This article is a draft and is not linked from the public index.

AI for Organizations

Your district has an AI policy. Here is how to find out whether it works.

Banner showing an app permission consent screen whose list of granted permissions runs off the bottom edge, with one permission row highlighted in orange, under the headline Your district has an AI policy. Here is how to find out whether it works.

By Justice Jones Instructional designer and AI strategist. Former K-12 principal. Co-founder and CSO, 24/7 Teach. Published August 24, 2026. Reading time: 11 minutes.

Here is a test for any district AI policy.

Hand it to a teacher who just found a tool that would save them four hours a week. Ask them what they are supposed to do on Tuesday morning. If the honest answer is "escalate to the technology office and wait," you have an adopted document. You do not yet have governance.

Two years ago the useful question was whether your district had an AI policy at all. That question is close to settled. The Consortium for School Networking's U.S. State of EdTech 2026 report, which surveyed more than 600 K-12 technology leaders across 44 states, found that nearly 80 percent of districts now report having established AI guidelines. The share without them fell from 43 percent in 2025 to 21 percent in 2026.

So the interesting question changed. Most districts wrote their policy in a compliance sprint, against a state deadline or a board agenda, using four or five peer policies as the model. That process produces a document. It does not reliably produce a system that answers the Tuesday morning question.

This is an audit, not a drafting guide. Seven checks, in the order I would run them. Full disclosure before you read further: I lead AI strategy at Naomi-AI, a K-8 classroom platform built by our sister company 24/7 AI, which means my own product asks districts for exactly the kind of access I am about to tell you to interrogate. I would rather you interrogate it.

1. Start with the law, not with peer policies

Most district policies were built by reading what neighboring districts published. That tells you what other systems were willing to say in public. It tells you nothing about what already obligates you.

Three layers, in order of how universally they apply.

FERPA applies to you no matter what state you are in, and it is the layer most AI policies handle in a single sentence. When any tool accesses, processes, stores, or generates content based on student education records, FERPA is engaged. There is no AI exception. Nearly every district running an AI tool that touches student data is relying, whether anyone said so out loud or not, on the school official exception at 34 CFR 99.31(a)(1). That exception holds only when a set of conditions is met: the vendor performs a service the district would otherwise use employees for, the vendor is under the district's direct control with respect to the use and maintenance of education records, the records are used only for the purpose of the disclosure, and the re-disclosure restrictions at 34 CFR 99.33 apply.

Direct control is where generative AI creates a problem the regulation was not written for. Direct control means the district dictates how records are used, retained, and disposed of. When your vendor routes student work to a model provider, those terms are set by the provider's contract, not by yours. If the terms reserve any right to use inputs for model improvement, the purpose limitation has already failed. And if a model was trained on records you shared, ending the contract does not obviously undo that.

Here is the part that connects to step two. A click-through agreement is poor evidence of direct control. Written terms are how districts actually establish and enforce it. Every tool that arrived through a consent screen rather than through procurement arrived without that evidence.

COPPA sits on top for students under 13, and its deadline has already passed. The FTC's amended Rule took effect June 23, 2025, with a compliance date of April 22, 2026. The amendments add biometric identifiers to the definition of personal information, require separate verifiable parental consent before disclosing children's personal information to third parties for purposes that are not integral to the service, and require operators to maintain a written information security program and a written data retention policy. Those obligations sit on operators, which in practice means on the vendors your policy approves. If your approval process does not ask a vendor to demonstrate them, your process is behind the federal floor as of four months ago.

State law is the third layer and varies sharply. Illinois shows how much can already be decided for you. Under the Student Online Personal Protection Act, effective July 1, 2021, districts must enter into written agreements with operators before covered student information is shared, designate a privacy officer, notify parents of a breach within a defined window, and publicly post on the district website the list of operators, the data elements collected, copies of the agreements, and how parents exercise their rights.

Read that last requirement as an audit question rather than a compliance obligation. It is essentially a public inventory of every tool touching student data, with a named owner attached. Illinois already told its districts what the governance artifact has to contain. More states are moving: ExcelinEd reported that the PIE Network tracked nearly 100 state bills in 2026 affecting students' AI use in K-12, and MultiState notes that states including Ohio and Tennessee require districts to adopt their own AI policies rather than issuing a single statewide mandate.

Audit check: For your three most-used AI tools, can anyone in your district demonstrate that the school official exception actually holds under the configuration you deployed, including the model provider behind the vendor? That is the question, and "the vendor says they are FERPA compliant" is not the answer to it.

A note on how to use this section. Student privacy and state AI law are both moving monthly. Treat everything above as a pointer to the right door, not as a compliance opinion, and verify the current text before you rely on it. I am not your counsel, and the analysis that matters is the one your counsel runs against the vendor's actual data terms rather than its compliance page.

