Skip to content
Articles

Sector Signal Issue 08: Nobody asked for an AI policy. They asked for five edits.

Sector scanner

Five printed policies fanned across an oak table in a school staff room, tabbed and annotated, with the oval beyond the glass.

17 September 2026

Every fortnight we read the sector so you do not have to. No alarm, no spin. Every link below goes to a primary source: a regulator, a parliament, a government department, a commission, or the affected organisation's own statement.

This issue covers 24 August to 7 September 2026, and it leans on one theme, because the fortnight did: artificial intelligence, and what the people who regulate schools are actually asking you to do about it.

The driving story

Somewhere in your school there is an AI policy.

It was probably written in 2024, after the national framework landed. It is probably good. It was probably approved by the board, filed, and referred to twice since. And this fortnight is the clearest evidence yet that no regulator in Australia or New Zealand is asking for it.

What they are asking for is narrower, and harder.

On 31 August, NESA did not ask New South Wales schools for an AI policy. It issued Official Notice 29/26, which caps take-home assessment and then closes with a single instruction that leaves the curriculum lane entirely: "Check your malpractice policy does not rely on the use of AI tools to detect malpractice." Before Term 4.

On 28 July, eSafety did not ask for an AI policy. Its school imagery advisory says: "Schools should update their student behaviour and acceptable use policies to cover AI-manipulated content and the posting of images. Their critical online incident plans should also cover the misuse of student and staff images, including the possibility that a deepfake linked to the school could go viral."

From 10 December, the Privacy Commissioner is not asking for an AI policy. It is asking for a paragraph in the privacy policy that says what personal information the school uses in automated decisions, and what kinds of decisions those are.

On 31 August, the Attorney-General's Department released an exposure draft of the next tranche of privacy law that would make an inference drawn by AI count as a collection of personal information, and make a child's best interests a primary consideration in whether that handling is fair. Submissions close on 18 September.

And the Australian Institute of Company Directors, in a guide most independent school boards can use as written, says the accountability for a vendor's AI stays with the organisation that deployed it. On 3 September, Mathspace showed what that looks like in practice.

Five regulators and one incident. Not one of them asks for a new document. Every one of them asks for a specific change to a document the school already holds and already answers for. Assessment and malpractice. Behaviour and images. Incident response. Privacy. Vendor due diligence.

Meanwhile, a survey published on 24 August by Instructure, the company behind Canvas, found that only 28 per cent of Australian education professionals were confident their institution had a clear strategy for where AI fits. It is a vendor survey of 215 people across primary, secondary and higher education, panel sourced, and we treat it accordingly. But it is the number the sector press led with, and the honest response to it is not "write the strategy". It is "make the five edits".

The AI policy is not the document that gets a school fined. It is not the document a regulator reads after an incident. The five it reads are already on the shelf.

What has a clock

Since Wednesday 9 September. Under the Age-Restricted Material Codes, app distribution services must have had age assurance in place for age-restricted apps. eSafety's own FAQ: "some of the requirements around age checks for app distribution services don't need to be in place until 9 September 2026." This is the first structural friction on the nudify class of app reaching a student's device, and the date to cite when a parent asks what the platforms are obliged to do.

Tomorrow, Friday 18 September. Submissions close on the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026. "Unfortunately, we will not be able to consider submissions received after the closing date."

Friday 25 September. The Commonwealth Student Attendance Semester 1 collection closes, through the new Education Funding System portal for the first time.

October. Education ministers have agreed to discuss "the use and impact of Artificial Intelligence in schools" at their next meeting.

Term 4 2026. NESA's limit and the malpractice policy instruction take effect for HSC courses. Week 6 for compressed curriculum. Term 1 2027 for Preliminary.

Thursday 10 December. Two obligations land together: the automated decision making paragraph in the privacy policy, and registration of the Children's Online Privacy Code, which the OAIC says will reach "educational tools".

The five edits

Edit 01. The malpractice policy

NESA's notice does two things, and most schools will file it under the first.

