Current status: This checklist is educational information, not legal advice or a model policy adopted for every district.
A K-12 AI acceptable use policy should make daily decisions easier. It should tell a student, educator, administrator, and technology leader what may be done with AI, which account and data may be used, who remains responsible for the result, where to ask for approval, and how to report a problem. A policy that only says “use AI responsibly” does not provide an operational rule.
Use this checklist to draft a new policy or test whether an existing technology acceptable use policy covers AI clearly enough. The policy should connect to the district’s broader K-12 AI governance program, not replace it.
The minimum policy in one page
A district should be able to summarize its baseline in these ten statements:
- Scope: The policy names the people, devices, networks, accounts, applications, and school activities it covers.
- Approved access: Users may use only products, account types, and features the district has approved for their role and purpose.
- Purpose: AI use must support a defined instructional or operational task.
- Data: Users may not enter, upload, connect, or expose data outside the approved boundary for that use.
- Human responsibility: A qualified person remains responsible for review, decisions, communications, grades, records, and actions.
- Learning expectations: Educators state when AI is permitted, limited, required, or prohibited for an assignment.
- Transparency: Users follow district and course rules for disclosing or citing AI assistance.
- Safety and respect: AI may not be used to harm, harass, impersonate, deceive, discriminate, or defeat district safeguards.
- Reporting: Users know how to report an error, unsafe output, suspected data exposure, account misuse, or unclear rule.
- Review: The district owns the policy, publishes changes, and reviews it on a stated schedule and after material events.
These statements are a baseline, not finished board language. District counsel and policy owners should align the final text to local law, collective bargaining, student codes, records requirements, and existing board policy.
Part 1: define scope without gaps
Confirm that the policy addresses:
- students, educators, substitutes, staff, contractors, volunteers, and service accounts as applicable;
- district-managed and personally owned devices when used for district work;
- direct AI products, AI features inside existing software, and district or vendor applications that call models in the background;
- text, images, audio, video, code, files, connected repositories, and retrieved documents;
- school, home, field-trip, remote-learning, and extracurricular use when it falls under district authority;
- free consumer accounts as well as district-managed education, enterprise, and API deployments.
Do not define AI so narrowly that an embedded writing assistant or automated recommendation feature falls outside the policy. Use the K-12 AI governance glossary to keep public definitions consistent.
Part 2: publish an approved-use matrix
Convert broad policy into a table people can use.
| Context | Default status | Conditions to state |
|---|---|---|
| Student assignment | Teacher-defined within district policy | Learning goal, permitted assistance, disclosure, sources, and account |
| Teacher planning | Approved uses only | No unapproved student data, educator review, and curriculum expectations |
| Staff administration | Purpose-specific approval | Data boundary, account, human decision owner, and records handling |
| Public communications | Draft support when approved | Source verification, communications review, and no confidential inputs |
| Grading or placement | Elevated review | Validity, human authority, appeal, accessibility, and data requirements |
| Student support or discipline | Elevated review | Qualified human judgment, legal and privacy review, and documented safeguards |
| District application or automation | Registered use | Application owner, purpose, data, model deployment, constraints, and disable path |
The status should attach to a defined use, not only a vendor name. One product may be suitable for staff brainstorming with public information and unsuitable for a consequential student decision.
Part 3: state the data rules precisely
Avoid relying only on “do not enter personal information.” Users need examples and an escalation path.
The policy or linked guidance should identify:
- data that is permitted for a named use;
- data that is prohibited unless separately approved;
- whether files, images, audio, or connected drives are in scope;
- which district account and provider configuration must be used;
- whether conversation history, retention, sharing, or provider training settings matter;
- what a user should do when a task cannot be completed without sensitive information;
- where suspected disclosure or exposure must be reported.
Use the K-12 AI data-boundary framework to document systems, fields, documents, recipients, model deployments, logs, and retention. Do not describe redaction as a substitute for purpose, authorization, contract, or provider review.
Part 4: make classroom rules observable
District policy should establish the baseline while educators define assignment-level expectations within their authority.
A classroom direction should answer:
- Is AI prohibited, optional, expected, or required for this task?
- Which product and account may be used?
- Which parts of the work must the student complete without AI?
- May the student use AI for brainstorming, feedback, translation, revision, coding, or source discovery?
- What must the student submit to show process or disclose assistance?
- How will sources and factual claims be checked?
- What equivalent path exists for a student who cannot or should not use the tool?
Example assignment rule:
Students may use the district-approved AI account to generate three possible counterarguments after completing their own claim and evidence outline. Students must identify which counterargument they used, verify any factual claim with course sources, and attach a short AI-use note. AI may not write the final response.
This is more enforceable and more useful than a general instruction to “use AI ethically.”
Part 5: connect academic integrity to learning purpose
Define unacceptable conduct, but do not make an unreliable detector the sole basis for discipline. The policy should address:
- submitting AI-generated work as independent work when the assignment prohibits it;
- fabricating sources, quotations, data, observations, or process evidence;
- using AI to impersonate another person or evade an assessment condition;
- misrepresenting the extent or purpose of AI assistance;
- the review and appeal process when use is questioned;
- educator responsibility to communicate rules before work begins.
Different assignments can have different legitimate rules. The district should preserve a clear baseline and a fair process rather than forcing every course into one AI-use category.
