How to Write an AI Policy for Your School

An AI policy for schools is a written governance document that defines how students, teachers, and staff may use artificial intelligence tools (such as generative AI, chatbots, and automated decision systems) on campus, what data those tools may process, and who is accountable when they fail. A defensible policy covers four pillars: permitted and prohibited uses, academic integrity, student data privacy, and bias and oversight controls. The fastest way to produce one is to adapt an existing framework to your jurisdiction's laws, then ratify it through your school board or governing body before the next term.

Schools that skip a formal policy do not avoid AI. They get shadow AI instead: unsanctioned tools used without review, with student data flowing to vendors no one vetted. A written policy converts that exposure into a set of decisions you can defend to parents, auditors, and regulators.

What is an AI policy for schools, and why does your school need one?

An AI policy is the governing rulebook that sits above individual classroom decisions. It states which AI systems are approved, the conditions of use, and the consequences for misuse. It applies to three distinct populations with different risk profiles:

  • Students using AI for coursework, research, and assignments.

  • Teachers and staff using AI for lesson planning, grading assistance, communications, and administrative work.

  • The institution procuring AI systems for admissions, enrollment, advising, proctoring, or operations.

The need is driven by exposure on four fronts:

  1. Legal and regulatory. Federal student-privacy law (FERPA) governs how education records are shared with third parties, and AI vendors are third parties. State laws increasingly regulate automated decisions.

  2. Academic integrity. Without a stated standard, plagiarism and cheating cases collapse on appeal because the rules were never published.

  3. Equity and bias. AI systems can produce discriminatory outcomes against protected groups, including in admissions and discipline.

  4. Operational and reputational. A single unvetted tool that leaks student records becomes a public incident and a breach notification obligation.

A policy does not slow adoption. It is what lets a school adopt AI on purpose instead of by accident.

What laws and regulations must a school AI policy account for?

Your policy is a compliance instrument, not just a statement of values. It must map to the legal regime you operate under. The table below summarizes the load-bearing authorities for U.S. schools and where they apply.

Authority: Family Educational Rights and Privacy Act (FERPA)
What it governs: Access to and disclosure of student education records.
Relevance to schools: AI vendors that process student records are considered third parties, and institutions must satisfy the conditions of the FERPA "school official" exception before sharing data.

Authority: Children's Online Privacy Protection Act (COPPA)
What it governs: Collection of personal information from children under the age of 13.
Relevance to schools: Many AI-powered educational tools require verifiable parental consent before collecting data from younger students.

Authority: EEOC guidance on AI (Title VII and ADA)
What it governs: Employment discrimination involving AI-assisted hiring and employment decisions.
Relevance to schools: Applies when schools use AI to recruit, screen, or hire faculty and staff.

Authority: EU AI Act
What it governs: High-risk AI systems, including those used in education and employment.
Relevance to schools: AI systems used for educational access, student assessment, and employment may be classified as high-risk and subject to extensive compliance requirements.

Authority: Colorado AI Act (SB 24-205)
What it governs: Consumer protections for high-risk AI systems, including those used in education and employment.
Relevance to schools: Requires organizations to exercise reasonable care to prevent algorithmic discrimination in consequential decisions.

Authority: Illinois AI Video Interview Act
What it governs: AI systems that analyze recorded video interviews.
Relevance to schools: Applies to staff hiring and some admissions interview processes, requiring candidate notice and consent.

Authority: NYC Local Law 144
What it governs: Bias audits for Automated Employment Decision Tools (AEDTs).
Relevance to schools: Applies to AI-assisted hiring by schools in New York City and requires independent bias audits and candidate notice. Enforcement began in July 2023.

Two points matter for accuracy. First, FERPA does not prohibit using AI vendors; it conditions it. A vendor can qualify under the "school official" exception only if it performs a service the school would otherwise perform, stays under the school's direct control, and does not reuse the data. Second, employment-facing AI (hiring teachers, screening applicants) is regulated separately from instructional AI, so a complete policy addresses both. For a focused treatment of the records-privacy question, see our guide on student data privacy, FERPA, and AI.

