What Every District Must Cover in a 2026 Student AI Use Policy
A legally grounded compliance checklist for district student AI use policies, covering seven domains most state model policies omit — including special-education accommodations under the Sixth Circuit's William A. holding and AI detector evidentiary limits.
- Applicable role
- school district counsel
- Workflow stage
- review
- Primary source
- William A. v. Clarksville-Montgomery County School System, 6th Cir. 2025
A district can have an AI policy on the books in 2026 and still have no usable answer when a parent asks why an accommodation was denied, a student challenges an AI-misconduct finding, or procurement asks whether a consumer tool may process student records. This checklist is for compliance verification, not legal advice. It is current to Q3 2026. Before adoption or publication, counsel should recheck current bill status, state model-policy guidance, local board requirements, and any intervening case law.
The useful question is not whether students should ever use AI. The useful question is where the district’s policy would fail if a parent, student, regulator, procurement reviewer, or hearing officer asked for the rule, the evidence, the exception, and the record.

The Seven-Domain Review Surface
| Domain | Policy clause or review question that must be auditable |
|---|---|
| Special-education accommodation boundaries | Does the policy distinguish AI used to provide access or implement an IEP/Section 504 support from AI use that masks, substitutes for, or avoids remediation of a disability-related need? |
| Data-privacy contract controls | Does the policy identify which AI environments may receive student data, which may not, and which contract terms are required before use? |
| AI detector evidentiary limits | Does the policy prohibit detector output from serving as standalone proof of misconduct and require human review, notice, and appeal? |
| Academic-integrity tiering by grade band | Does the policy define permitted, restricted, and prohibited uses differently for elementary, middle, high school, and dual-enrollment or college-credit contexts? |
| Vendor-procurement evaluation | Does procurement review privacy, retention, training-data use, security, accessibility, audit rights, and subcontractors before an AI tool is approved? |
| Staff AI-literacy training | Does the policy say which staff are trained, on what topics, how often, and who records completion? |
| Revision cycle and model-change review | Does the policy reopen review when state law changes, a model silently changes capability, a vendor changes terms, or new enforcement guidance appears? |
State model policies are useful starting points, especially for districts trying to meet statutory deadlines. They are not liability shields. KJK’s June 2026 review of Ohio’s July 1 school-AI-policy deadline is valuable for exactly that reason: it warns that the Ohio model-policy approach leaves unanswered the issues most likely to produce legal exposure, including special education, AI detectors, and vendor contracts.[1]
The urgency is real, but the numbers should be handled carefully. RAND reported in March 2026 that 62% of grades 6–16 students were using AI for homework by December 2025, up from 48% in May 2025, and that 67% believed AI harms critical thinking.[2] That is a grades 6–16 sample. It should not be casually rewritten as a K–12-only claim, and it should not be treated as evidence that every grade band needs the same rule.
Special Education: The Accommodation Line Has to Be Written Before the Complaint
The most dangerous student-AI clause is often the one that sounds fair: “Students may use AI tools only as authorized by the teacher.” That may work for ordinary classroom management. It is not enough for a student whose IEP, Section 504 plan, language-access need, or assistive-technology support changes what “authorized” must mean.
William A. v. Clarksville-Montgomery County School System gives this issue a sharper edge in the Sixth Circuit. The 2025 decision is binding in Ohio, Kentucky, Michigan, and Tennessee, and supports the proposition that AI tools which mask rather than remediate a disability-related need can contribute to a denial of FAPE. Outside those four states, the reasoning may be persuasive, but it is not controlling precedent.[3]

A defensible policy therefore needs a boundary clause, not a general blessing or ban. The clause should require the IEP or Section 504 team, not an individual classroom teacher acting alone, to decide when AI is an accommodation, assistive technology, supplementary aid, or prohibited substitution. That decision should be recorded in the plan or related service documentation, with enough specificity that staff can apply it during actual assignments.
The operational distinction is practical. Speech-to-text, reading support, brainstorming support, translation assistance, or organizational scaffolding may help a student access instruction. A tool that completes the core task the student is supposed to practice may conceal the need the district is legally required to address. The policy does not need to answer every classroom scenario in advance, but it must say who decides, what record controls, and how teachers are told.
- Require IEP and Section 504 teams to evaluate AI supports when they affect access, output, communication, reading, writing, executive functioning, or assistive technology.
- Document whether the AI tool supports access, modifies how the student demonstrates learning, or replaces the skill being assessed.
- Identify who may approve temporary AI use pending a team meeting, and how that temporary approval is recorded.
- Prohibit disciplinary use of a generic AI rule when the disputed conduct may involve an unreviewed disability-related support need.
- Train teachers and administrators to route accommodation questions to the proper team instead of resolving them through ordinary academic-integrity procedures.
This is also where a district should avoid language that quietly transfers legal responsibility to families. A policy that says students must disclose AI use may be reasonable for academic integrity. It cannot be the only mechanism for identifying disability-related AI use. Staff still need a route for recognizing when an AI question belongs in an IEP or Section 504 discussion.
