Controlled document · AIL-01 · Rev A
Readiness 0%
Regulation (EU) 2024/1689 · Article 4 · Instrument for schools

AI literacy is already a legal duty. Here is the whole programme.

A single working instrument for an international school: what the law requires, where you stand today, a six-module staff course, a full student programme mapped to the OECD–EC framework, twelve classroom activities, and the policy set that closes the loop.

Providers and deployers of AI systems must take measures to ensure a sufficient level of AI literacy among staff and other people operating AI on their behalf — proportionate to their technical knowledge, experience, education and the context of use, and to the people the systems are used on. Article 4, EU AI Act — applicable since 2 February 2025. Supervised and enforced by national market surveillance authorities from 2 August 2026.
Part 1 / 11

Where the law stands right now

The Act arrives in waves. Two of those waves have already broken over schools. A third lands in days. The one everybody worries about — high-risk systems — has been pushed back, and that is exactly why the near-term duties get forgotten.

2 Feb 2025In force
Prohibited practices, and the Article 4 literacy duty

Both applied from this date. If your staff have been using AI tools without training since then, the duty was already unmet — it did not begin in 2026.

2 Aug 2025In force
General-purpose AI model obligations

Applies to model providers, not to you as a school. Relevant only when you assess a vendor's paperwork.

2 Aug 2026This is the one
Enforcement of Article 4 begins · Article 50 transparency applies

National market surveillance authorities start supervising and enforcing the AI literacy duty. Separately, transparency and disclosure obligations for AI-generated content and AI interactions become enforceable — these were left untouched by the 2026 Digital Omnibus.

2 Dec 2027Deferred
Annex III high-risk obligations — including education

Political agreement reached on 7 May 2026 moved these from August 2026 to December 2027. Confirm the final adopted text before relying on the later date. The deferral does not touch Article 4 or Article 5.

2028Deferred
Annex I high-risk — AI embedded in regulated products

Rarely relevant to a school unless you deploy regulated medical or safety equipment with AI components.

The trap

Headlines in mid-2026 said "EU delays AI rules." Leadership teams read that and stood their projects down. What was delayed was the high-risk regime. The literacy duty, the prohibitions, and the transparency duties were not. A school that paused on the strength of those headlines is now exposed on the exact obligation that is easiest to evidence and cheapest to meet.

Part 2 / 11

Is your school in scope, and as what

Almost every school is a deployer. A small number are also providers. The label determines which duties attach, so settle it before anything else.

Deployer — nearly certainly you

You use AI systems in your professional activity

Staff use a chatbot for planning. Your MIS has AI features. You run a writing-feedback tool, a translation tool, a safeguarding filter, or a timetabling optimiser. Any one of these makes you a deployer.

Article 4 applies to you in full.

Provider — check carefully

You develop an AI system, or put your name on one

You built a custom GPT, agent, or marking assistant and made it available to others under the school's name. You white-labelled a vendor tool. You substantially modified a high-risk system.

Provider duties are heavier. Get advice if this is you.

Which school uses count as high-risk

Annex III, point 3 — education and vocational training

Four education uses are listed as high-risk. Their obligations are deferred, but you should still know which of your systems will land here, because the inventory you build now is the same inventory you will need then.

Listed useWhat it looks like in a schoolStatus
Admission and assignment AI ranking or shortlisting applicants; automated setting or streaming on entry.Includes scholarship triage. High-risk · deferred
Evaluating learning outcomes Automated marking that contributes to a reported grade; AI systems used to steer the learning process.Formative-only tools sit lower, but document the distinction. High-risk · deferred
Assessing appropriate level of education AI-assisted setting decisions, pathway recommendation, predicted-grade generation used for placement. High-risk · deferred
Monitoring behaviour during tests Remote proctoring and cheating-detection during examinations.Check the vendor's emotion-inference claims against Part 3. High-risk · deferred
Everything else Lesson planning, resource generation, admin drafting, translation, differentiation, staff productivity, chatbots for parents. Limited / minimal risk

The practical reading

Most of what a school actually does with AI is minimal or limited risk. That is good news, and it is also why the compliance job is small enough to finish this term. Your obligations are: don't cross the red lines, know what you run, train your people, disclose where required, and keep the paperwork.

Part 3 / 11

Red lines you must not cross

Article 5 — prohibited practices · applicable since 2 February 2025

These are not risk-managed. They are banned. Penalties reach the highest tier in the Act — up to €35 million or 7% of worldwide annual turnover, with proportionate caps for smaller organisations. One of the eight prohibitions names education explicitly.

Article 5(1)(f) — the one aimed at you

Using AI to infer the emotions of a person in an education institution is prohibited

The exception is narrow: systems intended for medical or safety reasons only, and it is read restrictively. The Commission's guidelines confirm that both "emotion recognition" and "emotion inference" are caught, tied to inference from biometric data. It covers public and private institutions, all levels, in person or online — and it reaches admissions too.

Where this bites in real schools: engagement-tracking in video lessons, webcam attention or "focus" scoring, sentiment analysis of student faces or voices, proctoring tools that flag stress or suspicion from expression, wellbeing dashboards that infer mood from biometrics.

