AI Reference Guidelines (draft)
Draft guidance for using generative AI in coding on NowWhat.
This page is made with AI support!
University of Padova follow this guidelines for the use of generative AI in research. The document frames generative AI as a support tool, not as a replacement for scientific judgement, and emphasizes human responsibility, transparency, privacy, security, intellectual property, bias awareness, and sustainability.
For research software and peer review, two useful references are:
- Software Review in the Era of AI: What We Are Testing at rOpenSci
- Navigating LLMs in Open Source: pyOpenSci's New Peer Review Policy
Both rOpenSci and pyOpenSci focus on transparency and human accountability. If generative AI is used to write, refactor, document, or test code, the author should describe how it was used and confirm that the generated material was reviewed, edited, tested, and understood by humans before submission or publication.
Practical Principles
Use generative AI as an assistant. It can help explain unfamiliar code, draft tests, suggest refactorings, identify possible bugs, translate code between languages, or explore implementation options. It should not be treated as an authority for scientific claims, software design, security decisions, or final correctness.
Keep responsibility with the researcher. Code, text, figures, analyses, and interpretations remain the responsibility of the people who submit or publish the work. Before using generated output, check that it is correct, appropriate for the research context, maintainable, and consistent with the project's license and contribution rules.
Protect data and unpublished work. Do not paste sensitive, personal, confidential, proprietary, or unpublished data into external AI tools unless the tool, account, and data-processing terms are approved for that use. Check whether prompts, files, datasets, or source code may be retained or used for model training.
Document meaningful AI use. For substantial AI assistance, record which tool was used, where it affected the project, what was generated or suggested, and what human review was performed. This can go in a README, a project log, an AGENTS.md file, code comments where appropriate, or the documentation required by a journal or software review process.
Review for quality, security, and licenses. AI-generated code may be incorrect, inefficient, insecure, overcomplicated, or too similar to existing licensed code. Pay particular attention to algorithms, domain-specific logic, security-sensitive code, and code intended for public release or technology transfer.
Coding Workflow
For coding work, prefer a Git workflow that makes AI-assisted commits traceable. After initializing a repository, define a dedicated commit alias that records commits made by the AI agent with a distinct author identity.
Initialize the repository:
git initAdd an alias for AI-agent commits:
git config alias.commit-ai '!git -c user.name="$USER-codex" -c user.email="$USER-codex@local" commit'When accepting code produced or substantially modified by the AI agent, inspect the changes and commit only the intended hunks:
git add -p
git commit-ai -m "<AI_INPUT_PROMPT>"For your own follow-up changes, use your normal Git identity:
git add -p
git commit -m "refactor AI implementation"This keeps the line history explicit: later, git blame, review tools, and repository history can distinguish code introduced by the AI agent from code introduced by the human author. This does not remove the need for human review; it only makes provenance easier to inspect.
Other Resources
- Using Git with coding agents explains practical Git patterns for working with coding agents, including commits, history review, recovery, and debugging with Git tools.
- git-ai is an open source Git extension that aims to track AI-generated code and connect lines of code to the agent, model, and session that produced them.
git-ai example
The following short guide shows how to install Git AI, connect it to Codex CLI, and test it on a small demo repository.
Prerequisites (example with codex but it works also with others)
Check that Git and Codex CLI are available:
git --version
codex --versionIf Codex CLI is not installed, install it with one of the official methods:
npm install -g @openai/codexor, on macOS:
brew install --cask codexInstall Git AI
On macOS, Linux, or Windows WSL:
curl -sSL https://usegitai.com/install.sh | bashOn Windows without WSL:
powershell -NoProfile -ExecutionPolicy Bypass -Command "irm http://usegitai.com/install.ps1 | iex"Restart your shell, terminal, IDE, and any running agent session after installation. Then verify the installation:
which git
which git-ai
git ai --help
git ai configOn macOS and Linux, which git should point to the Git AI wrapper, for example:
~/.git-ai/bin/gitInstall Git AI Hooks
Run:
git ai install-hooksGit AI uses hooks around agent file edits to create checkpoints. A checkpoint before the edit marks existing user changes as human-authored; a checkpoint after the edit records the new agent-authored changes.
Enable Hooks in Codex
Open your Codex user configuration:
mkdir -p ~/.codex
nano ~/.codex/config.tomlAdd or update:
[features]
hooks = trueIf your file still contains:
[features]
codex_hooks = truereplace it with:
[features]
hooks = trueYou can also enable the feature from the command line:
codex --enable hooksInside Codex, review pending hooks:
/hooksApprove only hooks that match the expected Git AI behavior, such as commands related to:
git ai checkpointCreate a Demo Project
Create a clean repository:
mkdir demo-git-ai-codex
cd demo-git-ai-codex
git init
echo "# Demo Git AI + Codex" > README.md
git add README.md
git commit -m "initial commit"Check the initial Git AI state:
git ai statusAt this point it is normal to see no checkpoints, because no agent has edited the repository yet.
Make a Human Edit
Add one line manually:
printf "\nThis line was written manually by the user.\n" >> README.mdInspect the current state:
git diff
git ai statusAsk Codex to Edit the Project
From the same repository, start Codex:
codexAsk Codex:
Create a file hello.py.When Codex finishes, inspect the result:
git status
git diff
git ai statusIf the hooks are working, git ai status should show checkpoints and AI attribution for the working tree.
Commit and Inspect Attribution
Commit the demo changes:
git add README.md hello.py
git commit -m "add demo script with codex"Then inspect attribution:
git ai blame hello.py
git ai diff HEAD
git ai stats HEADgit ai blame extends git blame with AI attribution, git ai diff shows a diff annotated with AI or human authorship, and git ai stats summarizes human and AI contributions for a commit.
Push Attribution to GitHub
Git AI stores attribution metadata in Git notes. If you want that metadata to travel with pushes to GitHub, configure the remote to fetch and push notes as well as commits:
git config --add remote.origin.fetch "+refs/notes/*:refs/notes/*"
git config --add remote.origin.push "refs/notes/*:refs/notes/*"Run these commands inside the repository after adding the origin remote. Without this configuration, regular code commits can still be pushed, but the Git AI notes used for attribution may remain only in your local repository.