Data Privacy: Treat FERPA and State Student-Data Law as Approval Gates
A student-AI policy that tells staff to protect privacy, but does not identify approved tools, leaves the real decision to whoever is preparing a lesson at 9 p.m. The policy should draw a visible line between approved district environments and uncontrolled consumer services.
Columbus City Schools’ March 2026 approach is a useful example of the kind of line a district can write. The district designated Microsoft Copilot as an approved AI service for district use while prohibiting consumer ChatGPT for student-data handling.[4] The point is not that every district should choose the same vendor. The point is that staff need to know which environment is covered by district controls and which environment is not.
For policy drafting, FERPA and state student-data laws should operate as contract-control triggers. If an AI tool will receive personally identifiable student information, student work tied to an identifiable student, disability information, behavioral records, assessment data, or teacher-entered student notes, the question is not whether the tool is convenient. The question is whether the district has approved the tool through the required privacy, security, and contract review.
- Name the office that approves AI tools for student-data use, such as technology, legal, privacy, procurement, or a designated review committee.
- Bar staff and students from entering identifiable student data into consumer AI tools unless the district has approved that environment for such use.
- Require contract review for retention, deletion, training-data use, redisclosure, subcontractors, audit rights, breach notice, and data location.
- Require a separate review for special-education, health, discipline, or counseling records because those uses carry higher sensitivity.
The clause should be written so an administrator can enforce it without becoming a privacy lawyer. “Do not enter student data into unapproved AI tools” is enforceable. “Use AI responsibly and protect confidential information” is an aspiration.
AI Detector Evidence: Build the Appeal Before the First Accusation
AI detectors create an evidentiary problem before they create a discipline problem. A detector score looks official, arrives in a percentage, and can be pasted into a referral. That is exactly why a policy must say what the score can and cannot prove.
Liang et al. reported in Patterns in 2023 that AI detectors produced a 61.3% false-positive rate on TOEFL essays written by non-native English writers.[5] That finding should not be stretched into a claim that every detector result is wrong or that all student-writing cases are identical to TOEFL essays. It does show why multilingual context matters and why detector output should not be treated as standalone proof of misconduct.

The same caution belongs in special-education contexts. A student who uses assistive technology, translation support, predictive text, speech-to-text, grammar support, or structured writing tools may produce work that differs from a teacher’s expectations. The policy should not let a detector score collapse those facts into a misconduct presumption.
| Evidence tier | Policy treatment |
|---|---|
| Detector output alone | May prompt review, but may not support discipline, grade penalty, or misconduct finding by itself. |
| Detector output plus writing-process evidence | May support further inquiry when paired with drafts, version history, assignment-specific expectations, or teacher-student conference notes. |
| Direct admission or documented unauthorized use | May support discipline if notice, opportunity to respond, accommodation review, and grade-band procedures are satisfied. |
| Multilingual, disability, or assistive-technology context | Requires heightened review before any finding; route accommodation questions to the appropriate team. |
The policy should also control the paperwork. If a teacher uses a detector, the record should identify the tool, date, version if available, submitted text, score or output, other evidence reviewed, student explanation, parent notice where required, and final decision-maker. Without that record, the district is asking an assistant principal or counsel to reconstruct the basis for discipline after the fact.
A workable appeal path does not need to be elaborate. It needs to be available before a grade is finalized or a discipline consequence is imposed; it needs to allow the student to provide drafts, notes, version history, source materials, or an explanation of authorized AI use; and it needs to require review by someone other than the initial accuser when the consequence is significant.
Academic Integrity Should Vary by Grade Band
A single AI rule for every student is easy to print and hard to defend. Elementary students, middle-school students, high-school students, and students taking college-credit courses do not face the same instructional expectations or due-process consequences. A district policy should set districtwide categories, then require schools or departments to map those categories to assignments.
| Category | What the policy should require |
|---|---|
| Permitted use | Examples may include teacher-authorized brainstorming, accessibility support, translation support, outlining, practice feedback, or tool use explicitly allowed by the assignment. |
| Restricted use | Examples may include AI drafting, revision, code generation, problem solving, or source summarization when allowed only with disclosure, citation, process documentation, or teacher approval. |
| Prohibited use | Examples may include submitting AI-generated work as the student’s own, using AI on assessments where outside assistance is barred, bypassing required skill practice, or entering student data into unapproved tools. |
Grade-band tiering matters most at the edges. Younger students may need simpler disclosure routines and more teacher-controlled environments. High-school students may need assignment-level citation rules, transcript-sensitive discipline safeguards, and separate rules for Advanced Placement, career-technical, or dual-enrollment work. If a college partner or testing organization imposes stricter rules, the district policy should tell staff where those external rules control.
Disclosure language should also be concrete. “Cite AI” is rarely enough. The policy can require students to identify the tool used, the kind of assistance received, and the portion of the work affected. For younger students, a teacher-provided checkbox may do more than a formal citation format.
Procurement Review Is Part of the Student Policy
Procurement often appears in a separate administrative regulation, but AI makes that separation risky. If the student-use policy permits AI tools without tying permission to vendor approval, staff may reasonably assume that free or low-cost tools are available for classroom use.
