AI Adoption and Organisational Change

What Should Leaders Do When Staff Get AI Wrong?

Treat an AI error as misconduct and you will not hear about the next one. Treat it as nothing and the rule was decorative. The Rule-First Test asks whether the organization had a rule specific enough to break before it asks anything about the person.

Three blue cut-paper blocks of increasing size stand in a row on a hand-drawn black ground line with a black ring circled around the smallest, standing for choosing the smallest response that fits rather than the largest one available.

In brief

When a member of staff gets AI wrong, decide first whether the organization had a written rule specific enough to break, and only then decide anything about the person. Three responses follow in order: if no written rule covered it, the failure is the organization's and the response is to write the rule; if a rule covered it and the person misapplied it, correct the work and support them; if they knew the rule and chose otherwise, it is a conduct matter and belongs in the conduct process the organization already has. CoSN's U.S. State of EdTech 2026, surveying 607 US districts between January 14 and March 1, 2026, found 79% have AI guidelines while 56% have a policy on acceptable use of generative AI, so most incidents fall in the first category.

The incident is almost never the dramatic one. A report goes home with a paragraph about a child who is not in that class. A letter to parents quotes a policy the school has never had. A set of comments turns out to have been drafted in a tool nobody approved, by one of your strongest teachers, who is now sitting in your office looking at the floor.

You have about an hour to decide what happens next, and the two obvious responses are both wrong. Treat it as misconduct and you will not hear about the next one. Treat it as nothing and you have told the staffroom that the rule was decorative.

What should you do when a member of staff gets AI wrong?

Decide first whether the organization had a rule specific enough to break, and only then decide anything about the person. Three responses follow from that question, and the order matters: if no written rule covered what happened, the failure is the organization's and the response is to write the rule; if a rule covered it and the person misapplied it, the response is to correct the work and support them; if a rule covered it and they knew and chose otherwise, it is a conduct matter and belongs in the conduct process you already have, not in a new one you invent for AI.

Most incidents land in the first category, which is the uncomfortable part. The leader arrives expecting a judgment about a person and leaves with a job of their own.

Why "is this a disciplinary matter?" is the wrong first question

It is the wrong first question because it assumes a rule existed, and in most organizations the rule is thinner than the leader remembers. Guidance is not a rule. A slide from a training day is not a rule. A rule is a sentence a member of staff could have read beforehand and recognized as covering what they were about to do.

The published figures point at the rulebook rather than at the staff. CoSN's U.S. State of EdTech 2026, which collected 607 district responses between January 14 and March 1, 2026, found 79% of districts have AI guidelines in place, up from 57% a year earlier, while 56% have a policy on the acceptable use of generative AI, up from 38%. More districts have guidelines than have a rule about use. That gap is where incidents happen, and it is not the fault of the person standing in your office.

The documents written for staff are no firmer, including the good ones. The District of Columbia's Office of the State Superintendent of Education published an LEA AI Model Policy for Staff Use in September 2026 for this school year, and it is careful work. Staff uses are sorted into red, yellow and green. AI "cannot be used for final decision-making regarding staff and students". Staff must complete approved training before using it, review all outputs, and get named approval for anything outside the policy. On what happens when somebody crosses one of those lines, it offers a single sentence: "The person and the organization using an AI tool may be held responsible for any improper use." No tiers of response, no reporting duty, no procedure. Graduated permission with an undefined response is the standard shape, not one author's oversight.

Now compare the rules schools have written for students, because that is where a leader's instinct about an AI incident quietly comes from. F. Chris Curran and Jiyeon Goo of the University of Florida read 73 codes of conduct across Florida school districts for the 2024 to 2025 school year. Only 23.3% mentioned AI at all. Of those that did, about 94% placed it inside a section on academic dishonesty, and 94% attached potential punishments running from parent notification up to suspension, expulsion or legal action. The one place AI has been written into a rulebook with teeth, it was written as cheating with a penalty on the end. That is the template sitting in a leader's mind at four in the afternoon, and it was built for a different person doing a different thing.

The Department for Education, meanwhile, puts responsibility in two places at once. Its position paper, Generative artificial intelligence (AI) in education, last updated on 12 August 2025, states that "the quality and content of any final documents remains the responsibility of the professional who produced it and the organisation they belong to, regardless of the tools or resources used". Both names are on it. The same paper tells schools to expect "uses of generative AI by staff or pupils that have not been explicitly approved" and to put "plans for mitigating against unauthorised use cases" in their risk assessments. The gap is foreseeable, and planning for it is the organization's job. A response that lands entirely on the individual misreads the guidance it claims to enforce.

