AI Policy for Schools: A Practical Guide for School Leaders
- Amy McRae Johnson

- Aug 5
- 9 min read
An AI policy for schools should explain why the school uses artificial intelligence, where its use is permitted, what remains prohibited and who is accountable for every consequential decision. It should cover staff and pupil use, teaching and assessment, personal data, safeguarding, product approval, transparency, incidents, training and review.
That is the practical answer. The leadership challenge beneath it is harder.
AI can enter a school through lesson planning, pupil research, parent communication, reporting, assessment, accessibility tools, administration and products purchased by different departments. A policy written only as a response to cheating will miss much of the organisation. A policy copied from another school may contain sensible rules without reflecting the educational purpose, risk tolerance or community expectations of the school adopting it.
The governing question is not simply which tools are allowed. It is where machine assistance may be useful, where human judgement must remain accountable and how the school will protect learning and trust while the technology continues to change.
Why Schools Need an AI Policy Now
Waiting for AI products to stabilise is not a realistic policy. Staff and pupils may already be using publicly available tools, suppliers are adding AI features to familiar platforms, and administrative teams are finding new ways to draft, summarise or analyse information. The absence of an approved school approach does not create neutrality. It creates inconsistent decisions.
One teacher may permit AI-supported brainstorming while another treats the same behaviour as misconduct. A member of staff may paste sensitive information into a free tool because nobody has explained the data boundary. A department may purchase a product because it promises personalisation without establishing what evidence supports the claim or how pupil information is processed.
Current guidance is also becoming more specific. The UK Department for Education’s data-protection guidance for generative AI tells schools to use approved tools, understand how personal data is handled, be transparent with their communities and seek appropriate data-protection or technical advice. Its 2026 product safety standards give leaders further questions to ask about purpose, evidence, filtering, governance and child development.
Requirements differ by jurisdiction, school type and use case. A useful policy therefore combines applicable obligations with institutional judgement. It should be precise enough to guide a decision today and structured so it can change without being rewritten every time a product adds a feature.
Start With Educational Purpose, Not Available Tools
Many weak technology policies begin with products. They list what is blocked, permitted or being trialled, then become obsolete when names, versions or access models change.
A stronger AI policy begins with purpose. What educational or operational problem is the school trying to solve? What improvement would justify using AI? What should never be delegated because the human process is itself part of the value the school promises?
An international school may explore translation support while deciding that sensitive parent communication still requires careful human authorship. A school may allow staff to use AI when generating initial lesson ideas but require teachers to validate curriculum accuracy, appropriateness and accessibility. Leaders may test administrative summarisation while prohibiting identifiable pupil information from entering unapproved systems.
Purpose creates a stable basis for changing tools. It also prevents adoption from becoming a collection of unrelated experiments. The School Growth Method treats schools as systems because a decision in one area changes the conditions elsewhere. AI adoption is no exception. A tool that saves time for one team may create data, communication, training or trust consequences for another.
Distinguish Users, Contexts and Consequences
One universal rule rarely works across every form of AI use. A spell-checking suggestion, a pupil chatbot, an automated admissions score and a draft staff newsletter do not carry the same educational or institutional consequence.
The policy should distinguish at least four groups: pupils, teaching staff, non-teaching staff and leaders or governors. It should then consider different contexts, including learning, assessment, pastoral support, admissions, communication, administration, analytics and procurement.
The most important distinction is consequence. The greater the possible effect on a child, family, employee or important institutional decision, the stronger the requirement for human review, transparency and evidence should become.
This helps schools avoid two unhelpful extremes. A blanket ban may be impossible to apply and may prevent thoughtful learning about the technology. Unrestricted experimentation may expose pupils and staff to risks the organisation has not understood. A proportionate policy permits bounded use while reserving consequential judgement for accountable people.
Protect Personal Data Before Chasing Convenience
Generative AI tools can make routine work feel easier. The convenience can hide the significance of what is being entered, stored or inferred.
Staff should know whether they may use personal data, confidential information, safeguarding material, assessment records, health information, admissions notes or identifiable work in any AI system. The default for public tools should be clear: do not enter sensitive or identifiable information unless the school has expressly approved the tool and the specific use.
Approval requires more than a familiar brand name. Leaders need to understand what data is collected, where it is processed, whether inputs train the system, what contractual protections apply, how long information is retained and how rights or incidents will be handled. Privacy notices and internal records may also need updating.
Schools should involve their data-protection, safeguarding, technical, legal and procurement advisers as appropriate. This article cannot determine the obligations applying to every country or school. The policy must name the jurisdictional checks the institution requires rather than presenting general guidance as universal law.
Protect Learning, Not Only Academic Integrity
AI policy discussions often begin with plagiarism or unauthorised assistance. Academic integrity matters, but it is only part of the educational question.
Leaders also need to decide which forms of cognitive work pupils must practise for themselves. If the purpose of a task is to develop reasoning, writing, recall, interpretation or creative judgement, an AI system completing that work may undermine the learning even when the output is technically original. In another task, comparing an AI answer with trusted sources may develop useful critical understanding.
The policy should allow teachers to define acceptable use by task. Pupils need to know when AI is prohibited, when it is allowed for a limited purpose, what must be acknowledged and what evidence of their own thinking they are expected to retain. These expectations should be understandable across subjects rather than relying on every teacher to invent a separate vocabulary.
Assessment rules must also align with the relevant awarding body and qualification requirements. AI detection scores should not be treated as certain proof. Where a concern arises, the school needs a fair process based on evidence, professional judgement and the applicable assessment rules.
The deeper principle is that technology should support the purpose of learning rather than quietly redefine it. UNESCO’s human-centred guidance emphasises ethical, safe, equitable and meaningful use. A school policy makes those values operational in the decisions pupils and teachers face.
