
An AI Policy, or AI in the Policies You Already Have
By Ryan Speak, Co-founder and CTPO, Arvoe. 14 August 2026. Regulatory position current as at publication.
One question we often get asked when talking about AI governance with schools is whether they should have an AI policy.
The short answer is that every school needs a formal position on AI. Staff and students are using it now, and where a school has not said what it expects, people are making their own calls in good faith and without guidance.
What is genuinely open is where that position lives. It can sit in a single AI policy. It can sit inside the policies a school already has. Either can work, and in practice the strongest arrangement uses both deliberately. What causes trouble is arriving at a position without choosing one: rules in different documents that say different things, no one clearly responsible, and staff who cannot find the answer when they need it.
This piece works through that decision. It draws on the published policy sets of independent schools around Australia, and on the governance work we do alongside schools.
The AI you have chosen, and the AI you have not
AI is arriving in schools from two directions, and only one of them is being watched.
The AI you have chosen arrives through the platforms the school already runs: the learning management system, productivity suites, tools issued by state systems. Vendors are switching features on and releasing new ones at a pace that is difficult to track. Keeping up is demanding, but this remains a school decision. Features can be enabled or not. Tools can be adopted or not. Somewhere there is an administrator with a setting and a business manager who can ask what changed.
The AI you have not chosen is harder. Staff and students are using tools the school has not selected, cannot see and cannot switch off. A student can use anything, on any device, anywhere. A staff member without a stated guardrail is left to their own judgement about what may be entered into a tool, what may be produced with one, and whether AI might reasonably inform a decision about a student or a colleague.
Most are making sensible calls. That is not the issue. The issue is that they are making those calls without knowing the school's position, because in most cases the school has not settled one.
The Learning First study of nearly 3,400 New South Wales teachers and more than 750 school leaders puts a number on the gap. About half of secondary teachers report that students use AI for schoolwork. Of those teachers, around three quarters say students use it to complete assessments, even though more than 80 per cent say students face restrictions on using AI for exactly that purpose. Restrictions exist in most schools. A settled position is a different thing, and the gap between the two is where the behaviour is sitting.
A stated position is the only thing that reaches the second group.
The obligations today, and where they are heading
The regulatory picture is often described with more urgency than it warrants, so it is worth setting out what actually binds a school and what does not.
No Australian law requires a school to hold an AI policy. The Australian Framework for Generative AI in Schools, endorsed by education ministers, was designed to be aspirational rather than a step-by-step operating manual. It leaves the shape of implementation to schools and systems, and expresses no preference between writing new policy and amending what already exists. That silence is the whole subject of this piece, and it is the framework gap in its most practical form.
What is moving fastest is assessment. In August 2026 the New South Wales Deputy Premier and Minister for Education asked the NSW Education Standards Authority to consider a moratorium on unsupervised take-home assessment tasks, while a broader review is undertaken into the effect of AI on student learning and assessment. NESA has also been asked to develop a common approach to help schools identify inappropriate AI use. Subject to NESA's advice, any interim changes would apply from the start of Term 4 this year. This is a request to consider rather than a decision, and it applies in one state. It is still the clearest sign yet that the ground is moving, and it lands on the assessment policy rather than on anything AI-titled.
The clearest existing obligation is in privacy law. From 10 December 2026, entities covered by the Privacy Act must disclose in their privacy policies the kinds of personal information used in automated decisions, and the kinds of decisions made that way. The obligation is directed at automated decisions with the potential to significantly affect a person's rights or interests, rather than at every automated process. Nearly all independent schools are covered entities. It is worth noticing where the requirement sits: not in an AI statute, but in the privacy policy the school already has. Regulator guidance is expected before commencement, and we have written separately on what December actually asks of schools.
Beyond that, the direction is set but nothing yet binds. South Australia has announced a Royal Commission into AI, expected to begin on 1 October and to report by 1 July 2027, with terms of reference still to be confirmed. Federally, an Office of AI has been established within the Department of the Prime Minister and Cabinet, and a set of policy workstreams is underway covering a digital duty of care, further privacy reform, workplace AI safety and automated decision-making in government. These are announced programs of work, not duties on schools.
None of that changes what a school must do this term. What it does mean is that a school which has settled its position will be answering questions rather than starting from a blank page.
Policy, and the instruments that sit around it
A policy sets out the school's formal expectations and standards, authorised by leadership. It balances two priorities: guidance, meaning clear expectations, the values behind them and what standard practice looks like here; and accountability, meaning consistency across a large staff and a documented record of the school's commitments. Strong policy exists to build culture, not simply to manage compliance.
