Policy implementation

K-12 AI Acceptable Use Policy Implementation Checklist

A useful AI acceptable use policy tells students and staff what is allowed, under which conditions, with which accounts and data, and what happens when the rules are unclear or violated. Implementation requires owners, examples, training, technical alignment, reporting, and scheduled review.

Audience
District cabinet, board policy, technology, curriculum, privacy, legal, school leadership, educators, students, and families
Read time
12 min read
Published
Reviewed
Review
TrueMadeAI Engineering

Current status: This checklist is educational information, not legal advice or a model policy adopted for every district.

A K-12 AI acceptable use policy should make daily decisions easier. It should tell a student, educator, administrator, and technology leader what may be done with AI, which account and data may be used, who remains responsible for the result, where to ask for approval, and how to report a problem. A policy that only says “use AI responsibly” does not provide an operational rule.

Use this checklist to draft a new policy or test whether an existing technology acceptable use policy covers AI clearly enough. The policy should connect to the district’s broader K-12 AI governance program, not replace it.

The minimum policy in one page

A district should be able to summarize its baseline in these ten statements:

  1. Scope: The policy names the people, devices, networks, accounts, applications, and school activities it covers.
  2. Approved access: Users may use only products, account types, and features the district has approved for their role and purpose.
  3. Purpose: AI use must support a defined instructional or operational task.
  4. Data: Users may not enter, upload, connect, or expose data outside the approved boundary for that use.
  5. Human responsibility: A qualified person remains responsible for review, decisions, communications, grades, records, and actions.
  6. Learning expectations: Educators state when AI is permitted, limited, required, or prohibited for an assignment.
  7. Transparency: Users follow district and course rules for disclosing or citing AI assistance.
  8. Safety and respect: AI may not be used to harm, harass, impersonate, deceive, discriminate, or defeat district safeguards.
  9. Reporting: Users know how to report an error, unsafe output, suspected data exposure, account misuse, or unclear rule.
  10. Review: The district owns the policy, publishes changes, and reviews it on a stated schedule and after material events.

These statements are a baseline, not finished board language. District counsel and policy owners should align the final text to local law, collective bargaining, student codes, records requirements, and existing board policy.

Part 1: define scope without gaps

Confirm that the policy addresses:

  • students, educators, substitutes, staff, contractors, volunteers, and service accounts as applicable;
  • district-managed and personally owned devices when used for district work;
  • direct AI products, AI features inside existing software, and district or vendor applications that call models in the background;
  • text, images, audio, video, code, files, connected repositories, and retrieved documents;
  • school, home, field-trip, remote-learning, and extracurricular use when it falls under district authority;
  • free consumer accounts as well as district-managed education, enterprise, and API deployments.

Do not define AI so narrowly that an embedded writing assistant or automated recommendation feature falls outside the policy. Use the K-12 AI governance glossary to keep public definitions consistent.

Part 2: publish an approved-use matrix

Convert broad policy into a table people can use.

Context Default status Conditions to state
Student assignment Teacher-defined within district policy Learning goal, permitted assistance, disclosure, sources, and account
Teacher planning Approved uses only No unapproved student data, educator review, and curriculum expectations
Staff administration Purpose-specific approval Data boundary, account, human decision owner, and records handling
Public communications Draft support when approved Source verification, communications review, and no confidential inputs
Grading or placement Elevated review Validity, human authority, appeal, accessibility, and data requirements
Student support or discipline Elevated review Qualified human judgment, legal and privacy review, and documented safeguards
District application or automation Registered use Application owner, purpose, data, model deployment, constraints, and disable path

The status should attach to a defined use, not only a vendor name. One product may be suitable for staff brainstorming with public information and unsuitable for a consequential student decision.

Part 3: state the data rules precisely

Avoid relying only on “do not enter personal information.” Users need examples and an escalation path.

The policy or linked guidance should identify:

  • data that is permitted for a named use;
  • data that is prohibited unless separately approved;
  • whether files, images, audio, or connected drives are in scope;
  • which district account and provider configuration must be used;
  • whether conversation history, retention, sharing, or provider training settings matter;
  • what a user should do when a task cannot be completed without sensitive information;
  • where suspected disclosure or exposure must be reported.

Use the K-12 AI data-boundary framework to document systems, fields, documents, recipients, model deployments, logs, and retention. Do not describe redaction as a substitute for purpose, authorization, contract, or provider review.

Part 4: make classroom rules observable

District policy should establish the baseline while educators define assignment-level expectations within their authority.

A classroom direction should answer:

  1. Is AI prohibited, optional, expected, or required for this task?
  2. Which product and account may be used?
  3. Which parts of the work must the student complete without AI?
  4. May the student use AI for brainstorming, feedback, translation, revision, coding, or source discovery?
  5. What must the student submit to show process or disclose assistance?
  6. How will sources and factual claims be checked?
  7. What equivalent path exists for a student who cannot or should not use the tool?

Example assignment rule:

Students may use the district-approved AI account to generate three possible counterarguments after completing their own claim and evidence outline. Students must identify which counterargument they used, verify any factual claim with course sources, and attach a short AI-use note. AI may not write the final response.

This is more enforceable and more useful than a general instruction to “use AI ethically.”

Part 5: connect academic integrity to learning purpose

Define unacceptable conduct, but do not make an unreliable detector the sole basis for discipline. The policy should address:

  • submitting AI-generated work as independent work when the assignment prohibits it;
  • fabricating sources, quotations, data, observations, or process evidence;
  • using AI to impersonate another person or evade an assessment condition;
  • misrepresenting the extent or purpose of AI assistance;
  • the review and appeal process when use is questioned;
  • educator responsibility to communicate rules before work begins.