2. Pull the export before you audit anything else

Ask whoever runs your identity systems for the list of third-party applications with access to your environment.

In most districts that means Google Workspace for Education, often with Clever or ClassLink sitting in the middle. Ask for the OAuth grant report, not the list of purchased licenses. Those are different documents, and the gap between them is the audit.

Districts are rarely surprised by one or two entries. They are surprised by the shape of the list. Meeting recorders, mail assistants, document add-ins, classroom tools, grading helpers, all granted through a setup screen by staff who were doing their jobs and had no reason to think a consent click was a procurement decision.

While you are in there, learn the distinction most policies miss. Approving a tool is not the same as approving what that tool can reach. A delegated access grant persists after the session ends. It runs under the user's own credentials. It looks like legitimate activity to every control built to catch an intrusion, because technically it is legitimate activity.

Granting an AI assistant access to a staff mailbox does not feel like a decision. It feels like clicking through a setup screen. Very few people picture what an assistant can then read, including attachments in messages they never sent, which in a school inbox routinely means IEP documents, disciplinary records, and communication with families.

So govern the grant separately from the tool, with a named owner, a defined scope, and an expiration date. And find out whether grants at your district survive account deactivation, because in many environments they do. A teacher who left in June may still have a live pipeline into district data in October.

Now put the export next to section one. Every entry on that list that arrived through a consent screen rather than through procurement is a tool with no written agreement behind it, which means no evidence of direct control, which means the school official exception was never established for it. The export is not only an inventory. It is a list of your open legal-basis questions, ranked by how much each tool can see.

Audit check: Does your policy govern grants, or only tools? Most govern only tools.

3. Find the gate that already exists, then ask what it was built for

You almost certainly already have a control here. A technology office review of third-party requests. An edtech approval process run out of curriculum. An acceptable use policy. Academic integrity language that probably already covers undisclosed AI use without ever naming AI.

Do not build a parallel structure next to those. Find them, name them, and add what they were missing.

Then do the part almost everyone skips. Ask what threat model that gate was designed for.

A common criterion is that read-only access gets approved and write access gets denied. That is a sound rule for a permissions problem. It does very little about an AI tool that reads everything it can see and sends it somewhere else. The gate is working correctly and is calibrated for a different era. Finding the existing control is half the job. Recalibrating it is the other half.

Audit check: Pull the last ten approvals your existing gate processed. How many would have been decided differently under the AI policy you adopted? If the answer is zero, either your gate was already excellent or your policy is not actually connected to it.

4. Put names in the ownership map, then check whether those people can review

Not the risk taxonomy. The names.

Who approves a moderate-risk use this week, before any committee is seated? Who maintains the approved tools list? Who revokes an access grant when a staff member leaves? Who can shut a system off on a Friday afternoon? What happens when the person who owns a tool changes buildings?

Every district has to answer these and most have not written them down. If your framework feels stuck, it is usually because you are describing a process that has no owner yet.

Then comes the step that decides whether any of the rest works. Governance writing assumes a competent reviewer is waiting at the end of every escalation path. In most districts that person does not exist yet. Your assistant superintendent may have deep authority over academic standing and no experience with AI systems. There may be no dedicated counsel and no information security function at all. That is normal for a district of 3,000 students. Design for it rather than pretending otherwise.

What goes wrong without it. An inexperienced reviewer defaults to one of two settings and holds it. They approve everything, because it all sounds like software. Or they deny everything, because it all sounds like risk. Both produce a clean approval record. Neither is governance, and the rubber stamp is the more dangerous one because it looks like the process working.

The deny-everything setting is visible in the data. Writing in EdSurge in July 2026, Jody Britten reported that nearly 30 percent of districts are actively restricting or prohibiting AI use, an approach she argues is increasingly difficult to sustain because student access to these tools extends far beyond the school network.

Legal review has its own version. A lawyer without AI-specific background will review the vendor contract well, because that is a thing lawyers do well. What goes unreviewed is everything outside the contract: whether the tool works with assistive technology, whether families received notice before a feature was switched on, whether the privacy analysis holds for how you configured the tool rather than how the vendor describes it. A vendor's statement of compliance does not establish yours.

Build for it this way.

Escalate the decision, not the technology. Your assistant superintendent does not need to understand how a model works to decide whether an automated system may influence a student's placement or discipline. That is a decision they have made many times in other forms. Strip the technology out of the question and hand them the version they already know how to answer. That is what a risk tier model is actually for. It is not a taxonomy. It is a translation layer.

Use structured intake instead of open-ended review. A template that asks specific questions does the technical reasoning up front. The reviewer supplies judgment about the answers, which is what you wanted from them anyway. Handing an uncertain reviewer a blank "please review" is how you get one of the two default settings.