The first is a cap. For Preliminary and HSC courses, no more than one take-home assessment task, worth a maximum weighting of 15 per cent. A take-home task is anything completed outside a classroom, formal examination setting or teacher-approved monitoring conditions. Fourteen major project and practical courses are exempt. The ACE Rules will be updated before the end of Term 3, and the limit starts in Term 4 for HSC courses.

The second is a position on evidence, and it is the governance half. "Schools must design formal assessment tasks so that marks reflect the student's own knowledge, skills and understanding. Marks must not reflect a student's use of generative AI." Then: "Schools should not rely on AI detection tools as the main safeguard against malpractice. If used at all, detection software should be treated as only one input for teacher professional review, not as sole proof of AI use or malpractice." NESA's standing HSC rules page gives the reasoning: detection tools "can produce false positives and false negatives, and research has raised equity concerns for some student cohorts, including students who do not speak English as a first language."

If your school has spent the last two years quietly leaning on a detection score as the backstop for academic integrity, that position now has a use-by date, and the document that has to change is a governance document.

New South Wales is not alone in the position, only in the deadline. NZQA's standing guidance says to use AI checkers carefully, "be very mindful of false positives, and do not rely on this alone." The VCAA, in Notice to Schools 36 of 30 April, added a generative AI declaration to the VCE Extended Investigation and now requires "a written authentication investigation report endorsed by the School Principal" where a teacher cannot declare the work is the student's own. The New Zealand Ministry of Education's guidance, updated in May, says schools with consent to assess "are required to have an authenticity policy" which "must include the acceptable use of GenAI."

Even the largest detection vendor now says the same thing. Turnitin's own documentation states the AI writing indicator percentage "should not be used as the sole basis for action."

Already covered. A dated, owned compliance calendar entry against "Term 4 2026, malpractice policy amended and approved" is exactly what the EthosOne compliance calendar exists to hold: the edit, the person, and the date, in one place the board can see.

Worth asking your senior team. Does our academic integrity or malpractice policy currently name an AI detection tool as a safeguard, and who is changing it before Term 4?

Edit 02. The behaviour policy, the image policy, and the incident plan

eSafety's July advisory is the regulator's first school-specific document on deepfakes, and its figures are the sector's baseline until something replaces them.

"Last year, eSafety saw twice as many reports from under-18s about digitally altered intimate images, including deepfakes." "Between January and March 2026, eSafety received more than 100 reports about anonymous accounts targeting schools and school staff. Almost all involved imagery harvested from school social media accounts or websites." The material included "AI-generated dance videos and face swaps, as well as memes using staff photographs and fabricated stories about teachers, principals and other school staff." Those running the accounts "are often believed to be current or former students from the targeted school."

The accompanying media release adds the line a board should not skip: "We also know of a significant number of recent cases involving AI-generated child sexual exploitation material (deepfake image-based sexual abuse) occurring in school settings." And a limit: "not all harmful material can be addressed under the Online Safety Act, especially material that targets adults." Which means that for a staff member targeted by a non-intimate deepfake, the school's own behaviour policy and complaints process may be the only remedy that exists.

The regulator is also shutting the tools. In May, eSafety issued its first Direction to Comply under the Age-Restricted Material Codes against a nudify service drawing nearly 40,000 Australian visits a month, with exposure to "civil penalties of up to $49.5 million". By June, three services had withdrawn from Australia and a further direction had issued. By July, seven of the most widely used services had withdrawn or taken steps to comply.

The criminal exposure for a student is now specific and severe. Under the Commonwealth Criminal Code, using a carriage service to transmit sexual material without consent carries six years, and seven years where the person "was responsible for the creation or alteration of the material." In New South Wales, producing a sexually explicit deepfake of a real, identifiable person is an offence carrying up to three years, and the Department of Education has published a parent explainer. In South Australia, using AI to create invasive, humiliating or degrading images resembling a real person carries "fines of up to $20,000 or four years imprisonment" since 3 November 2025. In Victoria, section 53R of the Crimes Act carries three years, with the statutory example of superimposing a person's face onto a photograph of a naked person.

