AI governance

School AI Policy Template: A Practical International Framework

A useful AI policy tells staff and learners what they may do, what they must never do, and who makes the final decision. Adapt this framework with your legal, safeguarding, IT, curriculum, and data-protection leads.

Updated 2026-08-10JENECONK editorial teamInternational edition

Important: This is an operational starting point, not legal advice. Schools must align the final policy with national, state, provincial, territorial, local, contractual, safeguarding, and examination requirements.

Ten sections every school AI policy needs

1. Purpose and scope

State who and what the policy covers, including staff, learners, contractors, devices, accounts, and school-approved AI systems.

2. Approved uses

List permitted teacher, administrative, and learner activities, including when disclosure or citation is required.

3. Prohibited uses

Ban unsafe data entry, impersonation, harmful content, undisclosed assessed work, and automated high-impact decisions.

4. Privacy and security

Set rules for tool approval, data minimisation, access, retention, deletion, accounts, and incident reporting.

5. Teaching and assessment

Explain acceptable assistance, authorship, verification, citation, misconduct procedures, and teacher responsibility.

6. Safeguarding and inclusion

Address age limits, harmful outputs, accessibility, bias, learner wellbeing, and escalation routes.

7. Human oversight

Name decisions AI cannot make and identify the people accountable for review and approval.

8. Procurement

Require privacy, security, accessibility, evidence, contract, and data-location checks before adoption.

9. Training and communication

Set expectations for recurring staff learning and clear information for learners and families.

10. Review cycle

Assign an owner, review date, version history, feedback route, and emergency update process.

Copy-ready policy opening

[SCHOOL NAME] uses approved artificial intelligence tools to support teaching, learning, and administration where they provide a clear educational or operational benefit. AI output is treated as a draft or source of options, not as an unquestioned authority. Users must protect personal and confidential information, verify accuracy, disclose AI assistance where required, follow assessment and safeguarding rules, and keep final decisions with authorised people.

Minimum acceptable-use rules

  • Use only school-approved tools and accounts for school work.
  • Do not enter personal, confidential, safeguarding, medical, or special-category information unless specifically authorised.
  • Verify generated facts, sources, calculations, images, and recommendations.
  • Disclose AI assistance in assessed or published work when required.
  • Do not use AI to impersonate, harass, deceive, discriminate, or create harmful material.
  • Report unsafe output, suspected data exposure, or inappropriate use promptly.

Official regional starting points

United States

Review FERPA and state or district requirements. The US Department of Education provides guidance on privacy and data sharing.

US student privacy guidance
United Kingdom

Align with UK GDPR, the Data Protection Act, safeguarding duties, and Department for Education guidance.

UK school AI data guidance
Canada

Education and privacy obligations vary by province and territory. Canada's privacy regulators emphasise children's privacy in EdTech.

Canadian EdTech privacy resolution
Australia

Use the national framework alongside state, territory, sector, privacy, and safeguarding requirements.

Australian school AI framework

Frequently asked questions

Who should approve a school AI policy?

Approval should follow the school governance structure and involve leadership, teaching, safeguarding, IT, data protection, legal or compliance, and assessment responsibilities.

How often should the policy be reviewed?

Set a regular review date and allow interim updates when tools, contracts, guidance, incidents, or assessment requirements change.

Should students be allowed to use AI?

The policy should define age-appropriate permitted uses, supervision, disclosure, assessment boundaries, privacy rules, and alternatives for learners who cannot or should not use a tool.