What Is Your AI Problem?

The AI Tools Schools Are Using This Fall Are Also Cybersecurity Decisions

By Dr. Jamiylah Jones, CEO of Creative Transformations · Sep 9, 2026 · 11 min read

At the beginning of a school year, educators make hundreds of decisions about the tools they will use to get their work done. A teacher finds an AI platform that makes lesson planning easier. A department experiments with a chatbot that can help draft feedback. A counselor uses an AI assistant to organize a difficult communication, while a school leader tries a tool that can summarize information more quickly. Most of those choices feel instructional, administrative, or practical because the person using the tool is trying to solve a problem that already exists in the work.

What often receives less attention is what happens to the information required to make the tool useful. A planning assistant may work better when it knows more about the students in a class. A writing tool may produce a stronger draft when it receives details about the situation being described. A platform may offer more tailored feedback when a student's work is uploaded directly. At that point, the question is no longer only whether the technology helps someone do the work. The school also needs to know what information entered the system, where it went, who can access it, how long it is retained, and whether that use was reviewed before it became part of someone's routine.

This is becoming more important as AI tools move into ordinary school work because many of them do not enter through the same process schools have traditionally used to adopt technology. A district may spend months reviewing and purchasing a major instructional platform, while an individual educator can begin using an AI tool during a planning period simply by creating an account. A free tool can become part of someone's workflow before a principal, curriculum leader, technology department, or privacy officer knows it is being used.

Every AI tool that receives student or staff information becomes part of the school's data and cybersecurity environment, even when the tool was adopted for an instructional or administrative reason.

Schools do not need to treat AI governance and cybersecurity as the same responsibility. They do, however, need to recognize that the two now overlap around some of the same questions: what information is being shared, where that information is going, who has access to it, how long it remains there, and who is responsible for deciding whether that use is appropriate.

Consider what this can look like for a teacher. A teacher finds an AI tool that can create several versions of a reading activity for students who need different levels of support. Instead of spending part of the evening creating those materials by hand, she can generate a useful starting point in a few minutes, revise it, and spend the remaining time reviewing student work or preparing for a small group. The tool is solving a real problem, and the teacher may be using it thoughtfully.

The concern begins when the tool becomes more useful if the teacher provides more information. She may enter student names, reading levels, assessment results, accommodations, or information copied from a class roster because those details help the system produce materials that more closely match what her students need. She may have no reason to believe she is doing anything inappropriate, especially if the tool is accessible on a district device and no one has explained what information can or cannot be entered. The instructional result may be useful, but usefulness does not answer what happened to the student information after it was submitted.

This is not primarily a teacher problem. If an educator is expected to determine alone whether a company stores prompts, retains uploaded documents, uses submitted information to improve its products, allows information to be deleted, or has been reviewed for a particular type of student data, the school has already left an important responsibility unclear. Teachers need enough guidance to make the decisions that belong to their role, and they need the organization to make the decisions that require technical, privacy, legal, or procurement expertise.

The same issue can appear during a classroom walkthrough. A principal moves through several classrooms and notices different AI tools open on teacher screens. One teacher is using a district-approved platform, another is experimenting with a tool a colleague recommended, and another found something over the summer that helps generate feedback more quickly. All three educators may be using the technology for reasonable instructional purposes, but the principal may not know which tools have been reviewed, whether student work is being uploaded, what information the companies retain, or whether those particular uses are covered by district expectations.

The fact that a tool is accessible on a school device does not necessarily mean the district has approved every way an educator might use it. A product may be appropriate for brainstorming generic lesson ideas and inappropriate for entering identifiable student information. Another may be acceptable for staff use but not for direct student accounts. Without clear guidance, those distinctions are easy to miss because the same tool can move from a relatively simple use to a much more sensitive one depending on what someone enters into it.

Counselors and student-support staff face an even more sensitive version of the same issue. A counselor may use an AI assistant to help organize a parent communication about a complicated student situation, and the tool may make the message clearer and easier to write. The privacy and security question depends on what information the counselor entered to produce that draft. If the prompt contains details about a student's mental health, family circumstances, disability, behavior, attendance, or another sensitive situation, the school needs to know whether that system is appropriate for receiving those details and how the information is handled after it is entered.

Similar questions arise in special education, intervention, and student-support work. Staff may use AI to summarize notes, organize information across documents, create a first draft, or identify patterns that deserve closer attention. Those uses can make complicated work more manageable, but they can also move sensitive information into systems that the adults involved have never been asked to evaluate. The issue is not whether AI can be useful in those settings. It is whether the school has decided what information those tools are permitted to receive before staff are left to make that judgment individually.

Why It Matters

Schools have traditionally been able to place much of the responsibility for cybersecurity with technology departments because many technology decisions moved through a centralized process. AI makes that arrangement more difficult because many tools can be adopted without a purchase order, formal implementation, or districtwide rollout. An educator can begin using one during a planning period, a department can experiment after someone shares a link, and a free version can become part of a daily workflow long before anyone thinks to include it in the district's technology inventory.

That changes what a school needs to know. A technology department can protect and monitor the systems it manages, but it is much harder to evaluate information moving through tools the district does not know people are using. At the same time, curriculum and instructional leaders may be asking whether an AI tool improves planning, supports differentiation, strengthens feedback, or reduces teacher workload. Those are appropriate questions, but they do not answer whether the tool is appropriate for the information required to produce those benefits.

