California school AI policy

California School AI Model Policy: What SB 1288 Means for Districts

California SB 1288 required state AI guidance and a model policy. CDE now publishes that model, but expressly labels it exemplary and nonmandatory. Districts should use it as a reviewed starting point, not misstate every recommendation as law.

Audience
California superintendents, boards, technology, curriculum, privacy, legal, procurement, and instructional teams
Read time
9 min read
Published
Reviewed
Review
TrueMadeAI Engineering

Current status: Last reviewed August 17, 2026 against SB 1288 and the California Department of Education model-policy page. This is educational information, not legal advice.

California SB 1288 required the state to publish artificial-intelligence guidance and a model policy for education. The California Department of Education now publishes that model, but expressly describes it as exemplary and nonmandatory. Districts should use it as a structured benchmark, not claim that every recommendation is a statewide legal mandate.

This distinction is especially important for guardian consent, autonomous student-facing AI, AI-assisted grading, approved vendors, privacy-by-design review, and ongoing monitoring. Those are serious governance practices in the model. Their appearance in a nonmandatory model policy does not, by itself, make every sentence binding on every district.

Three California layers to keep separate

Layer Verified effect What not to claim
SB 1288 Required CDE guidance by January 1, 2026 and a model policy by July 1, 2026 That every local district must copy the model verbatim
CDE model policy Provides exemplary recommendations for local AI governance That every recommendation is independently required by statute
AB 2876 Directs consideration of AI literacy in specified curriculum frameworks and materials criteria That every district must offer a standalone AI course

California districts may have separate duties under privacy, student-records, procurement, accessibility, civil-rights, labor, assessment, security, and local board authorities. The point is not that the model is irrelevant. The point is that each requirement needs the right source label.

What the CDE model addresses

The published model offers a broad governance structure that includes:

  • authorized AI tools and defined educational purposes;
  • privacy-by-design and data-minimization review;
  • vendor and product evaluation;
  • human oversight and rights to challenge AI-assisted output;
  • AI-assisted grading and feedback boundaries;
  • autonomous student-facing AI and guardian communication or consent;
  • monitoring, incidents, bias, accessibility, and periodic review;
  • professional learning and AI literacy; and
  • alignment with existing policy and legal obligations.

These are useful categories for a district gap analysis even when the exact model language is not adopted.

The model recommends annual informed guardian consent before students independently interact with autonomous AI systems. If a district adopts that practice, it needs more than a paper form.

The workflow should define:

  1. what counts as autonomous student interaction;
  2. which products, features, grades, classes, and purposes are covered;
  3. how the guardian is verified;
  4. what information the notice provides;
  5. how long the choice remains effective;
  6. what non-AI alternative is available;
  7. how educators see the choice at the right time;
  8. how a change or revocation propagates; and
  9. what evidence is retained without collecting unnecessary student content.

Do not combine every type of AI use into one vague consent. An educator using an approved assistant to draft a lesson is not the same event as a student independently conversing with an autonomous system.

Preserve human authority over grading and feedback

The model recommends that educators retain sole authority over final grades and that AI-assisted grading and feedback remain reviewable.

A district implementing that principle should record:

  • which assessments permit AI assistance;
  • what the tool may produce;
  • what the educator must review;
  • what context the educator receives;
  • whether the output can be rejected or revised;
  • how a student can question or correct the result;
  • which evidence is retained; and
  • which decisions may not be delegated.

The strongest control is not a footer that says “human in the loop.” It is a workflow in which a qualified person has time, context, authority, and a documented responsibility to decide.

Build an approved-tool process that survives product changes

AI product names are not stable scopes. Features, models, account tiers, data practices, and embedded assistants change.

An approval record should identify:

  • the exact product, feature, account, and model path;
  • approved users, grades, purposes, and data;
  • prohibited uses and decisions;
  • privacy, security, accessibility, equity, and instructional findings;
  • human-review and parent-choice requirements;
  • implementation owner and configuration;
  • approval and next-review dates; and
  • events that suspend or reopen approval.

Use the AI application register, tool vetting template, and vendor and DPA questions to maintain this at feature level.

How Tenet may support a California implementation

Tenet by TrueMadeAI is K-12 AI governance software. Tenet Edge applies district and classroom policy on supported direct-use AI surfaces on managed Chrome. Tenet Gateway is a founding-district program for approved backend AI operations.

A district could evaluate Tenet as one layer for:

  • delivering current district and classroom rules on supported AI surfaces;
  • controlling supported approved and unapproved AI chat or writing interfaces;
  • applying supported on-device data-loss-prevention controls;
  • differentiating policy by district, grade, roster, class, teacher, subject, and schedule where supported;
  • governing an approved backend AI operation by application identity, purpose, data boundary, model route, and failure behavior; and
  • retaining bounded operational evidence without turning raw student conversations into analytics.

TrueMadeAI is preparing an administrator-managed parent opt-out capability. It is not represented here as shipped. California’s model-policy recommendation and Oklahoma’s enacted opt-out are useful design inputs, but the final product must have a defined authoritative source, scope, propagation path, alternative workflow, tests, and evidence boundary.

Tenet does not make the CDE model mandatory, choose local policy, complete procurement, guarantee legal compliance, or cover every AI product and data path. Review the dated capability matrix before relying on a specific surface.

If your district wants to map the California model to current policy and supported controls, request a Tenet District conversation.

A local adoption method

For every model-policy provision, use one of four labels:

Local decision Meaning
Adopt Use the recommendation substantially as written
Adapt Change it to fit local authority, operations, bargaining, or risk
Covered elsewhere Cite the existing policy or procedure that already controls the issue
Do not adopt Record why the recommendation is inapplicable, impractical, or superseded

Then add the responsible owner, implementation procedure, evidence, effective date, and review trigger. This creates a defensible local record without pretending that model text implements itself.

What this guide does not establish

This guide does not determine that a model-policy recommendation is legally required, calculate consent obligations for a particular use, resolve collective-bargaining or employment issues, approve a vendor, or establish that any product makes a district compliant. Those conclusions require current law, the district’s facts, local process, and qualified review.

Sources

Frequently asked questions

Does California SB 1288 require every district to adopt the state AI model policy?

No. SB 1288 required the state to develop guidance and a model policy. The California Department of Education says the published model is exemplary and nonmandatory under Education Code Section 33308.5.

The CDE model policy recommends annual informed guardian consent before students independently interact with autonomous AI systems. Because CDE labels the model nonmandatory, districts should not present that recommendation as a universal statutory requirement without another applicable authority.

Can California schools use AI to grade students?

The model policy recommends that educators retain sole authority over final grades and that AI-assisted grading remain subject to human review and challenge. Districts should separately verify any binding law, contract, collective-bargaining, assessment, or local-policy requirements.

What is the difference between SB 1288 and AB 2876?

SB 1288 directed state AI guidance and model-policy work. AB 2876 directed the Instructional Quality Commission to consider AI literacy in specified curriculum frameworks and instructional-material criteria. Neither should be summarized as a standalone mandate that every district offer an AI course.

Should a district ignore a nonmandatory model policy?

No. A nonmandatory model can still be a valuable benchmark. The district should review each provision, record whether it adopts, adapts, or rejects it, identify any separate binding authority, and test whether the resulting local controls work.

Choose your Tenet path

Start with one district baseline. Add context when you need it.

Tenet Basic is free. Tenet District adds roster, classroom, teacher, grade, and schedule context.