The incident is almost never the dramatic one. A report goes home with a paragraph about a child who is not in that class. A letter to parents quotes a policy the school has never had. A set of comments turns out to have been drafted in a tool nobody approved, by one of your strongest teachers, who is now sitting in your office looking at the floor.
You have about an hour to decide what happens next, and the two obvious responses are both wrong. Treat it as misconduct and you will not hear about the next one. Treat it as nothing and you have told the staffroom that the rule was decorative.
What should you do when a member of staff gets AI wrong?
Decide first whether the organization had a rule specific enough to break, and only then decide anything about the person. Three responses follow from that question, and the order matters: if no written rule covered what happened, the failure is the organization's and the response is to write the rule; if a rule covered it and the person misapplied it, the response is to correct the work and support them; if a rule covered it and they knew and chose otherwise, it is a conduct matter and belongs in the conduct process you already have, not in a new one you invent for AI.
Most incidents land in the first category, which is the uncomfortable part. The leader arrives expecting a judgment about a person and leaves with a job of their own.
Why "is this a disciplinary matter?" is the wrong first question
It is the wrong first question because it assumes a rule existed, and in most organizations the rule is thinner than the leader remembers. Guidance is not a rule. A slide from a training day is not a rule. A rule is a sentence a member of staff could have read beforehand and recognized as covering what they were about to do.
The published figures point at the rulebook rather than at the staff. CoSN's U.S. State of EdTech 2026, which collected 607 district responses between January 14 and March 1, 2026, found 79% of districts have AI guidelines in place, up from 57% a year earlier, while 56% have a policy on the acceptable use of generative AI, up from 38%. More districts have guidelines than have a rule about use. That gap is where incidents happen, and it is not the fault of the person standing in your office.
The documents written for staff are no firmer, including the good ones. The District of Columbia's Office of the State Superintendent of Education published an LEA AI Model Policy for Staff Use in September 2026 for this school year, and it is careful work. Staff uses are sorted into red, yellow and green. AI "cannot be used for final decision-making regarding staff and students". Staff must complete approved training before using it, review all outputs, and get named approval for anything outside the policy. On what happens when somebody crosses one of those lines, it offers a single sentence: "The person and the organization using an AI tool may be held responsible for any improper use." No tiers of response, no reporting duty, no procedure. Graduated permission with an undefined response is the standard shape, not one author's oversight.
Now compare the rules schools have written for students, because that is where a leader's instinct about an AI incident quietly comes from. F. Chris Curran and Jiyeon Goo of the University of Florida read 73 codes of conduct across Florida school districts for the 2024 to 2025 school year. Only 23.3% mentioned AI at all. Of those that did, about 94% placed it inside a section on academic dishonesty, and 94% attached potential punishments running from parent notification up to suspension, expulsion or legal action. The one place AI has been written into a rulebook with teeth, it was written as cheating with a penalty on the end. That is the template sitting in a leader's mind at four in the afternoon, and it was built for a different person doing a different thing.
The Department for Education, meanwhile, puts responsibility in two places at once. Its position paper, Generative artificial intelligence (AI) in education, last updated on 12 August 2025, states that "the quality and content of any final documents remains the responsibility of the professional who produced it and the organisation they belong to, regardless of the tools or resources used". Both names are on it. The same paper tells schools to expect "uses of generative AI by staff or pupils that have not been explicitly approved" and to put "plans for mitigating against unauthorised use cases" in their risk assessments. The gap is foreseeable, and planning for it is the organization's job. A response that lands entirely on the individual misreads the guidance it claims to enforce.
The Rule-First Test
The Rule-First Test is two questions I ask before responding to a member of staff whose use of AI has gone wrong, in this order: was there a written rule, specific enough that this person could have read it beforehand and known that what they did was not allowed? And if there was, did they know it and decide otherwise anyway? A no to the first question makes this the organization's failure, and the response is to write the rule. A yes to the first and a no to the second makes it a mistake, and the response is to put the work right and support the person. A yes to both makes it a conduct matter, and it belongs in the process you already have for conduct.
This is my suggested way of ordering the decision, not a validated procedure. Its purpose is to stop a leader reaching for the third response when the evidence only supports the first, because the third is cheaper in the moment and expensive for the rest of the year.
Note what the test does not ask. It does not ask how serious the outcome was. Severity decides how fast you move and who you tell. It does not decide whether the person did anything wrong, and conflating the two is how an organization ends up disciplining someone for an error its own silence made likely.
Response one: write the rule
When no written rule covered what happened, the response is a rule, published this week, with the incident described in it.
The rule has to be specific enough to be broken. "Use AI responsibly" cannot be broken by anybody. "Any letter or report that goes to a parent is read in full by the person whose name is on it, out loud if it is going to more than one family" can be. Name the thing that went wrong, in the words of the work: the unchecked paragraph, the pasted detail, the tool nobody signed off. If you cannot write the rule in the time it takes to draft an email, you have found a decision your leadership team has been avoiding rather than a sentence you cannot phrase.
Then say publicly that no consequence follows for the person who found the gap. That sentence takes ten seconds and buys you the next six reports.
Response two: correct the work, support the person
When a rule existed and the person meant to follow it, fix the work and treat the failure as a process failure, because that is what it is.
