Artificial intelligence will enter schools this year through more than new, stand-alone tools.
Teachers will experiment with generative AI platforms. Students will encounter AI-powered learning experiences. Departments will use AI to improve productivity. Vendors will continue adding AI features to products districts already own—sometimes without calling attention to how those features affect data collection, accuracy, security, or instructional practice.
For technology leaders, the goal should not be to approve or prohibit every possible use of AI. That approach cannot keep pace with the technology.
The goal is to create a governance system that enables responsible innovation while giving employees clear boundaries, reliable processes, and approved alternatives.
Before the school year gains momentum, districts should put the following procedures in place.
Establish a Cross-Department AI Governance Team
AI governance cannot belong to the technology department alone.
AI decisions can affect instruction, student privacy, cybersecurity, accessibility, procurement, communications, human resources, legal compliance, and district policy. Establish a standing team that includes representatives from:
-
- Technology
- Curriculum and instruction
- Data privacy and cybersecurity
- Special education and accessibility
- Finance and procurement
- Human resources
- Communications
- Legal counsel or policy leadership
- School administration
- Classroom educators
The team should define who reviews new tools, who approves different types of use, who communicates decisions, and who monitors tools after adoption.
It should also establish an escalation process for sensitive or high-risk uses involving areas such as student evaluation, discipline, special education, mental health, employee decisions, or automated recommendations.
Create an Inventory of AI-Enabled Products
Districts cannot govern what they cannot see.
Begin with an inventory of stand-alone AI tools and products that have recently added AI functionality. Look beyond generative chatbots to include:
-
- Adaptive learning platforms
- Automated writing or feedback tools
- AI tutoring products
- Translation and transcription tools
- Content-generation features
- Meeting assistants
- Data analytics and prediction tools
- Plagiarism or AI-detection products
- Automated monitoring systems
- Chatbots and virtual assistants
- AI features embedded in productivity platforms
For every product, document:
-
- The vendor and product owner
- The AI features available
- Who can access them
- The intended use
- The data involved
- Whether student or employee information is processed
- The current approval status
- Contract and privacy documentation
- Applicable restrictions
- The date of the most recent review
- Whether the feature can be disabled
Do not assume that a previously approved platform remains covered by its original review. A significant new AI feature may introduce different functionality, data practices, risks, or terms.
Publish an Interim AI Use Standard
Districts do not need to wait for a perfect, comprehensive policy before giving employees direction.
Publish a clear interim standard that explains:
-
- Which AI tools are approved
- Whether students may use them
- Which uses require additional review
- What information may never be entered
- When human review is required
- How employees should disclose AI assistance
- How teachers should address student AI use
- How to request a new tool or use case
- Where employees should report concerns or incidents
The standard should distinguish between different levels of use.
For example:
| Use level | Example | Recommended procedure |
|---|---|---|
| Lower risk | Brainstorming ideas without protected information | Use an approved tool and verify the output |
| Moderate risk | Creating instructional materials or student-facing content | Use an approved tool, review for accuracy, bias and accessibility |
| Higher risk | Entering student work, records or identifiable information | Require formal privacy, security and legal review |
| Restricted | Using AI as the sole basis for grades, discipline, placement or eligibility | Prohibit or require executive and legal approval with meaningful human oversight |
This provides practical guidance while the district develops more permanent policies.
Standardize the AI Tool Review Process
Employees need one clearly communicated process for requesting new AI tools.
That process should begin with the use case—not simply the product name. Ask the requester to explain:
-
- What need the tool addresses
- Who will use it
- Whether students will access it directly
- What data will be entered or generated
- What decisions the tool may influence
- Whether an approved alternative already exists
- What benefit the district expects
- How success will be evaluated
The review should then route the request to the appropriate stakeholders. A classroom content generator may need curriculum, privacy and accessibility review. An administrative analytics tool may require technology, security, legal and executive review.
At minimum, evaluate:
-
- Instructional or operational value
- Student-data practices
- Security controls
- Age and consent requirements
- Accessibility
- Accuracy and potential bias
- Human oversight
- Data ownership and deletion
- Model-training practices
- Contract terms and indemnification
- Cost and overlapping products
- Offboarding requirements
The U.S. Department of Education advises teachers to confirm that an online application is district-approved before classroom use. When education-record information is involved, the service must satisfy applicable FERPA requirements, including restrictions on data use and redisclosure.
Don’t have an automated review process? Ask for a demo!
Define Clear Data Rules
A general warning to “protect student data” is not enough. Employees need specific examples.
District guidance should identify information that may not be entered into a public or unapproved AI tool, including:
-
- Student names and identification numbers
- Grades and assessment records
- IEP or Section 504 information
- Health or counseling information
- Behavioral and disciplinary records
- Student images, voices or videos
- Personally identifiable student work
- Confidential employee information
- Passwords or security details
- Unreleased district records
- Information that could identify someone indirectly
For approved tools, document whether prompts and uploads are retained, shared, used for model training, or available to other users.
Contracts should address data ownership, retention, deletion, breach notification, sub-processors, model training, secondary use, and what happens when the relationship ends.
Data minimization should be the default: collect and share only what is necessary for the approved purpose.
Set Age and Consent Procedures
Many publicly available AI tools have minimum-age requirements or require parental permission for younger users. These requirements can differ based on the product, account type, contract, and intended use.
For each student-facing tool, document:
-
- Minimum user age
- Approved grades
- Whether students create accounts
- Whether parental consent is required
- Whether the district provisions accounts
- Whether students can publish or share content
- Whether advertising or public interaction is present
- What data is collected
- Whether a teacher-led demonstration is permitted when direct student use is not
Make this information visible in the district’s approved-tools catalog so educators do not have to interpret vendor terms independently.
