Skip to content

SOLUTIONS

Can peer reviewers use AI on manuscripts?

Most publishers prohibit it, and the reason is custody rather than quality: uploading a manuscript under review is a distribution the author never consented to.

Built by NIH-funded cancer researchers

Affiliations

Built by researchers funded by leading cancer-prevention institutions

  • University of Utah
  • Huntsman Cancer Institute
  • National Cancer Institute
  • American Cancer Society

Current platform

A review workflow built around the decisions only the author can make

PerfectPaper now carries context from setup through research, revision, and export—without turning the paper into a generic writing prompt.

Prepare

Tell the review what the paper cannot

Author interview

PerfectPaper asks targeted questions about design decisions and fixed constraints before review, then carries your answers into the critique.

Journal-aware setup

Search the journal catalogue, choose up to three targets, and compare compatible open-access journals before the review starts.

Your own review panel

Brief up to three custom reviewers, declare ground truths, attach instructions, and choose standard or deep-research depth with specific tools.

Investigate

Read the evidence as a connected whole

Methods, claims, citations, and visuals

Specialist reviewers inspect the full paper in context, including figures and tables—not isolated paragraphs.

Cited research

Deep-research reviewers can search the web and scholarly literature, inspect sources, and attach vetted citations to research-backed findings.

Visible review progress

The reading room shows which review areas are working, which findings have arrived, and when a research step could not complete.

Revise

Turn critique into a submission-ready draft

Anchored reading room

Move between each comment and its passage, read your paper as you wrote it in Word, filter feedback, and discuss any finding.

Apply, track, and undo

Preview suggested revisions, apply accepted changes, keep an edit history, and reverse a change without losing the review trail.

Submission exports

Export the revised paper and saved feedback as DOCX, annotated PDF, or print view, and prepare an anonymous copy for blinded review.

Can peer reviewers use AI on manuscripts?

Most major publishers prohibit reviewers from uploading a manuscript under review to an external AI service, and the reason is not that AI produces poor reviews. It is custody. A manuscript sent to a referee is confidential material belonging to someone else, shared for a single purpose, and uploading it anywhere is a distribution the author did not agree to.

That framing matters because it explains what does and does not change the answer. A better privacy policy does not cure it. A no-training guarantee does not cure it. The author did not consent, and consent is the thing at issue.

The published wording converges on that reading. Elsevier’s journal policy states that “Reviewers should not upload a submitted manuscript or any part of it into an AI tool as this may violate the authors’ confidentiality and proprietary rights and, where the paper contains personally identifiable information, may breach data privacy rights.” Wiley’s ethics guidelines state that “editors and peer reviewers are not permitted to upload manuscripts (or any parts of manuscripts including figures and tables) into AI Technology.” Neither clause turns on how good the output is.

What the prohibition covers

The prohibition covers three distinct acts: pasting any part of the manuscript into a general-purpose chat product, uploading the file, and — in stricter policies — using AI to draft the review text itself even without uploading the paper.

Policies increasingly extend to editors as well as reviewers, and some now require reviewers to declare any AI assistance used. Wiley’s clause names editors and peer reviewers in the same sentence; Elsevier states the editor obligation in its own paragraph, in wording that mirrors the reviewer clause — “Editors should not upload a submitted manuscript or any part of it into an AI tool” — and the ICMJE Recommendations address editors separately, warning that “Editors should be aware that using AI technology in the processing of manuscripts may violate confidentiality.”

Read the object of the clause carefully, because it is broader than most reviewers assume. Elsevier’s formulation is “a submitted manuscript or any part of it”: one table, one figure legend, the abstract alone, or a single methods paragraph is a part. Wiley’s is more explicit still, naming “any parts of manuscripts including figures and tables”. A derived artefact carries the same content — a summary you write and then paste in for critique reproduces the author’s findings, and a reference list pasted in for a plausibility check reproduces the author’s reading of the literature.

The ICMJE Recommendations set the test at confidentiality rather than at product category: “Reviewers must maintain the confidentiality of the manuscript as outlined above, which may prohibit the uploading of the manuscript to software or other AI technologies where confidentiality cannot be assured.” That wording reaches translation services, reference managers with cloud features, transcription tools and grammar checkers that transmit text off the device, none of which most reviewers think of as an AI service. The operative question in the published clauses is whether the author’s text leaves the reviewer’s control, not what the product is called.

Two edge cases come up repeatedly and neither is carved out. A manuscript already posted as a preprint on bioRxiv or medRxiv is public text, but no major publisher’s reviewer clause contains a preprint exception, and the review assignment, the reviewer’s identity and the confidential version under revision remain covered. A manuscript the reviewer has already declined is still confidential; the obligation attaches to receipt, not to acceptance of the invitation.

