AI Governance and Responsible Leadership

What Should a School AI Policy Contain? Eight Decisions Leaders Must Settle

Most schools that ask what belongs in an AI policy already have one, and it still cannot answer the question a teacher asks on Monday. A policy is a record of decisions, not a document you write. Here are the eight decisions it has to record.

A bank of five levers on a blue panel, three thrown and two still standing upright, standing for the decisions a school's AI policy has settled and the ones still left open.

In brief

A school's AI policy should contain eight decisions: purpose, permission, data, students, disclosure, approval, accountability and review. A policy is the written record of decisions a school has already made, not a template it adopts, so any decision left open will come back as a question to the leader the policy was supposed to spare. Dan Fitzpatrick's Heading Test checks each line: does it record a decision somebody made and could you name them, could a member of staff follow it on Monday without asking what it means, and would anything happen if someone did the opposite next week. A line that fails any of the three is a heading, not policy.

Most leadership teams who ask me what belongs in an AI policy already have one. It runs to four pages, the governors approved it last term, and when a teacher asks whether she can paste a half-written report into ChatGPT, nobody in the room can find the answer in it.

That is not a drafting problem. A policy is not a document you write. It is the written record of decisions you have already made, and a document can only record a decision that was actually taken. Every template circulating this term hands you the headings. The headings were never the hard part.

So here is the short answer. A school's AI policy should contain eight decisions: purpose, permission, data, students, disclosure, approval, accountability and review. Each one settled by a named person, each written so a member of staff can act on it without asking what it means. What follows is the eight, a test for telling a decision from a heading, and an honest account of when a template is the right move anyway.

What should a school's AI policy contain?

A school's AI policy should contain the eight decisions above and the reasoning behind them, and almost nothing else. The reason is that a policy's job is to be the place where a recurring question is already answered. If the question comes back to you, the policy did not contain the decision, whatever heading it was filed under.

This is also what separates a policy from a strategy, and the two keep getting written as though they were the same document. The Prevent or Direct Test is one question to ask of any AI document: does it change a decision someone would otherwise make, or only prevent one? A document that only prevents is a policy, whatever it is called. A document that changes decisions is a strategy. You need both, and the difference between an AI strategy and an AI policy decides which one you are in the middle of writing.

The demand for the document is real and it is now partly statutory. Ohio's House Bill 96 requires that "each school district, community school established under Chapter 3314. of the Revised Code, and STEM school established under Chapter 3326. of the Revised Code shall adopt a policy on the use of artificial intelligence", with a deadline of July 1, 2026, and the state's AI model policy for Ohio districts and schools supplies a template districts may adopt. In England the Department for Education takes the opposite stance and leaves the choices with you: schools and colleges, its policy paper says, "are free to make their own choices about the most suitable use cases for generative AI (artificial intelligence) tools in their settings, as long as they comply with their wider statutory obligations."

Read those two together and the picture is clear. One jurisdiction tells you that you must have a policy. Neither tells you what to put in it.

The Heading Test

The Heading Test is three questions I ask of every line in a school's AI policy before anyone signs it: Does this line record a decision somebody actually made, and could you name them? Could a member of staff follow it on Monday without asking a second person what it means? And if someone did the opposite next week, would anything happen? A line that survives all three is policy. A line that fails any of them is a heading, and a document made of headings is how a school ends up with a policy and no answers.

This is a suggested filter rather than a validated instrument, and it is deliberately unkind. Run it down a draft and most schools find that three or four lines survive. "Staff should use AI responsibly and in line with data protection legislation" names no decision, no decider and no consequence. It is a heading with a verb in it.

The test matters because policies now exist in numbers that flatter us. RAND's survey of nationally representative panels of teachers, school leaders, district leaders, students and parents, published on September 30, 2025 as AI Use in Schools Is Quickly Increasing but Guidance Lags Behind, found that 45 percent of principals reported having school or district policies or guidance on the use of AI, while only 34 percent of teachers reported policies that specifically addressed academic integrity. Those are different populations answering different questions, so the gap is not a measurement of any one school's failure. But it points at what I see in rooms: the document arrives before the decisions do, and the question staff ask most often is the one it never settled.

The Eight Decisions an AI Policy Records

The Eight Decisions an AI Policy Records are the eight questions a school has to settle before a policy can be written rather than adopted: purpose, permission, data, students, disclosure, approval, accountability and review. A policy is the written record of those eight decisions. Any one of them left open will come back, in the form of a question, to the leader the policy was supposed to spare. This is my suggested way of organizing the work, not a legal standard; where a state, a regulator or a trust specifies required components, those govern and the eight sit inside them.