In the window itself, the Senate committee reported on 25 August on a bill to expand eSafety's information gathering powers and increase civil penalties under the social media minimum age, and Roblox has until roughly 20 November to implement a court-enforceable undertaking that includes the first independent third party audit ever required under the Online Safety Act.

None of this asks for an AI policy. It asks for three edits: the behaviour policy covers AI-manipulated content, the image policy covers what is posted and with what consent, and the incident plan covers the morning a deepfake of a teacher is on every phone in Year 10.

Worth asking your senior team. If a face-swapped video of a staff member appeared on a student-run account tonight, which document tells us what to do, and does it mention AI?

Edit 03. The privacy policy

Two things land on 10 December 2026 and both need a privacy policy that has been drafted rather than found.

The first is the automated decision making obligation. In the OAIC's words: "From 10 December 2026, APP entities that use personal information in ADM with the potential to affect rights or interests will be required to provide information in their privacy policies about the kinds of personal information used and the kinds of decisions made using ADM." Schools run more of this than they think: enrolment ranking, scholarship scoring, attendance flagging, wellbeing triage, integrity detection. The policy edit is an afternoon. The inventory behind it is not, and the OAIC's guidance on commercially available AI products is blunt about who carries it: "If your organisation is using AI to provide a product or service, including internally within your organisation, then you will be a deployer."

The second is the Children's Online Privacy Code, which must be registered by the same date and which the OAIC says will reach "educational tools".

Then there is what is coming behind them. The exposure draft released on 31 August proposes three things a school should read closely. Inference becomes collection: personal information "may be generated or derived through means such as data analysis, artificial intelligence or other technological processes", and "inferences drawn by AI-enabled technology about an individual would be considered collection of information for the purpose of the Act." Children's interests become a primary factor: "Where personal information relates to a child, the child's best interests must be a primary consideration when assessing whether the handling is fair and reasonable." And precise location becomes sensitive information: data identifying location "to within a radius of 500 metres" and "held by reference to the individual's location over time" would require consent, which reaches bus tracking, campus wayfinding and excursion apps. The paper also names wearables directly: an entity collecting through "technologies like smart glasses, including photos, videos, audio recordings and/or AI-generated inferences, it must comply with privacy laws."

Submissions close tomorrow, 18 September. A school holds more information about children than almost any other institution a family deals with. This is the window in which the rules for holding it are being written.

Worth asking your senior team. Can we list every tool that makes or shapes a decision about a student using their personal information, and does our privacy policy say so?

Edit 04. The vendor due diligence

On 6 August, a software company called Metabase published a critical security advisory. Mathspace runs a self-hosted Metabase instance for internal reporting. In their own published words: "Our existing vulnerability-notification process did not identify and escalate that advisory for action." Access began on 10 August. Data was downloaded on 27 August. Mathspace patched on 29 August, and states: "At the time of updating, we did not complete the additional compromise checks recommended for potentially affected systems." On 3 September they confirmed what had happened.

A total of 1,079,819 people were affected, students, parents or guardians and school staff, and only people in Australia and New Zealand. Names, email addresses, usernames, internal identifiers, account types and activity dates. No academic records, no results, no passwords, no single sign-on tokens. Former and inactive users are in scope: "Leaving a school or stopping use of Mathspace does not, by itself, establish that your information was unaffected." School administrators can request their school's affected numbers from data-breach-response@mathspace.co. Mathspace says it reported the incident to the OAIC, the Australian Signals Directorate's Australian Cyber Security Centre, and New Zealand's Privacy Commissioner and National Cyber Security Centre on 4 September. As at 7 September, none had published anything about it.

Nothing in that sequence is a technology failure. It is a vendor's intake failure. And the reason it belongs in an AI issue is what the governance bodies said about vendors in the weeks before it happened.

