The acceptable use policy schools adopted five years ago probably covers passwords, gaming, social media, and inappropriate websites. It may say nothing about a student uploading an assignment to a public chatbot, a teacher using AI to draft feedback, or an algorithm influencing which students receive intervention.

Schools and districts must ensure students cannot use school-issued technology to access inappropriate content, expose themselves to cyber threats, or distract themselves from schoolwork (via gaming, streaming shows or movies, or social media).

Artificial intelligence is now built into search engines, productivity suites, learning platforms, accessibility tools, tutoring products, and the devices students use every day. Blocking one chatbot does not create an AI policy. Neither does adding “Do not cheat with AI” to the student handbook.

For the 2026–27 school year, districts need an acceptable use policy that explains how students and staff may utilize school-issued tech, screen time, and AI, which tools are approved, what information must stay out of prompts, when people must disclose AI assistance, and which decisions always require qualified human judgment.

The answer lies in three words: Acceptable Use Policy, or AUP.

What Is an Acceptable Use Policy?

An AUP is an agreement between the student and the district designed to keep students safe online. This agreement allows them to explore the digital world as part of their education, instead of accessing inappropriate or harmful sites, such as bullying, school violence, pornography, etc.

The CoSN guide on AUPs defines the two main components as:

  • Protecting students from harmful content on the Internet and regulating their use of the Internet so it does not harm or interfere with other students.
  • Providing students with access to digital media that supports engaged learning.

AUPs enable students to accept responsibility for their online and digital device usage.

Key Components of an Acceptable Use Policy for Schools

It’s important to know what should be part of your AUP as you begin to write one. The National Education Association suggests including these six elements for an AUP:

  • Introduction: Why the policy is needed, goals, and an explanation of the process for creating this AUP.
  • Definitions: Key words used in the AUP.
  • Policy Statement: Explains which computer services are covered by the AUP and the circumstances under which students can use those services (i.e., students must complete a “computer responsibility” course before accessing these services).
  • Acceptable Uses: Define appropriate student use of the computer, such as “educational purposes”.
  • Unacceptable Uses: Gives clear, specific examples of what constitutes unacceptable use.
  • Violations/Sanctions: Tells students how to report AUP violations and defines how violations will be handled (typically the same as the school’s general student disciplinary code).

As a case study, Boston Public Schools (BPS) created an AUP for their 57,000 students across 128 schools. They took a student-centered approach and enlisted high schoolers to make it easier for students to understand, especially those in younger grades. In this example, BPS high schoolers created podcasts to deliver the AUP message. (All of their AUP materials can be found here.)

When students sign an AUP, they need to understand what it actually means, which is why this age-appropriate model is critical.

Why the Traditional School AUP Is No Longer Enough

Traditional acceptable use policies focused primarily on access: which websites, applications, networks, and devices people could use. Generative AI adds a second layer of risk: what users put into a tool and what they do with its output.

An AI system may produce confident but inaccurate information, reveal bias, generate inappropriate content, imitate a real person, create copyrighted material, or retain information entered in a prompt. A technically accessible tool is not automatically instructionally appropriate, privacy-safe, or approved for every age group.

Federal guidance also points districts toward responsible, educator-led adoption. In July 2025, the U.S. Department of Education clarified that federal grant funds may support certain AI-related activities when those uses align with the requirements of the specific program. That flexibility does not remove obligations involving privacy, security, accessibility, civil rights, transparency, evidence, or human oversight.

Privacy expectations have also changed. The Federal Trade Commission’s 2025 updates to the Children’s Online Privacy Protection Rule strengthened protections involving children’s data, third-party disclosure, security, and retention. FERPA, state student-privacy laws, vendor contracts, district policy, and age-specific consent requirements may add further obligations.

What Is an Acceptable AI Use Policy?

An acceptable AI use policy is a district-approved set of rules for using artificial intelligence safely, ethically, and effectively in instruction and school operations. It should apply to students, educators, administrators, contractors, and other users of district accounts, devices, networks, or data.

A strong policy answers six questions:

  1. Which AI tools may people use?
  2. What may they use those tools to do?
  3. What information may never be entered?
  4. When must AI use be disclosed or cited?
  5. Which decisions require human review?
  6. How will the district monitor, teach, and enforce the rules?

10 Components of an Acceptable AI Use Policy for Schools

1. A clear purpose and scope

Start by explaining why the district permits AI use and who the policy covers. Tie AI to educational goals such as improving instruction, building AI literacy, increasing accessibility, supporting staff productivity, and preparing students to evaluate emerging technology.

The scope should cover:

  • District-owned and personally owned devices used for school activities
  • District networks, accounts, data, and licensed applications
  • On-campus, take-home, remote, and extracurricular use
  • Students, employees, contractors, volunteers, and vendors where applicable
  • Generative AI, embedded AI features, automated decision tools, and AI-enabled tutoring or analytics

2. Approved tools and permitted purposes

Do not make every teacher, student, or department conduct an improvised vendor review. Maintain a current list of approved AI tools and the purposes for which each tool may be used.

