Student Images, Deepfakes and the New Digital Safety Reality for Schools
In May 2025, we became aware of a deeply concerning emerging threat affecting schools: the use of publicly available student images to create...
4 min read
9ine
:
October 2, 2026
AI is already part of everyday school life. Teachers use it to plan lessons and draft reports, pupils come across it in the apps they use for homework, and suppliers are adding AI features to tools schools bought years ago. For most schools, the question is no longer whether AI needs governing. It is where to start, who needs to be involved, and how to turn good intentions into something that works in practice.
Many schools have responded by writing an AI policy. That is a sensible first step, but on its own it rarely changes much. Below are the five gaps we see most often when schools try to govern AI, and what can be done about each.
In most schools, AI arrived informally. A teacher signs up for a free tool to save time on marking. A department starts using a chatbot for revision resources. An existing platform switches on a new AI feature in a routine update, and nobody is told.
None of this is unusual, and much of it is well intentioned. The problem is visibility. If a school cannot say which AI tools are in use, by whom, for what purpose and with what data, it cannot make informed decisions about any of them. Schools cannot govern what they cannot see.
AI touches teaching and learning, safeguarding, technology, data protection and leadership accountability all at once. Responsibility for those areas rarely sits with one person.
Academic leads tend to focus on educational value and innovation. Safeguarding leads think about online safety and digital harms. IT teams consider systems, access and security. Whoever leads on privacy is looking at personal data, impact assessments and vendor assurance. Each perspective matters. The problem starts when they operate separately, because every decision is then made with only part of the picture.
Often, "AI" is simply handed to one individual as an addition to an existing role. That person is then expected to understand and act on every one of those perspectives alone.
A written AI policy sets out intent. What it cannot do by itself is answer the operational questions staff face every week. How do I ask to use a new tool? Who decides? What happens if a tool I already use adds an AI feature? Where is the decision recorded?
Without the processes that sit behind it, a policy tends to live in a shared drive while practice carries on around it. Schools do not just need an AI policy. They need a governance structure capable of putting it into operation.
When a member of staff asks to use a new AI tool, the decision should weigh educational value alongside safeguarding, privacy, cyber security and what the supplier can actually evidence about how it handles data. In many schools, that assessment happens informally, if at all.
The result is inconsistency. One request is approved after a quick conversation, another is refused for reasons nobody wrote down, and a third is never formally considered. When a parent, governor or inspector later asks how a decision was made, there is little to show.
Staff, pupils, parents and governors all need to understand how AI is used in school, but they need different things. Teachers need practical guidance on acceptable use. Pupils need age-appropriate AI literacy. Parents increasingly want to know which tools their children are using and why. Governors need enough understanding to provide meaningful oversight.
Where this is left to chance, expectations drift and confidence in the school's approach weakens.
There is no single correct AI governance model, and every school starts from a different position. These steps, however, apply almost everywhere:
We created the 9ine AI Governance Academy for schools that know AI needs governing but want a structured way to do it.
The Academy is a guided implementation programme that runs across the academic year. Rather than a set of standalone training sessions, it takes schools through a connected journey: from establishing an AI governance baseline, through risk and opportunity, strategy and policy, acceptable use, recording AI use, and assessment and approval, to AI literacy and longer-term planning. Each stage builds on the last.
It is built around 9ine's Diamond Formation, our model for bringing academic, technology, safeguarding and privacy perspectives together under leadership accountability. Schools take part as a governance team rather than sending one person to be trained, so decisions are shaped by the people who will need to own them.
Between live sessions, schools apply what they have covered within their own environment. That work is supported by the 9ine platform, including the AI Readiness Toolkit, alongside practical templates, access to completed vendor assessments from the 9ine Vendor Library, and time with a named 9ine Data Privacy & AI Consultant. By the end of the programme, schools will have worked towards the structures, processes and documentation their approach needs, along with a 12-month AI governance roadmap to keep it moving.
Find out more about the 9ine AI Governance Academy.
For further guides, templates and insights, explore our resources library. If you would like to discuss your school's approach with our team, book a meeting.
In May 2025, we became aware of a deeply concerning emerging threat affecting schools: the use of publicly available student images to create...
New vendors are entering the sector with AI-first products. Existing vendors are adding AI features into platforms schools already use. Some are...
KCSIE 2026 is confirmed. AI-generated deepfakes are now an explicit safeguarding risk. Here is what your school must do before 1 September 2026.