"Is this AI tool allowed?" is now one of the most common questions school IT teams get. Controlling AI access is not one switch — it is several layers working together. Here is how the layers fit, and a simple process for deciding what to allow.

The layers of control

1. Web filtering

Your filtering provider categorises websites, often including an AI category. Schools can allow approved AI tools and block others, and set different rules for staff and pupils or for different year groups.

2. Microsoft 365 admin settings

If you use Microsoft 365, admins control access to Copilot Chat and paid Microsoft 365 Copilot, which users get it, and retention and audit settings. See setting up Copilot education accounts.

3. Google Workspace admin settings

In Google Workspace for Education, admins turn Gemini on or off by organisational unit — for example staff only — and manage related settings. See is Gemini free for teachers?

4. Device management

Mobile device management for iPads and Chromebooks controls which apps and extensions can be installed. See AI tools for school Chromebooks and iPads.

5. Sign-in and app approvals

Many AI tools offer "sign in with Microsoft" or "sign in with Google". Admins can control which third-party apps staff and pupils can grant access to their school account.

The decision process

Technology is the easy part. The hard part is deciding. A simple process:

  1. Request: a member of staff asks for a tool, stating the purpose.
  2. Check: IT and the DPO review privacy terms, data location and any DPIA needs. For pupil-facing tools, the DSL checks it against the product safety expectations.
  3. Decide: approve for staff, approve for pupils, or decline, with a reason.
  4. Record: add it to the approved tools list in your AI policy.
  5. Configure: set filtering and account settings to match.

Want a straight answer for your school?

Ask me anything about AI in your school — policy, tools, training or safeguarding. I reply personally, usually the same day.

Common mistakes

For trusts

In a multi-academy trust, central decisions and a shared approved list avoid every school repeating the same checks. See an AI rollout plan for multi-academy trusts.

Tie it to safeguarding

AI access decisions belong in your annual filtering and monitoring review. See KCSIE filtering and monitoring for AI.

A sample approved tools list

ToolStaffPupilsPersonal data?
Copilot Chat (school account)YesSecondary sixth form pilot onlyOnly as the policy allows
Oak AilaYesNoNo
CuripodYesTeacher-led lessonsFirst names only
Personal ChatGPT accountsNot for school workNoNever

This is an illustration — your list should reflect your school's own decisions and DPIAs.

Handling new AI features in existing apps

AI features now appear inside tools schools already use — search engines, learning platforms, office software. Ask suppliers to tell you when they add AI features, check whether they can be switched off, and review them against your policy like any new tool.

Frequently asked questions

How can schools control which AI tools are used?

Through web filtering, Microsoft 365 and Google Workspace admin settings, device management, and controlling third-party app access, all tied to an approved tools list.

Can schools turn off Gemini or Copilot?

Yes. Admins can enable or disable Gemini by organisational unit in Google Workspace, and control Copilot access in Microsoft 365.

Should schools block all AI tools?

Blocking everything usually pushes staff to personal accounts and devices. Approving a small set of protected tools is safer.

Who decides which AI tools are approved?

A simple process involving IT, the data protection officer and the DSL, recorded in the school's AI policy.

How often should AI access be reviewed?

At least annually as part of the filtering and monitoring review, and whenever significant new tools or features appear.

← Back to all articles Ask me a question →