Screening questions for every tool you run

If you find one

Stop using it. Record the date you stopped, who authorised the stop, and what replaced it. A prohibited practice discovered and remediated with a dated record reads very differently to a regulator than one still running.

Part 4 / 11

AI system register

You cannot train people on systems you have not listed. The register is the first artefact any authority will ask for, and it takes about ninety minutes to build if you ask heads of department directly. Start with the rows below and add your own.

System Used by Purpose Risk Owner Disclosed?

Two columns people forget

Shadow use. Add a row for tools staff use without approval. You are the deployer whether or not procurement knew. A monthly amnesty question in briefing surfaces more than a policy ever will.

Disclosure. Article 50 means people should know when they are dealing with an AI system or looking at AI-generated content. The parent chatbot needs a line. AI-generated images in your prospectus need a line. This is enforceable from 2 August 2026.

Part 5 / 11

Readiness audit

Twenty-four questions across six domains. Answer honestly — a low score on a first pass is normal and is itself useful evidence that you assessed yourself. Mark Evidenced only where you could hand someone a document today.

A

Governance and accountability

0 / 8
A single named person is accountable for AI across the schoolNot a committee. A name in a job description.
Governors or the board have received a written AI position paperMinuted, with a date.
A route exists for staff to request approval for a new AI toolAnd someone actually answers it.
An incident log exists for AI-related problemsWrong output acted on, data exposure, integrity dispute.
B

Inventory and risk classification

0 / 8
A complete AI system register exists and was updated this termPart 4 of this instrument.
Every system is classified against the Act's risk tiersProhibited / high / limited / minimal.
Every Article 5 screening question has a written vendor answerEspecially emotion inference.
Shadow AI use has been surveyed at least onceAnonymous staff survey counts.
C

Staff AI literacy — the Article 4 core

0 / 8
All staff who touch AI have completed baseline trainingTeaching, admin, leadership, and anyone operating a tool on the school's behalf.
Training is differentiated by role and technical backgroundArticle 4 requires proportionality, not one identical session.
Attendance and completion are recorded per personNames, dates, module, duration.
New starters get AI literacy in inductionIncluding supply and contract staff.
D

Student programme and curriculum

0 / 8
AI literacy appears in schemes of work, not only in assembliesNamed outcomes in at least three subjects.
Progression is mapped across year groupsWhat a Year 4 learns differs from a Year 12.
Students know when they may and may not use AI in assessed workWritten, per subject, and understood.
Student outcomes reference an external frameworkThe OECD–EC AILit framework, or an equivalent you can name.
E

Transparency, data and safeguarding

0 / 8
Anyone interacting with an AI system is told soParent chatbots, automated replies, AI-marked feedback.
AI-generated content published by the school is labelledImages, copy, translated material.
No child's personal data goes into a tool without a lawful basis and a DPACoordinate with your GDPR record of processing.
Safeguarding leads have been briefed on AI-specific risksSynthetic imagery, chatbot dependency, grooming vectors.
F

Evidence and review

0 / 8
An evidence file exists in one placePart 10 lists what goes in it.
Policies carry a version, an owner and a review dateUndated policy is weak evidence.
A review is diarised at least annuallySooner if the deferred deadlines move again.
Someone tracks changes to the Act and to national guidanceNamed person, named sources.
0 / 48
Not started
Answer the audit above to generate a readiness position you can paste into a board paper or a governors' report.
Part 6 / 11

The staff course

Discharges Article 4 · six modules · 4 hours 45 minutes total

Built to be delivered as one INSET day, or as six twilights across a term. Modules 1, 2 and 6 are mandatory for every member of staff who touches an AI system. Modules 3–5 are differentiated: run the teaching track and the operations track separately. That differentiation is not a nicety — Article 4 asks for measures proportionate to people's technical knowledge and role.

M1 What these systems actually areAll staff · mandatory 45 min
Whole staff
Why it exists

You cannot judge an output you do not understand the origin of. Most poor AI decisions in schools trace back to staff believing the system knows things, checks things, or remembers things that it does not.

Learning outcomes
  • Describe in plain language how a language model produces text, without using the word "thinks"
  • Explain why a confident answer and a correct answer are unrelated properties
  • Identify three tasks where these tools are strong and three where they are unreliable
  • State what happens to data typed into a consumer tool versus a licensed one
Content
  • Prediction, not retrieval. A live demonstration: same prompt, three runs, three different answers. Ask the room what that tells them about citation.
  • Training data and cutoffs. Why a model invents a plausible policy reference for your own school.
  • Confidence is a style, not a signal. Show a fluent, wholly fabricated exam-board reference. This is the moment the room changes.
  • Where the data goes. Consumer account, school licence, enterprise agreement — three different answers, three different risk positions.
Activity — Hallucination hunt (15 min)

In subject pairs, ask a model for five specific facts inside your own specification: syllabus codes, mark scheme wording, past paper questions. Verify each against the real document. Pairs report their hit rate to the room. Nobody forgets their own subject's failure rate.

