Gateway AI in EDU Summit  /  23 July 2026

AI Governance Is Not
a Policy Document.

The distance between the rules a district writes and what actually happens the moment a student or staff member hits Enter.

Caleb Vail  Founder, TenetInteractive working sessionApprox. 50 minutes
A show of hands

You wish the rule
was enough.

Who here has kids? You want them to follow every rule, and to never cross the street alone. And none of us leaves it at the rule. We hold the hand, we watch the corner, we build the habit until it holds without us. Your AI policy is the rule you wrote down. Your students and staff are already at the street.

What a written rule cannot touch

Here is what is actually at stake

Advance to reveal each
83%
could not quote their own essay
At stake · The ability to think

They stop building the muscle

In an MIT brain-scan study, students who wrote with ChatGPT showed the lowest brain engagement of any group, and 83% could not quote a single line of the essay they had just finished. Students feel it themselves: two-thirds now say the more students use AI, the more it harms their critical thinking.

MIT Media Lab, Your Brain on ChatGPT, 2025 · RAND American Youth Panel, 2026
1 in 50
children hit every year
At stake · Their data privacy

A child's record is the prize

A student's data is a clean slate: an untouched Social Security number and spotless credit. That is why children are targeted, about one in fifty every year, and why the theft stays hidden for years, often until they apply for a first loan, job, or apartment. Whatever gets pasted into an ungoverned tool does not come back.

Javelin Strategy, Child Identity Fraud, 2021 to 2022
1 in 3
teens: AI over a person
At stake · Learning to be with people

The friend that only ever agrees

AI companions are always available and built to keep kids talking, which means built to agree. Among the 72% of teens who have tried one, a third have already turned to it instead of a real person for a serious conversation. For a generation still learning how to be with each other, a friend that never pushes back is its own kind of risk.

Common Sense Media, Talk, Trust, and Trade-Offs, 2025

None of this is settled by the document in the binder. It is settled the moment someone hits Enter. So let us look at how fast that moment is arriving.

The problem

AI is already everywhere. The policy is the only thing standing still.

Students and staff use AI every day, on district devices and their own. One in ten teens now do all or most of their schoolwork with a chatbot. Most districts answered with a written policy, and almost none can say whether it changes anything the moment someone opens a chat.

Teens using AI chatbots for schoolwork
13%
26%
54%
202320242025
Doubled, then doubled again. Pew Research, 2023 to 2026. 2023–24: ChatGPT specifically; 2025: any AI chatbot.
6 in 10

teachers used AI for their work this school year.

Gallup / Walton Family Foundation, 2025
82%

of teachers have received no formal guidance on using AI.

Gallup, 2026
The plan

How this session works

Part 1

The tradeoffs

The real tensions in writing an AI policy, and the nuance most rules ignore.

Part 2

The test

In groups of three, we run a reasonable policy through a normal school day, live.

Part 3

The break, and the cost

Where these policies fail, how districts try to enforce them, and what that enforcement costs in reliability and in people.

This is not only about students

Governance has two arenas

Exhibit 1
Arena 1

The classroom

Students using AI for the work itself: academic integrity, safety, and the personal data they paste into a prompt.

Arena 2

The back office

Staff and the program you are building: teachers, counselors, and administrators putting rosters, IEPs, and records into AI, plus the internal tools a district stands up on its own data.

A program that covers one arena and forgets the other is not a program. Most policies forget the second.

Self-assessment

Three levels of AI control

Exhibit 2  /  click your level
Most districts live at Level 1, believe they are at Level 2, and need Level 3.
Before we write a single rule

Good policy has to hold real tensions

For discussion
Teacher autonomyvsDistrict consistency
Teachers advocate for their own judgment and academic freedom, and the best classroom use is often the one a teacher invented. A blanket rule can override the professional closest to the student.
UsablevsSafe
Too restrictive and students leave for ungoverned tools. Too open and the guardrails are gone. The rule has to keep AI worth using on the governed path.
OversightvsPrivacy
To govern use you have to see it, and seeing it creates its own surveillance risk. Governance has to act without hoarding what students and staff type.
The open question

Should the rules change by grade? A second grader and a graduating senior are not the same user, yet most policies treat them as one.

K-56-89-12
Working session

Test a policy against
a normal day.

Find two people near you. Each takes one role and plays it honestly, pressures and all. The goal is not to design a perfect policy. It is to watch a reasonable one meet reality.

Groups of three  /  assign now

The three roles

Protects the district / builds the program

The Administrator

"I answer for everyone, and I cannot be everywhere."

  • Owns FERPA, COPPA, and reputation
  • Is standing up the internal AI program
  • Has authority, but no view into the chat
Protects the learning

The Teacher

"I want them to think, not outsource the thinking."

