Reference

K-12 AI Governance Glossary

A stable vocabulary helps district leaders, educators, technologists, privacy teams, vendors, and families make the same AI decision with the same meaning.

Audience
District leaders, educators, technology teams, privacy teams, vendors, board members, and families
Read time
12 min read
Published
Reviewed
Review
TrueMadeAI Engineering

Current status: Terms describe a governance framework. Tenet Gateway is a founding-district program.

K-12 AI governance is easier when everyone uses the same terms. This glossary defines the policy and architecture language district leaders need to discuss direct AI use, backend application AI, identity, purpose, data, model deployment, controls, and evidence. Definitions are written for district operations and link to deeper Tenet resources where the distinction matters.

Federal laws and frameworks may define particular terms for their own purposes. Districts should use the controlling legal definition when applying a statute, regulation, contract, or board policy.

AI application

Software that uses one or more AI models to perform an operation such as generating, summarizing, classifying, extracting, recommending, searching, or taking an approved action. The AI may be the visible product or a backend feature inside another application.

A district should register each AI use separately because one vendor may support several applications with different purposes, data, and owners. See the AI application register template.

AI application register

A district-owned inventory of AI applications and approved uses. Each entry should have an owner, purpose, eligible users, source systems, data boundary, model deployment, decision status, constraints, evidence, and review date.

AI gateway

Infrastructure that commonly handles model API traffic, including credential protection, routing, quotas, retries, provider selection, and operational telemetry. Product capabilities vary. A generic AI gateway does not automatically know a school district’s approved purpose, data boundary, or instructional policy.

See AI gateway vs. AI governance control plane.

AI governance

The operating model an organization uses to decide which AI uses are allowed, who or what may use them, for what purpose, with which data and model deployment, under what safeguards, and with what evidence and review.

For a district implementation framework, read AI Governance in K-12.

AI model

A computational component that produces outputs from inputs based on learned or designed patterns. A model is only one part of an AI system. The surrounding product, data sources, instructions, tools, account settings, user interface, human workflow, and provider operations affect actual behavior.

AI system

The full socio-technical arrangement in which an AI model is developed, configured, deployed, used, reviewed, and governed. It can include people, policies, software, data, infrastructure, vendors, and downstream decisions. NIST’s AI RMF addresses risk across the AI system lifecycle, not only model selection.

Application identity

A stable identity representing a district or vendor application. It should resolve to an accountable owner, approved purposes, allowed data, eligible model deployments, policy, and lifecycle record. A shared provider API key is not a complete application identity.

Approval

A district decision that a defined use may proceed within documented boundaries. Approval should attach to a specific purpose, user group, product, account type, deployment, data boundary, constraints, and review date. It is not a permanent endorsement of every feature a vendor offers.

Audit evidence

Records needed to explain an approval, policy decision, exception, incident, review, or operational outcome. Appropriate evidence may include policy version, application identity, decision, constraint, timestamp, and reviewer action. It does not require a routine archive of every prompt and response.

Authentication

The process of establishing that a user, device, service, or application identity is genuine. Authentication answers “Who are you?” It does not, by itself, answer what the identity is allowed to do.

Authorization

The decision about what an authenticated identity may do in a particular context. For district AI, relevant context can include role, authority, purpose, class or application, approved data, model deployment, constraints, and current policy.

Backend AI

AI used by an application through an API or other machine-to-machine interface. The person using the application may never see a chatbot or model interface. Backend AI belongs to the backend application plane of district governance.

Constraint

A condition attached to an approval or authorization decision. Examples include required human review, an approved model route, a limited data class, a quota, a time window, redaction, or an expiry date.

Control plane

The layer that defines and distributes policy, identity context, approved uses, data boundaries, model eligibility, constraints, exceptions, and decision semantics. It is distinct from the traffic plane that moves model requests.

A shared control plane does not require a shared conversation archive.

COPPA school authorization

A limited model described in Federal Trade Commission guidance under which a school may, in certain circumstances, provide authorization for collection of children’s personal information in an educational context. It is not a universal approval for any commercial use or any tool marketed to schools. Districts should evaluate current FTC rules and guidance with qualified counsel.