What funders require, and why their wording is stronger

Funder policy on generative AI in peer review is stricter and more specific than publisher policy.

The NIH issued NOT-OD-23-149, “The Use of Generative Artificial Intelligence Technologies is Prohibited for the NIH Peer Review Process”, on 23 June 2023. Its operative sentence prohibits reviewers “from using natural language processors, large language models, or other generative Artificial Intelligence (AI) technologies for analyzing and formulating peer review critiques for grant applications and R&D contract proposals”, and it warns reviewers that “uploading or sharing content or original concepts from an NIH grant application, contract proposal, or critique to online generative AI tools violates the NIH peer review confidentiality and integrity requirements.” NIH backed it with paperwork: reviewers sign a modified Security, Confidentiality and Nondisclosure Agreement certifying that they understand the prohibition. The notice carves out one narrow category — computer technologies used for accessibility needs may be granted an exception — which tells you what NIH considers the rule to be about, since an accessibility tool is a way of reading the application rather than a way of judging it.

The NSF followed on 14 December 2023 with a notice stating that “NSF reviewers are prohibited from uploading any content from proposals, review information and related records to non-approved generative AI tools.”

The two differ in one word that matters. NIH prohibits the analytic use outright — a reviewer may not use a model to formulate a critique even in principle. NSF prohibits uploading to non-approved tools, which presumes a category of approved ones and leaves room for a reviewing organisation to operate its own. That is the same distinction publishers draw between a referee’s borrowed custody and a body acting under custody it already holds, and it is the distinction the rest of this page turns on.

Why a better privacy policy does not cure it

A vendor’s terms cannot supply the author’s consent, because the author is not a party to those terms.

Three separate obligations are bundled in the prohibition, and vendor assurances reach only one of them. The first is confidentiality owed to the author. The second is the author’s proprietary rights in unpublished work, which Elsevier names alongside confidentiality in the same clause. The third is the undertaking the reviewer gave the journal when accepting the invitation. A retention window and a training exclusion address how a processor behaves; they do not address whether the reviewer was entitled to hand over the file. A guarantee that content is never used to train a model is a real and checkable property, and it is decisive on the author side and irrelevant on the referee side. Applying it to the referee question answers a question nobody asked.

Elsevier has now written that answer into the policy itself, which is worth knowing because it forecloses the argument in advance. Its reviewer guidance defines a private tool precisely — one “that does not retain, re-use, share, or learn from the content you submit to it” — and then declines to let the definition do the work: “Even if an AI tool is described as ‘private,’ uploading a manuscript still means sharing confidential and unpublished research with a third-party system.” A reviewer who has read the vendor’s terms carefully and concluded the tool is safe has answered the retention question correctly and the custody question not at all.

The locally run model is the genuine hard case. If a model executes entirely on the reviewer’s own machine and no text is transmitted, the distribution argument narrows sharply. It does not disappear from the published wording: Elsevier’s clause is categorical about “an AI tool” and Wiley’s about “AI Technology”, and neither carves out local execution. ICMJE’s clause turns on whether “confidentiality cannot be assured”, which is a determination the journal makes rather than the reviewer, and ICMJE settles the procedure explicitly — “Reviewers must request permission from the journal prior to using AI technology to facilitate their review.” Ask the handling editor in writing and keep the reply. If you are weighing a hosted service for your own work rather than someone else’s, the three checks in is it safe to upload an unpublished manuscript to ChatGPT apply instead.

Why editors should have an explicit policy

Reviewers are already using these tools. A journal without a stated policy is not preventing use; it is preventing disclosure of use, which is worse — it means the editor cannot tell which reviews were assisted, cannot assess whether confidentiality was breached, and has no basis for acting when it was.

The one large-scale measurement available supports the premise. Liang and colleagues, in “Monitoring AI-Modified Content at Scale: A Case Study on the Impact of ChatGPT on AI Conference Peer Reviews” (ICML 2024, arXiv:2403.07183), estimated that between 6.5% and 16.9% of text submitted as peer reviews to ICLR 2024, NeurIPS 2023, CoRL 2023 and EMNLP 2023 could have been substantially modified by large language models. Bound that figure honestly before quoting it: it is a corpus-level statistical estimate at four machine-learning conferences with public review text, in the year after ChatGPT’s release, and the study does not extend to clinical, biomedical or humanities journals. It establishes that the practice is not rare in at least one field. It does not establish a rate for yours.

An explicit policy does three things: it tells reviewers what is prohibited, it gives them something permitted so the prohibition is realistic, and it creates a disclosure path.

Put the clause where the reviewer will meet it, which is the invitation email and the review form, not a policies page they will never open. A journal that states its rule only on its website has published a rule; a journal that states it in the invitation has delivered one.