Evidence produced

Signed attendance sheet · completed hallucination-hunt sheets retained per department · three-line personal reflection collected.

AI Act Art. 4 AILit · Engage with AI
M2 The law, in the form it reaches a classroomAll staff · mandatory 40 min
Whole staff
Why it exists

Staff do not need the Act. They need the four rules that change what they do on Monday, and the confidence to say "I need to check that" to a vendor or a parent.

Learning outcomes
  • Name the four practices that are banned outright in an education setting
  • Recognise when disclosure is required and phrase it
  • Explain what makes a use high-risk rather than routine
  • Know who to tell, and how, when something goes wrong
Content
  • Red lines. Emotion inference in education is prohibited. Walk the room through what that rules out — attention scoring, mood dashboards, expression-based proctoring.
  • Disclosure. If a parent, student or colleague could reasonably think a human wrote it or answered it, say otherwise.
  • High-risk uses. Anything touching admission, grading, placement or exam monitoring. Currently deferred, and still worth flagging today.
  • Escalation. One route, one named person, one log.
Activity — Red, amber, green (20 min)

Twelve scenario cards drawn from real school practice. Tables sort them into banned, needs-a-decision, and fine. Deliberately include three genuinely contested cards — the argument is the learning. Suggested contested cards: AI-generated report comments; a wellbeing tool that infers mood from written check-ins; using a model to draft a reference.

Evidence produced

Photographed table sorts with dates · the three contested cards written up as a school position and added to the policy annex.

AI Act Art. 4 Art. 5 Art. 50
M3 Teaching track — using AI without eroding the workTeaching staff 60 min
Teaching
Why it exists

The productivity case is real and the pedagogical risk is also real. This module refuses to resolve that tension for teachers and instead gives them a way to decide, subject by subject.

Learning outcomes
  • Apply a test for whether AI use protects or removes the learning
  • Redesign one task so that AI assistance makes it harder, not easier
  • Write a permitted-use statement for one unit
  • Use AI for differentiation without lowering expectations for any group
Content
  • The struggle test. If the difficulty you removed was the point of the task, you removed the task. Worked through with real examples from three departments.
  • Assessment redesign. Process evidence, in-class checkpoints, oral defence, versioned drafts, and specification of permitted tools.
  • Detection is not a strategy. Why AI-detection scores are contestable, what a fair process looks like when you suspect misuse, and why the conversation beats the tool.
  • Differentiation that holds the bar. Scaffolds and alternative explanations, not simplified outcomes.
Activity — Rebuild one task (30 min)

Every teacher brings one assessed task from their current unit. In department groups, rewrite it so a model cannot complete it well, and write the two-line permitted-use statement students will see. Departments leave with a real artefact, not a plan to make one.

Evidence produced

One redesigned task per teacher, filed by department · permitted-use statements collected into the assessment integrity annex.

AI Act Art. 4 AILit · Create with AI AILit · Manage AI
M4 Operations track — data, procurement and disclosureAdmin, SLT, office, admissions 60 min
Operations
Why it exists

The highest-consequence AI decisions in a school are usually made by people who never enter a classroom: which system gets bought, what data it receives, and whether anyone was told.

Learning outcomes
  • Run the nine-question vendor screen before any purchase
  • Decide what child data may enter a tool, and on what basis
  • Write compliant disclosure lines for parent-facing systems
  • Maintain the register and the incident log
Content — the vendor screen
  • Does the system infer emotion, mood or attention from biometric signals?
  • Does it fall into any Annex III education category?
  • Where is data processed, and is there a data processing agreement?
  • Is our data used to train their models, and can we opt out in writing?
  • What is the documented accuracy, and on which population was it measured?
  • What does human oversight look like in practice, not in the brochure?
  • How are errors reported, and what is the fix commitment?
  • What happens to our data on termination?
  • Will you confirm all of the above in writing?
Activity — Screen a live vendor (25 min)

Take a tool the school is currently considering. Run the nine questions against its actual documentation. Most groups discover that four or five cannot be answered from public material — which is the finding.

Evidence produced

Completed vendor screen per system, dated and filed · disclosure lines drafted and published · register updated in the session.

AI Act Art. 4 Art. 50 GDPR interface
M5 Safeguarding, bias and the harder conversationsAll staff · pastoral emphasis 50 min
Whole staff
Why it exists

The safeguarding surface changed faster than most schools' policies did. Staff need to recognise the new patterns and know that the existing routes still apply.

Learning outcomes
  • Recognise AI-specific safeguarding patterns and respond through existing routes
  • Explain how bias enters a system and where it surfaces in school use
  • Handle a student disclosure involving synthetic imagery
  • Talk to parents about AI without alarm or dismissal
Content
  • Synthetic imagery and peer-on-peer abuse. Response protocol, evidence preservation, reporting, and support for the child. Note that the EU has moved to prohibit AI systems generating non-consensual intimate imagery and child sexual abuse material outright.
  • Companion chatbots and dependency. What emotional reliance looks like in a young person, and why it can present as withdrawal.
  • Bias, concretely. Where training data skews show up in a school: name recognition, dialect and EAL penalties in writing feedback, cultural assumptions in generated resources.
  • Parent conversations. Three scripts: the worried parent, the parent who thinks it is cheating, the parent who wants more of it.
Activity — Bias audit of your own resources (20 min)

Generate three teaching resources for your subject. Examine names, contexts, examples, images and assumed prior knowledge. Departments record what they found and what they will check for routinely.