The policy should require approval before an AI tool is used with students, student records, student work, or district instructional systems. Approval should not be limited to privacy. Accessibility, bias-risk review, security, records retention, age restrictions, advertising, intellectual-property terms, and whether prompts or outputs are used to train models all belong in the review file.
- Does the vendor receive personally identifiable student information or student work?
- Are prompts, uploaded files, or outputs used for model training or product improvement?
- Can the district delete, export, audit, or restrict data?
- Do subcontractors receive data, and are they bound to equivalent terms?
- Does the tool meet accessibility requirements for students and staff?
- Who owns or may reuse instructional content, student submissions, prompts, and outputs?
This is where Columbus’s approved-environment approach becomes administratively useful again. The policy does not have to name every banned tool. It can say that only tools approved through the district’s AI review process may be used for covered student-data or instructional uses, and that consumer tools are barred unless expressly approved for that purpose.
Staff Training Must Match the Decisions Staff Actually Make
A training clause should not merely say that staff will receive AI literacy training. It should identify who must be trained and what decision they are expected to make afterward. Teachers need assignment-design, disclosure, accommodation-routing, and detector-evidence training. Administrators need discipline, appeal, documentation, and parent-communication training. Technology and procurement staff need vendor-review training. Counsel and compliance staff need the policy-review calendar and escalation triggers.
The policy should assign ownership for training records. If the district later relies on a teacher’s detector referral or an administrator’s discipline decision, it should be able to show that the staff member was trained on the evidentiary limits and accommodation safeguards that applied at the time.
- Annual training for teachers on permitted AI uses, disclosure routines, student-data limits, accommodation referrals, and detector limits.
- Role-specific training for administrators on investigation records, appeal rights, discipline thresholds, and parent notice.
- Procurement and technology training on vendor intake, contract review, security, privacy, accessibility, and model-change monitoring.
- Board and cabinet briefing on policy scope, state-law changes, approved-tool categories, and unresolved risk decisions.
Revision Cycles Need Triggers, Not Just Dates
Annual review is useful, but AI policies also need event-based review. Models change capability without a school-board vote. Vendors change terms. States pass AI-in-education bills. Agencies issue guidance. A policy that is reviewed only once a year may be stale before the next semester begins.
FutureEd’s legislative tracker, updated July 13, 2026, and MultiState’s 2026 state-legislative coverage both show active state attention to AI in education and related governance.[6][7] Those sources should be treated as monitoring tools, not as final legal status. Bill status may have changed since the July 13, 2026 FutureEd update and must be verified before a district relies on it.
- Review the policy at least annually before the school year begins.
- Reopen review when state law, state model guidance, federal privacy guidance, or disability-law precedent changes.
- Reopen review when an approved vendor changes data terms, model capabilities, training-data practices, age restrictions, or subcontractors.
- Reopen review after a significant complaint, grievance, OCR-style inquiry, procurement dispute, or discipline appeal involving AI.
- Keep a version history showing what changed, who approved it, and when staff were retrained.
Version control is not clerical decoration. It tells counsel which rule applied on the date of the assignment, which vendor terms were in force, and whether staff had notice of a changed procedure.
What a Defensible 2026 Policy Can Actually Do
A defensible policy does not eliminate judgment. It makes judgment reviewable. The remedial-reading teacher knows when AI use is an accommodation question. The assistant principal knows a detector score is not enough. The technology director knows which tools can receive student data. Procurement knows which contract terms must be checked. Counsel knows which record to ask for when the first complaint arrives.
That is the minimum standard for 2026 student AI use policies in schools: not a broad statement that AI should be used responsibly, but a set of enforceable clauses that produce consistent decisions under disability law, privacy law, academic-integrity procedures, vendor controls, staff-training duties, and ongoing model-change risk.
References
- Ohio’s July 1, 2026 School AI Policy Deadline, KJK Law, June 12, 2026, https://kjk.com/2026/06/12/ohios-july-1-2026-school-ai-policy-deadline/
- Teen and Young Adult Perspectives on Generative AI, RAND Corporation, March 2026, https://www.rand.org/pubs/research_reports/RRA4742-1.html
- William A. v. Clarksville-Montgomery County School System, United States Court of Appeals for the Sixth Circuit, 2025, https://www.ca6.uscourts.gov/
- Generative AI Guidelines, Columbus City Schools, March 2026, https://www.ccsoh.us/
- GPT detectors are biased against non-native English writers, Patterns, 2023, https://doi.org/10.1016/j.patter.2023.100779
- AI Legislation Tracker, FutureEd, updated July 13, 2026, https://www.future-ed.org/
- Artificial Intelligence 2026 State Legislative Update, MultiState, 2026, https://www.multistate.us/
Grounded in
This procedure is grounded in William A. v. Clarksville-Montgomery County School System, 6th Cir. 2025, independent of any single documented case. See the Regulation tracker for the governing text.
Cases this step would have prevented
No cases have been explicitly linked to this checklist yet. See Risk Digest for documented incidents generally.
← Back to WorkflowsReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this workflow checklist should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →