A review manuscript is not ordinary prompt material
Reviewers receive research before publication for one limited purpose. The files may expose novel hypotheses, patentable ideas, participant information, confidential collaborations and author identity. Uploading any of it can create another recipient and processing purpose even where the user interface does not publish the conversation.
Removing the title and names may not anonymise a distinctive study. Citations, sample location, acknowledgements, rare methods and data patterns can reveal a project. Short extracts remain confidential. Data minimisation helps only after the journal has permitted the processing; it cannot convert a prohibited transfer into an acceptable one.
Read the invitation, reviewer policy and service terms together
Start with the journal’s current reviewer instructions and the terms accepted for this assignment. Publishers vary: some prohibit generative systems from receiving manuscript content, while others define limited uses and disclosure requirements. An institutional licence is not automatically editorial permission.
Then inspect the actual deployment. “Local” software may call a remote model, and an enterprise service may apply different retention from a public account. Identify provider, subprocessors, region where relevant, retention, training settings, administrator access and deletion evidence. If a material field remains unknown, do not upload confidential content merely to save time.
Solve many support needs without exposing the paper
A reviewer-developed checklist can cover design, methods, data access, statistics and inference. Local spelling tools may be suitable where their configuration truly keeps content on the approved device. To improve the tone of a comment, draft a fictional example that contains no claim, phrase or detail from the manuscript.
Do not ask a model to guess citations, identify concealed authors or decide novelty. Open relevant sources yourself. A model-generated summary may omit qualifications that matter to the recommendation. Translation also transmits text and requires the same permission analysis as any other processing.
Four seemingly small tasks differ. Summarisation needs the scientific core and normally triggers a stop without permission. Literature checking needs claims and references and can hallucinate. Stylistic editing can expose passages. Generic guidance on structuring a review can be requested without any manuscript detail. Record the category rather than labelling everything “minor AI help”.
Academic judgement and accountability remain with the reviewer
Read the whole submission and build comments from verifiable observations. Check calculations, methods and cited sources where necessary. Never paste an output into a report without testing its assertions. Plausible criticism can be irrelevant to the actual design, and fabricated references can harm authors.
Recommendations to accept, revise or reject must not come from a concealed automated vote. Document manuscript version, materials read, checks performed and remaining uncertainty. Separate comments for authors from confidential comments for editors. If assistance is permitted, describe tool, date, purpose, information transmitted and human verification at the level required by policy.
The AI authorship responsibility matrix explains why a system cannot accept accountability. The redundant-publication audit is a human-led method for one review concern. The publication ethics hub joins related duties. The single foundation route is the evidence-review guide.
Respond accurately to a possible confidentiality incident
If content may already have been sent without permission, stop further use. Preserve factual details: service and account type, time, material entered, files attached, settings and any provider receipt. Contact the editor and relevant privacy or information-security channel. Do not claim provider-side deletion unless it can be demonstrated.
Deleting a visible conversation may not erase retained logs, and silence prevents the responsible organisation from assessing risk. Equally, do not speculate that data were used for training without evidence. Separate observed transmission, published service terms, uncertain retention and remediation requested.
- Confirm the current reviewer policy.
- Map every recipient and storage point.
- Exclude manuscript content unless expressly permitted.
- Use content-free or genuinely approved local alternatives.
- Verify every scholarly statement yourself.
- Record permitted assistance precisely.
- Escalate any suspected disclosure through the proper channel.
This workflow protects authors and reviewers without pretending that every software feature is identical. The decisive questions are what left the trusted review environment, under whose authority, for which purpose, and with what evidence of control.