top of page

IACAIP Artificial Intelligence Guidance and Policy Framework for UK Schools 2026

2 hours ago
7 min read

Download the full Artificial Intelligence for Schools guidance:



Artificial intelligence is already in classrooms, staffrooms and homework routines, often before a school has agreed what safe use looks like. Pupils may use AI tools to plan essays. Teachers may test AI for lesson resources. Leaders may be asked whether a tool is suitable, secure or fair. Without a clear policy, each decision becomes a one-off judgement.


The IACAIP AI-01:2026 Artificial Intelligence Guidance and Policy Framework for UK Schools is designed to meet that gap. Published by the International Association of Cybersecurity and Artificial Intelligence Professionals, it sets out a professional framework for the safe, responsible, ethical and educationally appropriate use of AI in United Kingdom education.


This article summarises the purpose, governance value and practical implications of the framework for schools, academy trusts, governing bodies and education leaders across the UK. It is an editorial overview for general information, not legal advice.


Wide-angle view of a UK classroom with tablets and a teacher guidance folder.
AI policy should connect technology choices with everyday classroom practice.

Why UK schools need a clear AI framework in 2026


AI tools now sit across many parts of education. They can draft text, summarise reading, generate quizzes, translate content, suggest code, create images and respond to pupil questions. Some can support accessibility and workload reduction. Some can also create risks that schools cannot ignore.


The risk is not simply that pupils might use AI to cheat. That is only one concern. Schools also need to think about:


  • Safeguarding

    AI tools may expose pupils to unsuitable content, persuasive chat behaviour or unsafe advice.


  • Data protection

    Staff and pupils may enter personal data into systems that were not approved for school use.


  • Fairness

    AI output can reflect bias, produce inaccurate claims or disadvantage pupils who do not have equal access to tools.


  • Assessment integrity

    Schools need a shared position on when AI support is acceptable and when it crosses a line.


  • Cybersecurity

    AI services can create fresh risks around accounts, prompts, files, extensions and third-party platforms.


  • Staff practice

    Teachers need clear guidance on lesson planning, feedback, marking support and professional judgement.


A policy framework helps move the discussion from reaction to governance. It gives leaders a way to decide what is allowed, what needs approval, what needs training and what must be prohibited.


The IACAIP AI Guidance and Policy Framework for UK Schools 2026 places AI use in the context of United Kingdom education. That matters because schools do not operate in a vacuum. They sit within safeguarding duties, data protection law, curriculum expectations, trust governance, inspection pressures and parent confidence.


What the IACAIP AI-01:2026 document sets out


The publication is presented as a professional guidance framework, not a one-off classroom tip sheet. Its document control details show that it is intended for institutional use by schools, academy trusts, governing bodies and education professionals.


Field

Details

Publication

IACAIP AI Guidance and Policy Framework for UK Schools

Document reference

IACAIP AI-01:2026

Edition

First Edition

Publication year

2026

Issuing organisation

International Association of Cybersecurity and Artificial Intelligence Professionals

Status

Guidance Framework

Jurisdiction

United Kingdom

Classification

Public Professional Guidance

Intended users

UK schools, academy trusts, governing bodies and education professionals

Review cycle

At least annually


Those details matter because AI policy should not sit as an informal note in a staff handbook. It needs ownership, review and governance. The framework gives schools a reference point for building a local AI policy that can be approved, communicated, reviewed and improved.


It also sets a clear purpose. The framework focuses on AI use that is:


  • Safe

  • Responsible

  • Ethical

  • Educationally appropriate


Those four tests are a useful way for leaders to judge new tools and practices. A tool may be technically impressive, but that does not mean it is safe for pupil use. A workflow may save time, but that does not mean it is fair or appropriate for assessment. A chatbot may answer questions fluently, but that does not mean it can replace professional judgement.


Close-up of a printed AI policy folder beside school stationery.
A written framework gives schools a shared reference point for AI decisions.

How schools can turn the framework into daily practice


A framework only helps if schools turn it into decisions people can follow. The strongest AI policies are clear enough for classroom use and structured enough for governance.


Set ownership before setting rules


AI policy should have named leadership. In a school, that may involve the headteacher, designated safeguarding lead, data protection lead, IT or cybersecurity lead, curriculum leaders and governors. In a trust, central oversight may sit with a senior education, safeguarding, digital or risk lead.


Clear ownership avoids a common problem: AI decisions being passed between curriculum, IT, safeguarding and compliance teams without anyone taking responsibility.


A practical model is to define:


  • Who approves AI tools for staff use

  • Who approves AI tools for pupil use

  • Who reviews data protection concerns

  • Who handles AI-related safeguarding incidents

  • Who communicates policy changes to staff, pupils and parents

  • Who reports AI risk to governors or trustees


Create simple categories of use


Schools can make AI guidance easier by grouping use into clear categories. For example:


Category

Meaning in practice

Approved use

Tools and activities that the school has checked and permitted

Restricted use

Use that needs staff supervision, consent, risk assessment or a specific purpose

Prohibited use

Activities that create unacceptable safeguarding, privacy, assessment or security risk

Under review

Tools or practices that are being assessed before approval


This helps staff avoid guesswork. It also supports pupils, because they can learn where AI fits within acceptable academic practice.


