AI governance and the new Ofsted report card

AI governance in schools

Ofsted’s renewed education inspection framework has been in use since 10 November 2025. An updated inspection toolkit took effect on 7 September 2026. For state-funded schools in England, there are six core graded evaluation areas, with additional grades for early years and post-16 provision where applicable.

AI doesn’t have a category of its own in the inspection framework. There’s no separate grade or prescribed AI-specific checklist.

So where does AI fit? The clearest governance link is through leadership and governance, although AI may also be relevant to safeguarding, curriculum and teaching, inclusion, and personal development and wellbeing.

This article looks at where AI may be relevant within the framework, the questions schools may want to consider and the practical evidence that can help heads, deputies and governors explain their approach clearly.

The new report card in brief

The five grades are exceptional, strong standard, expected standard, needs attention and urgent improvement. Expected standard means a school is meeting the standard described in Ofsted’s toolkit. Leaders should treat it as a clear baseline and keep evidence of how they monitor practice and respond when something needs attention.

For state-funded schools, the six graded evaluation areas are:

  • achievement
  • curriculum and teaching
  • inclusion
  • leadership and governance
  • attendance and behaviour
  • personal development and wellbeing

Safeguarding is reported separately as met or not met.

Where AI may be relevant

AI can touch several parts of the framework. Under leadership and governance, this might include oversight of AI use, the school’s approach to risk, and how decisions about new tools are made. In curriculum and teaching, it may come up where staff use AI to support learning. It can also connect with personal development and wellbeing, through how pupils are helped to use AI safely and responsibly.

Safeguarding matters here too, particularly where concerns involve AI-generated child sexual abuse material, manipulated or non-consensual intimate imagery, impersonation, harmful chatbot interactions or AI-facilitated grooming.

Questions governors may want to consider

Ofsted does not prescribe a specific set of AI questions for school inspections. However, if AI is having a meaningful impact on teaching, assessment, safeguarding or school decision-making, inspectors may want to understand how it is being managed. These prompts can help governors explain their school’s approach in practical terms.

How does the board keep informed about the school’s use of AI?

A recent briefing or discussion covering how AI is being used by staff and pupils, which tools have been approved and where the main opportunities and risks lie gives governors something concrete to point to. Meeting minutes can also show the questions raised and any follow-up actions agreed, demonstrating that the board has enough information to offer constructive challenge.

Where does AI sit within the school’s existing priorities, policies or risk-management arrangements?

AI-related actions might appear in the school development plan, digital strategy, risk register or another established plan. The most useful records will make clear who is responsible, what needs to happen and when progress will be reviewed.

What oversight does the board have of the AI tools being used?

Where AI tools are in use, governors may want to understand how they are selected and approved. This could include consideration of educational purpose, safeguarding, accessibility, data protection, supplier terms, value for money and what happens to school data when a contract ends. Schools may also consider whether a tool could disadvantage particular groups, whether it is accessible to pupils and staff with disabilities or SEND, and how potentially inaccurate or biased outputs will be identified and managed. A proportionate tool register or approval record can help provide that overview.

How does the school manage academic integrity risks associated with AI?

Leaders should be able to explain the expectations set for pupils and staff, how concerns are handled and how assessment is designed to give teachers a reliable picture of what pupils know and can do.

Who coordinates decisions about AI, and how is appropriate oversight maintained?

Responsibility may sit with one senior leader or be shared across curriculum, safeguarding, data protection and IT roles. What matters is that responsibilities are clear and relevant colleagues work together. Oversight can fit within an existing committee or reporting cycle, giving governors opportunities to ask questions, review progress and agree further action.

Questions senior leaders may want to consider

For heads and deputies, the conversation is more likely to focus on how the school’s approach works day to day and whether written guidance matches what staff and pupils understand and do in practice.

How are expectations for acceptable AI use communicated to staff and pupils?

This might sit in a dedicated AI policy or across existing policies covering acceptable use, teaching and learning, assessment, safeguarding and data protection. Guidance could address approved uses, information that must not be entered into AI systems, checking AI-generated outputs, pupil use and routes for reporting concerns. It should be reviewed regularly to reflect KCSIE 2026 and the tools currently in use.

How are the data-protection implications of AI tools assessed before they are introduced?

A clear process might start with a record of the AI tools in use or under consideration. Initial screening can identify how personal data will be processed and whether a full Data Protection Impact Assessment (DPIA) is required. Leaders should be able to explain when the DPO becomes involved, how supplier information is checked and how any concerns are addressed before a wider rollout.

How is staff AI use supported and governed?

Useful evidence might include practical training, clear guidance on approved tools and straightforward routes for seeking advice. Staff need to know which information they can enter, when an AI-generated output needs checking and where professional judgement remains essential. Schools can use surveys, procurement records, system reporting or proportionate checks to build a clearer picture of use and identify where further support is needed.

How are parents informed where AI tools affect their children or use their data?

This can use the channels the school already relies on: the website, privacy information or a letter about a pupil-facing service. Where AI tools use personal data, the school’s privacy notice should explain what data is used and how it is used. Depending on the tool and its use, additional communications can explain its purpose, the safeguards in place and who parents can contact with questions. Clear, accessible language will help families understand what the use of AI means in practice.

How does the school respond to AI-related safeguarding risks?

AI should sit within the school’s established safeguarding arrangements. Staff and pupils need to know how to report concerns involving harmful generated content, explicit imagery, impersonation or AI-facilitated contact. The designated safeguarding lead (DSL) should understand the relevant escalation routes, while online-safety risk assessments and filtering and monitoring reviews should reflect the risks that are relevant to the school’s context.

Bringing your AI governance records together

Ofsted does not require a separate AI evidence pack, and schools should not create inspection-specific paperwork. However, making existing records easy to locate can help leaders explain how their approach works in practice.

There is no need to create a large folder of paperwork. A simple, up-to-date collection might include:

  • Written guidance on acceptable AI use, reviewed following KCSIE 2026 and connected to relevant safeguarding, data protection and assessment policies.
  • A register of the AI tools being used, covering their purpose, who is responsible for them, who uses them, the data involved, equality and accessibility considerations, and their approval or DPIA status.
  • Governing board or committee minutes showing that AI has been discussed, including questions raised and any actions agreed.
  • Staff CPD records covering safe and acceptable use, data protection, checking AI-generated outputs, academic integrity and safeguarding concerns.
  • Relevant parent communications, such as a letter, privacy notice or website policy covering a pupil-facing tool.
  • A clear record of who coordinates AI-related decisions and how updates or concerns are reported through the school’s existing leadership and governance arrangements.

What matters most is that the records tell the same story. The school’s guidance sets out what is expected, day-to-day practice reflects that guidance, and governance records show that leaders are asking questions and following up where needed.

There is no need for elaborate paperwork. If you have identified a gap, record what needs to happen, who is responsible and when it will be reviewed. Follow through on the action and check that it is working, addressing safeguarding concerns promptly and making sure relevant legal requirements are met.

A few focused hours can reduce inspection anxiety

For many schools, most of this material already exists across policies, procurement files, DPO records, training logs and governor minutes. A short review involving the AI lead, DSL, DPO, IT lead and a member of SLT can bring it together and confirm where updates are needed.

Everything ICT can help schools and trusts source suitable AI, safeguarding, data-protection and ICT support through a compliant procurement route. If you would like practical help reviewing your requirements and finding an appropriate supplier, contact our team.