Why does AI bias matter for admissions and hiring decisions?

Bias is not hypothetical, and real cases set the baseline for what a policy must prevent.

  • Amazon scrapped an internal AI recruiting tool around 2018 after it learned to down-rank resumes associated with women, having trained on a male-dominated hiring history.

  • The EEOC settled with iTutorGroup in 2023 for $365,000 after the company's software automatically rejected older applicants based on age.

  • In Mobley v. Workday, a court allowed claims to proceed that AI-driven applicant screening discriminated on the basis of age, race, and disability.

The lesson for schools is direct. An AI system that influences who gets admitted, hired, disciplined, or flagged can encode discrimination at scale and create liability under existing civil rights law. Your policy must require human review and bias testing for any AI that touches a consequential decision about a person.

How do you write an AI policy for your school, step by step?

Use this sequence. Each step produces an artifact that feeds the next.

  1. Convene a governance group. Include administration, IT and security, a legal or compliance contact, teachers, and at least one parent or board representative. Assign a single accountable owner.

  2. Inventory current AI use. Survey what tools students and staff already use. You cannot govern what you have not counted, and you will find shadow AI.

  3. Classify use cases by risk. Sort each use into low, medium, or high risk based on whether it touches student records, influences decisions about people, or is student-facing.

  4. Set permitted and prohibited uses. Write explicit rules per population. Name what is encouraged, what requires disclosure, and what is banned.

  5. Define the data rules. State what student data may enter any AI tool, what may never, and the vendor-vetting standard (FERPA terms, data deletion, no model training on student data).

  6. Write the academic integrity standard. Define acceptable AI assistance versus academic dishonesty, with disclosure requirements and a process for suspected violations.

  7. Set bias, accuracy, and oversight controls. Require human review for consequential decisions and bias testing for high-risk systems.

  8. Build the approval and procurement gate. No new AI tool gets used with student data until it clears a documented review.

  9. Add training and an incident process. Specify required training and a clear path to report misuse or a data incident.

  10. Ratify, publish, and schedule review. Adopt the policy formally, distribute it in plain language, and set a fixed review date (at least annually).

What sections should the policy document contain?

A complete policy document has these named sections. Use them as your table of contents.

  • Purpose and scope: who and what the policy covers.

  • Definitions: AI, generative AI, automated decision system, and student data, in plain terms.

  • Guiding principles: effective and responsible use, equity, and transparency.

  • Permitted uses: by student, staff, and institution.

  • Prohibited uses: including entering protected student data into unapproved tools.

  • Academic integrity: disclosure rules and the violation process.

  • Data privacy and security: vendor standards, consent, retention, and FERPA alignment.

  • Bias, fairness, and human oversight: testing and review requirements.

  • Accessibility: accommodations under the ADA and Section 504.

  • Procurement and approval: the gate every new tool passes.

  • Roles and responsibilities: who owns, approves, and enforces.

  • Training: required for staff and age-appropriate for students.

  • Incident response: reporting and remediation.

  • Review and revision: owner and cadence.

How should the policy handle academic integrity and AI?

Academic integrity is where most policies are tested first, so write it to survive an appeal. Avoid a flat ban that you cannot enforce and that ignores legitimate uses. Instead, define a tiered standard:

  • Permitted without disclosure: brainstorming, studying, spell-check, and accessibility tools.

  • Permitted with disclosure: AI used to draft or substantially assist graded work, where the student cites the tool and the prompt.

  • Prohibited: submitting AI-generated work as one's own, using AI on assessments where it is banned, or using AI to fabricate sources.

State the standard at the assignment level too, because acceptable use differs between a take-home essay and a closed-book exam. One accuracy note: AI-detection tools are unreliable and produce false positives, so do not let a detector score alone determine a violation. Require corroborating evidence and give the student a chance to respond.

