
Building an AI Governance Approach Without Resorting to Blanket Bans
asitplan Strategy Team
Author
Rob Lloyd
Technical Reviewer
06 August 2026
Last Reviewed
School leadership teams, DSLs, and IT managers
Target Audience
The Context
The rapid adoption of Generative AI (like ChatGPT, Copilot, and Gemini) has left many schools scrambling to establish policies. The immediate, fearful reaction is often to attempt a blanket ban on the school network. However, students and staff simply bypass these blocks using personal devices or cellular data, pushing AI usage into the shadows where it cannot be monitored or guided.
Who This Guide is For
School leadership teams, Designated Safeguarding Leads (DSLs), and IT managers.
Why This Matters
Attempting to ban AI is both technically futile and educationally disadvantageous. It prevents staff from exploring significant workload-reduction tools and fails to prepare students for a digitally integrated workplace. However, unmanaged AI usage presents severe data privacy risks (e.g., staff inputting pupil PII into public models) and safeguarding concerns.
What Good Looks Like
A mature AI governance approach acknowledges that the technology is here to stay. It establishes clear boundaries (Acceptable Use Policies specific to AI), provides approved, secure 'walled garden' tools for staff, and focuses on digital literacy and critical evaluation rather than futile technical blocking.
Approach and Methodology
- Accept Reality: Acknowledge that blanket technical bans on public AI tools are easily bypassed and drive usage underground (Shadow AI).
- Update Policies Immediately: Revise the staff Acceptable Use Policy (AUP) to explicitly prohibit the entry of any sensitive, personal, or identifiable pupil data (PII) into public, consumer-grade AI models.
- Provide Secure Alternatives: Procure and deploy "enterprise" or "education" tiers of AI tools (like Microsoft Copilot with commercial data protection) where prompts and data are not used to train public models.
- Establish an AI Working Group: Create a cross-functional team (including teaching staff, IT, and safeguarding) to evaluate new AI tools before they are adopted school-wide.
- Staff Training: Train staff not just on how to use AI for lesson planning, but on the ethical implications, data privacy risks, and the phenomenon of AI "hallucinations" (confident inaccuracies).
- Curriculum Integration: Begin integrating critical AI literacy into the curriculum, teaching students how to evaluate AI-generated outputs for bias and accuracy.
Evidence to Retain
- An updated, signed Staff AUP containing explicit AI data privacy clauses.
- A central register of approved, risk-assessed AI tools permitted for school use.
- Records of staff training regarding AI data security.
Questions Leadership Should Ask
- "Are we confident that our staff understand the difference between a public AI tool and a secure, enterprise-grade AI tool?"
- "Do we have a mechanism to detect if unapproved AI tools are being heavily utilized on our network?"
Common Pitfalls
- The Whack-a-Mole Blocklist: Wasting IT resources endlessly trying to block every new AI domain that appears on the internet.
- Policy Vacuum: Ignoring the issue entirely, leaving staff to make their own uninformed decisions regarding data privacy and AI use.
- Over-Reliance: Allowing staff to rely on AI for assessment or reporting without implementing mandatory human-in-the-loop review processes.
How asitplan Can Help
asitplan's framework helps schools track their software inventory, enabling IT teams to monitor which AI tools are actively being used across the estate. This visibility is the first step in moving from Shadow AI to managed, governed AI adoption.