Several related instruments sit alongside policy and behave differently.
| Instrument | What it does | In an AI context |
|---|---|---|
| Policy | Sets expectations and assigns accountability | The school's position on AI use, and who owns it |
| Procedure | Defines a sequence of steps | How a new tool is assessed and approved |
| Guideline | Advises without binding | Practical advice on using AI in lesson preparation |
| Framework | Connects principles to practice | How AI principles apply across teaching and operations |
| Register | Records facts and authorised assets | The current list of approved tools |
| Capability | Staff capacity to act | Professional learning in AI literacy |
The distinction matters more for AI than for most subjects, because AI changes faster than a policy review cycle. A policy is written to hold for one to three years. The tools change every few months. Naming five approved tools in a policy means the policy is out of date the first time one of them is replaced. Naming who maintains the approved list, and where it lives, does not go out of date. The same logic applies to training: a policy clause requiring AI training states an intention, but a professional learning program with a budget and a calendar behind it is what makes it happen.
Which AI risks are actually new
Sorting risks accurately is what tells a school where each one belongs, and it stops a school building new controls for problems it already manages well.
Risks AI does not change
A good deal of what gets discussed as AI risk is an existing risk with a new tool attached. Sharing information with a third party, access and credential control, copyright, and the fact that anything produced with AI is still a school record are all longstanding concerns, and every one of them is already handled through procurement, due diligence, information security and recordkeeping. AI is one more entry in those conversations. It does not need new ones.
Risks AI amplifies
The category is familiar. The scale, speed or ease has changed. These belong in their existing policy, updated to name AI.
- Image-based abuse. AI-generated intimate or humiliating images of a student or staff member are bullying and a child protection matter. What has changed is that it now takes minutes, needs no skill, and produces something plausible enough to cause real harm. It belongs where the reporting duty and response pathway already sit, and which of those pathways applies turns on the nature of the image rather than on the fact that AI produced it. That is a distinction the existing policies can make and an AI policy cannot.
- Academic misconduct. Every school has an academic integrity process, and the principle behind it has not changed. Prevalence and detectability have. It is worth being honest that this is the one place where a policy is the smaller half of the answer. If unsupervised take-home tasks are restricted, the real work is assessment redesign across every faculty, which is a curriculum and workload question rather than a governance one. The policy sets the rule. The redesign is what makes the rule hold.
- Impersonation and fraud. Cloned voices and convincing written impersonation raise the risk of a fraudulent payment instruction, a fake message from a school leader, or falsified enrolment documents. This sits with finance controls, verification steps and cyber awareness.
- Inaccurate or fabricated content. AI produces fluent output that can be wrong. Where that reaches a report comment, a wellbeing note or a parent communication, the school owns the error. A supervision question, not a new risk.
- Equity of access. Where some students hold paid tools and others do not, an existing equity concern takes a new form.
Risks that are genuinely new
AI companions. A young person can form a sustained relationship with a system that responds warmly, remembers them and is always available. The nearest comparison is social media, but it is not the same thing. It is relational rather than social, and it usually happens outside school hours and outside school systems. An AI policy does not reach this. A rule about AI in assessment has nothing to say about a student's relationship with a chatbot late at night at home. What reaches it is wellbeing and pastoral practice, and staff who know what to look for, which is the same capability schools already rely on when harm begins outside the gate.
Decisions made or shaped by a system. Fairness, review and appeal processes assume a decision-maker who can explain their reasoning. Where a system contributes to a decision about a person, whether an enrolment, a placement, a wellbeing flag or a disciplinary outcome, that assumption no longer holds automatically. This is what the December privacy obligation addresses, and it requires the school to know where such systems are in use.
AI that takes action, not just advice. Tools are increasingly able to act: to send, book, update a record, or complete a multi-step task on someone's behalf. A system pursuing an instruction can take steps nobody intended and nobody approved, having followed the request as it understood it. The governance question is not what the tool says, it is what it is permitted to do without a person in the loop, and what it can reach.
What this means for the risk register
There is a question boards ask early and the sorting above answers it. Is AI a risk in its own right, or something that changes risks the school already carries?
Mostly the second. Most of what a school faces is an existing risk with a new driver attached, which means annotating the risks already in the register rather than opening a new one. The exception is the short list of genuinely new risks, which nothing in a typical register currently describes. That is the practical decision: annotate the many, add the few.
What goes into an AI policy, and where else it could sit
Sorting the risks tells you what a school's AI position has to cover. The next question is which document carries each part, and that is where the choice actually gets made.
The AI policies that exist in schools today are consistent in what they contain. For nearly every part, the school already has a policy covering the same ground for every other subject it deals with.
| What an AI policy typically covers | The existing policy covering the same ground |
|---|---|
| Student use in learning and assessment, and attribution | Assessment or academic integrity policy |
| Consequences for misuse | Assessment policy and student code of conduct |
| Acceptable and unacceptable use | ICT acceptable use policy |
| What must not be entered into a tool | Privacy and information security policies |
| Staff use of AI in decisions about people | HR, enrolment and wellbeing procedures, and privacy |
| Deepfakes and image-based abuse | Bullying and child protection policies |
| The list of approved tools | A register, maintained outside the policy set |
| Staff and student training | The professional learning program |
| Blocking unapproved platforms | An ICT procedure |
| Communication with families | The communications plan |
For most of these, either column can hold the provision, and the school can decide which. Two are different.