Data boundary

The documented limit on which identity may use which source systems, fields, records, or document sets for a defined purpose through an eligible model deployment, under stated constraints and review.

See Data Boundaries for K-12 AI Applications.

Data class

A category used to apply handling rules to information. A district might use public, internal, confidential, and restricted classes, then map them to its records, privacy, and security requirements. Class labels are useful only when permitted and prohibited elements are defined.

Data loss prevention (DLP)

Processes and controls intended to detect and reduce unauthorized exposure of sensitive information. DLP can include local pattern matching, roster-aware detection, structured-data rules, redaction, file handling, and policy decisions. Coverage depends on the exact content type, path, product, and configuration. DLP should not be described as perfect or universal.

De-identification

A contextual process and determination intended to reduce the ability to identify a person in information. Removing a name alone may not be enough because combinations of attributes, free text, or external data can restore identity. Applicable legal or statistical standards may define additional requirements.

Direct AI use

A person interacting directly with an AI product, such as a student using an approved chatbot or an educator using an AI feature in a managed account. Direct use belongs to the Edge plane.

Edge

The governance surface where a person directly uses an AI product. Tenet Edge applies district and classroom guardrails through a managed Chrome client on supported products and configurations.

Tenet Edge is not described as supporting every AI website or every file and upload path. Current support and data-flow documentation control the claim.

Eligible model deployment

A provider, product or API, account type, model or model family, region, route, logging configuration, training-use setting, contract, and other conditions that a district has approved for a specific use. “Approved model” is often too vague.

Enforcement point

The place in a workflow where a policy decision can affect what happens. Examples include a managed direct-use surface, a district application runtime, an API authorization service, an identity platform, or a human approval step.

Exception

A documented, time-bounded departure from standard policy. A useful exception record includes owner, reason, scope, compensating controls, approver, start, expiry, and review outcome.

Generative AI

AI that creates content such as text, images, audio, video, or code in response to input and context. NIST’s Generative AI Profile describes risks and actions that organizations can consider as a companion to the AI RMF.

Guardrail

A policy, technical, or procedural control that constrains how an AI use operates. Examples include approved-product access, classroom rules, data minimization, required human review, model-route eligibility, or a prohibited-use rule. A guardrail reduces or manages a risk; it does not guarantee error-free behavior.

Human review

A defined responsibility for a qualified person to examine AI input, output, evidence, or a proposed action. Meaningful human review requires sufficient authority, context, time, and a way to change or stop the outcome. A ceremonial click is not the same as accountable review.

Least privilege

The principle that a user, application, or service should receive only the access needed for an approved purpose and time. For an AI application, this can mean limiting source systems, fields, document collections, roles, model routes, and credential scope.

Material change

A change that can alter the risk or approval basis of an AI use. Examples include a new purpose, user group, data source, model, provider term, connector, action capability, region, retention practice, or human-review process. Material change should trigger review before continued use when district policy requires it.

Model deployment

The actual way a model is made available in a product or API. It includes more than the model name. Account type, provider, region, configuration, logging, retention, tools, route, and contract can make two deployments of the same model materially different.

Model provider

An entity that develops, hosts, or makes a model available. The provider may be different from the application vendor, cloud platform, reseller, or district traffic platform involved in the complete data flow.

Model routing

The technical selection of a provider, model, region, or endpoint for a request. Routing is commonly a traffic-gateway function. Governance defines which routes are eligible for a particular identity, purpose, and data boundary.

On-device processing

Processing performed on a managed endpoint rather than on the vendor’s backend. It can reduce the need to send content to another service, but it does not mean the entire product has no backend data flow. Configuration, identity, updates, and event metadata may still use network services.

Personally identifiable information (PII)

Information that directly identifies a person or can identify a person when combined with other information. Specific laws and district policies define PII for their own purposes. In education, free text, persistent identifiers, images, voice, location, and combinations of attributes can matter in addition to names and email addresses.

