Why Every School Needs an AI Governance Framework - and how to build one
Last week, a youth worker where I was delivering AI safety training admitted she copied detailed safeguarding case notes into ChatGPT because she was exhausted and needed to create a summary for the safeguarding team. The AI produced a perfect summary. The problem? She'd just shared a vulnerable 15-year-old's trauma disclosure (including family circumstances, mental health concerns, and previous abuse) with a commercial AI system that may retain that data permanently.
The young person had disclosed to a trusted human practitioner in a confidential relationship. They had no idea their words would be processed by artificial intelligence, stored in a system with no duty of care, and potentially used to train future models.
This wasn't malicious. It was a tired professional using a tool that appeared helpful. And it's happening in schools and education settings across the UK and Europe right now.
The Real Problem We're Facing
The problem isn't that people are using AI. The problem is that most education settings have no framework for deciding what's safe, what needs review, and what should never happen.
But there's a deeper issue: we're approaching AI in education from entirely the wrong angle.
As Gerry Docherty recently observed in our Novus Learning Network discussions, schools are so far behind that any transition will take too long to have an impact. The kids are already putting a bomb under the whole thing by simply not going anymore. Meanwhile, I've had requests for AI training from some of the most advanced tech companies who are having to admit they have staff who don't know how to use AI and are afraid of it.
We're at a collapse point. And the question isn't whether AI will transform education, it's whether we can ensure that transformation makes us more human, not less.
What Europe's Education Systems Are Struggling With
The European Schoolnet's December 2025 survey of AI in education across 23 systems reveals both progress and persistent gaps:
What's happening:
20/23 systems have developed or are developing AI policies
13/23 consider AI a high-priority topic
Nearly all systems include AI literacy in curriculum
Teacher training is widely available
What's still missing:
Practical implementation frameworks practitioners can actually use
Clear boundaries between permitted, restricted, and prohibited practices
Operationalised consent mechanisms that go beyond tick-boxes
Evidence of real classroom impact (most examples are pilots, not embedded practice)
And here's the critical finding: 22 out of 23 education authorities cited teacher capacity building as their key priority, with 21 highlighting the need for ethical and practical guidelines. But across these systems, there's widespread difficulty measuring whether guidance actually changes practice.
The gap is this: we have policies, but schools don't know how to implement them. We have priorities, but not pathways.
This is the gap The Novacene Collective exists to fill.
The EU AI Act: What Schools Must Now Comply With
From August 2025, the EU AI Act regulation fundamentally changed what's required of education settings, even in the UK. The Act's influence on UK policy and international partnerships means schools cannot ignore it.
Critical classifications:
All AI systems working with children = high-risk systems
Certain AI practices have transparency obligations (Article 50) and others are prohibited (Article 5)
High-risk systems require human oversight, transparency, data governance, and risk management
This isn't optional. 20 out of 23 European education systems are currently reviewing AI Act implications. 5 have completed assessments. The rest are in progress.
Yet most schools have no idea how to operationalise these requirements in daily practice.
The European Schoolnet report shows a common challenge: education systems struggle to distinguish between overlapping AI initiatives, making implementation unclear. We have multiple policies, guidelines, and frameworks but at the point where a teacher needs to make a decision, the complexity creates paralysis. Paralysis creates workarounds. Workarounds create risk.
The Diamond Standard: Implementation Layer for AI Policy
After working through this at The Novacene, The Haven and at Nudge Education Limited (who work across 67 Local Authority areas, approximately 300 practitioners, and the most vulnerable cohort in UK education) we've developed what we call the Diamond Standard.
It's not another policy document. It's the implementation layer that connects international policy to daily decisions.
The Diamond Standard addresses four non-negotiable requirements, all of which must be met:
1. Safety - Systems Must Actively Reduce Risk
This isn't about avoiding obvious dangers. It's about recognising that AI can cause harm even when "working as designed."
EU AI Act alignment: Article 5 prohibited practices and Article 9 risk management requirements.
In practice:
No AI-only safeguarding decisions (human professional judgment is non-negotiable)
All digital media treated as potentially synthetic (deepfakes are trivially easy now)
Identity verification requires multiple independent factors
Risk assessment happens before implementation, not after
2. Sovereignty - Children Own Their Data and Stories
Children are not data sources to be mined. Their developing identities belong to them, not to systems.
EU AI Act alignment: Article 10 data governance requirements and fundamental rights protections.
In practice:
Children know when AI is involved (transparency requirement)
AI cannot extract trauma or infer diagnosis without explicit therapeutic context
Opt-out must be genuinely available where reasonably possible
Children retain authorship of their narratives
This is what the European report misses: Most systems focus on "improved teacher efficiency" (21/23 systems cite this as the main benefit). Whilst efficiency matters, it's the wrong starting point.
