable policy has to specify
“No AI in peer review” is not a policy, because it does not tell a reviewer whether they may use a spelling checker with a language model in it. A usable one answers five questions.
- Which stage. Screening, review, editorial decision and post-acceptance production are different, and the confidentiality position differs across them.
- Whose text. The manuscript, the reviewer’s own comments, and the reference list are three different disclosures.
- Which systems. A locally hosted model, an enterprise API under contract, and a consumer chat interface have genuinely different disclosure profiles, and a policy that treats them identically will simply be ignored.
- What is disclosed, and to whom. A reviewer statement to the editor is a different thing from a public note on the paper.
- What remains the reviewer’s responsibility. The honest answer is all of it, and saying so is the part that actually changes behaviour.
It is worth being realistic about enforcement. Detection of generated text is unreliable for the reasons set out in the page on journal integrity, so none of this is a control. It is a norm plus an accountability rule, and norms in peer review have historically done more work than controls.