Who should own AI governance in your school?
Schools need a clear answer to who approves each use of AI. This guide explains how to assign accountability, involve specialist leads and review decisions over time.
On this page6 sections
A teacher wants to use a new AI tool. IT needs to check access and security. The data protection lead needs to understand how information will be handled. A curriculum lead is looking at its fit with teaching and assessment. Each person can advise on part of the proposal, yet the most basic question can still go unanswered: who decides?
That is where an AI initiative either stalls or quietly becomes practice without clear conditions. A new committee for every proposal will not fix the problem. The school needs one visible decision route: a senior leader accountable for the overall approach, relevant specialists involved at the right point, a named person responsible for implementation and a date when the decision will be reviewed.
Give one accountable leader the whole-school view
The Department for Education’s guidance on generative AI in education gives schools and colleges room to choose uses that suit their settings. It also makes clear that leaders and staff remain responsible for the quality and appropriateness of their work.
Accountability does not require one leader to approve every prompt, tool or classroom activity. It requires one person who can explain the school’s overall position: which uses are approved, why they are being used, what conditions apply and when the decision will be reviewed.
Depending on the organisation, the role may sit at school or trust level. Wherever it sits, that person needs to connect curriculum, safeguarding, data protection, IT, staff workload and implementation. Without that whole-school view, each specialist can review one part while the decision itself remains unresolved.
Teachers and other staff still retain professional responsibility for the material they use. They need clear boundaries, but they also need room to apply judgement within those boundaries.
Match the approval route to the use
Not every use needs the same level of review. A teacher using an approved tool to suggest worksheet variations, then checking every output, presents different questions from a pupil-facing service that processes personal data or influences assessment.
Putting both uses through the same heavy process can slow sensible experimentation. Treating both as light-touch decisions can leave serious gaps. The approval route should change with the purpose, the people affected, the data involved, the level of automation and the educational stakes.
Bring in specialist review when a proposed use:
- Gives pupils direct access or changes their learning experience
- Processes personal or special-category data
- Supports profiling or automated decision-making
- Affects assessment, safeguarding or another statutory responsibility
- Introduces a new supplier, integration or data flow
- Moves from a small pilot to wider use
The DfE’s data-protection guidance for generative AI in schools advises staff to understand how a tool processes data and consult their data protection officer or IT lead before it is approved.
Staff need a routing rule they can follow without reopening the whole debate every time someone proposes a use.
Keep a decision register people can use
A policy explains the school’s principles. A decision register records what the school has actually agreed.
For each proposed or approved use, record:
- The educational or operational purpose
- The accountable owner and the staff responsible for delivery
- The users and groups affected
- The specialist advice required
- The conditions for data, access and teacher review
- The evidence, incident or product change that would trigger a fresh decision
- The review date and the person authorised to continue, change or stop the use
Keep the record short enough for leaders and service owners to update. If the people running the use cannot understand its conditions, the register is not doing its job.
Ofsted’s research with early-adopter schools and colleges found that leaders were developing ways to manage data protection, safeguarding, bias and intellectual property risks, while evidence about educational impact remained limited. A useful decision register holds those questions together: is the use responsibly managed, and is it proving worthwhile?
Review educational value as well as risk
Approval is the start of governance, not the end. A tool can remain within its original safety boundaries and still fail to help the people it was meant to support.
At the review point, ask:
- Is the use helping with the problem it was approved to address?
- Are teachers repeatedly correcting the same errors or unsuitable outputs?
- Has it reduced work, or introduced new checks and confusion?
- What are staff and pupils noticing in practice?
- Have the product, data flow or terms changed since approval?
End the review with a decision to continue, change, pause or stop the use. This balance reflects UNESCO’s human-centred guidance for generative AI in education, which connects data privacy with age-appropriate use, ethical validation and pedagogical design.
Make the next leadership meeting end in a decision
Take one use that is already happening, or that staff want to begin next term, into the next leadership meeting. A real case exposes unclear ownership more quickly than another general conversation about AI.
Ask five questions:
- What school problem is this use meant to address, and who will be affected?
- Who is accountable for deciding whether it can proceed?
- Which teaching, safeguarding, privacy or technical advice is needed?
- What conditions must staff follow, and what evidence should be kept?
- When will the use be reviewed, and who can decide to change or stop it?
End the meeting with a recorded outcome: proceed within an existing approved route, seek specialist review, run a bounded pilot or do not proceed.
If the team cannot name the owner, advisers, conditions and review point, the use is not ready to expand. Make those four elements explicit first.
Clear ownership makes governance usable
Good AI governance does not require a committee to control every classroom choice. It requires the school to distinguish routine use within agreed boundaries from decisions that change data access, teaching, assessment, safeguarding or the pupil experience.
The practical test is simple. Can staff see who made the decision, which specialist advice informed it, what conditions apply and when it will be reviewed?
Start with one current use rather than waiting for a perfect whole-school policy. A clear record will expose missing responsibilities and show whether the wider governance model works in practice. Before wider rollout, use those decisions to work through the broader questions in what school leaders should look for before scaling AI and your school’s current data privacy requirements.
This model is not legal advice or a substitute for statutory duties and specialist guidance. It gives school teams a practical way to turn broad principles into a decision they can explain, act on and revisit.