When students use AI tools — for homework, for writing, for research — they provide personal information to systems that retain it. The district may have approved the tool without reviewing what the tool actually does with what students type into it. FERPA requires districts to protect student records. Most AI terms of service are written to be broad enough to use student input as training data. The gap between those two facts is a liability.
AI models generate confident, authoritative-sounding text that is sometimes wrong. Students who trust it without verification produce work built on errors. More acutely: deepfake audio and images are now accessible to any student with a smartphone. Realistic fake content involving staff or other students can be produced, shared, and go viral within a school community before anyone has the vocabulary to address it. Districts that have a response plan in place before this happens are in a different position than those improvising.
More than 70% of US teens have used an AI companion chatbot. These systems are designed to be agreeable, available, and emotionally responsive — which makes them attractive to adolescents in ways that don’t develop the same skills as human relationships. The concern is not exposure to an AI; it is the displacement of practice in tolerating social friction, building self-reliance, and sitting with difficulty. Those are learned capacities, and they require repetition.
Many AI vendors train their models on user input by default, unless explicitly opted out. Superintendents and curriculum directors approving new tools are often reviewing the tool itself — not the data practices embedded in the terms of service. A student’s written work, feedback to a teacher, or creative project may be enriching a commercial model the district had no knowledge of, let alone agreement with.
Heavy chatbot use correlates with reduced willingness to engage with uncertainty, discomfort, and human unpredictability. Students who outsource their processing to an AI — for emotional support, for decision-making, for coping — may be developing dependency rather than resilience. This is not a hypothetical risk; mental health researchers are actively documenting it. Schools are in the relationship business, which means this is squarely within their scope.
NIST, Google’s SAIF, and the major consumer guides were designed for enterprises and individuals — not for institutions responsible for minors, governed by school boards, and operating under a distinct legal framework. Applying them to a school district requires translation work that most superintendents don’t have time for and most vendors don’t provide.
Designed for enterprise risk management. Assumes a legal team, a compliance function, and dedicated security staff. No K-12 district of under 5,000 students has any of those.
A framework for AI builders and deployers. Addresses model security and supply chain risk — not the human and relational risks that schools actually face when students use AI.
Written for individuals making personal decisions. Institutional governance — board authority, staff accountability, incident reporting — is outside their scope.
Built from scratch for K-12. Addresses the actual governance decisions a school board makes, the actual risks students and staff face, and the actual policy language a district can adopt and defend.
Clear expectations let students use AI as a legitimate tool rather than a tool they have to hide. Disclosure norms replace detection games. Students learn to make intentional choices about when AI helps them and when it replaces the learning they actually need.
Teachers operating without guidance are making individual calls that should be institutional ones. A policy gives them a framework they can apply consistently and a safe harbor when they act in good faith within it. It also gives them something to say to parents who ask.
When an incident occurs, the question is whether the district had reasonable safeguards in place. A written, adopted policy is evidence of diligence. The absence of one is evidence of neglect, regardless of what any individual teacher did or didn’t do.
A board that has made a deliberate, documented decision about AI has fulfilled its governance obligation. A board that has not is exposed — to parent pressure, to media, and to the liability that follows when something goes wrong in a space they were warned about and chose not to address.
Most incident reporting mechanisms are disciplinary by design. Students associate reporting with getting someone in trouble — so they don’t report. The Safety Huddle is a non-disciplinary reporting structure built into the Windrose AI policy framework.
When a student encounters something that worries them — AI-generated content about a classmate, a tool behaving unexpectedly, something that felt wrong — the Safety Huddle gives them a path to surface it that is not connected to punishment. It protects the student, produces information the district needs, and creates a culture of transparency rather than concealment.
Student notices something concerning — AI content, unexpected tool behavior, a classmate’s use
Tells a trusted adult through the Safety Huddle — a designated, non-disciplinary report path
Staff receives the information, responds appropriately, and the policy determines next steps — not an improvised judgment call
Reporting is not punished. Silence is what the policy is designed to prevent.
Scope scales with district size — a single-school rural district and a large multi-building district need different things. Contact us to discuss what your district needs.
Under 300 students
300–1,500 students
1,500–5,000 students
5,000+ students
Single policy, combined board/staff session, one communication template
Policy with building-level guidance, separate board and staff sessions
Full framework, board presentation, training for up to 3 buildings, two communication templates
Full framework across all buildings, training series, complete communication package. Scoped per engagement.
Review of existing draft · gap report · board-ready recommendations
Quarterly currency review · new-tool vetting · one refresher/year · email access