The AICD's Director's Guide to AI Governance, version 2, June 2026, with an appendix written for SMEs and not for profits: "Boards are ultimately accountable for the adoption, implementation and outcomes of AI technologies in their organisations." And on vendors: "While these risks may originate with vendors, accountability remains with the organisation." The AICD and the Australian Signals Directorate, in board guidance on frontier AI cyber threats published on 3 August: "boards should consider cyber supply chain risks associated with their reliance on particular AI vendors", and "Have we reviewed our risk tolerance in light of frontier AI threats and is that risk tolerance still appropriate?"

Independent Schools NSW said the same thing after Canvas, in May: "Vendor incidents still require local governance, risk assessment and communication."

The practical instrument is maturing. Safer Technologies 4 Schools framework v2026.1, published in July and updated on 20 August, revised 41 assessment questions across the full assessment and the AI module, introduced "mandatory safety alert message requirements" for interactive AI sessions, and now assesses "a school's ability to manage and control AI features that are available to students." A Responsible AI standard is in pilot with a 2026 rollout aim. The Commonwealth's response to the House inquiry, tabled in April, funds that work with $1.8 million, supports one of the inquiry's twenty-five recommendations, and "notes" the rest. The burden stays with the school.

Already covered. A risk register entry against each AI vendor, with a named owner, a review date and the answer to "how do they triage a critical advisory", is the artefact the AICD line about accountability remaining with the organisation is describing. EthosOne schools already hold that register.

Worth asking your senior team. For each AI tool a student touches, do we know whether the vendor holds an ST4S assessment, and who at our school would receive their breach notice?

Edit 05. The board's own risk appetite

The last edit is the one no regulator can write for you.

The evidence base on what students are doing is now substantial. eSafety's research of 3 August, surveying almost 2,000 Australian children: "78% of children aged 10 to 17 had used an AI assistant, with ChatGPT the most commonly used tool"; one in five daily or more; "More than half of children (54%) who had used AI assistants or companions said they had used them for personal or social reasons." Commissioner Julie Inman Grant: "AI is not a trusted adult." Independent Schools Australia's February report, citing OECD data, has 66 per cent of Australian teachers using AI in the previous twelve months against an OECD average of 36, and warns that "Without a shared national direction, AI risks becoming a source of growing inequality."

The national direction is thin. The Australian Framework for Generative AI in Schools is unchanged since 2023. Ministers endorsed its 2024 review in June 2025 and agreed to review it annually. No 2025 review has been published. The next scheduled conversation is October's ministers' meeting.

What exists instead is a set of accountability statements, and they all point the same way. The National AI Centre's Guidance for AI Adoption, practice one: "your organisation is ultimately accountable for how and where AI is used", and organisations should "assign, document and clearly communicate who is accountable across the organisation (including contractors and third-party providers/systems)." The AICD: boards are ultimately accountable. The ASD: review the risk tolerance. New Zealand's Online Safety Bill, introduced on 24 August, brings "social AI companions" into a minimum age regime while carving out services that "support education (such as websites used for learning and school message boards)", which is a legislature drawing a line between AI that helps a child learn and AI that simulates a relationship with them, and expecting institutions to know which they have deployed.

That is the fifth edit. Not a policy. A sentence in the risk appetite statement that says what the school is and is not prepared to let AI do with, to and for its students, with a name against it. The 28 per cent in the Instructure survey is not a strategy gap. It is a decision that has not been made.

Worth asking your senior team. Has the board, as a board, decided what we are not prepared to let AI do in this school, and is that decision written down anywhere a regulator could find it?

The watchlist

Beyond the dated items above, three things belong in a board calendar now.

