Districts do not need more AI enthusiasm. They need a way to decide which tools are worth using, which workflows are too sensitive to automate, and when a pilot should stop. The hardest part is not finding a vendor demo. It is creating a process that protects students, supports staff, and produces evidence a board can trust.
The latest federal and research guidance points in the same direction: AI in schools should be evaluated by purpose, evidence, and oversight, not by novelty. The U.S. Department of Education’s recent message is clear that ed tech should be judged by whether it advances specific educational goals, with evidence of efficacy, accessibility, interoperability, cost, and implementation fit all part of the decision. It also asks product questions districts should be able to answer before adoption: what problem the tool solves, when it should be used, for whom, for how long, and what evidence shows it improves learning govtech.com.
Start with the district decision, not the vendor demo A durable AI policy begins with one basic question: what district problem are we trying to solve? If the answer is vague, the rollout will be vague too. A district that wants to reduce repetitive parent questions, speed up first-draft communications, or help staff summarize routine documents is making a very different choice than one that wants to support grading, discipline, or student risk screening.
That distinction matters because the governance burden rises quickly when AI is connected to students, records, or decisions that affect rights and services. USC’s Urban AI Unlocked work recommends concentrating on a small number of high-stakes tools and using familiar district processes—needs assessments, board review, privacy clauses, pilots, annual reporting, and cross-functional coordination—rather than building a separate compliance machine for every product rossier.usc.edu.
For district leaders, the practical move is simple:
- Name the use case in plain language.
- Assign a business owner and an operational owner.
- Define the outcome the district wants.
- Decide whether the use case touches student data, employee data, or public information.
- Route anything rights-sensitive into a higher review path.
This is also where internal alignment matters. If principals, communications staff, IT, curriculum, and legal are each answering the same AI question differently, the district will look inconsistent and uncertain. A shared process creates a shared answer.
Build a review path for risk, not a blanket yes or no A useful district AI framework does not say “approve everything” or “ban everything.” It sorts tools by risk and then applies the right level of review. Low-risk uses, such as drafting internal communications with no student data, can move through a lighter workflow. Higher-risk uses, such as anything that touches records, eligibility, discipline, special education, or surveillance, should require deeper review and explicit human oversight.
That approach is consistent with recent K-12 guidance from legal and research sources. Shipman & Goodwin advises districts to clarify what AI tools are permitted, whether staff may upload personally identifiable student information, what vendor agreements are already in place, and whether staff are logged into approved school accounts when using browser-based tools shipmangoodwin.com. Tenet’s FERPA and AI guide similarly recommends defining the purpose, tracing data flow, confirming the applicable FERPA exception, reviewing product terms and subprocessors, and recording an owner, approval status, and material-change triggers truemadeai.com.
A district review path should ask:
1. Does this tool use student or staff data?
2. Does it make or influence a decision?
3. Does it create, store, or transmit records?
4. Does it involve a third party, connector, or model subprocessors?
5. Can the district disable risky features by default?
6. Who can approve, monitor, and shut it down?
If the district cannot answer those questions clearly, the tool is not ready.
Put privacy and accessibility checks in the same lane Privacy and accessibility should not be separate afterthoughts. They should sit in the same review packet. A tool that is privacy-friendly but inaccessible still fails students. A tool that is accessible but over-collects data still creates risk.
Start with data minimization. Districts should limit access by role and purpose, disable unapproved features, and test text, files, images, voice, saved history, exports, deletion, and connectors separately. Tenet’s checklist specifically calls for role-based access, direct control over retention and deletion, security and incident terms, and exit planning truemadeai.com.