Different assignments can have different legitimate rules. The district should preserve a clear baseline and a fair process rather than forcing every course into one AI-use category.

Part 6: address age, accounts, privacy, and notice

Document who determines whether a product and account are eligible for a student group. Consider provider terms, district contracts, the specific data flow, FERPA, COPPA, state requirements, and local policy with qualified reviewers.

The Federal Trade Commission’s COPPA guidance describes circumstances in which schools may act on behalf of parents for collection in an educational context. That guidance is not a universal authorization for every product or purpose. The U.S. Department of Education likewise emphasizes examining the actual online educational service, agreement, use, and data practices.

Give families and students a plain-language explanation of:

  • which AI uses are part of instruction or operations;
  • what information the use needs;
  • which provider and account are involved;
  • who reviews the output;
  • available alternatives or opt-out processes where applicable;
  • how questions, corrections, and complaints are handled.

Part 7: include accessibility and equal access

The implementation team should evaluate whether the policy or an assignment creates barriers for students with disabilities, multilingual learners, students without comparable home access, or students who use assistive technology.

State who can approve an alternative path and how educators should implement an accommodation without exposing unnecessary records to an AI service. See AI, accommodations, and student privacy for a planning framework.

Part 8: define reporting and response

Publish a reporting path for:

  • suspected personal-information exposure;
  • harmful, discriminatory, sexual, violent, or otherwise unsafe output;
  • an AI feature acting beyond its approved purpose;
  • unauthorized product or account use;
  • suspected account compromise or credential exposure;
  • inaccurate output used in a consequential decision;
  • accessibility failure;
  • a provider term, model, data practice, or subprocessor change;
  • uncertainty about whether a proposed use is allowed.

Tell users what information to preserve, what not to redistribute, and whom to contact. Connect the policy to the K-12 AI incident response playbook and existing emergency, cybersecurity, privacy, student safety, and communications procedures.

Part 9: create a usable exception process

An exception should identify:

  • requester and accountable owner;
  • specific purpose and users;
  • product, account, model deployment, and duration;
  • permitted and prohibited data;
  • compensating controls and human review;
  • approver and policy basis;
  • expiry date and revocation conditions;
  • evidence and outcome review.

Do not create a permanent exception called “pilot.” Time-bound pilots need success criteria, stop criteria, and a decision date.

Part 10: implement the policy

Implementation item Complete when
Policy owner A named role owns interpretation, publication, and review
Cross-policy review Technology, privacy, academic integrity, records, accessibility, security, and conduct rules align
Approved-use list Users can find current products, account types, purposes, and conditions
Tool intake New uses enter a documented review using the AI tool vetting template
Role guidance Students, educators, leaders, and technical teams receive instructions written for their work
Training Required groups practice realistic decisions and reporting steps
Technical alignment Identity, access, product settings, and supported guardrails reflect policy
Exception workflow Requests have owners, evidence, expiry, and revocation
Incident workflow Reporting, triage, containment, communication, and review owners are named
Public notice Students and families can understand material district uses and questions
Review calendar Annual review and material-change triggers are assigned

A 30-day launch sequence

Week 1: reconcile policy

Inventory existing rules that already govern technology, privacy, conduct, academic integrity, accessibility, records, procurement, security, and incidents. Identify conflicts and missing owners.

Week 2: define real uses

List the AI products and embedded features already in use. Classify each use by user, purpose, account, data, consequence, and current approval. Start with the district AI application register.

Week 3: publish role-specific guidance

Create short versions for students, educators, families, administrators, and technical teams. Use examples from actual district workflows. Train school leaders before asking them to interpret the policy.

Week 4: test implementation

Run a tabletop exercise with four cases: an unclear assignment rule, a student-data disclosure, an unapproved AI feature, and an inaccurate output used in a decision. Record where people could not find an owner, rule, or response step, then revise the implementation.

Frequently asked questions

What should a K-12 AI acceptable use policy include?

It should define scope, approved and prohibited uses, eligible users and accounts, data rules, learning expectations, human responsibility, accessibility, reporting, consequences, exceptions, ownership, and review dates.

Should a district write a separate AI policy or update its existing acceptable use policy?

Either structure can work. The important requirement is that AI rules connect clearly to existing technology, privacy, academic integrity, records, accessibility, security, procurement, and incident procedures without creating conflicting directions.

Can one AI rule apply to every grade and class?

A district baseline can apply across the system, but age, course purpose, assignment design, account eligibility, accessibility, and student data can require narrower grade, role, school, or classroom rules.

How often should a district review its AI acceptable use policy?

Set an annual review at minimum and reopen the policy earlier after material product, legal, instructional, privacy, security, or incident changes. Approval records for individual uses may need more frequent review.

Does an acceptable use policy make an AI product safe or legally compliant?

No. A policy sets district expectations. Each product and use still needs appropriate privacy, security, accessibility, instructional, procurement, and legal review, plus controls that match the actual deployment.

Sources

This checklist is educational information, not legal advice. Districts should use qualified legal, privacy, accessibility, security, procurement, instructional, and policy review for their circumstances.

Choose your Tenet path

Start with one district baseline. Add context when you need it.

Tenet Basic is free. Tenet District adds roster, classroom, teacher, grade, and schedule context.