Evidence produced

Departmental bias-audit notes · updated safeguarding annex covering AI-specific patterns · DSL sign-off.

AI Act Art. 4 AILit · Manage AI Safeguarding
M6 Your commitments, on the recordAll staff · mandatory · closes the loop 30 min
Whole staff
Why it exists

Training that produces no artefact produces no evidence. This module exists to convert four hours of conversation into a signed, dated, per-person record — the thing a market surveillance authority would actually ask to see.

Learning outcomes
  • State three things you will do differently, specific to your role
  • State one thing you will stop doing
  • Know the escalation route without looking it up
  • Complete the ten-question knowledge check
Content
  • Knowledge check. Ten questions, open book, discussed as a room. Not a test — a shared calibration.
  • Commitment card. Three starts, one stop, one question I still have. Signed and dated.
  • The open questions. Collect every unresolved question in the room. These become the agenda for the next review and are themselves good evidence of an active programme.
Evidence produced

Signed commitment card per member of staff · knowledge check results · register of open questions with owners and dates. File all three in the evidence file at Part 10.

Evidence item E-05 AI Act Art. 4

Delivery shapes that work

One INSET day. M1, M2 before break. M3 and M4 in parallel tracks after. M5 and M6 to close. Everyone leaves with a signed card.

Six twilights. One module per fortnight across a term. Better retention, worse attendance. Record every session so absentees can complete asynchronously — and log that they did.

New starters. M1, M2 and M6 compressed to 90 minutes in induction. Non-negotiable.

Part 7 / 11

The student programme

Mapped to the OECD–European Commission AILit Framework, published June 2026

Article 4 is about staff. Your students are a separate matter — and the reason the job is worth doing properly. The AILit framework gives you an external reference to cite, which is exactly what inspectors and accreditation bodies want to see instead of a school inventing its own outcomes.

The four domains

The framework organises AI literacy into four domains and nineteen competences, each combining knowledge, skills and attitudes, with a three-level progression. The domains run as a developmental pathway: Engage and Create sit in parallel as hands-on encounters, then Manage adds judgement, and Shape asks students to see human choices behind the technology. It feeds the PISA 2029 assessment, so alignment now is not wasted work.

Domain 1

Engage with AI

Recognising AI when you meet it, understanding roughly how it works, and reading its outputs with appropriate suspicion.

School translation: can a student say what the tool is doing and why it got that wrong?

Domain 2

Create with AI

Using AI purposefully in making, problem-solving and delegating parts of a task — while keeping authorship.

School translation: can a student show which parts are theirs?

Domain 3

Manage AI

Responsible decision-making: privacy, dependency, verification, knowing when not to use it at all.

School translation: can a student justify a decision to switch it off?

Domain 4

Shape AI

Seeing that these systems embody human choices and values, and that those choices could have been made differently.

School translation: can a student name who decided, and propose an alternative?

Progression by year band

BandEngageCreate ManageShape
Years 3–4Ages 7–9 Spot AI in everyday things. Know a computer can be "taught" by examples. Use a tool with an adult to make something, and say which bit they did. Never share your name, photo or address with a machine that asks. People built this. People chose what it does.
Years 5–6Ages 9–11 Explain that examples shape what it learns. Notice when output is wrong. Iterate: change the instruction, see the change, keep the better one. Check a claim against a second source before believing it. Notice who is missing from the pictures it makes.
Years 7–9Ages 11–14 Describe prediction versus understanding. Explain training data and its limits. Decompose a task, delegate the right parts, keep authorship of the argument. Assess privacy trade-offs. Recognise dependency in their own habits. Audit a system for bias and propose a design change with a reason.
Years 10–11IGCSE Evaluate reliability by task type. Explain why confidence is not accuracy. Produce work with a declared AI-use statement they can defend orally. Apply the school's permitted-use rules and justify borderline decisions. Argue a position on a real governance question with evidence.
Years 12–13DP / A-level Interrogate a system's failure modes systematically. Use AI in extended research with a transparent, auditable method. Weigh societal costs — labour, energy, concentration of power. Propose and defend policy. Understand regulation as a design constraint.

Where it lives on the timetable

Cross-curricular, with an anchor. Computing or Digital Technology owns the Engage and Shape strands and the progression map. English, Humanities and Science each own one Create or Manage outcome per year. Pastoral owns dependency and privacy. One named person keeps the map — otherwise it dissolves within a year.

Part 8 / 11

Twelve classroom activities

Three per band, each mapped to an AILit domain. Most run in a single lesson and need nothing beyond what a classroom already has. The unplugged ones are deliberate — the strongest AI literacy activities for younger students involve no screens at all.