Part 6: address age, accounts, privacy, and notice
Document who determines whether a product and account are eligible for a student group. Consider provider terms, district contracts, the specific data flow, FERPA, COPPA, state requirements, and local policy with qualified reviewers.
The Federal Trade Commission’s COPPA guidance describes circumstances in which schools may act on behalf of parents for collection in an educational context. That guidance is not a universal authorization for every product or purpose. The U.S. Department of Education likewise emphasizes examining the actual online educational service, agreement, use, and data practices.
Give families and students a plain-language explanation of:
- which AI uses are part of instruction or operations;
- what information the use needs;
- which provider and account are involved;
- who reviews the output;
- available alternatives or opt-out processes where applicable;
- how questions, corrections, and complaints are handled.
Part 7: include accessibility and equal access
The implementation team should evaluate whether the policy or an assignment creates barriers for students with disabilities, multilingual learners, students without comparable home access, or students who use assistive technology.
State who can approve an alternative path and how educators should implement an accommodation without exposing unnecessary records to an AI service. See AI, accommodations, and student privacy for a planning framework.
Part 8: define reporting and response
Publish a reporting path for:
- suspected personal-information exposure;
- harmful, discriminatory, sexual, violent, or otherwise unsafe output;
- an AI feature acting beyond its approved purpose;
- unauthorized product or account use;
- suspected account compromise or credential exposure;
- inaccurate output used in a consequential decision;
- accessibility failure;
- a provider term, model, data practice, or subprocessor change;
- uncertainty about whether a proposed use is allowed.
Tell users what information to preserve, what not to redistribute, and whom to contact. Connect the policy to the K-12 AI incident response playbook and existing emergency, cybersecurity, privacy, student safety, and communications procedures.
Part 9: create a usable exception process
An exception should identify:
- requester and accountable owner;
- specific purpose and users;
- product, account, model deployment, and duration;
- permitted and prohibited data;
- compensating controls and human review;
- approver and policy basis;
- expiry date and revocation conditions;
- evidence and outcome review.
Do not create a permanent exception called “pilot.” Time-bound pilots need success criteria, stop criteria, and a decision date.
Part 10: implement the policy
| Implementation item | Complete when |
|---|---|
| Policy owner | A named role owns interpretation, publication, and review |
| Cross-policy review | Technology, privacy, academic integrity, records, accessibility, security, and conduct rules align |
| Approved-use list | Users can find current products, account types, purposes, and conditions |
| Tool intake | New uses enter a documented review using the AI tool vetting template |
| Role guidance | Students, educators, leaders, and technical teams receive instructions written for their work |
| Training | Required groups practice realistic decisions and reporting steps |
| Technical alignment | Identity, access, product settings, and supported guardrails reflect policy |
| Exception workflow | Requests have owners, evidence, expiry, and revocation |
| Incident workflow | Reporting, triage, containment, communication, and review owners are named |
| Public notice | Students and families can understand material district uses and questions |
| Review calendar | Annual review and material-change triggers are assigned |
A 30-day launch sequence
Week 1: reconcile policy
Inventory existing rules that already govern technology, privacy, conduct, academic integrity, accessibility, records, procurement, security, and incidents. Identify conflicts and missing owners.
Week 2: define real uses
List the AI products and embedded features already in use. Classify each use by user, purpose, account, data, consequence, and current approval. Start with the district AI application register.
Week 3: publish role-specific guidance
Create short versions for students, educators, families, administrators, and technical teams. Use examples from actual district workflows. Train school leaders before asking them to interpret the policy.
Week 4: test implementation
Run a tabletop exercise with four cases: an unclear assignment rule, a student-data disclosure, an unapproved AI feature, and an inaccurate output used in a decision. Record where people could not find an owner, rule, or response step, then revise the implementation.
Frequently asked questions
What should a K-12 AI acceptable use policy include?
It should define scope, approved and prohibited uses, eligible users and accounts, data rules, learning expectations, human responsibility, accessibility, reporting, consequences, exceptions, ownership, and review dates.
Should a district write a separate AI policy or update its existing acceptable use policy?
Either structure can work. The important requirement is that AI rules connect clearly to existing technology, privacy, academic integrity, records, accessibility, security, procurement, and incident procedures without creating conflicting directions.
Can one AI rule apply to every grade and class?
A district baseline can apply across the system, but age, course purpose, assignment design, account eligibility, accessibility, and student data can require narrower grade, role, school, or classroom rules.
How often should a district review its AI acceptable use policy?
Set an annual review at minimum and reopen the policy earlier after material product, legal, instructional, privacy, security, or incident changes. Approval records for individual uses may need more frequent review.
Does an acceptable use policy make an AI product safe or legally compliant?
No. A policy sets district expectations. Each product and use still needs appropriate privacy, security, accessibility, instructional, procurement, and legal review, plus controls that match the actual deployment.
Sources
- Empowering Education Leaders: A Toolkit for Safe, Ethical, and Equitable AI Integration, U.S. Department of Education
- Generative Artificial Intelligence Profile, NIST
- Protecting Student Privacy While Using Online Educational Services, U.S. Department of Education
- Complying with COPPA: Frequently Asked Questions, Federal Trade Commission
This checklist is educational information, not legal advice. Districts should use qualified legal, privacy, accessibility, security, procurement, instructional, and policy review for their circumstances.