When systems optimise for efficiency first, they create AI tools that:
Profile children to "personalise" learning (removing developmental uncertainty)
Track engagement to "improve outcomes" (removing privacy of thought)
Predict behaviour to "intervene early" (removing agency)
These may work "perfectly" whilst causing profound harm. Starting with children's rights produces different technology choices.
3. Symmetry - Systems That Interpret Must Be Interpretable
If an AI draws conclusions about a child, we must be able to understand how those conclusions were reached. Black-box algorithms that profile children without explanation are unacceptable.
EU AI Act alignment: Article 13 transparency and Article 14 human oversight requirements.
In practice:
No opaque scoring or profiling systems
AI outputs are never sole evidence for decisions about children
Forced coherence is recognised as a safeguarding risk
Why this matters: Children need space to be uncertain, inconsistent, developing. When AI insists on resolving ambiguity (labelling a child's behaviour, predicting their outcomes, stabilising their story) it removes the very uncertainty that learning requires.
4. Stewardship - Humans Remain Accountable
Technology must support practitioners, never replace them. The responsibility of care cannot be transferred to systems.
EU AI Act alignment: Article 14 human oversight requirements and Article 29 fundamental rights impact assessments.
In practice:
AI supports adults, doesn't replace them
Human accountability is non-transferable
Systems must know how to stop (recognise their own limitations)
Relationship comes before optimisation
This connects to our broader vision at The Novacene Collective:
AI could be the thing that finally breaks us out of the factory model of education. Not by making us more efficient at processing children through a system, but by freeing us to focus on the things that make us human: judgment, ethics, care, the capacity to slow down, to be uncertain, to hold space for someone else's becoming.
Knowledge is now like electricity: freely available, instantly accessible. What we need to teach are the human skills: how to judge what knowledge matters, how to care about why it matters, how to use it ethically, how to know when to stop and think.
The Traffic Light System: Making It Practical for Teachers
Theory is useless if practitioners can't apply it in real situations. At Nudge, every member of staff (from senior leadership to frontline practitioners) uses a simple traffic light system that operationalises both the EU AI Act and the Diamond Standard:
🟢 GREEN - ALLOWED (Proceed)
Supporting adult work with no learner data:
Lesson planning with generic examples
Drafting parent communications (no names or specific details)
Professional development and learning
Administrative support and scheduling
Critical rule: The moment you add ANY learner data, you've moved to amber.
Why this works: The European Schoolnet report shows systems want practical tools teachers can use immediately. This is that tool.
🟠 AMBER - PAUSE & REVIEW (Submit for Approval)
Anything involving learner data or direct child interaction:
Systems that process, analyse, or store information about specific children
Direct AI interaction with students (chatbots, tutoring, feedback tools)
Assessment, tracking, or analytics on individuals or groups
Systems that learn about a child over time
EU AI Act note: These are high-risk AI systems requiring Article 6 compliance verification.
Not automatic refusal - many amber systems can be approved with appropriate safeguards. The review ensures Diamond Standard and AI Act compliance. Typical timeline: 5-10 working days.
🔴 RED - PROHIBITED (Never Use)
Some practices are never permitted:
Mapped to EU AI Act Article 5 prohibited practices:
Webcam or biometric proctoring (coercive surveillance that's easily spoofed)
Emotion recognition or lie detection (scientifically questionable, harmful to neurodivergent students)
Behaviour prediction or scoring (creates self-fulfilling prophecies, manipulates vulnerable people)
Public AI tools with identifiable learner data (ChatGPT, Claude, etc. with student information violates GDPR, AI Act, and sovereignty)
The case notes scenario from the opening? That's red. Unambiguously prohibited.
Three Questions That Solve Most Problems
When staff are uncertain, we've given them three anchoring principles that work across any regulatory framework:
If it touches a child → PAUSE
If it stabilises a story (creates persistent narratives about who a child is) → REVIEW
If it can't accept refusal (children can't genuinely opt out) → DON'T USE
These aren't bureaucratic barriers. They're protective infrastructure that empowers good professional judgment.
And they embody what we're trying to build through The Novacene Collective and Project Weaver: education that puts human development first, that treats uncertainty as a feature rather than a bug, that recognises children as becoming rather than being.
Real Scenarios, Real Decisions
Let me show you how this works in practice:
Scenario 1: A teacher wants to use Gemini within Google Workspace to brainstorm lesson ideas about emotional regulation for Year 8. They provide no names, no specific student information.