In New Zealand, from 24 October 2026, a new core children's worker with an overseas conviction equivalent to a Schedule 2 offence cannot be employed as a core worker without an exemption, extending to existing core workers from 24 April 2027. In the early learning sector, the advanced child safety course on leading and governing child safety becomes available from 30 September 2026, and anyone already in a relevant role before that date is captured by the 31 March 2027 completion deadline. That course is aimed squarely at the people who sit on governing bodies. And a private senator's bill to lower the threshold for adult cyber abuse, which is where staff-targeted deepfakes currently fall through the Online Safety Act, has not moved since March; if it does, the gap eSafety named in July closes.

The regulatory space moved alongside the AI story this fortnight, and it moved in the same direction: towards records rather than policies. On 28 August the VRQA confirmed that Victoria's Working with Children Check, strengthened from 28 July, can now take into account "allegations of reportable conduct, including unsubstantiated allegations that may identify a pattern of behaviour", with the VCAT appeal replaced by internal review; a reportable conduct file your school wrote for one purpose is now read for another. On 24 August the NSW Children's Guardian reported more than 100 fines and warnings totalling over $99,500, naming failure to verify clearances online as the common breach, which is the step that links a worker to the school so a cancellation actually reaches it. On 25 August Western Australia's screening amendment received Royal Assent as Act No. 14 of 2026, which the Department of Communities summarises as "banned in one, banned in all", awaiting proclamation. On 1 September New Zealand's Education Review Office took over registration of private schools and licensing of hostels, so every escalation contact naming the Ministry is now quietly wrong. On 26 August the Queensland Protection Commission Bill 2026 was introduced, proposing a single safeguarding body. And on 1 September the Fair Work Ombudsman signed an enforceable undertaking with the University of Queensland covering about $11 million to 16,382 staff, caused by "incorrect payroll system configurations, clerical errors and other oversights", with oversight routed through the Senate Risk and Audit Committee. A school with casual staff and an enterprise agreement has the same failure modes.

Finally, what we could not report as at 7 September. No regulator had published anything on Mathspace. The OAIC had published nothing at all since 7 August. The annual review of the national AI framework had not appeared. And the deepfake conviction handed down in a Brisbane court on 2 September, which several outlets reported, exists in no police release, published sentencing remark or judgment we could find, so it is not in this issue. When a primary source appears, it will be.

The ten-minute test

Take your AI policy off the shelf. Do not read it. Instead, open the five documents this issue is about and look for the word "AI" in each.

Malpractice or academic integrity. Does it name a detection tool as a safeguard?

Student behaviour and acceptable use. Does it cover AI-manipulated content?

Critical incident plan. Does it cover a deepfake of a staff member or student going viral?

Privacy policy. Does it say what personal information is used in automated decisions?

Risk appetite or risk register. Does it say what the board will not let AI do, and does each AI vendor have an owner?

If the word appears in all five, in a sentence that commits the school to something, your AI governance is done and the standalone policy is decoration. If it appears in none of them, the standalone policy is the only place it lives, and that is the document no regulator this fortnight asked to see.

Seven questions worth putting to your senior team

  1. Does our malpractice or academic integrity policy currently name an AI detection tool as a safeguard, and who is changing it before Term 4?
  2. If a face-swapped video of a staff member appeared on a student-run account tonight, which document tells us what to do, and does it mention AI?
  3. Which of our public image posts could be harvested, and is our consent current for the ones that stay up?
  4. Can we list every tool that makes or shapes a decision about a student using their personal information, and does our privacy policy say so?
  5. For each AI tool a student touches, do we know whether the vendor holds an ST4S assessment, and who at our school would receive their breach notice?
  6. Has the board, as a board, decided what we are not prepared to let AI do in this school, and is that decision written down where a regulator could find it?
  7. Are we making a submission on the privacy exposure draft before it closes on 18 September, or is our association making one on our behalf?

Sector Signal is published fortnightly by EthosOne. We read the regulators, the parliaments, the departments and the commissions, and we tell independent school leaders what actually changed. Every claim traces to a primary source. If a fact cannot be confirmed from one, we do not publish it.

Sector Signal Issue 08: Nobody asked for anAI policy. They asked for five edits.