Require Human Review of AI Outputs
AI-generated content should be treated as a draft or recommendation—not as an unquestioned answer.
District procedures should require employees to verify:
-
- Facts and citations
- Calculations
- Reading level
- Curriculum alignment
- Bias and stereotypes
- Cultural representation
- Accessibility
- Age appropriateness
- Copyright and attribution concerns
- Confidential information
- Potentially harmful or misleading content
Human oversight is especially important when an AI output could affect a student’s grade, placement, services, discipline, opportunity, or wellbeing.
Publish an Approved AI and EdTech Catalog
Policies tell employees what the rules are. A staff-facing catalog helps them apply those rules.
For each approved tool, publish:
-
- What the product does
- Its approved instructional or operational purpose
- Who may use it
- Applicable grade levels
- How to access it
- What information may or may not be entered
- Required training
- Age or consent requirements
- Known limitations
- Support contacts
- Approved alternatives
- The product owner
- How to report a concern
A searchable catalog reduces uncertainty and makes compliance easier. It also helps prevent employees from adopting unapproved products because they could not find an existing solution. Don’t have a catalog? Ask us for a demo!
Provide Role-Based Training
A single general presentation about AI will not meet every employee’s needs.
Consider separate training for:
-
- Teachers using AI for lesson planning and classroom instruction
- Students using AI for learning
- Administrators evaluating AI-supported recommendations
- Support staff using AI for productivity
- Reviewers assessing privacy, security and accessibility
- School leaders responding to inappropriate or undisclosed use
- Communications staff handling AI-generated public content
Training should cover practical scenarios, not just broad principles. Employees need to practice recognizing protected information, verifying outputs, locating approved tools, responding to inaccurate content, and submitting requests.
The Department of Education’s 2025 AI guidance emphasized responsible use and educator professional development while recognizing potential uses such as personalized learning, administrative efficiency and differentiated instruction.
Connect AI Governance to Cybersecurity
AI tools should not bypass the district’s established security procedures.
Before approval, evaluate:
-
- Authentication and multifactor authentication options
- Role-based access
- Administrative controls
- Data encryption
- Logging and monitoring
- Integrations and permissions
- Vulnerability management
- Incident notification
- Vendor security practices
- Data export and deletion
- Account deprovisioning
Districts should also prepare for AI-assisted phishing, impersonation, synthetic media, and social engineering. Employees need a clear process for verifying unusual requests and reporting suspicious content.
CISA recommends that K–12 organizations prioritize measures such as multifactor authentication, vulnerability mitigation, tested backups, incident-response exercises, and cybersecurity training.
Establish an AI Incident-Response Procedure
AI incidents may not look like traditional cybersecurity incidents.
Create a simple reporting process for situations involving:
-
- Accidental disclosure of protected information
- Harmful or inappropriate output
- Biased recommendations
- Fabricated citations or information
- Unauthorized student use
- Impersonation or deepfakes
- Academic-integrity concerns
- Unexpected vendor feature changes
- Public release of inaccurate AI-generated content
- AI tools making or influencing consequential decisions
The procedure should identify:
-
- Where the concern is reported.
- Who investigates it.
- Whether access should be suspended.
- How affected records or individuals are identified.
- When privacy, legal, communications or executive leaders are notified.
- How the event and response are documented.
- How the district prevents a recurrence.
Encourage reporting without creating a culture of punishment. Early reporting gives the district a better opportunity to limit harm.
Review AI Tools Throughout the Year
Approval should not be permanent.
Set a review schedule based on risk. High-impact tools may need more frequent monitoring than low-risk productivity tools.
During each review, ask:
-
- Is the tool still being used for its approved purpose?
- Have its features or terms changed?
- Has the vendor added AI functionality?
- Are data practices still acceptable?
- Have incidents or complaints occurred?
- Is the output sufficiently accurate?
- Are employees following established restrictions?
- Does the product duplicate another solution?
- Is it delivering the expected value?
- Should it be renewed, restricted or retired?
Document the review and connect it to the product, contract, owner, approval history and renewal decision.
A Practical Back-to-School AI Checklist
Before the school year is fully underway, technology leaders should be able to confirm:
-
- A cross-department AI governance team has been established.
- AI-enabled products are included in the district’s inventory.
- Employees have clear interim AI guidance.
- A standardized request and review workflow exists.
- Student-data rules include specific examples.
- Age and consent requirements are documented.
- Human review is required for AI-generated output.
- Approved AI tools are visible in a staff-facing catalog.
- Employees receive role-based training.
- AI tools follow established cybersecurity requirements.
- Employees know how to report an AI incident.
- Every product has an owner and scheduled review date.
- Leadership can see approvals, risks, contracts and upcoming renewals.
Districts should also confirm current state laws, board policies and local requirements with qualified legal counsel, since obligations can vary by jurisdiction.
Govern AI as Part of the Complete EdTech Lifecycle
AI governance should not become another isolated spreadsheet, committee or document.
AI tools are part of the district’s broader EdTech ecosystem. They should move through the same connected lifecycle as other digital resources: discovery, evaluation, adoption, monitoring, renewal and retirement—with additional scrutiny based on their data use and potential impact.
Veracity helps K–12 districts centralize approved tools, coordinate cross-department reviews, connect contracts and documentation, communicate guidance to employees, and maintain actionable visibility throughout the EdTech lifecycle.
This school year, the question is not whether AI will be used. It is whether your district has the visibility and procedures to govern it responsibly.
