Skip to content

School cyber security and AI policy template

Cyber and AI, in one position the board can endorse

Cyber Security and AI Policy for Schools, free for independent schools.

Take the AI maturity assessmentThirty minutes, your data, no slides.
The Staff Conduct domain at grade A+ with 100 per cent of obligations met: the four Equal Opportunity Act 2010 (Vic) duties on sexual harassment, each Met and linked to the Staff Code of Conduct and Professional Boundaries Policy, with named accountability beneath.
Real captures · the same work running live in EthosOne · demo tenant.

A school cyber and AI policy template should do two jobs: show the board the controls are in place, and give staff a clear line on how AI and data may be used.

A cyber and AI position covers both. It pairs a practical cyber control checklist with a set of AI principles and a self-check, and data management principles, so a school can demonstrate posture to its board without buying a whole security platform first.

What goes in a school cyber and AI policy?

At minimum, three things: the controls you rely on and who owns them, the principles that govern how staff and students may use AI, and how personal and sensitive data is handled and retained. The pack gives you a starting position for each, written for a school rather than a corporate IT department. The point is not a long document nobody reads. It is a short, owned set of commitments the board can see, the staff can follow, and you can evidence when a parent, an auditor or an insurer asks.

  1. Cyber control checklist

    The controls a school is expected to hold, each with an owner and a review point.

  2. AI principles and self-check

    A clear line on acceptable AI use, with a self-check to find where you stand.

  3. Data management principles

    How personal and sensitive data is handled, shared and retained.

Is cyber and AI a board issue or an IT issue?

Both, but the accountability sits with the board. Cyber and AI risk is now a standing part of a school's risk position: a breach or a misuse of AI is a governance and reputational event, not just a technical one. The board does not run the controls, but it must be able to see that they exist and are owned.

That is why the position is written to be board-legible. It turns a technical subject into a short assurance picture a director can read, while still giving the people who run the controls something concrete to work from.

The Child Safety and Protection domain detail: eighteen obligations grouped by Act, four of the Child Wellbeing and Safety Act 2005 (Vic) reportable-conduct duties Met with the policy that answers each in the Linked column, the rest still gaps with their penalty.

PolicyAI answering the prompt “Draft me an AI Acceptable Use Policy.”, then working through: Reading the AI-engaged obligations; Matching privacy, records, child safety; Drafting against your existing library.

AI governance

Solutions for every school’s AI challenge.

There is no AI-specific legislation in force in Australia or New Zealand. The duties your school already carries are the ones AI engages.

Take the AI maturity assessment

Governing AI, before your board asks again.

“The board asked what our position on AI is, and we did not have one.”

Data privacyAlgorithmic biasSynthetic mediaAutomated decisionsRecords governanceSurveillance

An AI policy is not a new rulebook, it is a lens over duties your school already carries: privacy, records, discrimination and child safety, engaged by an AI-shaped set of facts. Which is why a downloaded template does not survive contact with a regulator.

We have tagged the duties AI activity in a school engages, so the conversation starts from the obligations you already hold rather than from a blank page. Almost none of them say “AI”.

Try Draft with AI.Five paragraphs against the obligations of your State, with the provision beside each. Free, no login.

Frequently asked questions

The two we are asked every time.

Still weighing something up? Thirty minutes with us, on your own registers, answers the rest.

Take the AI maturity assessment
  1. 01Do we need an IT team to use it?

    No. It is written for a school, not a corporate security function. The checklist and principles are practical enough for a business manager or principal to work through and assign owners.

  2. 02How does this connect to the rest of our governance?

    Cyber and AI is one category in your overall risk position. In EthosOne the controls, owners and reviews run live and roll up into the same board reporting as the rest of your risk and compliance picture.

    Preview of the EthosOne cyber and AI position

    Where to start

Where to from here

The cyber and AI governance position your school can adopt this term

The cyber and AI position starts with a read on where your school's AI governance sits today. The AI Maturity Assessment takes under ten minutes and gives you a position the board can read; the AI Risk Register is the free download beside it.

Take the AI maturity assessmentDownload the AI Risk Register →Take the AI maturity assessment · Download the AI Risk Register
“It meets all of the real frustrations of business directors in one place.”
Nick Miller
Nick MillerDirector of Business, Blackfriars Priory School
“School governance and risk is a complex area without a clear solution.”
David Ruggiero
David RuggieroPrincipal, Blackfriars Priory School

Cyber and AI, in oneposition the board can endorse