Build AI into existing policies


AI should not become a separate island. It should link with policies schools already use, including:


  • Safeguarding and child protection

  • Online safety

  • Data protection and UK GDPR

  • Behaviour

  • Curriculum and teaching

  • Assessment and examinations

  • Staff code of conduct

  • Acceptable use of technology

  • Cybersecurity and incident response

  • Special educational needs and disabilities support


This approach keeps AI governance realistic. Most AI risks are not entirely new. They are new versions of familiar issues, such as privacy, plagiarism, bias, unsafe content, harmful contact and unreliable information.


Keep human judgement central


AI can support tasks, but schools remain responsible for decisions about pupils. A policy should make that clear. Staff should not rely on AI as the sole basis for decisions about safeguarding, discipline, assessment outcomes, special educational provision or significant pastoral action.


A safe principle is simple: AI may assist, but accountable adults decide.


That principle protects pupils and staff. It also reflects the limits of AI systems. They can produce confident errors, invent references, misunderstand context, reproduce bias and fail to explain their reasoning in a way that meets school accountability standards.


The review cycle is one of the most important features


The IACAIP document states that the publication should be reviewed at least annually and sooner where there are significant changes affecting AI use in education.


A school AI policy should not be treated as finished. It should be reviewed whenever technology, law, guidance, safeguarding expectations or risk changes in a meaningful way.

The framework identifies several triggers for early review:


  • Artificial intelligence technologies

    New tools, model capabilities or platform changes may alter risk.


  • UK legislation or regulation

    Changes in law may affect data use, accountability, procurement or pupil rights.


  • Government guidance

    Schools may need to align with updated Department for Education or wider public-sector advice.


  • Education-sector requirements

    Exam boards, regulators, local authorities or trust policies may set new expectations.


  • Safeguarding expectations

    New patterns of harm, misuse or pupil vulnerability may require tighter controls.


  • Cybersecurity risks

    Account compromise, malicious prompts, unsafe integrations or data leakage may change the threat level.


  • Data-protection requirements

    Schools may need to revisit lawful basis, data sharing, retention or processor arrangements.


  • Significant AI-related incidents

    A serious event should lead to lessons learned and policy updates.


Eye-level view of a school corridor noticeboard with AI safety reminders.
AI guidance should be visible, practical and easy for pupils and staff to understand.

Annual review is the minimum. In practice, schools may need a lighter termly check, especially if staff are actively testing new AI tools.


A useful review process can include:


  1. Gather feedback from staff and pupils.

  2. Check whether approved tools are still suitable.

  3. Review any incidents, near misses or concerns.

  4. Check changes in law, guidance and exam requirements.

  5. Update staff training and pupil guidance.

  6. Report key changes to governors or trustees.


This does not need to become a heavy administrative exercise. A short review can still be effective if it asks the right questions and records the outcome.


What education leaders should prioritise first


For schools starting from little or no AI policy, the challenge can feel too broad. The best first step is to focus on the highest-risk decisions.


Protect pupil data


Staff and pupils need clear instructions not to paste identifiable pupil information into unapproved AI tools. That includes names, addresses, behaviour records, special category data, safeguarding details, assessment data and anything that can identify a pupil directly or indirectly.


Schools should know which tools process data, where data may be stored, whether prompts are retained and whether content may be used to train future systems. If those answers are unclear, the tool should not be used with personal or sensitive school information.


Give pupils clear assessment rules


Pupils need to know when AI support is allowed. Vague warnings about cheating are not enough.


Clear guidance may explain whether pupils can use AI for:


  • Brainstorming ideas

  • Explaining a concept

  • Checking grammar

  • Producing a study plan

  • Generating a first draft

  • Writing final assessed work

  • Creating images, code or references


Schools should also tell pupils how to acknowledge AI use where it is permitted. This supports academic honesty and reduces confusion.


Train staff in practical risks


Staff training should focus on real classroom decisions. It should cover prompt safety, hallucinated content, bias, copyright awareness, data protection, safeguarding escalation and assessment integrity.


Training should also include positive use. AI policy should not only say what staff cannot do. It should help them use approved tools well, within safe boundaries.


Make procurement and approval consistent


A school or trust should avoid a situation where every department signs up for different AI tools without checks. Approval should include education value, safeguarding, accessibility, data protection, cybersecurity and cost.


A simple approval form can ask:


  • What problem does the tool solve?

  • Who will use it?

  • Will pupils use it directly?

  • What data will be entered?

  • Has the privacy information been checked?

  • Can the tool produce unsuitable or biased content?

  • What supervision is needed?

  • How will the school review its use?


The aim is not to block useful tools. The aim is to make adoption safe and consistent.


Overhead view of a school library table with an AI policy review calendar.
Regular review keeps AI policy aligned with changing technology and school risk.

A practical takeaway for UK schools


The IACAIP AI-01:2026 framework gives schools a structured way to move beyond informal AI use. Its value lies in governance, not paperwork. It encourages schools to define safe use, assign ownership, protect pupils, respect data protection duties and review policy as technology changes.


A sensible next step is to audit current AI use across the school or trust. Ask what tools staff and pupils already use, what data is being entered, what rules exist for assessment, and who approves new tools. That audit will show where policy is strong and where urgent work is needed.


AI in education will keep changing. A clear framework gives schools something stable to work from, while leaving room to adapt when risks, tools and expectations change.


Comments


bottom of page