For example, a district may permit an approved tool for brainstorming, translation, practice questions, lesson differentiation, or feedback—but prohibit the same tool from making final grading, discipline, special-education, or intervention decisions.

The policy should explain that a tool is not approved simply because it is free, popular, embedded in another product, or accessible through a personal account.

3. Student privacy and prompt hygiene

Users need concrete rules about what must never be placed into an unapproved AI system. Prohibited inputs should include personally identifiable information, education records, health information, disability status, disciplinary records, credentials, confidential district information, unpublished assessments, and other protected or sensitive data.

The district’s vendor review should address:

  • What data the tool collects
  • Whether prompts and outputs are stored
  • Whether district data may be used to train or improve a vendor’s models
  • Which third parties receive data
  • How long data is retained
  • How records can be accessed, corrected, exported, or deleted
  • What happens to data when the contract ends
  • Whether the tool meets applicable age, consent, privacy, security, and accessibility requirements

Teach “Do not paste private information into a chatbot” with examples. Students and staff cannot follow a rule they do not understand.

4. Human review and responsibility

AI can assist judgment; it should not erase accountability. The person using the tool remains responsible for reviewing the result and the resulting decision.

Require qualified human review before AI influences consequential decisions involving:

  • Grades or academic standing
  • Student placement or eligibility for services
  • Special-education evaluation or accommodation
  • Discipline, threat assessment, or behavioral intervention
  • Attendance enforcement
  • Admissions, hiring, or employee evaluation
  • Communications presented as official district guidance

The policy should also give students, families, and employees a way to question or appeal an AI-assisted decision.

5. Academic integrity, disclosure, and attribution

“AI use is cheating” is too broad to guide learning. “Use AI responsibly” is too vague to enforce. Teachers need a shared framework that can still flex by assignment.

A practical model defines four levels:

  • AI prohibited: The student must complete the work without AI assistance.
  • AI permitted for limited support: AI may help with brainstorming, vocabulary, translation, or feedback, but not produce the submitted answer.
  • AI permitted with disclosure: AI may contribute to the work if the student identifies the tool, explains how it was used, and verifies the result.
  • AI required: The assignment intentionally teaches prompting, evaluation, editing, or another AI literacy skill.

Every assignment should make the permitted level clear. The district should provide a consistent disclosure or citation method rather than asking teachers to invent one on their own.

6. Accuracy, sources, and intellectual property

AI-generated content can sound polished while being wrong. Require users to verify facts, calculations, quotations, citations, and links before relying on or sharing an output.

The policy should also address copyright, licensing, authorship, and the use of third-party text, images, audio, code, or other material. Staff and students should not assume that an AI-generated asset is accurate, original, properly licensed, or safe to publish.

7. Bias, civil rights, and accessibility

AI tools may perform differently across languages, disabilities, demographic groups, dialects, or cultural contexts. Districts should test tools for their intended users, monitor outcomes, and provide alternatives when a system creates barriers.

An acceptable AI use policy should require users to:

  • Check outputs for stereotypes, exclusion, or discriminatory patterns
  • Preserve accommodations and accessible formats
  • Avoid using AI detection scores as conclusive evidence of misconduct
  • Involve qualified staff when AI affects students with disabilities or English learners
  • Report biased, harmful, or inaccessible output

Human review is especially important when an AI recommendation could affect a student’s opportunities, services, or record.

8. Age-appropriate access and family communication

AI access should reflect students’ ages, developmental needs, vendor terms, and applicable law. Younger students may need a teacher-mediated experience within a district-managed tool, while older students may be ready for more independent use with disclosure and verification requirements.

Explain the district’s approach to families in plain language. Include:

  • Which tools students may use
  • What data those tools process
  • The instructional purpose
  • How teachers supervise use
  • What controls and alternatives are available
  • Where families can ask questions or raise concerns

Make the policy accessible, translate it for the communities the district serves, and involve students, educators, families, special-education leaders, IT, privacy, curriculum, legal,  and procurement teams in its development.

9. Safety, impersonation, and harmful content

The policy should explicitly prohibit using AI to create or distribute harassment, nonconsensual intimate imagery, sexual content involving minors, threats, deepfakes, impersonation, discriminatory material, malware, phishing content, or instructions for unlawful activity.

Users should also know how to report concerning content quickly and without redistributing it. Incident procedures should distinguish deliberate misuse from accidental exposure so the response is proportionate and focused on student safety.

10. Monitoring, enforcement, and regular review

A signature is not implementation. Support the policy with instruction, technical controls, vendor management, reporting procedures, and consistent consequences.

Define:

  • Who owns and updates the approved-tool list
  • How access controls will be configured
  • What activity the district monitors and why
  • How long logs are retained and who may review them
  • How suspected violations are investigated
  • How users can report errors, unsafe output, or privacy concerns
  • How consequences align with existing student and employee codes
  • How often the policy will be reviewed

AI tools and laws change quickly. Review the policy at least annually—and sooner when the district adopts a significant new tool, a vendor changes its data practices, or legal requirements change.

Sample Acceptable AI Use Policy Language

The following starter language is intentionally concise. District leaders should adapt it with their legal, privacy, instructional, technology, and accessibility teams.