What a workable policy permits

Blanket prohibition with no alternative tends to fail quietly. Policies that hold up usually distinguish by what leaves the reviewer’s control:

Prohibited — uploading the manuscript, or any substantial portion, to any external service. Publisher wording is often stricter than “substantial”: Elsevier’s clause reads “any part of it”, and Wiley’s names figures and tables specifically. If your policy says “substantial portion”, expect to arbitrate what counts; if it says “any part”, you will not have to.

Generally permitted — using AI on the reviewer’s own written text, for language polishing of a review they composed, without the manuscript present. Wiley states the permitted lane and its condition together: “editors or peer reviewers may use AI Technology to help improve the clarity or quality of the written feedback in a peer review report. If this occurs, the reviewer must disclose that use to the handling editor when the review is submitted.” Elsevier draws the lane in the same place and adds one item to it, allowing supportive use “to improve the language and structure of their review reports, or for background literature searches, provided that confidentiality is maintained and human control and oversight are exercised” — a literature search is permitted because the query need not contain the author’s text. This lane matters most for reviewers writing in a second language, who are otherwise asked to accept a harder standard than colleagues writing in their first.

Requiring disclosure — any assistance that shaped the substance of the review. A usable declaration field captures four things: the tool and version, what it was applied to, whether any manuscript content was entered into it, and a confirmation that the reviewer takes responsibility for every statement in the report. Elsevier publishes a fill-in sentence to that effect and pairs it with a threshold worth copying: tools that only check spelling, grammar or punctuation do not require disclosure. Setting that floor is what keeps the field meaningful, because a declaration requirement that catches every autocorrect is one reviewers learn to tick without reading. The opposite failure is just as common: an open text box labelled “did you use AI?” collects nothing an editor can act on.

Separate question — tools the journal itself runs on submissions it holds. The journal has custody and a relationship with the author, so a journal-operated check is not a reviewer breaching confidentiality. This distinction is the one most policies fail to draw, and it matters because it is the route to reducing reviewer burden without asking reviewers to breach anything.

Why the distinction is the useful part

The prohibition exists to stop uncontrolled distribution by an individual with borrowed custody. It does not describe a general prohibition on computational assessment of manuscripts.

A journal that runs a structured check on a submission it already holds — reporting-guideline completeness, numerical consistency across tables, whether claims in the abstract are supported by the figures — is exercising custody it already has, under terms it can state to authors in its submission policy. That work is also the part reviewers most resent doing, which is why moving it upstream helps capacity. See why it is so hard to find peer reviewers.

Name the checks concretely, because “AI screening” is not a specification. The tractable ones are checklist completeness against the guideline that fits the design — CONSORT for randomised trials, PRISMA for systematic reviews, STROBE for observational studies, ARRIVE for animal work; internal numerical consistency, where a reported p-value is recomputed from the test statistic and degrees of freedom printed beside it; whether data availability statements name resolvable accessions rather than “available on reasonable request”; and whether every effect claimed in the abstract appears with the same magnitude in a table or figure. These are the findings a human referee produces last, reluctantly, at the end of an evening — and the ones a desk editor can act on before a referee is ever invited, which is the argument for screening at desk and the reason statistical review capacity is the binding constraint at most journals.

Drafting the clause: five decisions an editor has to make

An editor writing this policy makes five decisions, and the drafts that fail in practice leave three of them implicit.

Who is bound. Reviewers only, or reviewers and editors and editorial staff. Wiley and ICMJE both bind editors; a policy that names only reviewers implies the editor may do what the referee may not.

What the permitted lane is. Name it affirmatively, in the same paragraph as the prohibition. A prohibition with no adjacent permission reads as a prohibition on thinking with any tool, and is treated accordingly.

How disclosure is collected. A structured field in the submission system, attached to the review record, is auditable. An instruction to “mention it in your comments to the editor” is not, and produces no data you can review a year later.

What happens on a breach. Say whether the review is discarded, whether the author is informed, and who decides. A policy with no stated consequence puts the handling editor in the position of inventing one under time pressure.

What authors are told. The submission policy is where the journal states what it runs on manuscripts it holds, which vendors receive text, and on what terms. If the journal itself procures a service, the questions worth putting to that vendor are the same ones a research office asks, listed in the institutional AI procurement checklist.

For authors

If you are the author rather than the referee, these prohibitions largely do not apply to you. Author-side policies generally permit AI assistance on your own manuscript and require disclosure instead. Conflating the two is common, and it denies authors the use of tools they are entitled to use — journal AI policies for authors and referees covers that side.

Two boundaries are worth holding in mind while your paper is out for review. Your manuscript remains confidential to the referees, and that obligation is theirs and not yours; you may continue to work on your own text with whatever assistance you disclose. And the confidentiality that binds the referee does not bind you into silence about your own methods — what the referees wrote is confidential to the journal, but the paper is yours. The wider standard for handling unpublished work is set out in secure AI review for unpublished research, including what is not claimable.

