School leaders are asking the right questions about AI. Now we need the right answers and the right infrastructure
Last week, I attended the launch of the Institute of AI Education in York. The room was full of school leaders, educators and policy thinkers who are genuinely trying to get this right. The conversation was energetic, collaborative and urgent.
But one sentence kept returning, in different accents and different roles:
“We know we need to do something. We just don’t know what.”
That is where much of the sector is right now. Not reckless. Not resistant. Just operating without usable rails.
I work with Nudge Education Limited, The Haven and Riverside Virtual College supporting some of the most vulnerable and disengaged children in the UK: young people who have experienced educational trauma, persistent school avoidance and systemic exclusion. I also train educators and leaders through The Novacene Collective on how to use AI safely in education and care contexts.
When leaders tell me they lack practical guidance, I take it personally because the children who are most likely to be harmed by ungoverned AI are the children our systems already struggle to see clearly.
A framework worth borrowing, and the problem with borrowing it raw
This week I came across something from a group of technology practitioners: the AI First Principles framework. It offers a set of operational principles for organisations implementing AI, and two of them should be pinned above every senior leadership desk:
AI fails silently. AI accumulates errors across thousands of interactions before patterns become visible. Traditional systems failed loudly: a crash, an error message, an obvious gap. AI fails quietly, repeatedly, until harm has already scaled.
AI inherits messiness. AI learns from people. It absorbs bias, inconsistency and blind spots, then reproduces them at speed. Bolting AI onto broken processes doesn’t fix them. It industrialises the mess.
This is sharp, practical thinking and it’s worth reading.
But it isn’t built for UK safeguarding contexts. It doesn’t start with children’s rights. It doesn’t assume institutional trauma. And it doesn’t account for the specific conditions that shape day-to-day judgement in schools: cognitive overload, staffing pressure, accountability fear, procurement churn, and the slow drift of responsibility into “the system”.
That’s where we need something more specific and more enforceable.
The real risk: good people crossing invisible lines inside bad systems
The most dangerous place in AI governance right now is not malicious misuse.
It’s well-intentioned use without guardrails: good people crossing invisible lines inside systems that were never designed to protect children.
A practitioner who copies a child’s case notes into a commercial AI tool to “just tidy it up” isn’t a villain. They’re exhausted, under-resourced, and trying to do the right thing quickly.
But structurally, this is where harm is born:
the child’s data has moved into a commercial system,
consent was never obtained (and often cannot be meaningfully obtained in the way staff assume),
accountability becomes diffuse,
and risk becomes normalised because the output looks clean.
Under UK GDPR and the Data Protection Act 2018, the organisation remains responsible for how personal data is processed. And safeguarding guidance increasingly expects leaders to understand the digital conditions in which harm can occur, not just traditional, physical-world risks.
This is why we need governance that staff can actually use, not just policy that sits in a folder.
The Diamond Standard: a consent-first governance model built for children
The Diamond Standard (free training at using-ai-safely.com) exists because education and care settings need a framework that starts with children’s rights, and translates them into daily decision rules.
It’s built on four facets that must all be satisfied before an AI system is approved for use:
Safety: systems must actively reduce risk, not just avoid creating new ones
Sovereignty: children retain ownership of their data, stories and developing identities
Symmetry: if a system interprets a child, it must itself be interpretable
Stewardship: human relationships and accountability remain central; AI supports adults, it does not replace them
These are not abstract values. They are practical tests.
The traffic light most schools don’t have — and should
The most useful tool inside the Diamond Standard is its Traffic Light Model. It gives every practitioner — not just the DPO or DSL — a quick, defensible way to assess an AI use:
Green: supports adult work only, with no learner data involved. Proceed.
Amber: involves learner data or direct interaction with children. Pause and review.
Red: creates forced coherence, synthetic authority, or removes a child’s ability to refuse. Never use it.
This is deceptively simple, and that’s the point. In a sector working at speed, under pressure, “common sense” is not governance. Shared language and shared thresholds are.
Why policy alone still won’t hold
Even with a strong policy, there is a third layer of risk that most governance frameworks ignore and it’s the one that worries me most:
the erosion of human judgement over time...
This is where Verse-ality sits — not as a belief system, but as a diagnostic layer: an explanation of how safeguards drift when humans and automated systems interact under pressure.
Verse-ality names three failure modes I recognise every week in education and care:
Automation bias When tired people defer to system outputs — not because they “trust AI”, but because the system is present and their judgement feels risky.
Responsibility drift When accountability blurs: “The system flagged it.” “The platform suggested it.” “I was following the recommendation.” In safeguarding, that drift is catastrophic.
Context collapse When a child’s life is reduced to simplified categories, scores, labels, and “insights” — losing the nuance that makes them legible as a person.
These are not future risks. They are already happening in unremarkable ways. And “unremarkable” is exactly how systemic harm becomes institutionalised.
What policymakers and school leaders can do now
The regulatory environment is genuinely complex.
KCSIE (from 1 Sept 2025) reinforces expectations around filtering and monitoring, cyber resilience, and references out to generative AI guidance. Many schools have not yet translated this into operational staff rules.
The ICO’s Children’s Code (Age Appropriate Design Code) sets standards for online services likely to be accessed by children, pushing “best interests of the child” into design expectations for systems processing children’s data.
The EU AI Act is now in force, with a staged application timeline; obligations for general-purpose AI models began applying in 2025, and broader provisions become fully applicable in August 2026, with some high-risk categories subject to longer transitions. UK education leaders will increasingly feel this through vendors, procurement requirements, and cross-border services.
Complexity is not a reason to wait. It’s a reason to choose principles that can be audited.
Here are three actions that can be taken immediately and embedded into policy:
1) Mandate a baseline AI governance training for all staff
Start with the free Diamond Standard training (under two hours). Not because training “solves” safety, but because it creates a shared vocabulary and shared thresholds across roles.
2) Adopt three anchor questions as a non-negotiable decision rule
Before any new AI use:
If it touches a child, pause.
If it stabilises a story about a child, review it formally.
If it can’t accept refusal without penalty, don’t use it.
These three lines are simple enough to survive real life.
3) Stop treating AI governance as optional admin — name an accountable lead
Every school, trust, AP provider, and commissioning LA team needs a named AI governance lead with the remit to:
set permitted/prohibited uses,
align procurement and DPIAs with actual classroom reality,
and build feedback loops that catch “silent failure” early.
Right now, in most settings, no one truly owns this. That vacuum is liability and it’s where children get hurt.
The children who can’t afford our delay
I work with young people who have already been failed by systems that didn’t see them clearly: behaviour misread, potential capped by early categorisation, trust in adults eroded by institutions that prioritised compliance over relationship.
Used well, AI could be transformative: freeing adult capacity for the relational work that changes lives.
Used badly, it will repeat the failures of the systems that came before it only faster, at scale, and with the false authority that comes from looking like “data”.
AI First Principles is right: AI inherits messiness. The Diamond Standard is right: children’s rights must become infrastructure, not aspiration. And Verse-ality is right: human judgement must be deliberately preserved under pressure, over time.
School leaders are asking the right questions. The answers exist and we do not need to wait for enforcement to define safety for us.
In education, safety is relational before it is regulatory. That means we build it deliberately — now.
Start with the free training: using-ai-safely.com
Further reading
AI First Principles: aifirstprinciples.org
KCSIE (from 1 Sept 2025): DfE statutory guidance
ICO Children’s Code (Age Appropriate Design Code)
EU AI Act timeline overview
First published in Building Schools in the Cloud on LinkedIn, 12 February 2026.