Resources · 26 June 2026
AI policy for schools and colleges (UK): what to cover and where to start
By the Operating Bench Team · Last reviewed 26 June 2026
Staff and pupils in your school are already using AI. The trouble is that schools also handle some of the most sensitive data there is, children’s records, safeguarding information, SEND data and assessments, under some of the heaviest expectations, Keeping Children Safe in Education, the DfE, and the ICO’s Children’s Code. A clear AI policy is how you let staff use AI to save time without putting pupils, or the school, at risk. Here is what it needs to cover and how to start.
Why schools need this more than most
Three things raise the bar for a school:
- Children’s data. Most AI tools are not built for it, and the ICO’s Age Appropriate Design Code (the Children’s Code) sets a high standard for processing it.
- Safeguarding. AI notetakers, chatbots and “default-on” AI features can pull safeguarding and pastoral information into places it should never go.
- Assessment integrity. Pupils using AI in coursework is now a live malpractice and authentication question for any qualification.
Get this wrong and the consequences are not abstract.
What a school AI policy should cover
- Pupil and staff data. Set plainly what may and may not go into AI tools. Names, SEND data, safeguarding notes and pastoral records do not belong in a consumer chatbot. Ground the rule in UK GDPR and the Children’s Code.
- Safeguarding and monitoring. Address AI notetakers in meetings, AI built into your MIS, and how AI use sits alongside your filtering and monitoring duties under KCSIE.
- Assessment and academic integrity. Reflect JCQ guidance on AI use in non-examined assessment: what pupils may use, how staff authenticate that work is a pupil’s own, and a healthy caution about so-called AI detectors, which are not reliable enough to accuse a pupil on their word alone.
- Approved tools, and default-off. Name the AI tools you allow and for what (lesson planning, marking support, communications), and check what AI features are switched on by default in platforms that already process pupil data.
- Teaching and staff use. Allow the genuine wins, lesson planning, first-draft marking, parent communications, with one firm rule: a person checks the output before it is used or sent.
- Roles, DPIAs and records. Name who owns AI use (often the DSL, DPO and a member of SLT between them), and complete a data protection impact assessment before adopting any tool that touches pupil data, which the ICO expects for children’s data.
Where the DfE and regulators sit
The direction of travel is consistent: the DfE’s position on generative AI in education is to support staff and protect pupils while keeping data safe; the ICO expects DPIAs and high-privacy defaults for children’s data; KCSIE frames the safeguarding duties; and JCQ governs AI in assessment. A school policy that reflects all four is a defensible one.
How to start
- Find out what is already in use, by staff and by pupils. Ask, without blame.
- Decide your approved tools and what data may go into each.
- Set a simple data rule staff can apply in seconds: is this safe to put into this tool?
- Brief staff and pupils, with a one-page guide each.
- Complete a DPIA for any tool that processes pupil data.
- Name an owner and review each term.
That is a defensible baseline, and it is exactly what our AI Safe-Use Pack for schools and colleges is built to give you: seven core documents rewritten for schools, covering safeguarding, assessment integrity, the MIS and SEND data, plus the policy, risk register, approved-tools matrix and a DPIA starter. If you only need the essentials first, the general AI Safe-Use Pack covers the core, and the free AI Starter Kit sets out the ground rules on one page.
This article is general information, not legal advice. How safeguarding and data-protection duties apply to your setting should be considered with appropriate professional advice.