A Practical AI Policy for Schools: Learning, Privacy, Attribution and Assessment
A school AI policy should clarify acceptable use, privacy, attribution, assessment integrity, teacher oversight and tool procurement without pretending the technology will stop changing.

Research note: time-sensitive claims and source links were reviewed on . Primary sources are listed at the end of the article where available.

Schools do not need a 40-page AI policy that nobody reads. They need a small number of rules that teachers, students and parents can actually apply when a new tool appears next week.
Start with purpose
Define why AI is being used: explanation, accessibility, brainstorming, coding support, feedback, research assistance or another learning purpose. UNICEF's child-centred guidance starts with purpose, necessity, safety, privacy and human oversight for a reason.
Protect student data
Set explicit rules about what students and staff must not enter into public AI systems: personally identifiable student records, health information, assessment data, private communications and other sensitive material. Procurement should include data-handling review, not just feature comparison.
Define attribution
Students should know when they must disclose AI assistance. A simple disclosure can name the tool, explain how it was used and identify what the student changed or verified.
Redesign some assessments
If an assignment can be completed credibly by copying one prompt into a model, the assessment may no longer reveal what the teacher wants to know. Oral explanation, staged drafts, in-class reasoning and process evidence can restore visibility into learning.
Keep a human accountable
AI can support feedback and planning, but consequential decisions about students should not be handed to opaque systems without review. UNICEF specifically warns against systems that may wrongly label ability or limit opportunity.
Review the policy every term
Tool capabilities, age rules and vendor practices will change. A short review cycle is more realistic than pretending the first policy will be final.
Use a traffic-light model for everyday decisions
Policies become easier to apply when examples are concrete. A school can classify uses as green, amber or red. Green might include brainstorming practice questions or asking for explanations with no personal data. Amber might include editing student writing, coding assistance or AI-supported research that requires disclosure and verification. Red might include uploading confidential student information, impersonation, cheating in a restricted assessment or delegating high-stakes student decisions to an opaque system.
The exact categories should match the school's context and legal review. The value of the model is that a student or teacher can make a quick decision without searching a long policy every time a new app appears.
Write separate rules for students, teachers and vendors
- Students need clear examples of permitted assistance and disclosure.
- Teachers need guidance on assessment design, feedback and data handling.
- Administrators need procurement, access and incident-response rules.
- Vendors need contractual expectations around data, security, retention and support.
One policy document can contain all four audiences, but the school should publish a short version each group can actually use. A policy that exists only for inspection will not shape behaviour.
Publish examples alongside the policy
Students interpret policies through examples. Show what acceptable disclosure looks like, what kind of private information should not be uploaded, and how an AI-assisted assignment can cite or describe tool use. Teachers should have examples too: a permitted feedback workflow, a restricted assessment and an incident that should be escalated.
This makes the policy teachable. It also improves school marketing because parents can see a thoughtful approach to new technology instead of a vague promise that the institution is 'embracing AI responsibly.'
Sources and further reading
Want to test this in your school?
OnliGrow is being built to turn these ideas into a structured school program. A useful pilot starts with your context, not a standard promise.
Discuss a pilot