AI Disclosure Is Not an Audit Trail for STM Publishers
Scientific journals are moving quickly on AI policies. The direction is shared: AI may support writing, editing, visualisation or review, but humans stay accountable, AI cannot be an author, and certain uses must be disclosed. A disclosure statement tells an editor that AI was used, where the author says it was used, and who takes responsibility.
But a disclosure statement is not an audit trail. It does not show which tool version ran, which sources were suggested, which references were checked, what a figure altered, or where a human actually verified anything. For STM publishers, that gap is becoming operational. The question is no longer "should AI use be disclosed?" It is "where does disclosure stop being enough first?"
In short
Disclosure is a statement. An audit trail is a record. The major STM publishers now converge on disclosure but diverge in practice, and none of their policies can confirm that a declaration matches what happened.
Disclosure becomes insufficient first where publishing depends on reconstructability — and on that test, citations fail first. A fabricated or mismatched reference can pass through an accurate disclosure statement untouched, because the statement was never about whether the source exists. Figures come second, peer review third, the full editorial workflow last. The next governance layer is not more disclosure. It is evidence: records that make AI-content interactions observable, verifiable and auditable.
Three policies, one shared floor and different practical rules
The convergence is real: no AI authorship, human accountability, mandatory disclosure. But the rules an author or integrity officer has to operationalise still differ by publisher.
Question | Elsevier | Nature Portfolio | Taylor & Francis |
|---|---|---|---|
Where authors disclose | Separate AI declaration; research use in Methods | Methods section (or suitable alternative) | Article AI-usage statement; book preface, at proposal stage |
Copy-editing / grammar | No declaration for basic checks; disclose if structure changes substantively | AI-assisted copy editing does not need to be declared | Acknowledgement required, with tool name and version |
Generative images | By category: explanatory yes; data and primary research images no | Not permitted for publication, save narrow labelled exceptions | Data visualisations and process diagrams yes; research or clinical outputs no |
Reviewers and LLMs | No manuscript upload; private AI tools only | No manuscript upload; declare any AI support in the report | No upload; no AI-generated review reports at all |
None of this is contradictory in spirit. It is fragmented in practice. A grammar pass that needs no mention at Nature needs an acknowledgement at Taylor & Francis. An explanatory figure allowed by Elsevier's category logic runs into Nature's near-blanket restriction. An author submitting to three journals in a year navigates three disclosure regimes. That is a compliance cost — but it is a symptom, not the disease.
Why disclosure alone cannot govern AI use
Elsevier's recommended format is representative: a statement naming the tool, the reason for use, and a confirmation that the author reviewed the output and takes responsibility. That is an attestation — written after the fact, by the party whose work is assessed. It answers "what do you say you did?" An audit trail answers "what did the workflow record?" Scientific publishing has always depended on the second question being answerable, through peer review, version control, corrections and retractions. AI use is governed almost entirely by the first.
This is the same distinction we draw between content provenance and usage evidence: knowing where something came from is not knowing how it was used, by whom, under what conditions.
Four levels, not two: Disclose, Document, Verify, Audit
The useful distinction is not "AI allowed" versus "AI banned," but what each object requires. Disclose: tell readers AI was used. Document: keep records of what happened. Verify: confirm outputs are accurate and source-backed. Audit: make the workflow reconstructable later. Language polishing may need only disclosure; AI-suggested citations need verification; figures need original files; peer review needs role boundaries. Disclosure is the first level, not the control system.
Where disclosure fails first: citations
If disclosure is insufficient everywhere eventually, the order matters for anyone deciding what to instrument first. Citations go first, for a structural reason: a fabricated reference is the one AI failure invisible to disclosure by construction.
An author can truthfully declare "I used an AI tool to help draft the literature review," review the output, sign the statement — and still submit a reference that points to nothing. The disclosure is accurate. The citation is fiction. All three publishers place reference accountability on the author; Elsevier states plainly that AI-generated references can be fabricated and must be checked. That accountability is correct, and it is exactly what breaks at scale, because a fabricated reference that looks right travels.
The consequences are measurable. A 2026 audit in The Lancet examined 2.5 million biomedical papers and found roughly one in 277 from early 2026 carried at least one fabricated reference, against about one in 2,828 in 2023. We covered the mechanics in AI citation integrity in medical publishing. The policy point is narrower: disclosure statements did not stop those references, and were never designed to.