Seat functions, not expertise. Academic leadership holds the seat for academic integrity, not for AI. Counsel holds it for privacy and contracts. Nobody should be asked to be the AI person.

Put technical depth in a working group beneath the decision body rather than inside it. The working group assesses, the decision body decides. That gets you expertise without waiting to hire it. This is the structure we walk districts through in our AI governance work.

Treat "I do not know" differently from "no." An uncertain reviewer defaults to denial, and denial with no alternative pushes the work into unapproved tools.

Audit check: Name the last three decisions your governance body made. If you cannot, the body is not operating, whatever the policy says.

5. Solve supply before you enforce

Teachers do not route work around approved systems because they are careless. They do it because no approved tool does the job and the work is still due.

If your policy tells staff to move work into approved tools, that instruction only functions where a capable approved tool exists. Where it does not, you have written a rule people cannot follow, and they will follow the deadline instead. This is the oldest dynamic in school leadership wearing new clothes. Any principal who has ever mandated a documentation process without providing the time to complete it has run this experiment already.

Treat that gap as a finding you owe an answer to, not a violation to enforce.

Audit check: List the top five things staff use unapproved AI tools for. If your technology office cannot produce that list, you are enforcing against a problem you have not measured.

6. The honest objection, and the bigger question underneath it

The reasonable pushback to everything above is capacity. A district technology director running a one-person department, already handling devices, network, testing, and student information systems, does not have a spare quarter to run a seven-part audit. That objection is correct, and the CoSN survey supports it: budget constraints and lack of resources ranked as districts' top challenges to implementing technology-enabled learning environments, followed by organizational silos and lack of relevant professional development.

Two honest responses. First, steps one and two are not a quarter of work. Pulling a consent report and identifying your governing statute are a week, and they are the two that most change what you do next. Second, if the capacity genuinely is not there, name that as a finding in front of your board rather than absorbing it silently. "We adopted a policy we do not have the staffing to operate" is a fundable statement. A quietly non-operating policy is not.

There is a larger question underneath all of this, and it is the one teachers are actually asking.

Nearly every AI governance conversation in K-12 is about student records, privacy law, and academic integrity. All of that belongs in the policy. But if you teach children, the question underneath is what reading, writing, and assessment mean now, and what happens to a student who has their thinking done for them at the age they are supposed to be building it.

A policy that carefully governs whether a tool can touch a transcript, while saying nothing about what AI is doing to the purpose of the school, reads to teachers as an organization managing its liability rather than its mission. You lose their trust in the first paragraph and you do not get it back in an appendix. That is not a compliance problem. It is the reason your policy is sitting unread in a shared drive. If that is the conversation your staff are actually having, it belongs in professional learning rather than in policy language, which is what our AI Fluency for Educators bootcamp is built to carry.

7. What to do this week

Not a quarter. This week.

  1. Request the OAuth grant report from whoever administers your Google Workspace or Microsoft tenant. Ask for grants, not licenses.
  2. Ask counsel one question: for our three most-used AI tools, does the FERPA school official exception actually hold under the configuration we deployed, including the model provider behind the vendor?
  3. Identify the state statute that governs your vendor agreements. If you are in Illinois, New York, or California, you already have a specific answer. If not, that is question two for counsel or your state association.
  4. Write five names next to five decisions: approver, list owner, revoker, kill switch, escalation. Names, not titles.
  5. Pull your last ten technology approvals and ask how many your AI policy would have changed.
  6. Ask three teachers what they use that is not on the approved list, and treat the answer as a supply finding.

Whatever you write succeeds or fails on whether your district can answer three things on any given day.

What AI is running here. Who owns it. What is it allowed to touch.

Everything else is documentation.

Where 24/7 Teach fits

We have supported more than 50 organizations with training and AI tools, and the pattern above is drawn from that work. Where districts get stuck is almost never the policy language. It is step four: the reviewers exist on the org chart but have never been equipped to evaluate an AI system, so the escalation path terminates in a rubber stamp or a reflexive no. Our AI governance and adoption training is built for that specific gap, and it is designed around the decision-translation approach in section four rather than around teaching administrators how models work. If you want to see where your district sits before you commit to anything, start with our school AI readiness check.

If you want to talk through where your district actually sits, scope a partnership.

About the author

Justice Jones is an instructional designer, AI strategist, and former K-12 principal, and the co-founder and CSO of 24/7 Teach. He built the company to close the gap between what schools teach and what teens and professionals need to succeed, and he leads AI strategy at its sister company, Naomi-AI, a K-8 classroom platform. Through 24/7 Teach, he and his team have supported more than 50 organizations and placed more than 600 adults in new careers. Full bio

This article was researched and written by Justice Jones with AI assistance, then reviewed and edited by our team. External studies and sources are credited to their original authors. Examples from our own work reflect our organizational practice.