IACAIP Artificial Intelligence Guidance and Policy Framework for UK Schools 2026
Download the full Artificial Intelligence for Schools guidance:
Artificial intelligence is already in classrooms, staffrooms and homework routines, often before a school has agreed what safe use looks like. Pupils may use AI tools to plan essays. Teachers may test AI for lesson resources. Leaders may be asked whether a tool is suitable, secure or fair. Without a clear policy, each decision becomes a one-off judgement.
The IACAIP AI-01:2026 Artificial Intelligence Guidance and Policy Framework for UK Schools is designed to meet that gap. Published by the International Association of Cybersecurity and Artificial Intelligence Professionals, it sets out a professional framework for the safe, responsible, ethical and educationally appropriate use of AI in United Kingdom education.
This article summarises the purpose, governance value and practical implications of the framework for schools, academy trusts, governing bodies and education leaders across the UK. It is an editorial overview for general information, not legal advice.

Why UK schools need a clear AI framework in 2026
AI tools now sit across many parts of education. They can draft text, summarise reading, generate quizzes, translate content, suggest code, create images and respond to pupil questions. Some can support accessibility and workload reduction. Some can also create risks that schools cannot ignore.
The risk is not simply that pupils might use AI to cheat. That is only one concern. Schools also need to think about:
Safeguarding
AI tools may expose pupils to unsuitable content, persuasive chat behaviour or unsafe advice.
Data protection
Staff and pupils may enter personal data into systems that were not approved for school use.
Fairness
AI output can reflect bias, produce inaccurate claims or disadvantage pupils who do not have equal access to tools.
Assessment integrity
Schools need a shared position on when AI support is acceptable and when it crosses a line.
Cybersecurity
AI services can create fresh risks around accounts, prompts, files, extensions and third-party platforms.
Staff practice
Teachers need clear guidance on lesson planning, feedback, marking support and professional judgement.
A policy framework helps move the discussion from reaction to governance. It gives leaders a way to decide what is allowed, what needs approval, what needs training and what must be prohibited.
The IACAIP AI Guidance and Policy Framework for UK Schools 2026 places AI use in the context of United Kingdom education. That matters because schools do not operate in a vacuum. They sit within safeguarding duties, data protection law, curriculum expectations, trust governance, inspection pressures and parent confidence.
What the IACAIP AI-01:2026 document sets out
The publication is presented as a professional guidance framework, not a one-off classroom tip sheet. Its document control details show that it is intended for institutional use by schools, academy trusts, governing bodies and education professionals.
Field | Details |
Publication | IACAIP AI Guidance and Policy Framework for UK Schools |
Document reference | IACAIP AI-01:2026 |
Edition | First Edition |
Publication year | 2026 |
Issuing organisation | International Association of Cybersecurity and Artificial Intelligence Professionals |
Status | Guidance Framework |
Jurisdiction | United Kingdom |
Classification | Public Professional Guidance |
Intended users | UK schools, academy trusts, governing bodies and education professionals |
Review cycle | At least annually |
Those details matter because AI policy should not sit as an informal note in a staff handbook. It needs ownership, review and governance. The framework gives schools a reference point for building a local AI policy that can be approved, communicated, reviewed and improved.
It also sets a clear purpose. The framework focuses on AI use that is:
Safe
Responsible
Ethical
Educationally appropriate
Those four tests are a useful way for leaders to judge new tools and practices. A tool may be technically impressive, but that does not mean it is safe for pupil use. A workflow may save time, but that does not mean it is fair or appropriate for assessment. A chatbot may answer questions fluently, but that does not mean it can replace professional judgement.

