AI governance in education
Get AI governance right in your school or trust.
I’ve put this site together as a plain-English companion to my Use of Artificial Intelligence (AI) Policy template. It walks you through what you’ll need to decide, why each decision matters, and the law and guidance that sits behind it all. Written for adoption from September 2026.
AI is already in your classrooms and your offices: inside the everyday software your staff use, and a browser tab away for anyone who wants it. Good governance makes sure your use of AI is safe, lawful and defensible, so you get the benefits without putting at risk the safety of children and adults, the privacy of their data, fairness, or professional integrity.
Start wherever suits you
The landscape
Why you need a policy now, what counts as “AI”, and the law and guidance that applies to you.
Read ›Approved tools
The heart of the policy: how a tool becomes approved, and why “not approved” is the starting point.
Read ›Data protection
The rule on personal data, your lawful basis, controllers and processors, and how long data is kept.
Read ›Impact assessment
When you need a DPIA, what a product-safety check covers, and a free tool to get you started.
Read ›Safeguarding & Prevent
Deepfakes, online-safety duties, and how an AI concern reaches your designated safeguarding lead.
Read ›Pupil use
The optional module, and the two conditions to meet before pupils use AI at all.
Read ›The non-negotiables
As with many policies there need to be non-negotiables that help colleagues understand what they can and what they can’t do. In this AI policy there are 5 distinct areas which really must be non-negotiables. I’ve explained below what each of them are and why they are so important that they are, non-negotiable…
No personal data in
Personal or special-category data doesn’t go into AI tools. The only exception is a tool that’s been approved for that exact processing. Once information about a real child or colleague is inside a tool you don’t control, you can’t get it back.
A person always decides
AI never makes a decision about a person. A named member of staff makes, and owns, any decision that affects someone. Accountability has to sit with a person; it can’t sit with a piece of software.
A DPIA before you deploy
You complete a data protection impact assessment before deploying AI that processes personal data. An assessment completed after a tool is in use can’t change the decision to use it.
Approved tools only
Staff use approved tools only, through organisation accounts. Anything else, including public chatbots on a personal login, isn’t approved. Without that approval process, none of the other rules in the policy can be enforced.
Safeguarding duties hold
Your Prevent, safeguarding and online-safety duties apply to AI-assisted work exactly as they do to everything else. New technology doesn’t change those duties.
Two resources to take away
The policy template ↓
My completable Use of AI Policy for schools, trusts and colleges: a staff-use core, with optional modules for pupil use and governed exceptions.
Download ›The DPIA screening tool ↓
A plain-English tool that runs in your browser, for any AI or digital product you’re thinking of buying. Complete it, save it, and send it to your DPO.
Unlock ›Your questions, answered
Does every school need its own AI policy?
You need a position that’s yours, and that your stakeholders have agreed. If you’re a multi-academy trust, adopt one policy centrally and hold school-level detail in local appendices rather than running separate versions. The template is written to be completed for your setting, not used as it stands.
Are pupils covered by the policy?
Not by default. Pupils come into scope only when you switch on the optional pupil-use module, and only once a DPIA and an age-appropriate AI education plan are both in place.
Can staff just use ChatGPT for work?
Only if your organisation has approved it, and only through an organisation-provided account. Personal accounts aren’t used for work, and public consumer chatbots aren’t approved by default.
When do we need a DPIA?
Before you deploy AI that processes personal data, and wherever a tool is likely to create a high risk to people. Doing it early, before the decision is made, is what the DfE guidance expects. The screening tool helps you judge whether you’re ready.