The recently published report, Artificial intelligence and children’s rights: A narrative review of the evidence, by Smera Jayadeva and Sonia Livingstone, provides one of the most comprehensive overviews yet of how AI is already affecting children’s lives.
Its central message is clear. Children are not simply future users of AI. They are already living in environments shaped by AI systems, whether they know it or not. They encounter AI through chatbots, learning tools, recommendation systems, image generation, personalised content, digital advertising, school platforms, assessment tools, safeguarding systems, public services and the wider data infrastructure that increasingly determines how institutions make decisions.
The report is organised around the 2025 Joint Statement on Artificial Intelligence and the rights of the child, co-led by the International Telecommunication Union, the UN Committee on the Rights of the Child and UNICEF. It examines evidence across eleven themes, including child safety, data protection, accountability, transparency, best interests, non-discrimination, child participation, environmental impact, education and capacity building.
Although the report is global in scope, the implications for schools are immediate and practical. It shows that AI creates risks across the full lifecycle of design, development, deployment and use. It also shows that governance remains too reactive, too adult-centred, and too dependent on general principles that are not yet consistently translated into operational safeguards for children.
Most schools are trying to decide which tools staff can use, what students should be taught, what parents need to know, whether a vendor can be trusted, what data is being processed, whether a DPIA is required, how digital/safeguarding risks should be managed, and what evidence should be reported to leadership, governors, trustees, inspectors or accreditors.
That is why AI governance has to move from commentary to an operating model much like the Diamond Formation.
One of the most important points in the report is that AI affects children even when they do not directly interact with an AI tool. This is particularly relevant to schools. A student may never open a chatbot, but they may still be affected by AI in a learning platform, behaviour system, safeguarding tool, assessment product, accessibility feature, plagiarism detection service, admissions process, wellbeing tool, filtering system or analytics dashboard. The risk is not only in the visible interface. It is also in the systems behind the interface, the data used to train and operate them, the assumptions embedded into their design, and the decisions made by adults who rely on their outputs.
This changes the governance question for schools. It is not enough to ask whether students are allowed to use ChatGPT. That is only one part of the picture. Schools also need to understand where AI exists in the technology estate they already use, how vendors are adding AI into existing products, what data is being processed, whether children’s data is used to improve or train models, and whether the school has meaningful control over how these systems operate.
The report is particularly clear on child safety. It highlights the growth of AI-facilitated child sexual abuse material, nudification tools, deepfakes, cyberbullying, AI companions and emotionally adaptive chatbots. These are not theoretical risks. The evidence base now shows real-world harms, including the use of generative AI to manipulate children’s images, create sexualised content, simulate relationships, encourage dependency, and expose children to unsafe or inappropriate interaction. We have previously written about these issues here.
For schools, this has two consequences. First, AI has to be treated as part of digital safeguarding. It is not a separate innovation topic that sits only with teaching and learning or IT. It belongs in the same conversation as online safety, peer-on-peer abuse, harmful content, filtering and monitoring, image sharing, wellbeing, dependency, manipulation and child protection.
Second, schools need to think carefully about learner-facing AI systems. Any AI product that interacts directly with children requires scrutiny beyond whether it is useful or engaging. The school needs to consider whether the system is age-appropriate, whether it can prevent harmful content, whether it can identify safeguarding concerns, whether it encourages overuse, whether it simulates friendship or emotional intimacy, whether it collects personal information, and whether appropriate adults are alerted when risk emerges.
This is not about stopping AI in education. It is about recognising that children are not adult users. Their cognitive, emotional and social development matters. Their ability to understand systems, question outputs, protect their data and resist manipulative design is still developing. That is why AI products used in schools need to be reviewed through a child-centred lens.
The report also places significant emphasis on privacy and data protection. It makes the point that AI systems are built on data, and that children’s data is particularly sensitive because it can persist, be reused, be combined with other datasets, and affect children long after the original data was collected.
This is highly relevant to schools because schools process large volumes of children’s personal data. They hold information about identity, attendance, behaviour, learning, health, special educational needs, safeguarding, family circumstances and wellbeing. Some of this data is ordinary personal data. Some is special category data. Some may be extremely sensitive in context, even where it does not neatly fit a legal label.
When that data is shared with AI-enabled products, the governance burden increases.
Schools need to understand what data is collected, why it is needed, how long it is retained, whether it is used for model training or product improvement, where it is processed, which sub-processors are involved, what the contractual position is, and whether the vendor is acting only on the school’s instructions or also using data for its own purposes.
This is where the report aligns closely with the direction of travel in education technology regulation and assurance. Schools are expected to know how children’s information is used. They need to be able to explain that use to parents and students. They need evidence that privacy risks have been assessed. They need to ensure that AI adoption does not undermine data minimisation, transparency, rights, security or accountability.
In practical terms, that means AI governance needs to connect directly to Records of Processing, DPIAs, vendor assessments, privacy notices, retention schedules, contracts and incident management.
If those areas sit separately, the school’s AI governance will be fragmented before it starts.