  • Cares about learning and integrity
  • Also a daily AI user with student data
  • Little visibility into what is typed
Protects their time

The Student

"I am not trying to cheat. I am trying to be done."

  • Path of least resistance wins
  • Has a phone, home wifi, personal login
  • Treats friction as a thing to route around
How it works

Three short rounds

1

Write good rules  ·  5 min

As a trio, agree on three AI rules you genuinely believe are smart and fair. Write them down.

2

Take a situation  ·  2 min

Choose one everyday situation from the next exhibit. Your district on an ordinary day.

3

Play it out  ·  10 min

Run it through each role, then mark each rule: held, ignored, or could not tell.

Round 1

Write your three good rules

Do not overthink it. The rules already in your handbook are perfect. Three that come up constantly:

01 Only district-approved AI tools may be used.
02 Never put student or staff personal information into AI.
03 AI may assist as a tutor, but the work must be the person's own.
Round 1 timer
05:00
Round 2  /  choose one

Everyday situations

Exhibit 3
01Student

11:40pm Sunday. Jayden's essay is due first period. The approved AI tool only signs in on his school Chromebook, which is in his locker. His phone is on the desk, already logged into ChatGPT.

02Teacher

6:50am Tuesday. A 7th-grade ELA teacher has 63 graded essays, student names at the top, and a reteach at 9:00. She photographs the stack for a free AI tool: "list the most common errors."

03Student

The rubric allows AI "as a tutor." Maya pastes the whole assignment and asks for an outline with topic sentences, then writes every paragraph herself. She is not sure if she cheated. Neither is her teacher.

04Staff

3:05pm. A truancy letter has to go home today, in Spanish. The office secretary pastes the student's name, address, and attendance record into the first free translation chatbot Google offers.

05Student

A sophomore opens the district-approved study site. Its brand-new built-in assistant pops up: "Want me to write this for you?" The domain is allowlisted. To the filter, nothing happened.

06Program

The night before a board meeting, an assistant superintendent uploads three years of discipline records, student IDs included, to an AI to "find the trends." District data, district purpose, cleared staff.

Every one of these happens somewhere every week. Pick the one closest to home, and as you play it, watch whether anyone in the room would know.

Round 3

Play it out

Run it like a real Tuesday. Be honest about what each role can actually do with the tools they have today.

S Student: comply, or route around the friction.
T Teacher: notice it, prevent it, or prove it.
A Admin: watch the three rules and mark each.

The finding: when a rule was ignored, who would have known, and how? If the honest answer is "no one," write it down.

Round 3 timer
10:00
Compare notes

Which rule broke first?

01 What did the situation do that the policy never anticipated?
02 Could anyone actually see it happen?
03 Was the rule wrong, or simply impossible to enforce?

Hold on to your answer to 02. The rest of this session is about that question.

What you just watched

Your rules were not bad. They were undefended.

Exhibit 4

Failure one · Invisible

Most use is never seen at all: personal accounts, phones, and AI that appears inside sites you already allow.

Failure two · Seen, not stopped

What you do see, nothing acts on in the moment. The policy is a request, and the prompt has already been sent.

Failure three · Carried by people

Where enforcement does exist, it runs on human vigilance: teachers watching screens and staff clearing alert backlogs no one can keep up with.

Three failures. The rest of this session takes them one at a time.

Failure one · Invisible

Four ways districts try to enforce

Exhibit 5
Before, at the door

Web filters

Block known sites. Miss embedded AI, new tools, phones, and what gets typed.
During, if watched

In-class monitoring

A teacher watches screens. Blind after the bell, at home, and inside the prompt itself.
After the fact

Assignment review

Inspect the final product. Catches the essay, not the process or the data already shared.
Every prompt, everywhere

Point-of-use governance

Sees, enforces, and protects as it happens, on device. Where Tenet works.

Each earlier method guards one slice of time, and each can only defend what it can see. Only point-of-use governance covers the moment the prompt is sent.

Failure one · Why each defense misses

Enforcement is for sale. The currency is your people.

Exhibit 6  /  drag the dial

Two axes decide whether a rule survives a normal day: can you see it, and can you act on it. Human effort buys movement, at a price, with diminishing returns, and only so far.

Human effort invested in enforcement
The binder on the shelf0%

At zero effort, only point-of-use governance is already in the target quadrant.

Enforcement at point of use →
Real governance
All intent,
no control
Written policy
Web filter
Point-of-use governance
Visibility into actual use →
Failure one · The evidence

The filter was on. The gaps were still there.

Exhibit 7

Blocklists chase domains, but AI now spawns inside approved sites, on personal phones, and behind home wifi, exactly like scenario 05. A district already running an AI-governance web filter surveyed its high school teachers. With the filter live:

92%
of teachers do not trust students to use AI appropriately without direct human supervision
Rated 1 or 2 of 5. 70% chose the lowest rating. Not one teacher strongly agreed.
70%

say AI misuse is already a problem in their own classroom.

