Skip to content
Guide

AI governance in schools: who decides, what is logged, and which duties AI touches

The classroom debate about cheating is real, and it is not the governance question.

A library media-literacy seminar where a librarian and senior students compare sources, question an AI-produced summary on an unreadable tablet, and work with maps and books.

We would like to help you answer the question with your leadership team.

In one paragraph

AI governance in a school is the set of decisions, records and accountabilities that cover how staff

Students and the school itself use AI: who approves a tool, what data it can see, what is logged, and which existing obligations in child safety, privacy, records, WHS and staff conduct it affects.

What AI governance in a school is

Every leadership team we have sat with this year has the same three things on the table: staff already using AI tools nobody approved, a parent question about student data, and a board that has asked for "an AI policy" without anyone quite knowing what it should contain. A downloaded template answers the third and makes the first two worse, because it sits over the top of duties it does not name. Governance is the answer to three plainer questions: who decides, what is logged, and which of the duties you already carry does AI now touch. Why this is a duty question rather than an IT question is the story on AI governance for schools.

The duties AI touches

When PolicyAI reads a school's policy library against the AccuFind legislative graph, it does not find a missing AI policy. It finds child safety obligations that assume a human is making the decision, privacy obligations that assume data stays in a known system, records obligations that assume the record was written by a person, WHS obligations that assume the risk assessment was done by someone in the room, and staff conduct obligations that assume a person authored what went out under their name. More than 200 of them so far, and almost none of them say "AI". Those five duties are the spine of every section that follows. The Acts beneath them, scoped to your jurisdiction and sector with a source and an effective date on every record, live in the Legislation module, whose Change Monitor raises a review when a source moves.

Built to scale

Run at any scale. From one campus to a diocese, with every entity reporting the same way.

Switch
from your existing platform, for a low cost
25
policy domains help you make sense of the policies you have, and the ones you need
Every regulator
in Australia and New Zealand supported
Safe
data, processing and AI based in Sydney and Melbourne via AWS

Coverage spans the eight Australian states and territories, with Commonwealth law applying across all of them, and separately New Zealand. Domain figures come from the PolicyAI Research Atlas, refreshed weekly.

Who decides, and what is logged

Decision rights are the part most schools have never written down. The framework on our AI governance page sets out fourteen AI decisions a school makes, from approving a tool for staff use with no student data through to accepting a residual risk that stays above appetite, and for each names who proposes, who decides, who is consulted, who is informed and what it is logged as. The logging standard gives the rule: when AI is used to inform a decision about a person, to produce a communication that leaves the school, to generate a record the school relies on, or to process personal information, the use is logged. The board reporting line makes AI a standing item at the Risk Committee and a quarterly one-page report to the board, with serious incidents reaching the Chair within 24 hours. All of it, with a sixteen-slide chair's presentation ending in a motion to endorse, is in the AI governance pack for schools.

An editorial still life on a timber library table: an organised navy policy folder, cream planning cards, closed laptop, plain VR headset and illegible notes.

The AI risk register

A register is where duties become risks with owners. Our seed pack holds twelve AI risks written for an independent school on a 5 x 5 matrix, from student information entered into an unapproved tool and AI content acted on without verification, through harmful AI-generated content about students and vendors training on school data, to wellbeing chatbots, board oversight and the opportunity foregone by having no governed way to try. Each carries a cause, a consequence, inherent and residual ratings, existing controls, planned treatments, an owner role and a jurisdiction tag for South Australia, Victoria, New South Wales and Queensland. Business managers tell us they run it through the risk committee in one meeting: keep, edit or drop each row. In EthosOne the same fifteen load as an AI register beside the board, ICT and operational registers under one matrix and appetite. The rows and the reasoning are in the AI risk register template.

Printed AI risk cards and a scored risk register form a calm, legible working set on a board table.

Policies: a lens over duties you already carry

The useful AI policy is not a standalone document. It is a short governing statement plus amendments to the child safety, privacy, records, WHS and staff conduct policies AI now touches, run through the controlled policy lifecycle with an owner, a reviewer, an approver and immutable versions. PolicyAI reads the library against the obligations it must address, scores coverage across 25 policy domains as met, partial or unmet, drafts the sections a policy is missing, and flags what changed when the law moved, on AccuFind's the consolidated primary-source law of the Commonwealth, every Australian state and territory, and New Zealand, refreshed weekly. The principles that sit inside the framework, five school-ready AI principles with a self-check, ten data principles and a cyber control checklist, are the free cyber security and AI policy template. What your policies actually cover is the work of PolicyAI.

A healthy phone-free social culture at a typical Australian brick school.

Vendors and data sovereignty

Most of the five duties are tested at the vendor boundary, because privacy, child safety, records and accessibility all assume the school knows where its data is and who can reach it. ICT managers tell us the hardest AI question is not whether a tool is good; it is whether anyone can say where the student data goes, whether the vendor trains on it, how long they keep it, who else sees it and what happens on the day the school wants to leave. Our assessment asks those questions once, in writing: forty questions across nine areas, ten of them gates, where a failed gate means do not proceed without a decision by the principal. The gates run from where personal information is stored and processed and whether the vendor trains on customer data, through deletion on request, security attestation, sub-processors and child safety, to data export at exit. The questionnaire, scoring sheet and cover letter are the AI vendor assessment template.

A vendor proposal, contract and privacy assessment questions sit in controlled order while a school procurement discussion continues softly behind.

Incident response

The first AI incident is rarely dramatic: a class list pasted into a chatbot, a letter to families built on a clause the tool invented, a student's face on a video nobody made, a tool the timetable depends on going dark on a Monday. What makes those serious is that nobody had agreed who does what in the first day. The plan covers four incident types (data disclosure through a tool, hallucinated content acted on, student misuse, and vendor outage or breach), names the roles, and sets out the first 24 hours in eight steps from recognise and report through preserve, assess and decide notifications to closing the first day with the review booked. The notification duties page lists who must be told for each type across the Commonwealth and SA, VIC, NSW and QLD, from the Notifiable Data Breaches scheme and child safe reporting to the eSafety Commissioner, the insurer, families and the board, as a starting point for your own applicability review. It is the AI incident response plan template.

A redacted incident timeline, plain phone and response checklist sit sharply organised while urgent school-office movement blurs beyond.

PolicyAI answering the prompt “Draft me an AI Acceptable Use Policy.”, then working through: Reading the AI-engaged obligations; Matching privacy, records, child safety; Drafting against your existing library.

AI governance

Solutions for every school’s AI challenge.

There is no AI-specific legislation in force in Australia or New Zealand. The duties your school already carries are the ones AI engages.

Take the AI maturity assessment

Governing AI, before your board asks again.

“The board asked what our position on AI is, and we did not have one.”

Data privacyAlgorithmic biasSynthetic mediaAutomated decisionsRecords governanceSurveillance

An AI policy is not a new rulebook, it is a lens over duties your school already carries: privacy, records, discrimination and child safety, engaged by an AI-shaped set of facts. Which is why a downloaded template does not survive contact with a regulator.

We have tagged the duties AI activity in a school engages, so the conversation starts from the obligations you already hold rather than from a blank page. Almost none of them say “AI”.

Try Draft with AI.Five paragraphs against the obligations of your State, with the provision beside each. Free, no login.

Value creation

Boards have started to ask the other question: where is AI helping? The value kit holds an opportunity register seeded with twelve school use cases, from differentiated lesson resources and feedback drafts for teacher review to parent communication drafting. A use-case canvas makes every idea state its purpose, success criteria, data class, the duties it touches and its owner before it starts, and a prioritisation matrix scores value against effort and risk so the executive can pick two to trial this term and say why. Chairs tell us the one-page board proposal is the first AI paper they have received that asked for a decision rather than reassurance. It is the AI value creation kit for schools.

In brief

The board's eight questions

These are the questions directors ask the executive, each with the evidence that answers it. 1. Who approves an AI tool, and on what basis? The decision-rights matrix and the tool register. 2.

Take the AI maturity assessment

How EthosOne's own AI is governed

A school should be able to see, in its own platform, what governed AI looks like. EthosOne's embedded helper drafts risk, control and treatment wording, policy amendments, resolution text and incident summaries from your context; a human owns every decision, every action is logged and explainable, and the helper never acts alone. Frontier AI, hosted via Amazon Bedrock in AWS Sydney. Retrieval stays in EthosOne's Australian environment, the model is stateless and sees only scoped, school-specific context, it holds no credentials, and no school data trains any model. We apply the five OECD AI Principles (2019, updated 2024). The AI surface is the fifth of five independent rings, after identity proven at login, one locked path for every read and write, database guardrails that reject ownerless records, and private file storage with ownership checked before every download; cross-tenant isolation is tested with synthetic attacker schools before every release. The full model is on Five rings of defence.

A school technology leader stands in sharp focus at the threshold of a controlled communications room while layered secure doors and a busy school corridor create physical depth.
Everything you asked us, answered

The seven we are asked every time.

Still weighing something up? Thirty minutes with us, on your own registers, answers the rest.

Take the AI maturity assessment
  1. 01Does our school need an AI policy?

    A school needs to govern AI, and most will express part of that in policy. The useful version is a short governing statement plus amendments to the child safety, privacy, records, WHS and staff conduct policies AI now touches, with a clear rule on who approves tools and what is logged.

  2. 02Is AI governance a board matter or an IT matter?

    Both, and the accountability sits with the board. The board does not run the controls, but it must be able to see that they exist and are owned, which is why the framework gives it a standing item and a quarterly one-page report.

  3. 03How do we answer a parent who asks where the student data goes?

    With a data class on every approved tool and a vendor assessment behind it. A vendor who cannot say where personal information is stored and processed has failed a gate.

  4. 04What should we do in the first day of an AI incident?

    Recognise and report by phone, make safe, preserve the evidence before anything is deleted or reset, assess what data and whose, set severity, decide notifications, contain and communicate. The Chair hears of a serious incident within 24 hours.

  5. 05Where does EthosOne's AI run, and does it train on our data?

    Frontier AI, hosted via Amazon Bedrock in AWS Sydney. Retrieval stays in EthosOne's Australian environment, the model is stateless and sees only scoped context, and no school data trains any model.

  6. 06Do we have to buy anything to run the AI governance day?

    No. The day requires no licence and carries no obligation. Schools that go no further keep the register, the notes and the written read.

  7. 07AI Governance in Schools: The Complete Guide, in full: what does it cover?

    A school does not need a new body of law to govern AI; it needs to know where AI touches duties it already carries. PolicyAI, EthosOne's policy intelligence in beta, has tagged more than 200 such obligations across 25 policy domains using AccuFind legislative intelligence. EthosOne's own AI is frontier AI, hosted via Amazon Bedrock in AWS Sydney.

We would like to help you answerthe question with your leadership team.

The complete guide to AI governance in schools: who decides, what is logged, and which duties AI touches.