District AI Policy: How to Write One (2026 Guide)

Telo AI helps school districts improve speaking outcomes for English Learners and support bilingual education programs through conversational AI and practical tools for educators.

District AI policy for schools

Estimated reading time: 9 minutes

A clear AI policy for schools has moved from optional to essential: as of 2026, roughly 33 to 35 states plus Puerto Rico have issued official K-12 AI guidance, and some states now legally require districts to adopt their own AI policies. Ohio, for example, required every public district to adopt a formal AI policy by July 1, 2026. For district leaders, the question is no longer whether to have a policy but how to write one that is sound, compliant, and actually usable. This guide covers what a district AI policy must include and how to adopt one.

Table of contents

Executive Summary

A district AI policy governs how students, teachers, and staff may use artificial intelligence tools. A sound policy covers permitted and prohibited uses, data privacy under FERPA and COPPA, academic integrity, transparency to families, and a regular review cadence. The regulatory backdrop is moving quickly: most states have issued guidance, a growing number are legislating, and at least two (Ohio and Tennessee) require districts to adopt policies. Districts that treat this as a genuine governance task, rather than a box to check, protect students and reduce risk while enabling responsible use.

Key Takeaways

  • As of 2026, roughly 33-35 states plus Puerto Rico have official K-12 AI guidance.
  • Ohio required districts to adopt an AI policy by July 1, 2026; Tennessee also requires district AI policies.
  • A sound policy covers permitted uses, data privacy, academic integrity, transparency, and review cadence.
  • Data privacy (FERPA and COPPA) is the highest-risk area and the most common gap.
  • Model policies exist (state model policies, TSBA, NEA) that districts can adopt or adapt.

What Is a District AI Policy?

Quick answer: a district AI policy is a board-adopted document that defines how AI tools may be used across the district, by students and staff, and sets rules for privacy, integrity, and transparency. It functions like an acceptable-use policy specifically for artificial intelligence, and increasingly it is required by state law rather than merely recommended.

What a Sound AI Policy Covers

AreaWhat the policy should address
Permitted and prohibited usesWhat students and staff may and may not do with AI
Data privacyFERPA and COPPA compliance; what data may be entered into AI tools
Academic integrityWhen AI use is and is not appropriate on student work
TransparencyDisclosure to families and students about AI use
Vetting and approvalHow tools are reviewed before adoption
Review cadenceHow often the policy is revisited as the technology changes

The Data Privacy Core: FERPA and COPPA

The highest-risk area is data privacy. Under FERPA, student education records are protected, and entering personally identifiable information into a consumer AI tool can constitute an unauthorized disclosure. COPPA adds protections for children under 13. A district AI policy must specify what data may never be entered into AI tools and require that any approved tool meet existing privacy and security standards. This is where most policy gaps and most real risk sit. Tools built specifically for K-12, with privacy designed in, make compliance the default rather than a constant retrofit.

The 2026 Regulatory Landscape

State activity is accelerating. Most states have issued AI guidance, dozens of AI-in-education bills are moving through legislatures in the 2026 session, and a small but growing set of states mandate district policies. Ohio’s Department of Education and Workforce released a model policy and set a July 1, 2026 adoption deadline for districts. Tennessee likewise requires districts to adopt AI policies, and the Tennessee School Boards Association publishes a model (Policy 4.214). The National Education Association offers a sample board policy as well. The direction is clear: policy is becoming mandatory, and districts without one are increasingly out of step with both law and expectation. See the state AI guidance overview for details.

How to Adopt a District AI Policy

  1. Start from a model. Use your state’s model policy where one exists, or TSBA/NEA samples, rather than from scratch.
  2. Convene stakeholders. Include curriculum, technology, legal, teachers, and families.
  3. Anchor on data privacy. Make FERPA and COPPA compliance the non-negotiable core.
  4. Define uses clearly. Specify permitted, prohibited, and disclosure requirements in plain language.
  5. Build a vetting process for approving AI tools before classroom use.
  6. Set a review cadence, at least annually, because the technology changes fast.
  7. Adopt at the board level and communicate to families.