Someone who meant to check an output and did not had too little time, no habit, or no idea what checking an AI draft involves. All three are fixable and none is a finding about their character. Put the work right with the family or the student first, in writing, saying what happened. Then change what made the slip easy: a second reader on anything going to more than one household, a template with the check built into it, twenty minutes in a department meeting on what a wrong AI draft looks like. The organizations that get this right treat it the way they treat a marking error: seriously, and without ceremony.
Response three: use the process you already have
When someone knew the rule and chose otherwise, handle it through the staff conduct process the organization already runs, unchanged.
Resist the urge to build an AI version. A separate AI track sounds rigorous and does two kinds of harm: it marks AI errors as a special category of wrongdoing, which deters reporting, and it denies the person the procedural protections your ordinary process gives them. Dishonesty about using AI, a deliberate breach of a data rule, a refusal to stop after being told: your conduct framework already has names for all three. Use them.
This is not the same problem as shadow AI
A member of staff using a tool nobody approved is a different incident with a different diagnosis, and treating the two as one is the mistake I see most often in this area.
Shadow AI is a provision problem. Somebody had a job to do, the approved route was slower or worse, and they went around it, which is why what to do about staff using unapproved tools starts by asking what the approved way took from them. The incident in this article is different: the tool may have been approved and the use permitted, and the output was wrong anyway. One question is about your provision, the other about what happens after an error.
They overlap in one case, and it is the one that reaches leaders most often: an unapproved tool used for a legitimate job, which then produced something wrong. Run both questions and keep the answers apart.
Should the serious cases skip the test?
Yes, in one narrow set of cases, and it is worth saying plainly rather than pretending the sequence is universal.
Where a child's safety is engaged, where personal data has left the organization, or where a statutory duty is in play, the reporting obligation runs at once and waits for nobody's diagnosis. What to do when student data has gone into an AI tool is a separate sequence with its own clock, and the safeguarding route is the safeguarding route whatever caused the referral. The Rule-First Test governs what happens to the member of staff afterward, a different decision made on a different day and usually by somebody other than whoever took the first call.
The test is for the large middle: the ordinary, non-statutory incident nobody has written a procedure for, which is most of them.
What I See in Practice
The organizations that handle this well are not the ones with the best AI policy. They are the ones where somebody reported the first error and nothing happened to them.
I have trained more than 150,000 educators across more than 30 countries, which means I spend a good deal of time in rooms where staff say out loud what they would never put in an email. The thing they ask about most, once the session is over and the leadership team has left, is what happened to somebody else. Across the leadership teams I work with, the pattern holds at every level: the error rate is roughly constant and the reporting rate is not, and the reporting rate is set almost entirely by what happened to the last person who put their hand up. One disciplinary response to an honest mistake and the information stops, not loudly, just completely. The leader concludes things have settled down.
The mistake I see most often is a leadership team answering an incident with a new policy and no decision. A document appears, nobody's week changes, and the next incident is handled by whoever happens to find out. The second most common is its opposite: a measured, well-documented response to a case where the organization had never written the rule at all. That one does the most damage per incident, because the staffroom can see the unfairness even when the paperwork cannot.
What to put in place before the next one
The useful work is all done before the incident, and there is not much of it. Four things, settled in one meeting.
- One rule per route out of the building. Anything that goes to a parent, a student, an employer or a regulator has a named person who reads it in full. Write it as a sentence, not a principle.
- A named pair who decide. Who takes the first call about an AI error, and who they escalate to. Two names, written down, with a deputy for each. Who answers when AI gets something wrong is the same question asked earlier in the story.
- A stated reporting position. Say, in writing and out loud, that reporting an AI error is expected and carries no consequence in itself. Protection is one of the three conditions behind getting staff to use AI at all, and it is the one that an incident either confirms or destroys.
- No new process. Decide now that conduct goes through the conduct process. Deciding it under pressure, with a name attached, is how proportionality slips.
Then run the test on the next incident and notice which of the three responses you reach for. Leaders who never wrote the rule reach for the third one more often than they think, and counting is the only honest way to find out.
If your leadership team is turning AI guidance into rules specific enough to be broken, and deciding who answers when one of them is, that is the work I do with schools and trusts through AI strategy sessions and advisory work. I write each week for school and trust leaders about the decisions this kind of incident exposes, in the newsletter.
Sources and further reading
- U.S. State of EdTech 2026, CoSN, 2026. Survey of 607 US school district technology leaders, fieldwork January 14 to March 1, 2026.
- Generative artificial intelligence (AI) in education, Department for Education, policy paper published 29 March 2023, last updated 12 August 2025.
- LEA AI Model Policy for Staff Use, Office of the State Superintendent of Education, District of Columbia, September 2026, for the 2026 to 2027 school year.
- Curran, F. C. and Goo, J., Disciplining AI Use: How School District Codes of Conduct Govern Students' Use, Education Policy Research Center, University of Florida, 2025. Analysis of 73 codes of conduct across Florida school districts for the 2024 to 2025 school year.
Dan Fitzpatrick is the founder of The AI Educator and has trained more than 150,000 educators across more than 30 countries on leading through AI. More about Dan.