Decision: GREEN - Supporting adult work, no learner data, using approved ecosystem tool.
Scenario 2: The school is considering an adaptive maths tutoring system that builds profiles of each student over time, remembers their mistakes, and personalises learning paths.
Decision: AMBER - Requires review. Could potentially be approved if it meets Diamond Standard (students can see what it knows, can challenge inferences, can reset their profile, genuine human oversight exists).
EU AI Act note: High-risk AI system requiring full Article 6 compliance verification.
Scenario 3: A vendor offers webcam proctoring that analyses students' faces during exams to detect "suspicious behaviour."
Decision: RED - Prohibited. Creates coercive surveillance, high false positive rates, easily defeated, violates privacy, fundamentally undermines trust.
EU AI Act note: Likely falls under Article 5(1)(c) prohibited social scoring or Article 5(1)(f) prohibited biometric categorisation.
Evidence From Implementation at Scale
Unlike many AI in education initiatives that remain at pilot stage, Diamond Standard is operating at scale across The Haven and also Nudge Education's network.
Since implementation:
Amber review submissions increased significantly (showing framework awareness and application)
Red violations reduced to near-zero (showing clear boundaries work)
Staff confidence in AI decision-making measurably improved
Most critically: We can demonstrate actual practice changes, not just policy compliance
The European Schoolnet report identifies "the difficulty of identifying actual AI practices in schools" as a key challenge. Our experience shows that clear, practitioner-friendly frameworks enable documentation of real practice rather than aspirational policy.
The Broader Vision: Making Education More Human
This work sits within a larger vision at The Novacene Collective.
We're developing Project Weaver / Learning Mandala - an interdisciplinary curriculum framework focused on:
Learner traits and attributes (not knowledge accumulation)
Interdisciplinary ways of knowing (not subject silos)
Sustainable Development Goals (real problems, not abstract exercises)
Problem-solving capacities (what humans do that AI cannot)
Each strand of the curriculum asks: How does this make us more human?
Because if AI can do one brilliant thing for education, it's this: it could finally force us to abandon the factory model. Not by making the factory more efficient, but by making the factory obviously obsolete.
When knowledge is freely available and AI can process it instantly, what's left to teach?
Judgment - How do we decide what matters?
Ethics - How do we decide what's right?
Care - How do we decide who to care about and how?
Discernment - How do we decide when to use AI and when to think for ourselves?
Presence - How do we slow down in a world that demands speed?
Relationship - How do we connect authentically when everything can be synthetic?
These are the human skills. These are what the Diamond Standard protects space for.
Building Your Framework: Where to Start
You don't need to solve everything at once. Here's a practical roadmap:
Week 1: Audit Current State
Survey staff about AI tools they're using
Review contracts with ed-tech vendors for AI features
Identify where learner data is being processed
Document current practices (no judgment, just facts)
Week 2: Establish Clear Boundaries
Define prohibited practices (start with the red list above)
Identify approved tools within your ecosystem
Create simple decision framework (adapt the traffic light system)
Communicate clearly to all staff
Week 3: Build Review Process
Designate accountability (who reviews amber requests?)
Create simple review form (not a 40-page questionnaire)
Establish timeline expectations (we do 5-10 working days)
Include safeguarding lead in child-facing system reviews
Ensure EU AI Act compliance verification for high-risk systems
Week 4: Train and Support
Run practical training sessions (scenarios, not theory)
Provide quick reference guides staff can keep
Create reporting pathway for concerns
Normalise asking questions and being uncertain
Ongoing: Monitor and Learn
Track what gets submitted for review
Document decisions and reasoning
Build library of approved/rejected examples
Update framework as you learn
Share findings with peer networks
International Application and Cross-Border Collaboration
Whilst developed in the UK regulatory context, the Diamond Standard framework aligns with:
EU AI Act (Articles 5, 6, 9, 10, 13, 14, 29)
UNESCO's AI and Education guidance
OECD's AI literacy framework
UK GDPR / EU GDPR data protection requirements
KCSIE 2025 (UK safeguarding standards)
ICO Age Appropriate Design Code
Education systems across Europe are seeking practical implementation frameworks. The European Schoolnet survey identified peer-learning and resource sharing as critical needs that current policy documents don't meet.
We're making Diamond Standard freely available as an open framework that any school or education system can adapt to their local context whilst maintaining core child protection principles.
This is part of The Novacene Collective's broader mission: building the infrastructure for education that puts human development first. Not as a nice-to-have aspiration, but as the foundation everything else rests on.