Policy

A documented rule or set of rules expressing what is permitted, required, or prohibited. AI governance connects policy to owners, approvals, enforcement points, evidence, exceptions, and review.

Prompt

Input or instructions provided to a generative AI system. The effective context can include more than text a user types. It may also include system instructions, conversation history, retrieved documents, account data, tool results, and application-generated context.

Pseudonymization

Replacing an identifying value with another value while preserving controlled linkability. Pseudonymized data is not necessarily anonymous. The mapping, surrounding attributes, and authorized re-identification process need protection.

Retrieval-augmented generation (RAG)

A design in which an application retrieves information from an approved source and provides selected material as context to a generative model. RAG can improve relevance, but it also creates authorization questions about which documents may be retrieved, which user or application is asking, and what is sent to the model.

Redaction

Removing or replacing selected sensitive content before further use. A reliable process must detect relevant content, transform it, and verify the exact outgoing representation. File names, metadata, images, attachments, and surrounding context can remain even when visible text changes.

Retention

How long content, metadata, logs, backups, approval records, and other information remain. Retention should be defined by data type, system, purpose, access, legal obligations, and deletion process. “We do not train on your data” does not answer how long data is retained.

Risk

The combination of potential effects and uncertainty associated with an AI system or use. NIST’s AI RMF treats risk management as continuous work across Govern, Map, Measure, and Manage. A district risk decision should consider benefits as well as possible harm.

School official exception

A FERPA exception under which an outside party may be considered a school official if the educational agency or institution determines that the applicable conditions are met. Those conditions include requirements related to the institutional service or function, direct control, use and redisclosure, and legitimate educational interest. It is a district legal determination tied to the specific arrangement, not a vendor certification.

Service identity

A nonhuman identity used by an application, automation, or workload. A service identity should have its own credential, owner, scope, rotation, and revocation process. It can be one technical component of an application identity.

Supported surface

A product, interface, device, account, and configuration for which a control has been tested and documented. A capability shown on one supported surface should not be assumed to work across every AI product.

Tenet control plane

The shared policy model that aligns identity, district and classroom rules, approved use, data boundaries, model eligibility, constraints, and decision semantics across Tenet Edge and the Tenet Gateway founding-district program.

Tenet Gateway founding-district program

Tenet’s program for working with participating districts on backend AI authorization. It is not a generally available traffic-gateway replacement. Supported integrations, controls, failure behavior, and production validation are defined in each participating district’s implementation scope.

Traffic plane

The infrastructure path that carries model requests and responses. It can provide routing, credential protection, quotas, retries, normalization, and operational telemetry. Governance policy can control which traffic is eligible without requiring the governance layer to perform every traffic function.

Two planes of district AI

The distinction between people using AI products directly at the Edge and district applications using AI in the backend. Both planes need common district policy concepts while retaining separate enforcement and data paths.

Read The Two Planes of District AI.

Frequently asked questions

What is the difference between authentication and authorization?

Authentication establishes that an identity is genuine. Authorization decides what that identity may do in a specific context.

What is the difference between an AI gateway and a control plane?

An AI gateway commonly handles model traffic. A governance control plane defines identity, purpose, approved data, model eligibility, constraints, and evidence for the authorization decision.

Are redaction, pseudonymization, and de-identification the same?

No. Redaction removes or replaces selected content. Pseudonymization preserves controlled linkability through substitute identifiers. De-identification is a contextual determination about whether a person can be identified.

What are the two planes of district AI?

The Edge plane covers people using AI products directly. The backend application plane covers district applications calling models through APIs.

Is Tenet Gateway generally available?

Tenet Gateway is a founding-district program. Its supported production scope is defined and validated with each participating district.

Sources

This glossary is educational information, not legal advice. Use the definition in the controlling law, regulation, contract, or district policy when one applies.

Choose your Tenet path

Start with one district baseline. Add context when you need it.

Tenet Basic is free. Tenet District adds roster, classroom, teacher, grade, and schedule context.