The December disclosure has to be in the privacy policy. That is where the law points. A school can describe it in an AI policy as well, but the privacy policy is the operative version.
Consequences have to sit with the process that applies them. A statement that misuse will be penalised does very little on its own, because the grounds for a penalty, the process that applies it and the student's right of appeal all live in the assessment policy and the code of conduct. Restating the consequence in an AI policy is fine. It cannot be the only place it appears.
What the table does not contain is the small set of things nothing in a typical policy set carries: what AI means at this school and who the rules apply to, who approves a new tool and who can refuse one, who is accountable for AI across the school, and how AI risk reaches the Board. Each could be placed somewhere sensible, in a role description, the procurement policy or the risk management framework. But nothing picks them up by default, so a school has to decide deliberately where they go. That list is short, and it is the part that matters most.
Two ways to structure it, and what we recommend
A standalone AI policy
It can be found. AI is what staff, families and Boards are asking about. "Where is our position on AI" should have a one-word answer. Provisions spread correctly across six policies do not give anyone that.
It moves faster, for most schools. Amending eight policies means eight approval cycles across different owners and committees, several not due for review for another two years. One document is one cycle, and it can be reviewed annually while the others stay on their own schedules. The exception is a school running a managed policy library, where amendments to eight documents arrive as a single release on a single cycle, already reviewed. For those schools this argument runs the other way, and embedding is the faster path.
Repetition is not the enemy. A student who meets the rule in the assessment policy and again in the AI policy has met it twice. At a moment when practice is running ahead of guidance, saying something on several fronts is the point. What causes trouble is unmanaged repetition, where two versions of the same rule drift apart over successive reviews. The answer is to name which document is the source of truth for each rule, not to avoid saying it twice.
Writing it forces the conversation. The strongest of the four. In our reading, schools with a named person accountable for AI got there by writing a dedicated document. Amendments to existing policies did not produce one. The document is the vehicle for the decision, not just the record of it.
Where it breaks. A standalone policy tends to drift away from the mechanisms that give it effect. It states consequences that live elsewhere, so a teacher applying one has to go looking for the process anyway. It names tools that change, and dates itself the first time one is replaced. It duplicates rules that also sit in the assessment or ICT policy, and over successive reviews the two versions stop agreeing. And once the novelty passes it stops being opened, because nothing in a school's week routinely sends anyone to it.
AI in the policies you already have
Some content cannot move. The December disclosure and the consequences for misuse both have a fixed home, for the reasons above. Writing them into an AI policy as well is fine, but it does not shift where the authority sits, and if the two versions disagree, the original still governs.
Existing policies are refreshed by their own pressures. A clause in the privacy policy is revisited when privacy law changes. One in the assessment policy is revisited when the credential authority moves. A standalone AI policy is revisited only when someone remembers AI.
It reaches people where they already are. A teacher facing suspected AI use in an assignment opens the assessment policy. A staff member handling a fake image opens the child protection procedure. Neither opens the AI policy first.
Detail dates quickly. Policies naming specific products are out of date within a review cycle. Policies naming who decides, and pointing to a register for the current list, are not.
Where it breaks. Provisions added one at a time, by different people, on different review cycles, tend to contradict each other. Among the schools whose full policy sets we read, many did. One document says students may use AI if they acknowledge it, while another says AI may not be used in assessment at all. One sets a general ban with teacher exceptions, while another sets out levels of permitted use for different tasks. The junior school and the senior school say different things, with nothing indicating which applies to whom. In several schools the only working AI rule sits in a document the policy index does not point to, so a teacher looking for it would not find it. None of this was carelessness. It is what happens when a position is assembled piece by piece rather than decided once.
What we recommend
Keep the substance where it already carries weight, and put a short document over the top of it.
The operative rules do not move. Assessment rules and their consequences stay in the assessment policy and the code of conduct. The December disclosure stays in the privacy policy. Deepfakes stay with bullying and child protection. What must not be entered into a tool stays with privacy and information security. Every one of those provisions works because of the process sitting around it, and lifting it out weakens it.
Over the top of that sits a short AI position statement, carrying only what nothing else does. In practice it runs to two or three pages:
- Purpose and scope. What the school means by AI, and who the document applies to: students, staff, contractors, volunteers.
- The school's position. Three or four sentences on why the school uses AI and what it will not use it for. This is the part that shapes culture rather than compliance.