District Benchmark

A mid-sized district in a state with a mandate faces a hard deadline and real liability if it enters student data into non-compliant tools. The practical path is to adopt a model policy, stand up a tool-vetting process, and inventory which AI tools are already in use, often more than leaders realize. The policy is the easy part; enforcing the data-privacy provisions against the tools already in classrooms is the work.

Common Mistakes

  1. Writing a policy but not vetting the tools already in use.
  2. Treating data privacy as a footnote rather than the core.
  3. Copying a policy without adapting it to state requirements.
  4. Adopting once and never reviewing as the technology evolves.

Questions District Leaders Should Ask

  • Does our state require a district AI policy, and by when?
  • Which AI tools are already being used with student data?
  • Do our approved tools meet FERPA and COPPA?
  • How are we disclosing AI use to families?
  • When will the policy be reviewed?

A Realistic Adoption Timeline

Districts often underestimate how long a sound AI policy takes to adopt well, then rush it when a deadline looms. A realistic timeline runs a few months: two to four weeks to convene stakeholders and select a model policy, a month to adapt it and build a tool-vetting process, a few weeks for legal and board review, and time to communicate the final policy to staff and families before it takes effect. In a mandate state with a fixed deadline, working backward from that date is essential. Districts that start early, before a mandate forces the issue, get a better policy and avoid the compressed, error-prone scramble that comes from treating adoption as a last-minute compliance task. The timeline also should not end at adoption: a review date belongs on the calendar from day one, since the technology and the state landscape both keep moving.

Frequently Asked Questions

What is a district AI policy?

A board-adopted document defining how AI tools may be used across a district, covering permitted uses, data privacy, academic integrity, transparency, and review.

Are schools required to have an AI policy?

It varies by state. Most states have issued guidance, and some, including Ohio and Tennessee, legally require districts to adopt AI policies. Ohio set a July 1, 2026 deadline.

What should a school AI policy include?

Permitted and prohibited uses, FERPA and COPPA data-privacy rules, academic integrity guidance, transparency to families, a tool-vetting process, and a regular review cadence.

How does FERPA apply to AI in schools?

FERPA protects student education records. Entering personally identifiable student information into an AI tool that is not authorized can constitute an unauthorized disclosure, so policies must restrict what data may be used.

Conclusion

A district AI policy is now a governance requirement, not an option, and its center of gravity is data privacy. The districts that handle this well adopt a strong model policy, vet the tools already in their classrooms, and choose K-12-native tools that make compliance the default. Policy sets the rules; tool choice determines how hard those rules are to keep.

Sources: Ohio Department of Education and Workforce, Model AI Policy; AI for Education state guidance tracker; Ballotpedia; FutureEd legislative tracker.

The Policy Is Only as Safe as the Tools

Every district that writes a strong AI policy eventually faces the same discovery: tools are already in classrooms that the policy would never have approved. A staff survey turns up a dozen apps handling student data, none of them formally vetted.

The hard part is not drafting the rules. It is that consumer tools were never built for FERPA or COPPA, so the policy has to compensate for products that leak risk by default. The burden is structural, not a failure of diligence.

Districts that manage this well stand up a real vetting process and steer classrooms toward tools where compliance is built in. Telo AI is one example, designed for K-12 with data protection and educational purpose as part of the product rather than a later patch.

See how a K-12-native tool meets district privacy requirements: https://mytelo.ai/how-telo-works/

A policy on paper is the beginning, not the finish. The districts that stay compliant are the ones that shrink the risk their policy has to cover, by choosing tools that were safe to begin with.

See how Telo works in the classroom

Learn how Telo helps English Learners practice speaking at their own level while giving teachers real-time insights.