Sections 1–2 of the template

The landscape: why govern AI, and what applies to you

Before any rule: why you’d govern AI at all, what counts as “AI” here, and the law and guidance the policy sits within.

Home › The landscape: why govern AI, and what applies to you

A good AI policy starts with why you’re adopting AI in the first place: what it’s there to help with in your setting, whether that’s teaching, workload or inclusion. Set that out before any rule appears. The governance is there to serve that purpose, not to get in its way.

What it is

The policy statement sets out how your organisation uses AI: by whom, for what, and within what limits, so you get the benefits without putting at risk the safety of children and adults, data security and privacy, fairness, or professional and academic integrity. It sits within your wider digital strategy. You should review it on a set cycle, and again whenever the law, the guidance, or your own use of AI changes in any material way. AI develops at pace, so treat that cycle as a minimum rather than a formality.

What counts as AI here. Generative AI tools, and any software feature that creates content, or that makes or informs decisions or predictions about people. That holds whether the feature is a standalone product, built into software you already approve, or reached through a browser. In practice, it means chatbots, image and content generators, and the AI features now appearing inside everyday software. Long-established automation such as spellcheck or predictive text is out of scope, unless it starts doing one of those things.

Why it’s important

AI rarely arrives through one obvious route. It turns up inside the platforms you already license, and it’s a browser tab away for any member of staff. If your policy only covers “the AI tool we bought”, it’ll miss most of your real exposure. The template therefore defines scope by what a tool does: does it generate content, or make or inform decisions about people? Scoped that way, your policy stays relevant as products change around you.

There’s an inspection angle too. When Ofsted visits, schools and trusts will increasingly need to show how they manage the risks that come with AI — data privacy, intellectual property, bias and ethics — how they comply with safeguarding and data governance duties, and how they use AI to support workload, accessibility and equity. Similar expectations apply to British Schools Overseas and to independent schools inspected by ISI, whose frameworks follow the same lines.

If you’re a multi-academy trust, my advice is to adopt one policy centrally and hold school-level detail in local appendices. I’ve seen separate versions drift apart over time, and they become very hard to assure.

What you decide here

  • Your reasons for adopting AI: a sentence or two on what it’s there to help with in your setting.
  • Your organisation name, review cycle, and who is in scope (usually all staff, governors, trustees, volunteers and contractors).
  • Any platform AI features that are governed by a separate assessment, noted so the boundary is clear.
  • Whether pupils are in scope. They aren’t, by default, until the optional module’s conditions are met.

Guidance it speaks to

Working on your AI policy?

Support with writing or refining it, and with training your staff, is exactly the work I do. And if the template or the screening tool has helped in your school or trust, I’d love to hear about it.