Approve Use Cases, Not Just Products
A product can be acceptable for one purpose and inappropriate for another. A tool approved for staff brainstorming is not automatically approved for pupil counselling, automated decision making or processing identifiable records.
The approval process should therefore record both the product and the authorised use case. It should identify the users, age group, information involved, educational purpose, expected benefit, known limitations, human oversight and review date.
Supplier claims deserve scrutiny. Leaders should ask what evidence supports claims about learning, personalisation, workload or safety. They should examine age restrictions, accessibility, filtering, bias, content moderation, complaint routes, data handling and what happens when the product changes. Free access should not bypass review simply because no procurement form is triggered.
A small approved-tools register can be more useful than a long policy appendix. The policy establishes the principles and decision authority; the register holds product-specific permissions that may change more frequently.
Human Accountability Must Remain Visible
AI may generate, classify, recommend or summarise. It cannot carry institutional responsibility.
The school remains accountable for communication sent in its name, resources used with pupils, decisions affecting people and products introduced into the learning environment. “The system produced it” is not an explanation a parent, pupil or employee should be expected to accept.
The policy should name who reviews outputs and who has authority to approve use. It should also identify decisions that cannot be delegated. Safeguarding judgements, disciplinary outcomes, admissions decisions, high-stakes assessment, employment decisions and sensitive pastoral responses require explicit human responsibility and applicable professional processes.
This is a whole-school governance issue. The principle that growth needs leadership across departmental boundaries applies here because AI can move between curriculum, IT, safeguarding, data protection, communications, HR, admissions and finance. Technical ownership alone is too narrow; dispersed ownership without executive accountability is too weak.
Be Transparent With Pupils, Staff and Families
People should not have to guess when AI materially shapes an experience or decision.
Transparency does not require a technical disclosure beside every minor automated function. It does require the school to explain its approach clearly: which uses are permitted, how personal data is protected, how pupil work should acknowledge assistance, where human review occurs and how concerns can be raised.
Parent communication matters especially when AI is used in learner-facing products, assessment, pastoral contexts, profiling or communications about a child. Families will interpret the policy as evidence about the school’s judgement. A confident explanation should neither market AI as inevitable progress nor describe every use as a threat. It should show that the school knows what it is trying to achieve, what it will protect and who remains responsible.
This is why school communication builds confidence. The policy is not only an internal control. It is part of how the institution makes change understandable.
An AI Policy Is a Governance Process, Not a Finished Document
No policy drafted today will anticipate every product or use. Stability comes from a repeatable decision process, not from pretending the technology has stopped changing.
The school needs an accountable owner, a cross-functional review group or equivalent governance route, a process for proposing and approving uses, a way to report concerns and a scheduled review. Staff training should cover the decisions people actually make rather than providing a single generic introduction to AI.
The June 2026 school-leader research published by Teach First and Accenture highlights deliberate leadership, clear purpose and boundaries, low-risk starting points and continuing staff learning. Those practices matter because written rules will not create consistent judgement on their own.
Schools should also learn from incidents and near misses. A misleading output, inappropriate pupil interaction, accidental data disclosure or misunderstood instruction should trigger review of the system, training and use case—not only correction of the individual event.
What a School AI Policy Should Contain
A complete policy will normally address:
purpose, scope and governing principles;
definitions that distinguish relevant types of AI use;
roles and decision authority;
approved and prohibited uses for pupils and staff;
teaching, learning, homework and assessment expectations;
acknowledgement and record-keeping requirements;
safeguarding, age appropriateness and accessibility;
personal data, confidentiality and information security;
product and use-case approval;
human oversight for consequential decisions;
transparency with pupils, staff and families;
incident reporting, complaints and escalation;
staff development and pupil AI literacy; and
monitoring, review dates and version control.
The policy should link to—not duplicate—existing safeguarding, data protection, acceptable-use, assessment, behaviour, procurement, complaints and staff-conduct policies. Leaders should check for contradictions. An AI clause cannot authorise behaviour another governing policy prohibits.
A Practical Way to Develop the Policy
Begin with an honest inventory. Where is AI already being used, by whom and for what purpose? Include features embedded inside existing platforms, not only standalone chatbots.
Next, separate low-consequence assistance from uses that affect learning, personal data or significant decisions. Pause any activity the school cannot currently explain, supervise or protect. Identify the jurisdictional and professional guidance that applies.
Then agree the institutional position. What educational value is the school seeking? What human capabilities and relationships will it protect? Which decisions remain exclusively human? Translate those answers into clear permissions, boundaries and responsibilities.
Consult the people who will use and experience the policy. Teachers, operational teams, pupils, families, safeguarding leaders, data-protection advisers and governors may notice different risks or practical ambiguities. Consultation should improve the policy; it should not turn accountability into a vote.
Finally, test the draft against realistic situations. Can a teacher tell whether pupil brainstorming is allowed? Does an administrator know whether a parent email may be drafted using AI? Can a leader explain what happens if a supplier changes its terms? Does a family know where to raise a concern? If the policy cannot guide those decisions, it is not yet operational.
The Policy Should Make Human Responsibility Clearer
Schools do not need to predict the final shape of artificial intelligence before they establish a responsible position. They need to decide what they are trying to improve, what they will not compromise and how people will remain accountable while tools change.
That is the distinction a useful AI policy creates. It does not merely separate allowed software from forbidden software. It defines where machine assistance ends and human responsibility begins.
For some schools, the visible problem will be inconsistent classroom use. For others, it will be data exposure, unclear procurement, parent concern or fragmented leadership. When the policy problem is part of a wider organisational constraint, the School Growth Diagnostic can help leaders determine what must be aligned before adoption accelerates.
_edited.png)



Comments