78%

say it is a problem at home, where the filter does not reach. 61% strongly agree.

The takeaway

The answer is not to block harder. Lock everything down and students simply leave for ungoverned devices. The goal is to make the governed path the easy path.

District baseline teacher survey, grades 9 to 12, 2026. AI-governance web filter and transparency tooling already in place.

Failure two · Seen, not stopped

Guess the number

Exhibit 8

Suppose you fix visibility. One school we worked with switched on a monitoring tool that flags risky chats. In its first two days, across more than 1,500 student conversations, how many flags did it raise?

?flags in 2 days
across 0+ conversations

On paper, this is maximum visibility, a flag every thirty seconds. But with no realistic resources to act on them, it is as good as tracking nothing at all. Flagging told them it happened. Nothing stopped it. Visibility you cannot act on is not safety. It is noise.

TransparencyFlaggingActive governance

Transparency shows you the logs. Flagging sends the alert. Both arrive after the fact. Only active governance acts while the prompt is still on the screen.

Failure three · Carried by people

Control is manual, and it is wearing teachers down

Exhibit 9
Who feels in control
43%
of teachers feel in control of AI use in their classroom.
Fewer than half. And the ones who do are not relaxed about it.
What that control runs on
90%
of those in-control teachers still do not trust students to use AI unsupervised.
70% rate that trust at the very lowest, and only 10% trust them. 30% say monitoring AI already eats meaningful class time. Their control is vigilance, not the tool.
The human cost

The teachers who feel in control are the ones watching every session. The rest may simply not see what they are missing. Either way, a policy that runs on teacher vigilance is borrowing against the people you can least afford to burn out. Governance should carry that weight, not the teacher.

District baseline teacher survey, grades 9 to 12, 2026.

The second arena, revisited

The same three failures, inside your own walls

Exhibit 10

An internal AI program is not a vendor list and a training day. The same three failures appear the moment staff start working, and staff prompts carry record-level data.

Define the approved lane, then defend it

An allowlist no one enforces is the Level 1 policy again, just for adults.

Protect the data at the moment of paste

Rosters, IEPs, and personnel files leave through staff prompts, not student ones.

Govern what you build, not only what you buy

An internal assistant on district data needs the same guardrails you ask of any vendor.

The distinction underneath all three failures

Policy is not governance

Exhibit 11
PolicyGovernance
FormA documentA system
Sees actual useNoAt the point of use
TestedRarely, until an auditEvery prompt, in real time
Who carries the weightTeachers and staffThe system itself
Covers staff and internal useSeldom addressedBy design

Governance sees what policy cannot, acts where flagging stops, and carries what vigilance is dropping. We keep purchasing the first and reporting it as the second.  Source: Tenet, 2026.

In one line

A policy without enforcement
is a suggestion.

Where this leads

The gap we built Tenet to close

Governance inside the AI conversation, on the device, in real time, for students and staff. It sees the invisible, acts in the moment, and carries the weight so your people do not.

Prompt
A student or staff member types or uploads.
Tenet, on device
Redacts personal data, applies policy, checks safety, before anything leaves.
AI tool
Receives only what is allowed. Response rewritten on screen.

Sees the prompt

Redacts names and personal data before anything reaches the AI, typed or uploaded.

Enforces the rule

District, classroom, and staff policy applied live across every major AI tool.

Catches the crisis

On-device safety detection surfaces self-harm and bullying as it appears.

Selected evidence

What the research shows

Sources

54% of U.S. teens have used AI chatbots for help with schoolwork; one in ten do all or most of their schoolwork with one.

Pew Research Center, 2026

7 in 10 teens have used a generative AI tool; 40% used it for school assignments, and 46% of those did so without the teacher's permission.

Common Sense Media, 2024

About 6 in 10 teens say their school has no rules for generative AI, or they are unsure whether it does.

Common Sense Media, 2024

84% of high school students use generative AI for schoolwork, up from 79% just four months earlier; 69% use ChatGPT for assignments.

College Board, 2025

With student-monitoring software, 78% of teachers said students were flagged for discipline and 44% said a student was contacted by law enforcement from an alert.

Center for Democracy & Technology, 2022

OpenAI retired its own AI-text detector over a "low rate of accuracy"; such detectors also disproportionately misflag non-native English writers.

OpenAI / TechCrunch, 2023
Thank you

Governance is not what you
wrote. It is what you enforce.

Caleb Vail  Founder, Tenetcaleb@truemadeai.comtruemadeai.com773.766.5694
QR code: register for the next-step webinar
Next step

Scan to register for the implementation webinar

AI Governance Is Not a Policy Document1 / 27