AI Reference Guidelines (draft)

Draft guidance for using generative AI in coding on NowWhat.

This page is written by AI!

This page is made with AI support!

University of Padova follow this guidelines for the use of generative AI in research. The document frames generative AI as a support tool, not as a replacement for scientific judgement, and emphasizes human responsibility, transparency, privacy, security, intellectual property, bias awareness, and sustainability.

For research software and peer review, two useful references are:

Both rOpenSci and pyOpenSci focus on transparency and human accountability. If generative AI is used to write, refactor, document, or test code, the author should describe how it was used and confirm that the generated material was reviewed, edited, tested, and understood by humans before submission or publication.

Practical Principles

Use generative AI as an assistant. It can help explain unfamiliar code, draft tests, suggest refactorings, identify possible bugs, translate code between languages, or explore implementation options. It should not be treated as an authority for scientific claims, software design, security decisions, or final correctness.

Keep responsibility with the researcher. Code, text, figures, analyses, and interpretations remain the responsibility of the people who submit or publish the work. Before using generated output, check that it is correct, appropriate for the research context, maintainable, and consistent with the project's license and contribution rules.

Protect data and unpublished work. Do not paste sensitive, personal, confidential, proprietary, or unpublished data into external AI tools unless the tool, account, and data-processing terms are approved for that use. Check whether prompts, files, datasets, or source code may be retained or used for model training.

Document meaningful AI use. For substantial AI assistance, record which tool was used, where it affected the project, what was generated or suggested, and what human review was performed. This can go in a README, a project log, an AGENTS.md file, code comments where appropriate, or the documentation required by a journal or software review process.

Review for quality, security, and licenses. AI-generated code may be incorrect, inefficient, insecure, overcomplicated, or too similar to existing licensed code. Pay particular attention to algorithms, domain-specific logic, security-sensitive code, and code intended for public release or technology transfer.

Coding Workflow

For coding work, prefer a Git workflow that makes AI-assisted commits traceable. After initializing a repository, define a dedicated commit alias that records commits made by the AI agent with a distinct author identity.

Initialize the repository:

git init

Add an alias for AI-agent commits:

git config alias.commit-ai '!git -c user.name="$USER-codex" -c user.email="$USER-codex@local" commit'

When accepting code produced or substantially modified by the AI agent, inspect the changes and commit only the intended hunks:

git add -p
git commit-ai -m "<AI_INPUT_PROMPT>"

For your own follow-up changes, use your normal Git identity:

git add -p
git commit -m "refactor AI implementation"

This keeps the line history explicit: later, git blame, review tools, and repository history can distinguish code introduced by the AI agent from code introduced by the human author. This does not remove the need for human review; it only makes provenance easier to inspect.

Other Resources

  • Using Git with coding agents explains practical Git patterns for working with coding agents, including commits, history review, recovery, and debugging with Git tools.
  • git-ai is an open source Git extension that aims to track AI-generated code and connect lines of code to the agent, model, and session that produced them.

git-ai example

The following short guide shows how to install Git AI, connect it to Codex CLI, and test it on a small demo repository.

Prerequisites (example with codex but it works also with others)

Check that Git and Codex CLI are available:

git --version
codex --version

If Codex CLI is not installed, install it with one of the official methods:

npm install -g @openai/codex

or, on macOS:

brew install --cask codex

Install Git AI

On macOS, Linux, or Windows WSL:

curl -sSL https://usegitai.com/install.sh | bash

On Windows without WSL:

powershell -NoProfile -ExecutionPolicy Bypass -Command "irm http://usegitai.com/install.ps1 | iex"

Restart your shell, terminal, IDE, and any running agent session after installation. Then verify the installation:

which git
which git-ai
git ai --help
git ai config

On macOS and Linux, which git should point to the Git AI wrapper, for example:

~/.git-ai/bin/git

Install Git AI Hooks

Run:

git ai install-hooks

Git AI uses hooks around agent file edits to create checkpoints. A checkpoint before the edit marks existing user changes as human-authored; a checkpoint after the edit records the new agent-authored changes.

Enable Hooks in Codex

Open your Codex user configuration:

mkdir -p ~/.codex
nano ~/.codex/config.toml

Add or update:

[features]
hooks = true

If your file still contains:

[features]
codex_hooks = true

replace it with:

[features]
hooks = true

You can also enable the feature from the command line:

codex --enable hooks

Inside Codex, review pending hooks:

/hooks

Approve only hooks that match the expected Git AI behavior, such as commands related to:

git ai checkpoint

Create a Demo Project

Create a clean repository:

mkdir demo-git-ai-codex
cd demo-git-ai-codex
 
git init
echo "# Demo Git AI + Codex" > README.md
git add README.md
git commit -m "initial commit"

Check the initial Git AI state:

git ai status

At this point it is normal to see no checkpoints, because no agent has edited the repository yet.

Make a Human Edit

Add one line manually:

printf "\nThis line was written manually by the user.\n" >> README.md

Inspect the current state:

git diff
git ai status

Ask Codex to Edit the Project

From the same repository, start Codex:

codex

Ask Codex:

Create a file hello.py.

When Codex finishes, inspect the result:

git status
git diff
git ai status

If the hooks are working, git ai status should show checkpoints and AI attribution for the working tree.

Commit and Inspect Attribution

Commit the demo changes:

git add README.md hello.py
git commit -m "add demo script with codex"

Then inspect attribution:

git ai blame hello.py
git ai diff HEAD
git ai stats HEAD

git ai blame extends git blame with AI attribution, git ai diff shows a diff annotated with AI or human authorship, and git ai stats summarizes human and AI contributions for a commit.

Push Attribution to GitHub

Git AI stores attribution metadata in Git notes. If you want that metadata to travel with pushes to GitHub, configure the remote to fetch and push notes as well as commits:

git config --add remote.origin.fetch "+refs/notes/*:refs/notes/*"
git config --add remote.origin.push "refs/notes/*:refs/notes/*"

Run these commands inside the repository after adding the origin remote. Without this configuration, regular code commits can still be pushed, but the Git AI notes used for attribution may remain only in your local repository.