1. Purpose: what AI is for here, and what it is not for

Settled sounds like: "We use AI to cut the hours staff spend on written administration, and that time goes back into teaching and into talking to children. We do not use it to grade student work or to write anything that goes home about a named child." Unsettled sounds like: "We recognize the transformative potential of artificial intelligence." The second sentence has never stopped anybody doing anything.

2. Permission: which tasks staff may use AI for without asking

Staff do not want a philosophy of AI. They want the list of things they may do without checking with anyone, because checking is slow and a tool that needs permission every time gets used quietly instead. Three short lists do the job: what you may do freely, what you may do and then tell someone, what you may not do. If the middle list is empty, the thinking is not finished.

3. Data: what may never go into a tool, in words a person can recite

The Department for Education's position is plain: "Personal data must be protected in accordance with data protection legislation. It is recommended that personal data is not used in generative AI (artificial intelligence) tools." A policy that restates the law has recorded no decision; it has cited one. The decision is the recitable sentence underneath it, naming the things that must never be typed in: a child's name, a safeguarding note, a medical detail, anything from a pupil record. What staff can and cannot put into ChatGPT is the question they will test the policy with first.

4. Students: which tasks, and from which year group

This is the decision schools most often defer to "in line with supplier terms", which quietly hands the judgment to a company that has never met your students. Suppliers set a contractual floor. Your policy has to say which tasks students may use AI for, which they may not, and from which year group each permission starts, because those are curriculum decisions and nobody outside the building can make them for you.

5. Disclosure: when AI use must be declared, and what follows when it is not

Two halves, and schools usually write the first and skip the second. The first is when a student or a member of staff has to say that AI was used, and in what form. The second is what the school does when it believes a declaration is missing, which is a decision about fairness rather than about technology, and which is why it is worth settling before the first case lands rather than during it. What a school should do when a student is accused of using AI is the process this decision commits you to.

6. Approval: who puts a tool on the list, and what takes it off

Name the person who can add a tool, the person who can veto one, and the written conditions that would remove one. An approved list with no removal conditions is not a list of approved tools, it is a list of tools nobody has reviewed since the day somebody liked them. What schools should require before approving an AI tool sets out what to ask for in writing.

7. Accountability: who answers when it gets something wrong

A name and a role, not a committee. The useful form of this decision has three parts: who answers to the family or the member of staff affected, how someone raises a problem without needing courage to do it, and who puts the error right and by when. Who is accountable when a school's AI tool gets it wrong is the one decision in the eight that cannot be delegated downward.

8. Review: the date, and the event that brings the date forward

Every policy carries a review date and almost none carries a trigger. The trigger matters more, because the thing that dates an AI policy is not the calendar, it is a supplier changing what the product does. Write both: the date you look at it again, and the named events that bring that date forward. An approved tool that has changed is the commonest of those events and the one least likely to be noticed.

What I See in Practice

Across the leadership teams I work with, the eight do not stall evenly. Purpose and data get settled quickly, because they feel like compliance and compliance is familiar ground. The room slows at disclosure, because the honest version requires the school to say in advance what it will do to a student it cannot prove anything about. And it stops at accountability, because the sentence that finishes that decision has somebody's name in it, and until that moment everyone has been discussing a technology rather than agreeing who takes the call from the parent.

I sit on the other side of this table too, as a school trustee, and in board and governor sessions the pattern repeats from the oversight seat. A board asked to approve an AI policy will usually ask whether it is compliant. The more useful question, and the one I have started asking instead, is which of these eight decisions the leadership team made in a meeting, and which ones arrived in the document already written. You can hear the difference in the answer.

The gap this closes is not an administrative one. Public First's polling of 4,000 young people in England for Sir Anthony Seldon and Tim Bunting, published on September 22, 2026 as Britain's Greatest Education Opportunity Ever, found that only 9 percent of young people think schools and universities are preparing them very well for a world with AI, and 38 percent agree they are better at using AI than their teachers. Those students are not waiting for the policy. They are already working out the rules from how the adults around them behave, and an unsettled decision is a rule they get to write themselves.

When adopting a template is the right move

Sometimes it is, and pretending otherwise would be useless to anyone facing a deadline. If a statutory date is coming, adopt the model policy, meet the date, and do not spend the summer drafting prose nobody will read. Ohio's model policy exists precisely for this and its recommended components are sensible: clearly defined uses of AI by students and staff, standards for privacy and personally identifiable information, ethical use, teacher-specific uses, evaluation of purchased resources and vendor agreements, a process for evaluating third-party tools, and consideration of the impact on learning objectives and assessment.

The condition is this. Put the eight decisions on the agenda of the same meeting that adopts the template, and give them longer than the vote. A template adopted before the decisions is a compliance artifact, and it will still send every real question back to you. A template filled in after them is a policy, and nobody will care who supplied the headings.

