Writing an AI acceptable use policy for your school
Most AI policies fail in the same two ways: they are written as prohibitions nobody can enforce, or so vaguely that no teacher can apply them on a Tuesday. Here is a structure that avoids both.
A policy exists so that a teacher facing a decision at 9am, and a parent asking a question at 9pm, get the same answer. Judge every sentence you write against that.
This is a structure, not a template to adopt unread. The decisions inside it are yours, and a policy copied without those decisions being made is the kind that sits in a folder.
1. Scope: say what this covers
State which tools, which people, and which settings. Be explicit about school-owned versus personal devices and about school hours versus homework, because that is the first thing anyone will argue about.
A common trap: writing the policy so it applies only on school devices. That is the easy scope to enforce and it excludes most of the actual use.
2. Permitted, expected, forbidden
Three categories, not two. Most policies have permitted and forbidden and end up unusable, because the interesting cases are the ones where a teacher wants to require AI use — critique this draft, generate practice questions — and there is no category for it.
Then push the decision down to the assignment. A blanket rule cannot distinguish an essay testing unaided argument from a revision exercise where AI is the point. Give staff a standard phrase for each category to put on the assignment itself.
3. Content standards
This is where a school-specific policy earns its keep. Name the categories your community will not have in front of its children. Do not gesture at "inappropriate content" — a teacher cannot apply that and a filter cannot be configured from it.
Then say where the standard is enforced. If it is enforced in the tool, say which, and confirm it applies to images and video as well as to chat. If it is enforced only by expectation, say that too, honestly.
4. Attribution and honesty
Decide what a student must disclose and in what form. "Acknowledge AI use" is too vague to comply with. A single required sentence — which tool, for what part, what the student changed — is specific enough to follow and to check.
Also decide what happens when a student does disclose. If disclosure is punished, students stop disclosing, and you have built an incentive to conceal.
5. Verification
State plainly that AI output can be confidently wrong and that the student is responsible for what they submit. This single expectation does more good than most restrictions, because it is the habit that transfers to every tool they will use later.
Avoid promising to detect AI writing. Detectors are unreliable in both directions, and a policy that rests on one will eventually accuse a student who did nothing wrong.
6. Privacy
Say what students must never enter: their own or others' personal details, anything about another child, staff information. Then say what the school can see about their use, in specific terms.
Be accurate about the tool's own data handling. If you cannot state whether a vendor trains on submitted content, ask them in writing before you name them in a policy.
7. What happens when the rules are broken
Proportionate and stated in advance. Distinguish a student exploring from a student concealing; those are different behaviours and treating them identically teaches the wrong lesson.
Two wording traps
- "Students may not use AI to do their work for them." Nobody can apply this. Where is the line between a tool that explains and a tool that drafts? Name the specific activity instead.
- "AI use must be appropriate." This puts the whole judgement on the teacher in the moment and gives the student no notice of what was expected.
The test for any sentence: could two teachers apply it to the same piece of work and reach the same conclusion? If not, it needs to be more specific.
Common questions
What should an AI policy for schools include?
Scope (which tools, people and devices), three use categories rather than two, a specific content standard, an attribution requirement, a verification expectation, privacy rules, and proportionate consequences.
Should schools rely on AI detection tools?
No. Detectors are unreliable in both directions and a policy resting on one will eventually accuse a student who did nothing wrong. Assessment design and required disclosure are more dependable.
Should the policy cover personal devices?
Yes. A policy scoped only to school-owned devices excludes most actual use, which is the enforcement gap that makes many AI policies ineffective.
Published by Navōn. How these guides are written and checked.
Read next
- Kosher AI: what it means and how to evaluate it
A complete guide to what people mean by kosher AI, why no certification exists, and the specific properties to check before a tool enters your home or classroom.
- AI for schools: a complete guide
Everything a school needs to decide about AI — policy, filtering, staff training, parent communication and rollout — in one place, in the order the decisions arise.
- 12 questions to ask before you buy an AI tool for your school
A procurement checklist with the answers that should worry you. Print it, take it to the demo, and ask every question in order.