Years 3–4

A1 Teach the machineUnplugged · classification 40 min
Engage
Outcome

Students understand that a machine learns a rule from examples rather than being told the rule.

Materials

A pile of assorted objects or picture cards. Two hoops or trays.

How it runs
  • The teacher secretly picks a rule — "things that are soft".
  • Place objects one at a time into the correct tray. Say nothing.
  • After six examples, students guess the rule and place the next object. Teacher says only "yes" or "no".
  • Swap: a student becomes the rule-holder and the class becomes the machine.
  • Now break it. Give five examples that all happen to be blue as well as soft. Watch the class learn the wrong rule. That is the lesson.
The question that lands it

"What would we need to show it so it stops thinking blue means soft?"

AILit · EngageUnplugged
A2 Machine or person?Sorting · recognition 30 min
Engage
Outcome

Students can spot where AI is already present in their day.

Materials

Twenty picture cards: video recommendations, a spell-checker, a light switch, a smart speaker, a calculator, a photo filter, a doorbell, a book.

How it runs
  • Sort into three piles: learns from examples, follows fixed rules, not a computer at all.
  • Expect and welcome disagreement over the calculator and the spell-checker.
  • Finish with a home hunt: find one thing at home that learns. Report back.
Watch for

Children attributing feelings and intentions to devices. Name it gently and often — this is the root of later over-trust.

AILit · EngageUnplugged
A3 Catch the mistakeVerification · early critical habit 30 min
Manage
Outcome

Students build the reflex of checking before believing.

Materials

Three short AI-generated paragraphs about a topic the class knows well — the school, their town, an animal they have studied. Prepared in advance by the teacher, each containing two confident errors.

How it runs
  • Read as a class. Students hunt for anything they know is wrong.
  • Award a point per catch. Reveal the planted errors at the end.
  • Key discussion: "It sounded so sure. Did sounding sure help us at all?"
Extension

Students write their own confident-but-wrong paragraph for another class to catch.

AILit · Manage

Years 5–6

A4 The biased sorting machineUnplugged · training data 50 min
Shape
Outcome

Students can explain how a skewed set of examples produces a skewed system, and propose a fix.

Materials

Two prepared decks of "leaf" cards. Deck A: thirty leaves, twenty-eight of them oak. Deck B: thirty leaves, balanced across six species.

How it runs
  • Half the class trains on Deck A, half on Deck B. They write down the rule they infer for "what a leaf looks like".
  • Test both groups on the same held-back mixed set. Group A fails on maples and confidently calls them oaks.
  • Reveal the decks. Let the class work out what happened before you explain it.
  • Transfer: "If a system learned what a doctor looks like from old photographs, what would it get wrong?"
Assessment

Exit ticket: one sentence on what went wrong, one sentence on how to fix it.

AILit · ShapeUnplugged
A5 Prompt laboratoryIteration · authorship 50 min
Create
Outcome

Students learn that instruction quality drives output quality, and that the thinking stays theirs.

Setup

Teacher-operated on the board, or supervised devices depending on your policy and the age gate on your tools.

How it runs
  • Round 1 — everyone submits "write a story about a dog". Compare the results. Note how similar and how bland they are.
  • Round 2 — add one constraint each: a setting, a problem, a voice, a forbidden word. Compare again.
  • Round 3 — students take the best output and rewrite it by hand to make it genuinely theirs. Highlight in two colours: machine words, my words.
The point

The two-colour highlight is the whole activity. It gives students a physical sense of authorship they carry into secondary school.

AILit · Create
A6 Real or generated?Provenance detective 45 min
Manage
Outcome

Students develop checking strategies rather than relying on "it looks fake".

Materials

Twelve images, six real and six generated, printed. Mixed difficulty — include two that are genuinely hard.

How it runs
  • Individual guesses first, recorded, with a confidence rating out of three.
  • Pairs compare and argue. Guesses may change.
  • Reveal. Plot the class accuracy against confidence — the overconfidence gap is usually dramatic and is the real finding.
  • Build a class checklist of what actually helped: source, context, who posted it, does another outlet have it, is there provenance information attached.
Important framing

End on "you cannot reliably tell by looking, so you check the source instead". Do not leave them thinking they have a good eye.

AILit · Manage

Years 7–9

A7 Rules versus learningBuild both, compare 2 × 50 min
Engage
Outcome

Students can articulate the difference between a system a human programmed and a system that derived its own rule.

How it runs
  • Lesson 1. In pairs, write an explicit decision tree that classifies animals. Test it on classmates' held-back examples. Count the failures and patch the tree. Notice how quickly it becomes unmanageable.
  • Lesson 2. Train a simple image classifier in a browser-based teachable tool on the same categories. Compare: which was faster, which is explainable, which fails more gracefully, which would you trust in a hospital.
Assessment

A written comparison naming one context where you would choose each approach, with justification. This is a strong IGCSE-preparation task.

AILit · EngageComputing
A8 Occupation auditSystematic bias investigation 50 min
Shape
Outcome

Students collect their own evidence of representational bias and reason about its causes and effects.

How it runs
  • Assign each pair three occupation prompts — "a nurse", "a chief executive", "a scientist", "a cleaner", "a professor", "a criminal".
  • Generate ten images per prompt. Tally by apparent gender, apparent ethnicity, age, setting and dress.
  • Pool the class data into one spreadsheet. Now it is a dataset, not an anecdote.
  • Analyse: which prompts skewed hardest? Why might that be? Who is harmed and how?
Handle with care

Set expectations first. Some outputs will be stereotyped in ways students find uncomfortable — that discomfort is the evidence, and it needs framing before, not after.

Cross-curricular

Runs well jointly with Geography, PSHE or Maths — the data handling is real.

AILit · ShapePrepare the framing
A9 Synthetic media defenceVerification workflow 50 min
Manage
Outcome

Students can run a repeatable verification workflow on a suspicious piece of media.

How it runs
  • Teach the workflow: who published itwho else has itreverse image searchcheck for provenance metadatawhat would I expect to exist if it were real.
  • Give four cases, escalating in difficulty. Students work through the workflow and record their reasoning, not just their verdict.
  • One case should be genuinely unresolvable. Students must write "cannot determine" and say what evidence would settle it.
Safeguarding link

Close with the school's reporting route for synthetic images of students. State it plainly. Students should leave knowing exactly who to tell and that they will not be in trouble.

AILit · ManageSafeguarding link

Years 10–13

A10 Red-team the modelSystematic failure-mode testing 2 × 50 min
Engage
Outcome

Students design and execute a structured test plan against an AI system and report findings like an evaluator.

How it runs
  • Teams pick a failure hypothesis: arithmetic under distraction, recent events, niche subject knowledge, self-contradiction across turns, sycophancy under pressure, refusal inconsistency.
  • Design twenty test cases with predetermined success criteria — written before any testing begins.
  • Execute, log every result, calculate a failure rate with a confidence caveat.
  • Present findings in four slides: hypothesis, method, results, what a school should do about it.
Why it is worth two lessons

The discipline of writing success criteria before testing is transferable to every science practical and every DP internal assessment they will do.

AILit · EngageIGCSE / DP
A11 Write the permitted-use contractStudents author the rules 50 min
Create
Outcome

Students draft the AI-use rules for one of their own assessed units and defend the boundary they drew.

How it runs
  • Take a real upcoming assessment. Establish together what the task is actually assessing — the underlying skill, not the artefact.
  • Groups draft rules under four headings: always allowed, allowed if declared, not allowed, how we show our working.
  • Groups swap drafts and attack them: find the loophole in someone else's rules.
  • Negotiate one class version. The teacher holds a veto but must justify using it.
Why it works

Compliance with a rule you wrote is different in kind from compliance with a rule you were given. Schools that run this report noticeably fewer integrity disputes in that unit.

Output

A signed class contract, displayed, referenced at submission.

AILit · CreateIntegrity evidence
A12 Regulate it yourselfPolicy design under real constraints 2 × 50 min
Shape
Outcome

Students understand regulation as a design problem with trade-offs, not a list of rules handed down.

How it runs
  • Present a genuine case: should AI proctoring be permitted in school examinations? Note that the EU already prohibits inferring emotions in education settings, and that exam monitoring sits in the high-risk category.
  • Assign roles: student body, examinations officer, data protection officer, vendor, parent, regulator. Each prepares a position with evidence.
  • Hold the hearing. The regulator group must produce a written decision with reasons, conditions and a review date.
  • Compare the class decision with the actual position under the Act. Where the class went further or less far is the richest discussion of the unit.
Assessment

Individual 600-word position paper. Maps directly onto DP Digital Society and Global Politics assessment styles, and onto IGCSE extended response.

AILit · ShapeDP / IGCSE
Part 9 / 11

Policy templates

Five documents that close the loop. Replace everything in brackets, add a version number, an owner and a review date, and get them approved through your normal route. An undated policy is weak evidence; a dated, owned, reviewed policy is strong.

T1 · Staff AI acceptable use

[SCHOOL NAME] — Staff use of artificial intelligence
Version [1.0] · Owner [NAME, ROLE] · Approved [DATE] · Review [DATE]

1. SCOPE
This applies to all employees, contractors, supply staff and volunteers who use
any AI system in the course of work for the school. [SCHOOL NAME] is a deployer
of AI systems under Regulation (EU) 2024/1689 and carries the AI literacy duty
under Article 4.

2. BEFORE YOU USE A TOOL
2.1 Only tools on the approved register may be used with any school or pupil data.
2.2 Requests to add a tool go to [NAME] using the approval route at [LOCATION].
2.3 You may not enter pupil personal data into any tool that is not on the register.
2.4 Never enter safeguarding records, medical information, SEN reports or staff HR
    matters into any AI tool without written approval from [NAME].

3. HOW YOU USE IT
3.1 You remain the author. Anything issued under your name is your responsibility,
    whatever produced the first draft.
3.2 Verify every factual claim, citation, date and reference before use.
3.3 Do not use AI to generate a final grade or a reported assessment judgement.
    AI may support marking; a human makes and owns the decision.
3.4 Do not use any tool that infers emotion, mood or attention from faces, voices
    or body signals. This is prohibited in education settings under Article 5(1)(f).
3.5 Apply the same professional judgement to AI output as to anything else you would
    put in front of a child.

4. TELLING PEOPLE
4.1 Where a parent, pupil or colleague could reasonably assume a human wrote or
    answered something, say if AI was involved.
4.2 AI-generated images or text published by the school are labelled as such.

5. WHEN SOMETHING GOES WRONG
5.1 Report to [NAME] within [one working day].
5.2 Reportable: incorrect output acted on, personal data exposed, a suspected
    prohibited practice, a disputed integrity decision, a safeguarding concern.
5.3 Reports are logged. Reporting in good faith carries no penalty.

6. TRAINING
6.1 All staff complete the AI literacy programme before using AI tools at work.
6.2 New starters complete the induction module within [30 days].
6.3 Completion is recorded and retained.

Signed [ ................................ ]  Date [ .......... ]

T2 · Student AI use — secondary

[SCHOOL NAME] — Using AI in your work
Years [7–13] · Version [1.0] · Review [DATE]

WHY WE HAVE THIS
We are not banning AI. We are protecting the thing school is for: you getting
better at things. Some tasks are hard on purpose. If a tool removes the difficulty,
it removes the learning — and you will meet that gap later, in an exam hall or a
job, without the tool.

THE THREE LEVELS
Every assessed task tells you which level applies. If it does not say, ask.

  LEVEL 1 — NO AI
  Nothing generated by AI. This is used where we need to see what you can do
  unaided. Examples: [in-class assessments, controlled conditions, ...].

  LEVEL 2 — AI WITH A DECLARATION
  You may use AI for [named purposes: brainstorming, explaining a concept,
  checking grammar, generating practice questions]. You submit a short
  declaration saying what you used and for what. No penalty for honest use.

  LEVEL 3 — AI AS A TOOL OF THE TASK
  The task is about working with AI. Full use, documented method.

YOUR DECLARATION
Attach this to any Level 2 or 3 submission:
  Tool(s) used:
  What I used it for:
  What is entirely my own:
  Anything I checked and corrected:

WHAT COUNTS AS CHEATING
Submitting AI-generated work as your own thinking. Using AI at Level 1.
Declaring falsely. That is it — it is not complicated.

IF WE THINK SOMETHING IS WRONG
We will talk to you first. We will ask you about your work — how you got there,
why you made a choice, what you would change. We do not treat a detection score
as proof. You will always get to explain.

WHAT WE ASK OF YOU
Check what it tells you. It is confident when it is wrong.
Keep your own voice. Your teachers can tell, and it matters more than you think.
Do not put your personal information, or anyone else's, into these tools.
Tell someone if you see AI used to harm another student.

Student signature [ ................ ]  Tutor [ ................ ]  Date [ ...... ]

T3 · Letter to parents and carers

Dear parents and carers,

I am writing to set out how [SCHOOL NAME] approaches artificial intelligence, and
what we are asking of you.

WHERE WE STAND
AI tools are now part of the working world your children will enter. Our position
is that pretending otherwise fails them, and that unsupervised use also fails them.
So we teach it deliberately: what these systems are, where they fail, when to use
them, and when to switch them off.

WHAT WE HAVE DONE
Every member of staff has completed AI literacy training. We keep a register of
every AI system in use across the school and who is responsible for each. We have
checked all of them against the practices that European law prohibits in schools —
including any system that tries to infer a child's emotions, which is banned and
which we do not use. Our policies name an owner and a review date.

WHAT YOUR CHILD WILL LEARN
Our programme follows the AI literacy framework published by the OECD and the
European Commission in 2026. It runs from Year [3] to Year [13] and covers
recognising AI, creating with it, managing its risks, and understanding that people
design these systems and could have designed them differently.

WHAT WE ASK OF YOU
  · Talk about it. "What did it get wrong?" is a better question than "did you use it?"
  · Check the age requirements on tools at home. Most set a minimum of 13 or higher.
  · If your child uses AI for homework, ask them to show you what they changed.
  · Contact us rather than the internet if you are worried about something.

WHAT TO DO IF SOMETHING HAPPENS
If your child is affected by an AI-generated image or message, contact [NAME,
ROLE] on [CONTACT]. We will respond through our safeguarding procedures. Your
child will not be in trouble for reporting.

Our full policy is at [LOCATION]. I am glad to discuss it.

[NAME]
[ROLE], [SCHOOL NAME]

T4 · Vendor written confirmation request

Subject: EU AI Act — written confirmations required before procurement

Dear [VENDOR],

[SCHOOL NAME] is an education institution in [COUNTRY] and a deployer of AI systems
under Regulation (EU) 2024/1689. Before we can proceed with [PRODUCT], we need
written answers to the following. Marketing material is not sufficient for our
records; we need a signed response we can retain.

1. Does the system identify or infer emotions, mood, attention or engagement of any
   person from biometric signals, including facial expression, voice or posture?
   If yes, on what basis do you consider this compatible with Article 5(1)(f)?