If you suspect a review was AI-generated

Signs reported by editors: uniformly general comments with no specific line references, confident statements about content the paper does not contain, references that do not exist, and unusual fluency combined with unusual vagueness.

Treat it as a conduct question rather than a quality question. Ask the reviewer directly, and weigh the review accordingly.

Three correlates from the Liang analysis are worth knowing, and one caveat matters more than all three. Estimated LLM-modified text was higher in reviews reporting lower reviewer confidence, in reviews submitted close to the deadline, and among reviewers less likely to respond to author rebuttals. The caveat is the authors’ own: these are “corpus-level trends in generated text which may be too subtle to detect at the individual level”. Detection here is a property of a thousand reviews, not of the one on your screen.

That has a direct operational consequence: do not treat a detector score as evidence. Text classifiers for machine-generated writing have no established error rate on this material, and a false accusation against a reviewer who gave you three hours of unpaid work loses the journal that referee permanently. The defensible sequence is to establish whether the review is usable on its own terms — does it cite line numbers, does it engage with the actual data, are its references real — then ask the reviewer a specific question about a specific claim, obtain an additional review rather than relying on the disputed one, and record the exchange without relaying an accusation to the author.

What a reviewer should do when the tool is not available

A reviewer who cannot complete a review unaided has four permitted moves, and using an external service on the manuscript is not among them.

Decline promptly. Declining within a few days of the invitation is the highest-value action available to an overloaded referee, because it lets the editor invite someone else while the paper is fresh. A late decline and a thin review take the same three weeks off the clock.

Ask for the specialist you actually need. Where the difficulty is statistical rather than substantive, say so and ask the editor for a statistical reviewer, which is a request editors would rather receive than a hedged methods paragraph.

Request permission in writing. ICMJE’s clause exists for this: request permission from the journal before using AI technology to facilitate the review, and let the editor decide what confidentiality allows.

Work on your own words, not the author’s. Compose the review, close the manuscript, then use whatever language assistance you disclose on the text you wrote. That sequence keeps the author’s content out of the transaction entirely.

The structural version of this problem — too few referees, too many submissions, and the routine checks landing on the people least willing to do them — is the subject of the peer review capacity problem.

Related

PerfectPaper is used by authors on their own manuscripts before submission, and by journals on submissions they already hold, which are the two positions where custody is not borrowed. PerfectPaper does not stand in for a referee’s judgement and does not make editorial decisions; it produces the structured, checkable findings — guideline completeness, numerical consistency, abstract claims against the figures — that consume a referee’s evening and rarely need one.

Talk to us about journal use

Frequently asked questions

Is it a breach of confidentiality to upload a manuscript to ChatGPT as a reviewer?

Under most publisher policies, yes. The manuscript is confidential material belonging to the author, shared with you for one purpose, and uploading it to an external service is a distribution they did not authorise — independent of that service’s privacy terms.

Do publishers allow peer reviewers to use AI tools at all?

Elsevier and Wiley both prohibit uploading a submitted manuscript, or any part of it, into an AI tool, and Wiley’s clause names figures and tables explicitly. ICMJE requires reviewers to request the journal’s permission before using AI technology to facilitate a review.

Can reviewers use AI to improve the wording of their review?

Many policies permit this where the manuscript itself is not shared and the substance of the review is the reviewer’s own. Some require disclosure. Check the specific journal’s policy, as they differ.

Does a reviewer have to tell the journal they used AI?

Under Wiley’s guidelines, yes: a reviewer who uses AI to improve the clarity of a review report “must disclose that use to the handling editor when the review is submitted”. Other publishers vary, and a policy with no declaration field collects no disclosure in practice.

Can a reviewer use AI on a manuscript if the tool does not train on the text?

No, and Elsevier addresses this directly: “Even if an AI tool is described as ‘private,’ uploading a manuscript still means sharing confidential and unpublished research with a third-party system.” A training exclusion answers a question about the vendor, not about whether the reviewer was entitled to share the file.

Are reviewers allowed to use AI on NIH or NSF grant proposals?

No. NIH prohibits reviewers from using large language models or other generative AI to analyse and formulate peer review critiques, and requires a signed confidentiality agreement covering it. NSF prohibits uploading any content from proposals, review information or related records to non-approved generative AI tools.

Can a reviewer use AI on a manuscript that is already public as a preprint?

No major publisher’s reviewer clause contains a preprint exception. The review assignment, the reviewer’s identity and the version under revision remain confidential even where an earlier version of the text is public, so the safe course is to ask the handling editor rather than infer a carve-out.

Last updated September 10, 2026

A careful read when you need a second opinion.

Upload your paper and receive structured, sourced feedback before you submit.