- Accountability. The role or committee responsible for AI across the school, and what they decide.
- Tool approval. How a new AI tool gets approved, who can refuse one, and where the approved list is kept.
- What sits where. A short table pointing to the assessment policy, the privacy policy, the code of conduct and the rest, so a reader knows this document is not the whole picture.
- Reporting and review. How AI risk reaches the Board, how often, and when this document is next reviewed.
That is the whole thing. It is deliberately short, because everything operative lives elsewhere, and short documents get read.
This shape gets you both halves of the argument. Someone asking where the school stands on AI has one document to open. Someone dealing with an actual incident opens the policy that governs it, and finds a rule that still has teeth. The position statement is the front door. It is not the house.
Child safety is the closest parallel most schools will recognise, and it shows the same structure already working. A standalone policy carries the principles and the accountability. The operative obligations sit inside recruitment, the codes of conduct, complaints handling, excursions and curriculum, where the work actually happens. A named person holds it. There is a register, and it reports to the Board. Schools built that structure because the child safe standards required it. Nothing requires it for AI yet, which means the school has to decide the shape rather than being handed one.
Five questions worth asking
- Is anyone accountable for AI at your school today? Not a group that discusses it, but a role or committee that decides. If the answer is nobody, that is the first thing the position statement has to fix, and everything else waits on it.
- What do your existing policies already say, and do they agree with each other? Read the assessment policy, the ICT policy, the privacy policy and the code of conduct together before writing anything new. Contradictions between them are more urgent than a missing document.
- How exposed is your assessment program? With unsupervised take-home tasks under review in at least one state, this is the part of the operative rule set most likely to need work this year, and it sits in the assessment policy rather than in anything AI-titled.
- Can a staff member find the rule they need in the moment they need it? If the policy index is thin, or documents sit behind a portal, a correct rule in the right document is still effectively hidden.
- Would you know if any of it were working? Not whether the document exists, but whether what it says is holding up in practice.
What makes it real
Reading a good number of AI policies, the pattern is that they carry rules but not governance. They tell students what is permitted and say nothing about who decides, who approved it, or what happens when it needs to change. Approval by the governing body is uncommon. Some name no approver at all. One assigns accountability for AI to the student.
Five things separate a document that governs from one that describes:
- Approval by the governing body, rather than a signature from the Head alone.
- A decision right, meaning a named person or committee who approves a new tool and is able to refuse one.
- A review cadence expressed in words, not a single future date that will quietly lapse.
- A route into the risk register, so AI risk is assessed, recorded and reported like any other risk the school manages.
- A way of knowing it is working. The four above establish the position. This one tests it. It can be simple: the approved tools register was reviewed this term and matches what is actually in use; the assessment policy and the position statement still say the same thing; staff completed the training; AI appeared in Board papers when it was meant to. Without something like this, a school knows what it decided and not whether any of it held.
That is thin in page count. It is not thin in substance, and it is what most AI policies are missing. It is also close to what mature AI governance looks like in practice: not a longer document, but a shorter one with mechanisms behind it.
A closing note on evidence
Our reading covers what schools have published, which is not the same as what they hold. Some of the best-governed schools we came across are close to invisible from the outside, with Board oversight, a structured AI risk assessment and a full set of student rules held on an intranet. Others publish a polished document that turns out to be a template adopted without a decision behind it, which governs very little regardless of who drafted it. Publishing and governing are different decisions, and so are adopting a document and deciding a position.
The decision this piece is about is the second one in each case. Work out what your position on AI needs to say. Put each part where it can actually be applied. Notice the handful of things nothing currently carries, and give them somewhere to sit. Then make sure someone owns it, and that someone can tell whether it is working.
If you want a read on where your school currently sits before deciding any of this, the free five-minute Arvoe AI Governance Maturity Assessment scores you across eight areas and returns your next three steps. Accountability, tool approval and Board reporting are three of them, and they are the parts this piece says nothing else in your policy set will pick up by default.
See where your school sits on AI governance maturity
Take our free 5-minute self-assessment to see where your school stands — or book a demo to see the full platform in action.
Keep reading
All posts- What Good Looks Like
What Mature AI Governance Actually Looks Like
Australian teachers lead the world in AI adoption — 66% used AI tools in the past 12 months, double the OECD average. The gap? Governance. Here's what mature AI governance looks like in a real school.
5 min read - Framework Gap
The Framework Gap: What Australian Schools Need to Know About AI Governance
Australia has a national framework for AI in schools. What it doesn't have is a roadmap. Here's what that means for your school — and what you can do about it.
6 min read - Sector Intelligence
December 2026: What Every School Leader Needs to Know
By December 2026, Australian schools will face two major privacy-related changes that will affect how they use AI and other digital tools. These are not just compliance updates — they are leadership, governance, and risk management issues.
7 min read