Home › Approved tools & how tools are approved
Staff may use AI for work only through tools your organisation has approved, and only through organisation-provided accounts. Everything else is off-limits by default. That starting point is deliberate.
What it is
A single, clear approval process that every tool goes through before it’s used for work. The approved list names each tool and what it’s approved for. Anything not on that list, including public consumer chatbots and anything reached through a personal login, isn’t approved and isn’t used. One point catches people out: a new AI feature that appears inside a product you already approve isn’t approved by default. It goes back through the same process before anyone uses it. (The policy template refers to this process as the approval gate.)
Governed exceptions (section 4a, optional). Include these only if you choose to permit named tools for single, tightly-defined purposes, with the same scrutiny applied and the exception written down rather than assumed.
Why it’s important
Without an approval process, rules like “no personal data into AI” or “a DPIA before deployment” can’t be enforced. With one, the important questions — what data the tool uses, your lawful basis for it, and what the supplier does with it — are answered before the tool is in daily use, not discovered afterwards. The DfE product safety standards and the ICO’s audit findings both point the same way: assess before you adopt.
What you decide here
- Which tools you approve, and the specific purpose each one is approved for.
- Who approves additions, and how a member of staff requests one.
- Whether you permit any governed exceptions (4a), and how they’re recorded.
- How the approved list is published, and how staff know what’s blocked.
Assessing a particular product? The DPIA screening tool takes you through the questions your approval process should be asking.
Guidance it speaks to
- DfE position on generative AI in education and the DfE generative AI product safety standards (January 2026).
- UK GDPR & Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025); ICO guidance on AI and the ICO AI & data protection risk toolkit.
- the DfE filtering & monitoring, cyber security, and digital leadership & governance standards.
- DfE guidance on procuring edtech and data protection in schools.
A non-negotiable
Tool approval is a non-negotiable, and so is the rule that a new AI feature inside an existing product comes back through it. “We already use this supplier” isn’t the same as approval.