How do you handle student data privacy in an AI policy?

Treat every AI vendor as a third party that will receive student data unless you prove otherwise. The controlling questions are what data goes in, where it goes, and what the vendor may do with it.

Set these as hard rules:

  • No protected student data (names tied to records, grades, disabilities, discipline, identifiers) enters a tool that has not cleared procurement review.

  • Vendor contracts must bar secondary use, including training the vendor's models on your students' data, and must specify deletion timelines.

  • Consent obligations are honored: parental consent for under-13 use under COPPA, and FERPA-compliant arrangements for record disclosure.

  • Data minimization is the default: the least data needed for the task, de-identified where possible.

The recurring failure is staff pasting student work, IEP content, or grade data into a free public chatbot. Your policy must name that as prohibited and give staff an approved alternative so the rule is realistic.

What does an effective AI policy look like in practice?

The strongest school policies share four properties. The table contrasts a defensible policy with a weak one.

Property: Specificity
Weak policy: "Use AI responsibly."
Defensible policy: Clearly defines which AI uses are permitted, which require disclosure, and which are prohibited for different groups of users.

Property: Enforceability
Weak policy: Relies primarily on AI detection scores.
Defensible policy: Requires corroborating evidence and gives the student an opportunity to respond before any disciplinary action.

Property: Data rules
Weak policy: Does not address AI vendors or data handling practices.
Defensible policy: Requires a procurement review, prohibits unauthorized secondary use of data, and aligns vendor practices with FERPA requirements.

Property: Maintenance
Weak policy: Treated as a one-time document that is rarely revisited.
Defensible policy: Assigns a policy owner, requires annual reviews, and includes a documented process for handling AI-related incidents and updates.

An effective policy is short enough to be read, specific enough to be enforced, and current enough to be trusted. It is written for effective and responsible use, not as a list of fears. It says yes to clearly bounded uses so that the prohibitions carry weight.

Frequently asked questions

How long should a school AI policy be?

Long enough to cover the named sections and short enough that staff and older students will read it. Many workable policies run a few pages of plain-language rules, supported by separate appendices for procurement checklists and approved-tool lists. Length is not the goal; coverage and clarity are. If a section cannot be enforced or explained simply, rewrite it.

Should we ban AI in schools entirely?

A total ban is rarely enforceable and forgoes legitimate educational value. It also pushes use into shadow AI, which raises your data risk rather than lowering it. A tiered policy that permits bounded uses, requires disclosure for graded work, and prohibits specific high-risk actions is more defensible and more honest about how the tools are already used.

How often should the AI policy be reviewed?

Review at least annually, and sooner when a major law changes, a new tool category appears, or an incident exposes a gap. Assign a named owner responsible for the review cadence, and tie the schedule to a fixed calendar date so it is not skipped. AI capabilities and regulations change quickly, so a policy left unreviewed for years stops matching reality.

Who should be responsible for AI governance in a school?

Accountability should sit with a single named owner, usually a senior administrator or a designated AI or data officer, supported by a standing committee. The committee should include IT and security, a legal or compliance contact, teaching staff, and parent or board representation. Distributed input with single-point ownership keeps the policy from becoming everyone's responsibility and therefore no one's.

Next steps

  • Name a single accountable owner and convene a governance group.

  • Inventory every AI tool already in use by students and staff.

  • Classify each use case as low, medium, or high risk.

  • Draft permitted, disclosure-required, and prohibited uses per population.

  • Write the FERPA-aligned data and procurement rules.

  • Add a tiered academic integrity standard that does not rely on detectors alone.

  • Require human review and bias testing for consequential decisions.

  • Ratify through your board, publish in plain language, and set an annual review date.

Previous
Previous

Student Data Privacy and AI: FERPA in Practice

Next
Next

AI Literacy: What Every Student Should Learn