A repeated theme in the report is the gap between principles and practice. Many AI frameworks refer to transparency, accountability, fairness, safety and human oversight. The problem is that these principles are often not operationalised in ways that are measurable, auditable or child-specific.
For schools, this matters because vendor assurances can sound convincing without giving the school the evidence it needs. A supplier may say its tool is safe, responsible, ethical, secure or privacy-preserving. But those statements need to be tested against the realities of the school environment.
What is the tool being used for? Which children will use it? What age are they? What data is processed? Does the AI interact with learners directly? Can it generate unsafe content? Does it include monitoring? Does it alert school staff? Does it use personal data for training? Has the supplier carried out appropriate testing? Can the school configure the system? What happens when something goes wrong?
This is why vendor management is now a core part of AI governance.
Schools cannot reasonably be expected to build or audit AI models themselves. But they can create a structured process for asking the right questions, reviewing the evidence, recording the decision, identifying residual risk and escalating issues where necessary.
The decision to use an AI-enabled tool should not sit only with the person who wants to use it. Nor should it sit only with IT. It needs academic, safeguarding, privacy and technology input, because each of those functions sees a different part of the risk.
The report also spends significant time on the concept of the best interests of the child. This is important because it is often misunderstood. It is not simply a broad statement that something is good for children. It is a decision-making principle that should guide how competing rights, risks and benefits are considered.
There may be a strong academic case for an AI tool. It may reduce teacher workload, provide personalised practice, support feedback or increase access for students with additional needs. But there may also be privacy risks, digital/safeguarding risks, risks of over-reliance, risks to assessment integrity, risks of bias, or risks that the tool is not suitable for younger children.
The task is not to treat innovation and safety as opposites. The task is to assess the benefit and the risk together, which is another reason why every school should have an operationalised Diamond Formation set of roles.
The report is clear that AI literacy is essential. Children need to understand AI not simply as a tool they can use, but as part of the environment in which they are growing up. They need to be able to question outputs, recognise bias, understand misinformation, protect personal information, identify harmful or manipulative design, and know when to involve a trusted adult.
For schools, AI literacy cannot be confined to computer science. It belongs across the curriculum, pastoral education, safeguarding, staff training and leadership development.
Students need AI literacy because they are already using these tools. Teachers need AI literacy because they are increasingly expected to guide, supervise and model responsible use. Safeguarding teams need AI literacy because AI is now part of the risk environment for children. IT teams need AI literacy because AI changes the risk profile of systems and vendors. Privacy leads need AI literacy because AI changes how data is collected, inferred, stored and reused. Senior leaders and governors need AI literacy because they are accountable for the school’s approach.
Another important theme in the report is child participation. Children are often treated as passive recipients of protection, rather than people whose views should shape the systems, policies and safeguards that affect them.
This is particularly relevant to schools because schools have a direct relationship with children and young people. They are well placed to listen to students, understand how they are using AI, identify the risks they are already seeing, and involve them in building expectations around responsible use.
Students will often know where AI is being used before adults do. They will know which tools are popular, which uses are normal, where peer pressure exists, where misuse is happening, and where adults’ assumptions are out of date.
This does not mean students should decide the school’s AI strategy. But it does mean that student voice should inform it.
AI governance that ignores students will miss important evidence. It may also create rules that are impractical, poorly understood or disconnected from how young people are actually using technology.
The report’s global evidence base leads to a very practical conclusion for schools: the risks and benefits of AI cannot be managed by one person, one policy or one department.
AI adoption touches several areas at once. It affects teaching and learning, safeguarding, privacy, cyber security, procurement, contracts, staff training, parent communication, student wellbeing, inclusion and governance reporting. This is why schools need a cross-functional approach.
At 9ine, we describe this as the Diamond Formation: academic, safeguarding, technology and privacy working together to govern AI and emerging technology. Each function brings a different perspective. Each is necessary. Without one of them, the school risks making decisions that are either too narrow, too slow, too permissive or too disconnected from practice.
The report strengthens this argument because it shows how AI risks are interconnected. Child safety cannot be separated from privacy. Privacy cannot be separated from vendor management. Vendor management cannot be separated from contracts. Contracts cannot be separated from procurement. Procurement cannot be separated from educational purpose. Educational purpose cannot be separated from safeguarding and inclusion.
9ine helps schools turn AI governance from a set of concerns into an operating model. The 9ine platform connects the areas that schools need to manage if they are going to use AI safely, lawfully and effectively. Vendor Management helps schools assess suppliers across privacy, AI, safeguarding and cyber risk. Privacy supports Records of Processing, DPIAs, incidents, retention and accountability. Application gives staff a clear view of approved tools and guidance. Contract connects supplier risk to cost, renewal and obligations. Governance turns findings into assigned, trackable and reportable action. Academy LMS supports staff training across AI, privacy and cyber security. This matters because the work cannot sit in disconnected documents.
Alongside the platform, 9ine’s services help schools build the capability and assurance needed to manage AI in practice. This includes AI governance consultancy, vendor assessment support, privacy support, cyber security services, training, workshops and the Diamond Sprint: a facilitated working day that helps schools move from AI discussion to governed delivery.
For more information on our platform or services, get in touch.