A tool can be instructionally useful and still require additional review before student information enters it. A platform can save a teacher several hours each week without being appropriate for confidential information. A counselor can receive an excellent draft from an AI assistant while still using the wrong system for the information required to produce that draft. Instructional value and information security are different considerations, but schools increasingly have to examine them as part of the same decision.

Responsibility becomes unclear when those conversations remain separate. Technology staff may assume that instructional departments reviewed the tools teachers are using, while instructional leaders may assume that anything available on a district network or device has already passed a security review. Teachers may reasonably assume that if a tool were inappropriate for student information, someone would have told them, and a principal may not know whether questions about retention, access, or vendor practices belong to technology, curriculum, data privacy, procurement, or another office.

Everyone can be acting reasonably while no one has a complete picture.

That lack of clarity matters for every student, but the consequences can be greater when the information involves a disability, an IEP or 504 plan, counseling or mental health concerns, discipline, academic performance, family circumstances, language needs, or other information students and families expect schools to handle carefully. The concern is not limited to whether someone outside the district might gain unauthorized access. Schools also need to know which companies are receiving information, what those companies are permitted to do with it, how long it remains in their systems, and whether the school can retrieve or remove it when necessary.

There is also a larger issue of family trust. Families provide schools with significant amounts of information about their children because educators need that information to teach, support, evaluate, and protect them. Parents may reasonably expect the school to know which systems receive that information and why. A district cannot promise that no security incident will ever occur, but it should be able to explain the process it uses to decide which tools can receive student information and what protections are expected before those tools become part of school practice.

Schools can begin making this clearer without purchasing another product or creating an entirely new department. District leaders can start this month by building an inventory of the AI tools people are actually using, not only the products the district purchased or formally approved. Teachers, counselors, administrators, instructional coaches, special educators, and student-support staff should be asked what has become part of their daily work, and leaders should make clear that the purpose of asking is to understand current practice rather than punish people for answering honestly.

How that conversation is handled matters because a district needs an accurate picture more than it needs an appearance of compliance. If staff believe acknowledging an unapproved tool will immediately create a disciplinary problem, some of the tools leaders most need to know about may remain invisible. The first goal should be understanding what is already happening so the school can make better decisions about what should happen next.

Technology, data privacy, instructional, and student-services leaders can then review that inventory together. They do not need to begin by evaluating every feature of every product. They can begin with the tools that receive student or staff information and determine what data enters the system, where it is stored, who can access it, what the company says about retention and other uses of submitted information, whether the district can delete or retrieve it, and whether the intended use matches what the district has actually approved.

Building leaders can make the expectations easier for staff to use during the school day. In a faculty meeting or beginning-of-year communication, principals can make sure educators have a current list of approved AI tools, clear examples of information that should not be entered into an unapproved system, and one place to ask when they are unsure. The guidance should distinguish between types of use because telling staff that a tool is simply approved can create another problem if only certain uses have been reviewed.

A teacher should be able to understand whether a tool is appropriate for generic planning, student work, identifiable student information, or direct student accounts without having to interpret a company's privacy terms alone. The goal is not to turn teachers into cybersecurity specialists. It is to make the information they need for daily decisions clear enough that they do not have to guess.

Counselors, special educators, interventionists, and other student-support staff can use an existing team meeting to identify the information they handle that requires additional care. Their work often includes details that are not visible in a general classroom workflow, so the boundaries need to reflect those responsibilities. Teams can decide when AI may help organize or draft work, what information should be removed or de-identified before a tool is used, and which tasks should remain outside an AI system entirely.

District leaders can also adjust the technology review process so that AI products are not considered only through the department that wants to use them. If a curriculum team requests a tool because it improves planning or feedback, the review should include the people responsible for privacy, security, and data governance before the product becomes routine. The same principle applies when technology staff identifies a secure product that may affect instruction or student support. No single office is likely to see every part of the decision, which is why those responsibilities need a regular place to come together.

Teachers should still be able to find better ways to plan, create materials, communicate, and support students. Schools do not need to respond to every new AI tool by shutting experimentation down, and they should not make educators afraid to acknowledge what they are already using. They do need to make it possible for educators to recognize when an instructional or administrative choice has also become a data decision and to know what to do next.

That responsibility should not depend on a teacher reading privacy terms at nine o'clock at night, a counselor knowing which security questions to ask a company, or a principal discovering during a parent conversation that a tool was never reviewed for the information it received. Schools need enough visibility to know which tools are being used, enough coordination to review them, and enough clarity that the people working directly with students do not have to make those decisions alone.

Cybersecurity and AI governance will continue to involve different people and different areas of expertise, but schools can no longer manage the decisions as though they are unrelated. The same student information can move through both, and the same families are trusting the school to handle that information responsibly.

Schools do not need to eliminate every risk before educators can use AI. They do need to know where student information is going, why it is going there, and who is responsible for deciding whether it should.

This is one of many hidden shifts AI is introducing into education. I write these newsletters to help educators and school leaders see them early and respond intentionally. If that matters to you, stay with the series.

Keep reading each week

New editions publish weekly. Subscribe on LinkedIn or read the full archive here.

Previous edition

Why Are Schools Drawing Harder Lines Around AI? What Are They Protecting?

Next step

Want this thinking applied to your school?

Tell us the AI problem you are facing and we will show you what it looks like solved.