Limbrick Consultancy LLP


Sign In

or
Don't have an account? 

AI policy for schools: where to start

AI, Policy, Data Protection, Safeguarding, School Leadership, Digital Confidence
A bad workman blames his tools, and the proverb is seven hundred years old. It has never been more useful. Whoever sends the letter owns the letter, whether AI helped or not, and that is where a school AI policy starts.
An electrician's tools and wiring laid out ready for work
Image by sid74 via Pixabay
Share:
X

The complaint is older than almost any tool you own. In the late thirteenth century a French proverb was already doing the rounds: a bad workman will never find a good tool. Randle Cotgrave put a version into his French and English dictionary in 1611. By 1738 Jonathan Swift had it in Polite Conversation as "an ill workman never had good tools".

Seven hundred years, then, of people explaining that the work would have been fine if the equipment had been better.

I have been thinking about it because of AI, and because of a report published this week. Sir Anthony Seldon, with Tim Bunting, says schools were not prepared for AI's arrival and describes the way it has landed as chaotic. The report makes ten recommendations, including that every school and college develops its own AI strategy, that Ofsted looks at how that is being put into practice, and that England has a national framework by September next year.

Those are recommendations, not rules. Nothing in the report changes what your school has to do tomorrow. But the underlying observation is hard to argue with, and it is not really about strategy documents. It is that AI is already in use in almost every school, and almost nobody has written down what is acceptable.

The Tool Does Not Sign the Letter

Here is the part I would put in front of staff before any policy.

You are responsible for what goes out. The letter to parents. The report to governors. The risk assessment. The reference. The policy itself. If AI helped you write it, that changes nothing about who owns it.

"The AI wrote it" is not a defence. Not to a parent who has received something careless, not to a governor asking where a figure came from, not to an auditor, not to the ICO, and not to an inspector. The name at the bottom is still yours.

Which means the rule is simple, and it is not new. Check what goes out. We have always done this with a colleague's draft. AI does not earn an exemption because it writes confidently.

But Tools Do Matter

The proverb is only half the story, and the other half is worth saying out loud.

Geneticists have a good example. Spreadsheets kept turning gene symbols into dates: type SEPT1 or MARCH1 into Excel and you get a date back. A study in 2016 found the problem in around a fifth of the papers it checked that carried gene lists in spreadsheets. Nobody could make the software stop, so in 2020 the people responsible for naming genes renamed the genes instead. SEPT1 became SEPTIN1. The tool shaped the work, and the humans took ownership of the consequences.

The Post Office makes the opposite point just as sharply. There, the tool was wrong and the people were blamed anyway, and it took years and the courts to unpick it.

So both blame-shifts fail. You cannot hide behind the tool, and you cannot assume the tool is right. That is precisely why the choice of tool, and the habit of checking its output, belong in writing.

Which Is What a Policy Is For

A policy is not a compliance exercise. It tells staff what is allowed, so that thirty people are not each deciding privately. It shows governors the school has thought about this, which they will ask sooner or later. And it gives you something to point at afterwards, because the question afterwards is always the same. What did we say?

Eight things make it useful.

What counts as AI, and who is covered. The obvious tools, and the AI features already inside the software you pay for. Say whether it covers staff, pupils, governors, volunteers and contractors.

Which tools are approved, and who decided. A short list, each with a named person who signed it off. Signing in with a school email account tells you who is using something. It does not mean anyone has checked it.

Personal data. What must never go into a tool that has not been checked for it: pupils' names, safeguarding information, health data. A new tool, or a new use of an existing one, may need a data protection impact assessment. Your DPO can advise.

What staff can use it for. The useful uses, and the limits. A person checks anything that goes out. AI does not make decisions about individual pupils.

Pupils. At what age, in what circumstances, and how supervised. Say whether that includes homework, which happens outside your filtering and monitoring.

Safeguarding and incidents. KCSIE now refers directly to generative AI, including AI-generated images. Safeguarding concerns go to the DSL. A data breach also goes to the DPO. They are separate routes, and one incident can need both. If a breach is reportable, the ICO's 72 hours start when the school becomes aware of it.

Assessment and honesty. If you offer qualifications, reflect the JCQ's guidance. For everyone else, say how staff will treat AI-assisted work.

Ownership and review. Who owns it, how staff are trained, and when it is reviewed. At least yearly, and whenever a significant new tool arrives.

Two things make it stick. Be honest about what you have not decided yet, because a policy that lists its open questions is safer than one that hides them. And write it for your school. A template describes somebody else's pupils, staff and systems, which is the gap the report is complaining about.

If You Would Like a Draft Written for Your School

That is why we built the Digital Confidence AI Policy Builder. Rather than editing a template, you answer about fifteen minutes of questions about your own school: your setting and pupils, the tools staff already use, and the rules you want. Most are tick boxes, "not sure" is always an allowed answer, and you do not need an account.

We then write a draft AI policy for your school. A person checks it before it comes back to you, and it lists the decisions you still need to make. It is a draft for your school to review and adopt. It is not legal advice, and the decisions remain yours.

The first ten schools to send their answers get their draft free. After that it is £95 plus VAT. We send an invoice, the draft follows once it is paid, and purchase order numbers are fine. The price and the terms are on screen before you answer anything.

Start your school's AI policy, no sign-in needed

A Free Session on Wednesday 30 September

At 12:30, for forty-five minutes, I am running a free online session on writing the policy itself. It is for school business leaders and digital leads, it assumes no technical knowledge, and there is time for questions. It is not a workshop on using AI day to day.