Students and employees may use only district-approved artificial intelligence tools for authorized educational or operational purposes. Users must follow teacher directions and all district privacy, security, academic-integrity, accessibility, copyright, and records requirements.

Users may not enter personally identifiable student information, education records, credentials, confidential district information, or other protected data into an AI system unless the district has expressly approved that tool and use.

AI-generated information must be reviewed for accuracy, bias, appropriateness, accessibility, and source quality. The user remains responsible for any work, communication, recommendation, or decision produced with AI assistance.

Students and employees must disclose AI assistance when required and may not present AI-generated work as entirely their own. Teachers will identify the permitted level of AI use for each assignment.

AI may not be the sole basis for grading, placement, eligibility, discipline, evaluation, or another consequential decision. Qualified personnel must review relevant evidence and remain accountable for the final decision.

AI may not be used to create harmful, deceptive, discriminatory, sexually explicit, unlawful, or impersonating content; to harass others; to bypass security controls; or to violate intellectual-property rights.

Suspected privacy incidents, harmful outputs, security concerns, or incorrect AI-assisted decisions must be reported through the district’s established process. Violations will be addressed under applicable student, employee, and technology policies.

How Schools Can Put the Policy Into Practice

Build a cross-functional AI governance team

Include curriculum, instruction, IT, cybersecurity, data privacy, procurement, legal, special education, multilingual learning, communications, school leadership, educators, families, and students where appropriate. AI affects too many parts of a district to live in one department.

Inventory AI already in use

Ask which standalone tools and embedded features staff and students are using now. Districts cannot govern a tool set they have not identified.

Create an approved-tool review process

Evaluate educational purpose, evidence, privacy, security, accessibility, age restrictions, data retention, model training, integrations, support, total cost, and exit terms. Re-review material vendor changes.

Train adults before enforcing rules on students

Educators need practical guidance on assigning AI-supported work, protecting data, recognizing limitations, responding to suspected misuse, and teaching verification. Staff should not rely on AI detectors as a shortcut to due process.

Teach AI literacy, not just rule compliance

Students should learn how AI systems generate output, why hallucinations and bias occur, how to protect personal information, when disclosure is required, and how to verify claims with reliable sources.

Pilot, measure, and revise

Start with defined use cases and success measures. Collect feedback from students, educators, families, and support teams. Track instructional value, equity, accessibility, incidents, workload, and cost—not just logins.

How Filtering and Connectivity Controls Support the Policy

An acceptable AI use policy tells people what responsible use looks like. Technical controls help districts apply parts of that policy consistently.

For schools managing off-campus connectivity, Kajeet SmartSpot® provides portable student internet access with integrated, customizable filtering. The Kajeet Sentinel® platform gives administrators centralized visibility, policy controls, usage management, and reporting for Kajeet-connected devices.

Those capabilities can help a district allow approved educational resources, restrict access to unapproved sites, manage distributed devices, and apply connectivity policies beyond school walls.

Technical controls cannot fact-check an AI answer, decide whether a student’s use was academically appropriate, or replace educator judgment. The strongest approach combines policy, instruction, human oversight, privacy and vendor review, and technical enforcement.

Talk with Kajeet about managed, filtered student connectivity.

Frequently Asked Questions

Should a district create a separate AI policy or update its existing AUP?

Most districts need both district-wide AI guidance and updates across existing policies. Adding AI rules to the AUP helps govern day-to-day use, while privacy, procurement, academic-integrity, employee-use, records, accessibility, and disciplinary policies may need corresponding changes.

Does CIPA require an acceptable AI use policy?

No. CIPA requires covered schools and libraries to maintain an internet safety policy and use technology protection measures that block or filter certain visual content. Schools must also address monitoring of minors’ online activities and education about appropriate online behavior. An AUP can support those efforts, but signing an AUP does not by itself establish CIPA compliance.

Can students use public generative AI tools?

Only when the district has reviewed and approved the tool and its use for the relevant age group, instructional purpose, privacy requirements, and vendor terms. Students should not create personal accounts or enter protected information merely because a tool is publicly available.

Should schools use AI detectors to prove misconduct?

Schools should not treat AI detector results as conclusive evidence. Detection tools can produce false positives and may perform unevenly across different writers. Investigations should consider the assignment, drafts, citations, revision history, student explanation, and other evidence, with fair notice and an opportunity to respond.

How often should an acceptable AI use policy be updated?

Review it at least annually, and whenever the district adopts a significant AI tool, a vendor materially changes its data practices, or federal, state, or local requirements change. Publish the revision date so families and staff know which version is current.

The Goal Is Responsible Use, Not Policy Theater

Schools do not need a policy that treats every AI tool as either a miracle or a menace. They need clear rules that protect students, preserve educator judgment, support useful innovation, and tell everyone what to do when the technology fails.

That takes more than a signature collected during device distribution. It takes shared expectations, approved tools, ongoing instruction, technical controls, and regular review.

An acceptable AI use policy will not answer every future question. It will give a district a defensible way to answer the next one.