2. Does the system perform any function listed in Annex III point 3 — determining
   admission or assignment, evaluating learning outcomes, assessing the appropriate
   level of education, or monitoring behaviour during tests?

3. What is your classification of this system under the Act, and what documentation
   supports it?

4. Where is data processed and stored? Please provide your data processing agreement.

5. Is customer data, including pupil data, used to train or improve your models?
   If so, can we opt out in writing, and does opting out change the service?

6. What accuracy figures can you provide, and on what population were they measured?

7. What human oversight does the system require in operation, and how is it enforced
   rather than merely recommended?

8. How are errors reported, what is your remediation commitment, and what is your
   incident notification timeline?

9. What happens to our data on termination, and within what period?

Please also confirm the name and contact of the person accountable for AI Act
compliance at your organisation.

We cannot complete procurement without these. Thank you.

[NAME], [ROLE]
[SCHOOL NAME]

T5 · Board / governors position paper — skeleton

[SCHOOL NAME] — AI governance position
Paper for [BOARD / GOVERNORS] · [DATE] · Author [NAME, ROLE]

1. PURPOSE
To inform the [board] of the school's obligations under Regulation (EU) 2024/1689
and to seek approval for the AI literacy programme and policy set at Annex A.

2. THE OBLIGATION
The AI literacy duty under Article 4 has applied since 2 February 2025. National
market surveillance authorities began supervising and enforcing it on 2 August 2026.
Transparency obligations under Article 50 also became enforceable on that date.
Obligations for high-risk systems — which include several education uses — were
deferred to 2 December 2027 by political agreement reached on 7 May 2026. The
deferral does not affect Articles 4, 5 or 50.

3. OUR POSITION TODAY
Self-assessment completed [DATE] using [INSTRUMENT]. Score [ X ] of 48.
Position: [ ................ ].
Strongest domains: [ ]. Weakest domains: [ ].

4. WHAT HAS BEEN DONE
   · AI system register established, [N] systems recorded
   · All systems screened against Article 5 prohibitions; [N] issues found, [N] resolved
   · Staff programme delivered to [N] of [N] staff on [DATES]
   · Policy set T1–T4 drafted and [approved / pending approval]

5. RESIDUAL RISK
   [ ]

6. ASKS
   6.1 Approve the policy set at Annex A.
   6.2 Confirm [NAME] as accountable owner in their job description.
   6.3 Approve [BUDGET] for [ ].
   6.4 Diarise annual review for [DATE].

7. RECOMMENDATION
That the [board] approves 6.1 to 6.4.
Part 10 / 11

The evidence file

Article 4 asks you to take measures. Measures you cannot show are measures you did not take. Keep all of this in one place, dated, with a named owner. Twelve items — most schools already have five of them scattered across three drives.

What good looks like to an inspector

Not perfection. A named owner, a current register, evidence that real people were really trained in a way suited to their role, a policy someone can find, and a dated record showing you assessed yourself and knew where your gaps were. A school with a modest score and an honest, dated improvement plan is in a stronger position than a school with nothing written down.

Part 11 / 11

Twelve-week rollout

One term. Assumes a single person with roughly half a day a week, plus one INSET slot. Weeks 1–4 produce the compliance floor. Weeks 5–12 produce the programme that actually changes practice.

WeekDo thisOutputWho
1Name the accountable owner. Write it into a job description.Named owner, board informedHead / Board
2Build the register. Email every head of department the same three questions.E-01 draftAI owner
3Screen every system against Article 5. Send template T4 to each vendor.E-03, E-04 startedAI owner + Ops
4Classify each system. Stop anything prohibited, with a dated record.E-02 completeAI owner
5Draft T1 and T2. Circulate for comment — comments are engagement, not delay.Policy draftsAI owner + SLT
6Board paper using T5. Seek approval for the policy set and the owner.E-11Head
7Prepare the INSET. Build the scenario cards from your own register.E-06AI owner
8Deliver modules M1–M6. Collect every commitment card before people leave.E-05All staff
9Publish T3 to parents. Add disclosure lines to AI-facing systems.E-09Comms + Ops
10Map the student programme. Assign one AILit outcome per subject per year.Progression mapCurriculum lead
11Pilot three activities from Part 8 across three year bands.Student work samplesNamed teachers
12Re-run this audit. Print it. File everything. Diarise the annual review.E-12, complete fileAI owner

Roles, minimally

Accountable owner

One person. Holds the register, the evidence file and the review date. Typically Head of Digital Learning or a Deputy Head. Needs about half a day a week in term one, then a day a term.

Data protection lead

Owns the GDPR interface. Signs off what data may enter which system. Often external — brief them properly rather than assuming they know the Act.

Safeguarding lead

Owns the AI-specific safeguarding annex and the synthetic imagery response protocol. Must be in the room for module M5.

Curriculum lead

Owns the AILit progression map and makes sure outcomes reach schemes of work rather than assemblies.

Head of school

Names the owner, takes the board paper, and makes the programme mandatory rather than encouraged. This is the whole job.

Board / governors

Approve, minute, and ask for the review a year later. The minute is evidence.

Copied