The Rule-First Test

The Rule-First Test is two questions I ask before responding to a member of staff whose use of AI has gone wrong, in this order: was there a written rule, specific enough that this person could have read it beforehand and known that what they did was not allowed? And if there was, did they know it and decide otherwise anyway? A no to the first question makes this the organization's failure, and the response is to write the rule. A yes to the first and a no to the second makes it a mistake, and the response is to put the work right and support the person. A yes to both makes it a conduct matter, and it belongs in the process you already have for conduct.

This is my suggested way of ordering the decision, not a validated procedure. Its purpose is to stop a leader reaching for the third response when the evidence only supports the first, because the third is cheaper in the moment and expensive for the rest of the year.

Note what the test does not ask. It does not ask how serious the outcome was. Severity decides how fast you move and who you tell. It does not decide whether the person did anything wrong, and conflating the two is how an organization ends up disciplining someone for an error its own silence made likely.

Response one: write the rule

When no written rule covered what happened, the response is a rule, published this week, with the incident described in it.

The rule has to be specific enough to be broken. "Use AI responsibly" cannot be broken by anybody. "Any letter or report that goes to a parent is read in full by the person whose name is on it, out loud if it is going to more than one family" can be. Name the thing that went wrong, in the words of the work: the unchecked paragraph, the pasted detail, the tool nobody signed off. If you cannot write the rule in the time it takes to draft an email, you have found a decision your leadership team has been avoiding rather than a sentence you cannot phrase.

Then say publicly that no consequence follows for the person who found the gap. That sentence takes ten seconds and buys you the next six reports.

Response two: correct the work, support the person

When a rule existed and the person meant to follow it, fix the work and treat the failure as a process failure, because that is what it is.

Someone who meant to check an output and did not had too little time, no habit, or no idea what checking an AI draft involves. All three are fixable and none is a finding about their character. Put the work right with the family or the student first, in writing, saying what happened. Then change what made the slip easy: a second reader on anything going to more than one household, a template with the check built into it, twenty minutes in a department meeting on what a wrong AI draft looks like. The organizations that get this right treat it the way they treat a marking error: seriously, and without ceremony.

Response three: use the process you already have

When someone knew the rule and chose otherwise, handle it through the staff conduct process the organization already runs, unchanged.

Resist the urge to build an AI version. A separate AI track sounds rigorous and does two kinds of harm: it marks AI errors as a special category of wrongdoing, which deters reporting, and it denies the person the procedural protections your ordinary process gives them. Dishonesty about using AI, a deliberate breach of a data rule, a refusal to stop after being told: your conduct framework already has names for all three. Use them.

This is not the same problem as shadow AI

A member of staff using a tool nobody approved is a different incident with a different diagnosis, and treating the two as one is the mistake I see most often in this area.

Shadow AI is a provision problem. Somebody had a job to do, the approved route was slower or worse, and they went around it, which is why what to do about staff using unapproved tools starts by asking what the approved way took from them. The incident in this article is different: the tool may have been approved and the use permitted, and the output was wrong anyway. One question is about your provision, the other about what happens after an error.

They overlap in one case, and it is the one that reaches leaders most often: an unapproved tool used for a legitimate job, which then produced something wrong. Run both questions and keep the answers apart.

Should the serious cases skip the test?

Yes, in one narrow set of cases, and it is worth saying plainly rather than pretending the sequence is universal.

Where a child's safety is engaged, where personal data has left the organization, or where a statutory duty is in play, the reporting obligation runs at once and waits for nobody's diagnosis. What to do when student data has gone into an AI tool is a separate sequence with its own clock, and the safeguarding route is the safeguarding route whatever caused the referral. The Rule-First Test governs what happens to the member of staff afterward, a different decision made on a different day and usually by somebody other than whoever took the first call.

The test is for the large middle: the ordinary, non-statutory incident nobody has written a procedure for, which is most of them.

What I See in Practice

The organizations that handle this well are not the ones with the best AI policy. They are the ones where somebody reported the first error and nothing happened to them.

I have trained more than 150,000 educators across more than 30 countries, which means I spend a good deal of time in rooms where staff say out loud what they would never put in an email. The thing they ask about most, once the session is over and the leadership team has left, is what happened to somebody else. Across the leadership teams I work with, the pattern holds at every level: the error rate is roughly constant and the reporting rate is not, and the reporting rate is set almost entirely by what happened to the last person who put their hand up. One disciplinary response to an honest mistake and the information stops, not loudly, just completely. The leader concludes things have settled down.

The mistake I see most often is a leadership team answering an incident with a new policy and no decision. A document appears, nobody's week changes, and the next incident is handled by whoever happens to find out. The second most common is its opposite: a measured, well-documented response to a case where the organization had never written the rule at all. That one does the most damage per incident, because the staffroom can see the unfairness even when the paperwork cannot.

What to put in place before the next one

The useful work is all done before the incident, and there is not much of it. Four things, settled in one meeting.