Anyone can book here: www.sbforum.co.uk/events

Seven hundred years on, the proverb still holds. The tool is not the one who has to answer for the work.

Share:
X

Other Blog Posts
Don't Just Stop the Box Falling in the River: What the Parliamentary Red Box Can Teach Schools About Data Security
by Neil Limbrick
113 days ago 5490 views
Data Protection, Data Security, Information Governance, School Leadership, Risk Management, Digital Confidence
Your Data Is in the Cloud. Are You Sure It’s Safe?
by Neil Limbrick
178 days ago 2064 views
IT Risk Isn’t Technical - It’s Personal
by Neil Limbrick
182 days ago 2570 views
Stop Writing Reports. Start Sending Recipe Boxes.
by Neil Limbrick
189 days ago 1357 views
AI
Digital Strategy
Communication
Data
Leadership
Workload
Schools
Connect the Classroom: Free Funding - But Decisions That Will Last for Years
by Neil Limbrick
210 days ago 1671 views
Mission Control and the New DfE IT Support Standards
by Neil Limbrick
311 days ago 2597 views
DfE digital standards
IT support
Digital Confidence
School leadership
Cyber security
Digital strategy
Ink, Illusion and Internal Controls: When Pulling the Wool Over Eyes Goes Digital
by Neil Limbrick
321 days ago 1738 views
fraud
cyber risk
digital confidence
AI risk
training
Don't Bring a Frying Pan to an Emu War: Why IT Needs Leadership
by Neil Limbrick
1 year ago 2014 views
Leadership
Why did the Senior Leadership Team cross the road?
by Neil Limbrick
1 year ago 2667 views
IT Procurement
Network Infrastructure
School Leadership
Digital Strategy
Cost Saving
Infrastructure Planning
From Cabinets of Curiosity to Chromebooks: Why Your IT Asset Register Matters
by Neil Limbrick
1 year ago 2321 views
ChatGPT said: IT Asset Register
School IT Management
Digital Strategy
EdFITS
Budget Planning
Device Refresh
Safeguarding Compliance
IT Inventory
School Business Management
Infrastructure Planning
From Asterisks to AI: Reflections, Chocolate, and the Latest on Generative AI in Education
by Neil Limbrick
1 year ago 1994 views
AI
DfE Guidance
Training
The Walled Garden That's Lovely Until It Isn't: Avoiding Vendor Lock-In in School IT
by Neil Limbrick
1 year ago 2085 views
Vendor Lock-In
Procurement
Managed Service Providers
IT Strategy
EdFITS
Digital Maturity
School IT Contracts
Exit Planning
Infrastructure Flexibility
School Partnerships
Planting Orchards, Not Just Picking Apples: What Apple Farmers Can Teach Us About IT Strategy
by Neil Limbrick
1 year ago 1979 views
IT Strategy
EdFITS
School Leadership
Safeguarding
Long-Term Planning
Sustainable IT
Digital Maturity
Technology Planning
Curriculum Support
Device Refresh
Don't Get Caught by the Auto-Renewal Trap: Why Every School Needs a Contracts Register
by Neil Limbrick
1 year ago 1981 views
contract management
digital governance
DfE standards
school leadership
how to
templates
risk management
school business management
EdFITS
planning
Access Control: From Railway Block Tokens to Cybersecurity Sessions
by Neil Limbrick
1 year ago 2183 views
cybersecurity
access control
session management
IT best practice
digital security
railway history
historic lessons
heritage railways
risk management
technology leadership
What Shopkeepers and 99p Pricing Can Teach Us About Zero Trust Security
by Neil Limbrick
1 year ago 2190 views
Cyber Security
Zero Trust
Digital Confidence
School IT
Network Security
Why Do We Keep Fixing the Same IT Issues? - The Case for Problem Management in Schools
by Neil Limbrick
1 year ago 2023 views
Problem Management
EdFITS
Continuous Improvement
IT Efficiency
What Does Operational Excellence Look Like in School IT?
by Neil Limbrick
1 year ago 2056 views
IT Strategy
Operational Excellence
School IT
Self Audit
Cyber Essentials: The Policy Checklist Every School Needs
by Neil Limbrick
1 year ago 1971 views
Cyber Security
Checklist
Cyber Essentials
When the Wi-Fi Goes Down... Then What?
by Neil Limbrick
1 year ago 2034 views
Service Continuity
EdFITS
Blog
Digital Oversight for Governors: What to Ask and Why It Matters
by Neil Limbrick
1 year ago 2241 views
Governance
IT Strategy
Getting to grips with leadership and governance of IT
by Neil Limbrick
1 year ago 2039 views
Leadership
Governance
A Simple Guide to Cyber Security
by Neil Limbrick
1 year ago 2223 views
Cyber security
How to evaluate your IT provision
by Neil Limbrick
2 years ago 1907 views
Strategy
The questions you should be asking when implementing an IT strategy
by Neil Limbrick
2 years ago 1818 views
Strategy
Governance
Breaking down your IT Strategy
by Neil Limbrick
2 years ago 2020 views
The SBM guide to IT strategy
by Neil Limbrick
3 years ago 1863 views
Strategy
Leadership
Governance
Separate the wheat from the chaff
by Neil Limbrick
5 years ago 1849 views
Strategy
Improving your ICT game: The benefit of CPD programmes
by Neil Limbrick
9 years ago 1900 views
CPD
School Closures - The Simple Guide to Clear Communication
by Neil Limbrick
11 years ago 2018 views
Communication
Strategy
AI policy for schools: where to start on Limbrick Consultancy LLP