How to Write a School AI-Use Policy, With a Template You Can Adapt
A school AI-use policy that works has to survive a disputed grade. Here is what each section needs to say, and a template you can adapt for your setting.
The short answer. A workable AI-use policy answers four questions: what students may use AI for, how they must record it, what happens when staff suspect undeclared use, and who decides. Most school policies answer the first and skip the other three. Then a grade gets disputed and the policy has nothing to say. The template below covers all four, and it is written to be adapted rather than adopted.
Most AI policies are written for the wrong reader. They are written for an inspector, or for parents, or for a leadership team that wants the topic closed. The reader who actually matters is a teacher standing in front of a piece of work at nine o'clock at night, wondering what they are allowed to do next.
If your policy does not tell that teacher what to do, it is not a policy. It is a statement.
Why most policies fail
Three failure patterns come up repeatedly.
The unsupported blanket ban. "Students may not use AI", with nothing behind it. Bans are right in plenty of places, and required in some: examinations, supervised sessions, and any assessment whose specification says so. What fails is the blanket version with no mechanism, because it leaves staff with no graded response between ignoring something and alleging malpractice, and gives a student no way to use a tool legitimately and say so. Blanket bans also age badly, since the software is now inside the word processor.
The vague permission. "Students may use AI responsibly." Nobody can act on this. It creates the appearance of a position while leaving every difficult decision to whoever happens to be marking.
The detector as verdict. A policy that says work "flagged by AI detection software will be treated as malpractice" is the most dangerous of the three, because it outsources a professional judgement to a probability score. Detectors produce false positives on human writing, and JCQ's own guidance is explicit that detection output is one input inside a wider judgement, not proof. We cover what JCQ actually says about AI detection separately, because it is the part most policies get wrong.
The four questions your policy must answer
Everything else is detail.
- What may students use AI for, and where is the line? Be specific by activity, not by principle.
- How must they record it? A declaration nobody can complete is a declaration nobody completes.
- What happens when a teacher suspects undeclared use? The process, in order, with names attached to steps.
- Who decides, and what can the student say? A policy with no route of reply will not survive a challenge from a parent.
The template
Adapt the wording. The structure is the part that matters.
1. Scope
This policy applies to [all internally assessed work, coursework and non-examined assessment at Key Stage [X] and above]. It does not apply to [examinations under controlled conditions, where no device access is permitted].
State plainly which pieces of work this governs. Most disputes start with a disagreement about whether the policy applied at all.
2. Permitted use
Where the awarding body specification, the task conditions and this policy all permit it, students may use AI tools for: [research and finding sources, which they must then verify independently; explaining a concept they have not understood; checking spelling and grammar on work they have written themselves].
Students may not use AI tools to: [generate text that is then submitted as their own writing; produce analysis, argument or conclusions; write or rewrite whole paragraphs of an assessed piece].
Write this as two lists of activities. Resist the temptation to write a principle instead. "Use AI to support your learning, not replace it" sounds right and decides nothing.
3. Declaration
Where a student has used an AI tool as a source of information, they must record: the name of the tool, the date, the prompt they used, and how the output was used. A copy of the prompt and the output must be retained in a non-editable format, for example a screenshot.
This wording follows JCQ's requirement, which asks for the source, the date, and retained evidence in a form that cannot be edited afterwards. Give students the form. A declaration box on the front of the coursework cover sheet gets completed; a paragraph in a policy document does not.
4. When staff suspect undeclared use
Where a member of staff suspects that work contains undeclared AI use, they will:
1. Compare the work against the student's known standard, including previous work and any work produced under supervision.
2. Discuss the work with the student, including asking them to explain their process, sources and choices.
3. Record what was found and what the student said.
4. Refer the case to [named role] if concerns remain after that conversation.
A score from an AI detection tool may form part of the evidence considered. It is never proof, and on its own it is not enough to conclude misuse or impose a sanction. It may justify the checks set out above, and where the declaration of authentication has been signed and suspicion remains after those checks, the case must still be reported to the awarding organisation.
That last part is the single most important passage in the policy. It protects the student from a false positive, it protects the teacher from having to defend a number they did not generate, and it stops the opposite failure: a school quietly dropping a case it is required to report.
Note the order. The conversation comes before the referral, and the comparison with known work comes before the conversation.
5. Decision and right of reply
Decisions on [internal] cases are taken by [named role]. Before a decision is recorded the student will be given the allegation in writing, shown the evidence it rests on, told what the possible consequences are, and given reasonable time to respond in writing. Where the student is a child, they may be accompanied by an appropriate adult, and any reasonable adjustments they normally receive apply to the process as well. There is an internal route of appeal to [named role]. Where the work is part of a qualification and the declaration of authentication has been signed, the case will be reported to the awarding organisation.
6. Data protection
No student work is submitted to any AI or detection tool until [named role, normally the data protection officer, with the IT lead] has approved that tool in writing. Approval requires: a documented assessment of the processing, including whether a Data Protection Impact Assessment is required; a contract or data processing agreement with the provider; confirmation of what is stored, for how long, and where it is processed; confirmation of whether submissions are used to train models, and whether that can be switched off; coverage in the school's privacy notice; and a route for deletion and for subject access requests.
Staff will minimise what is submitted, removing names and other identifying details wherever the check does not require them.
Do not treat this as a formality. Student coursework is children's personal data, and putting it into a third-party tool is a processing decision that belongs to your data protection officer, not to an individual teacher deciding at the end of a marking session. Department for Education guidance is clear that schools should involve the DPO or IT lead before adopting these tools, and the assessment needs recording rather than remembering.
Our own breakdown of what happens to text you paste into a detector sets out what each major provider does with submissions, which is a starting point for that assessment and not a substitute for it.
7. Review
This policy will be reviewed [annually, and whenever JCQ or Ofqual guidance is updated].
Put a date on it. An undated policy is assumed to be out of date, usually correctly.
What to do with this
Take the structure, throw away our wording, and write it in your school's voice. Then do the two things that actually determine whether it works: put the declaration on the cover sheet where students will meet it, and walk your department through section 4 before term starts, so the first suspected case is not the first time anyone reads the process.
If you want the tool question addressed separately, the department guide covers selection and rollout, and our own detector is one input among several, never the decision.
Frequently asked questions
Does a school have to have an AI-use policy?
You do not need a separate document called an AI policy. You do need written malpractice and coursework authentication procedures that cover AI, because centres are required to have those and to be able to confirm that assessed work is the student's own. Most schools find it easier to write the AI part once and reference it from both. This template is that part.
Should the policy ban AI outright?
You can, and some settings have good reasons to. Be aware of what it costs: a ban gives staff no graded response short of malpractice, and it removes any incentive for a student to declare legitimate use. If you ban, say what happens when a student declares use anyway.
Can we say that detector scores will be treated as evidence of cheating?
Not as proof, no. Detector output can be evidence a teacher weighs, alongside the student's known standard and what they say when asked. It is never proof on its own, and a policy that treats a score as a verdict will not survive a challenge, because detectors produce false positives on human writing. Section 4 is written to keep that line visible in both directions: a score is not enough to conclude misuse, and it is also not a reason to quietly drop a case you are required to report.
Who should own the policy?
Someone named. "The school" is not an owner. In most settings it sits with the exams officer or a deputy head with responsibility for assessment, with heads of department responsible for applying it.
How often should it be reviewed?
Annually as a floor, and immediately whenever the awarding bodies update their guidance. That guidance has been revised more than once since 2023, and a policy that quotes a superseded version is worse than one that quotes none.