Important: This is an operational starting point, not legal advice. Schools must align the final policy with national, state, provincial, territorial, local, contractual, safeguarding, and examination requirements.
Ten sections every school AI policy needs
State who and what the policy covers, including staff, learners, contractors, devices, accounts, and school-approved AI systems.
List permitted teacher, administrative, and learner activities, including when disclosure or citation is required.
Ban unsafe data entry, impersonation, harmful content, undisclosed assessed work, and automated high-impact decisions.
Set rules for tool approval, data minimisation, access, retention, deletion, accounts, and incident reporting.
Explain acceptable assistance, authorship, verification, citation, misconduct procedures, and teacher responsibility.
Address age limits, harmful outputs, accessibility, bias, learner wellbeing, and escalation routes.
Name decisions AI cannot make and identify the people accountable for review and approval.
Require privacy, security, accessibility, evidence, contract, and data-location checks before adoption.
Set expectations for recurring staff learning and clear information for learners and families.
Assign an owner, review date, version history, feedback route, and emergency update process.
Copy-ready policy opening
Minimum acceptable-use rules
- Use only school-approved tools and accounts for school work.
- Do not enter personal, confidential, safeguarding, medical, or special-category information unless specifically authorised.
- Verify generated facts, sources, calculations, images, and recommendations.
- Disclose AI assistance in assessed or published work when required.
- Do not use AI to impersonate, harass, deceive, discriminate, or create harmful material.
- Report unsafe output, suspected data exposure, or inappropriate use promptly.
Official regional starting points
Review FERPA and state or district requirements. The US Department of Education provides guidance on privacy and data sharing.
US student privacy guidanceAlign with UK GDPR, the Data Protection Act, safeguarding duties, and Department for Education guidance.
UK school AI data guidanceEducation and privacy obligations vary by province and territory. Canada's privacy regulators emphasise children's privacy in EdTech.
Canadian EdTech privacy resolutionUse the national framework alongside state, territory, sector, privacy, and safeguarding requirements.
Australian school AI frameworkFrequently asked questions
Who should approve a school AI policy?
Approval should follow the school governance structure and involve leadership, teaching, safeguarding, IT, data protection, legal or compliance, and assessment responsibilities.
How often should the policy be reviewed?
Set a regular review date and allow interim updates when tools, contracts, guidance, incidents, or assessment requirements change.
Should students be allowed to use AI?
The policy should define age-appropriate permitted uses, supervision, disclosure, assessment boundaries, privacy rules, and alternatives for learners who cannot or should not use a tool.