  1. One rule per route out of the building. Anything that goes to a parent, a student, an employer or a regulator has a named person who reads it in full. Write it as a sentence, not a principle.
  2. A named pair who decide. Who takes the first call about an AI error, and who they escalate to. Two names, written down, with a deputy for each. Who answers when AI gets something wrong is the same question asked earlier in the story.
  3. A stated reporting position. Say, in writing and out loud, that reporting an AI error is expected and carries no consequence in itself. Protection is one of the three conditions behind getting staff to use AI at all, and it is the one that an incident either confirms or destroys.
  4. No new process. Decide now that conduct goes through the conduct process. Deciding it under pressure, with a name attached, is how proportionality slips.

Then run the test on the next incident and notice which of the three responses you reach for. Leaders who never wrote the rule reach for the third one more often than they think, and counting is the only honest way to find out.

If your leadership team is turning AI guidance into rules specific enough to be broken, and deciding who answers when one of them is, that is the work I do with schools and trusts through AI strategy sessions and advisory work. I write each week for school and trust leaders about the decisions this kind of incident exposes, in the newsletter.

Sources and further reading

Dan Fitzpatrick is the founder of The AI Educator and has trained more than 150,000 educators across more than 30 countries on leading through AI. More about Dan.

Key takeaways

  • Decide whether the organization had a rule specific enough to break before deciding anything about the person; most AI incidents turn out to be a missing rule rather than a staff failure.
  • CoSN's U.S. State of EdTech 2026, from 607 US district responses collected between January 14 and March 1, 2026, found 79% of districts have AI guidelines while 56% have a policy on acceptable use of generative AI.
  • The District of Columbia's LEA AI Model Policy for Staff Use, published in September 2026, sorts staff AI uses into red, yellow and green tiers and then specifies no graduated consequence, no reporting duty and no procedure for a breach.
  • The Department for Education's position paper, last updated 12 August 2025, places responsibility on both the professional who produced a document and the organisation they belong to, so a response that falls entirely on the individual misreads the guidance.
  • Curran and Goo found that only 23.3% of 73 Florida school district codes of conduct mentioned AI, and about 94% of those placed it inside academic dishonesty with punishments attached, which is the template leaders borrow without noticing.
  • Dan Fitzpatrick's Rule-First Test gives three responses in order: write the rule, correct the work and support the person, or use the staff conduct process the organization already runs.
  • Severity decides how fast a leader moves and who they tell; it does not decide whether the member of staff did anything wrong, and confusing the two is how an organization disciplines someone for an error its own silence made likely.
  • The error rate in an organization is roughly constant and the reporting rate is not: one disciplinary response to an honest mistake and the information stops arriving.

Frequently Asked Questions

What should you do when a member of staff gets AI wrong?

Ask first whether a written rule covered what happened, specific enough that the person could have read it and known. If none did, write the rule and impose no consequence. If one did and they misapplied it, correct the work and support them. If they knew and chose otherwise, use your existing conduct process.

Is a member of staff using AI badly a disciplinary matter?

Usually not. Discipline is the right response only where a specific written rule existed and the person knowingly chose to ignore it. Where the organization never wrote the rule, the failure belongs to the organization, and a disciplinary response to an honest error reliably stops anyone reporting the next one.

What is the Rule-First Test?

It is Dan Fitzpatrick's suggested way of ordering the decision: was there a written rule specific enough that this person could have known what they did was not allowed, and if so, did they know it and decide otherwise anyway? The answers point to one of three responses.

Should a school have a separate disciplinary process for AI?

No. A separate AI track marks AI errors as a special category of wrongdoing, which deters reporting, and it denies the person the procedural protections the ordinary process gives them. Dishonesty, a deliberate breach of a data rule and a refusal to stop already have names in any staff conduct framework.

How is this different from shadow AI?

Shadow AI is a provision problem: somebody went around an approved route that was slower or worse. This is a response problem: the tool may have been approved and the use permitted, and the output was wrong anyway. The two overlap when an unapproved tool produces a wrong result.

What should a leader do first when an AI error has already reached a parent?

Put the work right with the family in writing, saying plainly what happened, before deciding anything about the member of staff. Where a child's safety or personal data is involved, the statutory reporting route runs immediately and does not wait for any diagnosis of how the error happened.

What makes an AI rule specific enough to be useful?

A rule you could break. "Use AI responsibly" cannot be broken by anyone. "Any letter or report going to a parent is read in full by the person whose name is on it" can be. Name the thing that went wrong in the words of the work itself.

If your leadership team is working through these questions, this is the kind of work I support through AI strategy sessions and advisory work.

Learn more about working together
D
Dan Fitzpatrick

Delivered training to 150K+ educators | Founder of The AI Educator and AI Educator Tools | Forbes Contributor | International Keynote Speaker | 4 x #1 Bestselling Author