How schools can turn the framework into daily practice
A framework only helps if schools turn it into decisions people can follow. The strongest AI policies are clear enough for classroom use and structured enough for governance.
Set ownership before setting rules
AI policy should have named leadership. In a school, that may involve the headteacher, designated safeguarding lead, data protection lead, IT or cybersecurity lead, curriculum leaders and governors. In a trust, central oversight may sit with a senior education, safeguarding, digital or risk lead.
Clear ownership avoids a common problem: AI decisions being passed between curriculum, IT, safeguarding and compliance teams without anyone taking responsibility.
A practical model is to define:
Who approves AI tools for staff use
Who approves AI tools for pupil use
Who reviews data protection concerns
Who handles AI-related safeguarding incidents
Who communicates policy changes to staff, pupils and parents
Who reports AI risk to governors or trustees
Create simple categories of use
Schools can make AI guidance easier by grouping use into clear categories. For example:
Category | Meaning in practice |
Approved use | Tools and activities that the school has checked and permitted |
Restricted use | Use that needs staff supervision, consent, risk assessment or a specific purpose |
Prohibited use | Activities that create unacceptable safeguarding, privacy, assessment or security risk |
Under review | Tools or practices that are being assessed before approval |
This helps staff avoid guesswork. It also supports pupils, because they can learn where AI fits within acceptable academic practice.
Build AI into existing policies
AI should not become a separate island. It should link with policies schools already use, including:
Safeguarding and child protection
Online safety
Data protection and UK GDPR
Behaviour
Curriculum and teaching
Assessment and examinations
Staff code of conduct
Acceptable use of technology
Cybersecurity and incident response
Special educational needs and disabilities support
This approach keeps AI governance realistic. Most AI risks are not entirely new. They are new versions of familiar issues, such as privacy, plagiarism, bias, unsafe content, harmful contact and unreliable information.
Keep human judgement central
AI can support tasks, but schools remain responsible for decisions about pupils. A policy should make that clear. Staff should not rely on AI as the sole basis for decisions about safeguarding, discipline, assessment outcomes, special educational provision or significant pastoral action.
A safe principle is simple: AI may assist, but accountable adults decide.
That principle protects pupils and staff. It also reflects the limits of AI systems. They can produce confident errors, invent references, misunderstand context, reproduce bias and fail to explain their reasoning in a way that meets school accountability standards.
The review cycle is one of the most important features
The IACAIP document states that the publication should be reviewed at least annually and sooner where there are significant changes affecting AI use in education.
A school AI policy should not be treated as finished. It should be reviewed whenever technology, law, guidance, safeguarding expectations or risk changes in a meaningful way.
The framework identifies several triggers for early review:
Artificial intelligence technologies
New tools, model capabilities or platform changes may alter risk.
UK legislation or regulation
Changes in law may affect data use, accountability, procurement or pupil rights.
Government guidance
Schools may need to align with updated Department for Education or wider public-sector advice.
Education-sector requirements
Exam boards, regulators, local authorities or trust policies may set new expectations.
Safeguarding expectations
New patterns of harm, misuse or pupil vulnerability may require tighter controls.
Cybersecurity risks
Account compromise, malicious prompts, unsafe integrations or data leakage may change the threat level.
Data-protection requirements
Schools may need to revisit lawful basis, data sharing, retention or processor arrangements.
Significant AI-related incidents
A serious event should lead to lessons learned and policy updates.

Annual review is the minimum. In practice, schools may need a lighter termly check, especially if staff are actively testing new AI tools.
A useful review process can include:
Gather feedback from staff and pupils.
Check whether approved tools are still suitable.
Review any incidents, near misses or concerns.
Check changes in law, guidance and exam requirements.
Update staff training and pupil guidance.
Report key changes to governors or trustees.
This does not need to become a heavy administrative exercise. A short review can still be effective if it asks the right questions and records the outcome.
What education leaders should prioritise first
For schools starting from little or no AI policy, the challenge can feel too broad. The best first step is to focus on the highest-risk decisions.
Protect pupil data
Staff and pupils need clear instructions not to paste identifiable pupil information into unapproved AI tools. That includes names, addresses, behaviour records, special category data, safeguarding details, assessment data and anything that can identify a pupil directly or indirectly.
Schools should know which tools process data, where data may be stored, whether prompts are retained and whether content may be used to train future systems. If those answers are unclear, the tool should not be used with personal or sensitive school information.
Give pupils clear assessment rules
Pupils need to know when AI support is allowed. Vague warnings about cheating are not enough.
Clear guidance may explain whether pupils can use AI for:
Brainstorming ideas
Explaining a concept
Checking grammar
Producing a study plan
Generating a first draft
Writing final assessed work
Creating images, code or references
Schools should also tell pupils how to acknowledge AI use where it is permitted. This supports academic honesty and reduces confusion.
Train staff in practical risks
Staff training should focus on real classroom decisions. It should cover prompt safety, hallucinated content, bias, copyright awareness, data protection, safeguarding escalation and assessment integrity.
Training should also include positive use. AI policy should not only say what staff cannot do. It should help them use approved tools well, within safe boundaries.
Make procurement and approval consistent
A school or trust should avoid a situation where every department signs up for different AI tools without checks. Approval should include education value, safeguarding, accessibility, data protection, cybersecurity and cost.
A simple approval form can ask:
What problem does the tool solve?
Who will use it?
Will pupils use it directly?
What data will be entered?
Has the privacy information been checked?
Can the tool produce unsuitable or biased content?
What supervision is needed?
How will the school review its use?
The aim is not to block useful tools. The aim is to make adoption safe and consistent.

A practical takeaway for UK schools
The IACAIP AI-01:2026 framework gives schools a structured way to move beyond informal AI use. Its value lies in governance, not paperwork. It encourages schools to define safe use, assign ownership, protect pupils, respect data protection duties and review policy as technology changes.
A sensible next step is to audit current AI use across the school or trust. Ask what tools staff and pupils already use, what data is being entered, what rules exist for assessment, and who approves new tools. That audit will show where policy is strong and where urgent work is needed.
AI in education will keep changing. A clear framework gives schools something stable to work from, while leaving room to adapt when risks, tools and expectations change.





Comments