The Right to Be Unread
I'll end with the principle that underpins everything:
children possess the right to interior freedom: to remain partially unknown, incompletely defined, and provisionally understood.
When AI systems continuously observe, interpret, and profile children, they remove the essential space young people need to experiment, to fail, to be genuinely themselves. Early labelling (whether through diagnostic categories, ability groupings, or algorithmic predictions) can constrain development and create self-fulfilling prophecies.
This isn't abstract philosophy. It's practical safeguarding.
When children know they're constantly observed, interpreted, and profiled by AI systems, they lose the safety to be uncertain, to contradict themselves, to try on different identities. The right to be unread is the right to develop authentically.
Good AI governance isn't about preventing innovation. It's about ensuring innovation serves children rather than extracting value from them. It's about building systems where human relationships remain central and where technology genuinely supports rather than replaces professional judgment.
And ultimately, it's about making education more human, not less.
Your Next Steps
If you're a school leader, SENCO, DSL, or education provider:
Audit your current state - You can't govern what you don't know about
Establish clear boundaries - Start with the red/amber/green framework
Build accountability - Designate who reviews and approves
Train your people - Practical scenarios, not theoretical policy
Create support structures - Make it easy to ask questions
Verify EU AI Act compliance - Particularly for high-risk systems
If you're a practitioner working with children:
Before using any AI, ask: Does it involve learner data? → If yes, pause and ask
Use approved tools - Within your organisation's ecosystem, not public AI with student information
When in doubt, choose the more cautious category - Better to ask unnecessarily than proceed with unexamined risk
Speak up if something feels wrong - Your professional judgment matters
If you're developing system-level AI policy:
Consider how practitioners will actually implement it - Complexity creates paralysis
Provide practical decision tools - Not just principles, but pathways
Build in evidence mechanisms - How will you know if it's working?
Connect to existing safeguarding frameworks - Don't create parallel systems
Working With The Novacene Collective
At The Novacene Collective, we're building the infrastructure for a different kind of education:
What we offer:
Diamond Standard implementation support - Adapting the framework to your context
Staff training and capacity building - Practical, scenario-based learning
Project Weaver curriculum framework - Human-centred learning design
Ethics benchmark and quality mark - Independent verification of AI governance
Peer learning networks - Cross-organisational collaboration and evidence sharing
Who we work with:
Alternative provision settings and online schools
Mainstream schools implementing human-centred approaches
Education systems developing AI governance frameworks
Teacher training institutions
Ed-tech developers committed to ethical practice
Learning and Development in any organisation or institute
We're also exploring how The Novacene Collective might function as a quality framework or ethical benchmark for emerging online schools and alternative provision, providing the governance infrastructure that keeps human development central as education models evolve.
If you're interested in this work, want to collaborate, or are developing similar frameworks in your own context, I'd genuinely value the conversation.
Resources and Further Reading
Diamond Standard Framework:
Framework: https://theversenet.com/
Training materials: https://using-ai-safely.com/
Implementation guides: [Contact for access]
International Frameworks:
EU AI Act: https://artificialintelligenceact.eu
UNESCO AI and Education: https://www.unesco.org/en/artificial-intelligence/education
OECD AI Literacy Framework: https://ailiteracyframework.org
European Schoolnet (2025): Artificial Intelligence in School Education
UK-Specific Guidance:
KCSIE 2025: https://www.gov.uk/government/publications/keeping-children-safe-in-education
ICO Age Appropriate Design Code: https://ico.org.uk/for-organisations/childrens-code-hub
The Novacene Collective:
Using AI Safely with Children: https://using-ai-safely.com
Join the Novus Learning Network: https://thenovacenepress.gumroad.com/l/novuslearningnetwork
The infrastructure we build now will shape how an entire generation experiences education. Let's make sure we're building it with their dignity, agency, and developmental freedom as the foundation, not as an afterthought.
The kids are already telling us the current system doesn't work by simply not showing up anymore. We can either wait for the collapse, or we can build something better now.
The choice is ours.
Kirstin Stevens Director, AI Governance Lead The Novacene Collective
What's your organisation's approach to AI governance? What challenges are you facing in implementation? How are you balancing innovation with child protection? I'd be genuinely interested to hear your experiences and questions in the comments.
#AIGovernance #EdTech #Safeguarding #EducationalLeadership #ChildProtection #AlternativeProvision #KCSIE2025 #EUAIAct #DataProtection #UKEducation #HumanCentredEducation #FutureOfLearning #TeacherSupport #EdTechEthics #InternationalEducation #DigitalSafeguarding #EducationTransformation #Verseality The Novacene
First published in Building Schools in the Cloud on LinkedIn, 31 March 2026.