The other three rank behind, and the reason is enforceability. Figures come second: the evidentiary risk is real, but the policies are already stricter and more mechanical — Nature's near-ban and the category rules give editors something closer to a checkable line. Peer review ranks third: the confidentiality risk is serious, but the control is a prohibition (no upload) enforceable at platform level rather than a per-claim verification. The full editorial workflow ranks last because it is the sum of the others — you cannot instrument it before its weakest link, the citation.
What an evidence layer adds
The move is not to replace disclosure. It is to add a record underneath it, generated at the point of AI use. Where a disclosure says "AI helped prepare this manuscript," an evidence record attaches the claimed citation, the matched source record, whether the identifier resolves, whether the metadata is consistent, and the resulting decision — allowed, flagged, or sent for human review.
The difference is who can check the claim and when. A disclosure can only be assessed by trusting the author. An evidence record can be checked by an editor or a downstream system before the reference enters the published record, not after a correction workflow finds it. This is the shift from access to evidence applied to research integrity rather than licensing.
It does not eliminate misconduct — determined fraud adapts. But it changes the default: a reference with no matching record stops being plausible text that passes on appearance, and becomes a workflow event that has to be resolved.
The objection: disclosure plus existing checks is enough
A fair objection: editorial teams already run DOI, Crossref and PubMed checks. Layer disclosure on top and the gap closes.
The Lancet numbers answer it. Those checks exist, and the fabrication rate still rose roughly tenfold in three years. The failure is not the absence of checking; it is the gap between verification that is available and verification enforced at the point where AI enters the workflow — optional, late, manual or disconnected from AI-assisted drafting. Disclosure does not close that gap, because disclosure is a statement about verification, not verification.
What this means for STM publishers now
Three decisions follow, in priority order.
First, treat disclosure as necessary and insufficient, and say so internally. The three policies are a floor. A strategy that ends at "we require a disclosure statement" has instrumented the author's intention and nothing else.
Second, instrument citations before anything else. It is the failure disclosure cannot catch, the one with a measured contamination curve, and the one whose consequences propagate furthest. Source verification at workflow entry is the highest-leverage control available.
Third, decide who must be able to prove source use. If the honest answer to "can your team show which cited sources were verified before they entered an AI-assisted workflow" is no, that is a strategic exposure, not only an editorial one — because the asset STM publishing sells is confidence in the source.
Disclosure tells the community what someone says happened. The next standard is being able to show what actually did.
Frequently asked questions
What is the difference between an AI disclosure statement and an audit trail?
A disclosure statement is an author's declaration of how AI was used, written after the fact and assessed on trust. An audit trail is a record generated by the workflow itself, capturing which tools and sources were used and where verification occurred. Disclosure answers what an author says happened; an audit trail answers what the workflow recorded.
Do Elsevier, Nature and Taylor & Francis have the same AI policy?
They converge on core principles — no AI authorship, human accountability, mandatory disclosure — but diverge on implementation: where authors disclose, whether routine copy-editing must be declared, how generative images are treated, and what reviewers may do with AI tools.
Where does AI disclosure become insufficient for STM publishers first?
Citations. A fabricated or mismatched reference can pass through an accurate disclosure statement untouched, because the statement was never about whether the source exists. Figures, peer review and the wider editorial workflow follow, but citations are the failure disclosure cannot catch by design.
Does an evidence layer replace disclosure?
No. It adds a verifiable record underneath the disclosure, generated at the point of AI use, so claims about source use can be checked by editors and downstream systems rather than taken on trust.
Continue the evidence chain
AI Citation Integrity in Medical Publishing
Content Provenance vs Usage Evidence
Book an AI usage evidence assessment
Sources
Elsevier — "Generative AI policies for journals" (updated June 2026)
https://www.elsevier.com/about/policies-and-standards/generative-ai-policies-for-journals
Nature Portfolio — "Artificial Intelligence (AI)" editorial policies
https://www.nature.com/nature-portfolio/editorial-policies/ai
Taylor & Francis — "AI Policy"
https://taylorandfrancis.com/our-policies/ai-policy/
Manusights — "Journal AI policies 2026" (third-party comparison)
https://manusights.com/blog/journal-ai-policies-2026
The Lancet — audit of fabricated citations across 2.5 million biomedical papers (2026)
https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(26)00603-3/fulltext