If what you need is the practitioner's version, the step-by-step drafting process rather than the decisions behind it, how to write an AI policy for your school on the tools blog covers that ground and this article does not.

The check before you sign

Read these out before the vote. Eight questions, eight names.

  1. Can we say in one sentence what AI is for here, and one thing it is not for?
  2. Can a teacher name three things they may do without asking anyone?
  3. Can a teacher recite what must never be typed into a tool?
  4. Do we know which tasks students may use AI for, and from which year group?
  5. Do we know what we do when we think a declaration is missing?
  6. Who adds a tool to the list, and what takes one off it?
  7. Who answers when it gets something wrong, by name?
  8. What date do we look at this again, and what brings that date forward?

Eight yeses and you have a policy. Anything less and you have the headings, and the questions will keep arriving at your door.

Where this goes next

The eight decisions are a governance job, but seven of them are downstream of the first one, and purpose is a strategy question. If your leadership team can answer the eight but cannot agree what AI is for in your school, the policy is not the work. If this is where your team is stuck, it is the kind of problem I work on through AI strategy sessions with school and trust leadership teams, and the newsletter carries the thinking between them.

Sources and further reading

Dan Fitzpatrick is the founder of The AI Educator, a Forbes contributor and a school trustee who works with school and system leaders on AI strategy and governance. More about Dan.

Key takeaways

  • A school's AI policy should contain eight decisions: purpose, permission, data, students, disclosure, approval, accountability and review.
  • A policy is the written record of decisions a school has already taken, so a template adopted before the decisions records nothing and sends every real question back to the leader.
  • The Heading Test, Dan Fitzpatrick's filter, asks of every line whether it records a named person's decision, whether staff could act on it without asking what it means, and whether anything would happen if someone did the opposite.
  • Policies are now common without being complete: RAND found in September 2025 that 45 percent of principals reported school or district AI policies or guidance, while only 34 percent of teachers reported policies specifically addressing academic integrity.
  • Ohio's House Bill 96 required every district, community school and STEM school to adopt an AI policy by July 1, 2026, while England's Department for Education leaves the choices with schools as long as they meet their wider statutory obligations.
  • Accountability is the decision that stalls leadership teams, because finishing the sentence means putting a named person on the call from the parent.
  • Where a statutory deadline is close, adopt the model policy to meet it, then settle the eight decisions in the same meeting and give them longer than the vote.

Frequently Asked Questions

What should a school's AI policy include?

Eight decisions: what AI is for here and what it is not for, which tasks staff may use without asking, what may never be typed into a tool, which tasks students may use and from which year group, when use must be declared, who approves and removes a tool, who answers when it goes wrong, and when the policy is reviewed.

Is a school AI policy a legal requirement?

It depends on jurisdiction. Ohio's House Bill 96 required every school district, community school and STEM school to adopt an AI policy by July 1, 2026. In England the Department for Education leaves schools free to choose their own use cases, provided they comply with their wider statutory obligations.

What is the difference between an AI policy and an AI strategy?

A policy prevents decisions; a strategy changes them. Apply the Prevent or Direct Test: ask whether the document changes a decision someone would otherwise make, or only prevents one. A document that only prevents is a policy, whatever it is called. Schools need both, written separately.

Who should write a school's AI policy?

Drafting can sit with one person, but the eight decisions cannot. Each needs a named decision maker, usually the headteacher or superintendent for purpose and accountability, the data protection lead for data, and curriculum leaders for student permissions. The board approves the record, it does not make the decisions.

How often should a school review its AI policy?

Set a date and a trigger. The date keeps the review on the calendar; the trigger matters more, because what dates an AI policy is a supplier changing what the product does rather than time passing. Name the events that bring the review forward, including a change to an approved tool.

Is it acceptable to adopt a model AI policy template?

Yes, particularly against a statutory deadline. Ohio's model policy exists for that purpose. The condition is that the eight decisions go on the agenda of the same meeting that adopts the template and take longer than the vote, otherwise the document records nothing the school has actually decided.

What should an AI policy say about student data?

It should carry a sentence staff can recite, not a reference to legislation. The Department for Education recommends that personal data is not used in generative AI tools. The decision underneath that is the named list: a child's name, a safeguarding note, a medical detail, anything from a pupil record.

If your leadership team is working through these questions, this is the kind of work I support through AI strategy sessions and advisory work.

Learn more about working together
D
Dan Fitzpatrick

Delivered training to 150K+ educators | Founder of The AI Educator and AI Educator Tools | Forbes Contributor | International Keynote Speaker | 4 x #1 Bestselling Author