Resources 8 min read

AI Governance for K-12 Schools

Governing AI in a school district: the inventory, a data rule about student information, approved tools, student use, vendors and what to tell families.

An empty school corridor lined on both sides with blue student lockers.

School districts arrive at AI governance from a different direction from businesses. Staff adoption is already widespread, the data involved is about children, the community has a direct interest, and the organization frequently has no compliance function at all.

This page is about governing AI in a district. Whether a district is ready to adopt AI is a different question, covered in AI readiness assessment for K-12 school districts, and what districts actually use AI for is in AI use cases for K-12 school districts.

What makes a district different

Five things, and each changes a recommendation that would be straightforward elsewhere.

The data is about children, and much of it is education records. The obligations attached to that are real, specific, and not something a technology supplier can interpret for you.

Adoption is already ahead of policy, usually by a year or more, and it happened for good reasons: teachers are short of time and these tools save some.

Students use it too, which no business governance model addresses. Academic integrity, accessibility and the question of what students should learn about AI all sit in the same conversation as staff use.

The community is a stakeholder. Parents will ask, a board will be asked, and the answer has to be readable by people who do not work in technology.

There is rarely a compliance function. Governance has to be sized for people who already have other jobs, which means shorter documents and fewer meetings rather than a scaled-down version of a corporate program.

The federal picture, stated carefully

In July 2025 the Secretary of Education issued a Dear Colleague Letter to grantees on using federal grant funds to improve education outcomes with AI. It sets out five Principles for Responsible Use: educator-led, ethical, accessible, transparent and explainable, and data-protective. It affirms that systems must comply with federal privacy laws including the Family Educational Rights and Privacy Act.

Two things to be precise about. That letter concerns the use of federal grant funds and is addressed to grantees. It is guidance, and it is not a rule creating new obligations for every district. The Department has separately issued a supplemental grantmaking priority on advancing AI in education. It was proposed in July 2025 and published as a final priority on 13 April 2026 (34 CFR Part 75, Docket ID ED-2025-OS-0118), so describing it as a proposal is now out of date. What it is not is a blanket requirement on districts: it is a priority the Secretary may choose to apply to a discretionary grant competition, in whole or in part. It matters if you are applying for one of those grants, and not otherwise.

The Department's Student Privacy Policy Office is the standing reference for student privacy questions and is more useful to most districts than any AI-specific document.

What none of this does is tell a district whether a particular tool is permissible under its own obligations. That question involves federal law, state law, board policy and existing vendor agreements, and it belongs with the district's counsel.

Start where every district starts

Ask staff what they use, without consequence attached. The framing determines the answer, and an audit framing produces an undercount that misleads everything afterwards.

Districts consistently find more than expected, most of it lesson planning, differentiation, communication drafting and grading support. That is not a discipline failure; it is a workload signal, and treating it as misconduct guarantees the next round of adoption is invisible too.

Then find what staff cannot tell you: AI features already switched on inside the platforms the district licenses, which is where most student data actually sits. Check admin consoles rather than relying on recollection. The method is the same as building any AI inventory, with student data raising the stakes.

The data rule, which matters more here than anywhere

One sentence, specific enough to apply without asking: which categories of information may not be entered into a general-purpose AI tool.

For most districts that list includes anything identifying a student, education records, information about a student's disability, discipline or family circumstances, health information, and staff personnel matters. Write the categories your district actually holds rather than a generic phrase, and give an example of each.

Pair it with the positive half. Staff need to know what they may do, or the rule reads as a prohibition on the tools they already find useful and they will simply stop mentioning them.

Approved tools, and a route onto the list

Publish which tools are approved, for what, and how to ask about one that is not.

Districts that publish only restrictions get undeclared use. Districts that publish an approved list and answer requests within a week get told about new tools, which is the outcome governance actually wants. Commit to a response time and keep it; a route that takes a month is not a route.

Distinguish tools approved for staff use from tools approved for student use. They are different decisions with different considerations, and collapsing them causes most of the confusion in district AI policies.

Student use, academic integrity and accessibility

Three decisions that no business governance model will help with.

What students may use, and when. This is instructional rather than technical, and it belongs with academic leadership. The useful governance contribution is to ensure the decision is made and communicated rather than left to individual teachers to improvise.

Academic integrity. Districts should be cautious about AI-detection tools specifically: their reliability is contested and the consequences of a false accusation for a student are serious. A position built on assignment design and conversation is more defensible than one built on a detector's output.

Accessibility. Some AI capabilities are genuinely assistive, and a blanket prohibition can remove a support a student depends on. Any restriction should be checked against the district's obligations to students with disabilities before it is issued.

Vendors, and the agreements you already signed

Most AI reaching a district arrives inside platforms bought years ago under agreements that predate the feature.

Ask each major platform vendor, in writing, which AI features are available in your tier, which are on by default, whether student data is used to train or improve any model, how long it is retained, and which subprocessors are involved. Then ask which of those answers are contractual and which sit in a policy the vendor can revise.

Where a district uses a student data privacy agreement, establish whether it covers AI features added after signature. The general approach is in AI vendor risk assessment; the student-data specifics belong with your counsel and your state's requirements.

Human review, where a decision affects a student

The threshold that works in a district is consequence to a student. A draft of a routine parent newsletter needs no gate. Anything bearing on grading, discipline, placement, eligibility for a service, attendance enforcement or a referral does.

Two conditions make that review real rather than nominal. The reviewer needs the underlying information, not only the AI output, because judging a recommendation without seeing what produced it is not review. And they need actual authority to disagree. A teacher or administrator who cannot in practice overturn a recommendation is a rubber stamp, and describing them as human oversight in a board-facing document transfers accountability to someone who never had the power to exercise it.

Write the threshold down and name who holds it. Districts that leave it to professional judgment find that the judgment varies by building, which is the position hardest to defend if a decision is later questioned.

Telling the community

Decide what parents are told, and tell them before they ask.

A short public statement covering what the district uses AI for, what it will not use it for, how student data is protected, and who to contact does more for trust than a detailed policy nobody outside the district reads. Districts that wait until a question arrives end up explaining a position under pressure rather than presenting one.

A realistic first term

Inventory in the first weeks, by asking. A named owner and an escalation route. A one-page data rule with the positive half included. An approved list with a request route and a response commitment. A short statement to families. A review date.

That is achievable in a term for a district with no compliance function, and it is worth more than a comprehensive framework that arrives after another year of undeclared adoption. The fuller structure is in the AI governance framework, and the order to build it in is how to create an AI governance program.

None of the above is legal advice. Districts should review their position against federal and state law, board policy and existing agreements with qualified counsel. LABUSA works with districts and other public organizations on AI governance for public organizations, alongside the wider guidance in AI governance for public-sector organizations. If you would like help running the first inventory, get in touch.

About LABUSA

LAB Information Technology Incorporated (LABUSA) is a trusted provider of managed IT solutions, empowering organizations with secure, efficient, and scalable technologies. With expertise spanning cybersecurity, cloud services, enterprise software, and data management, LABUSA helps clients modernize operations, strengthen compliance, and optimize performance. Our customer-focused approach ensures tailored solutions that align with organizational goals while maintaining the highest standards of reliability and security. Headquartered in Houston, Texas, LABUSA serves government agencies, corporations, and nonprofits across the United States and internationally.