The AI adoption curve in K12 is steep, and governance is struggling to keep up. The National Center for Education Statistics found that 73% of public schools already have teachers using AI for work tasks, yet only 31% have a written policy on student AI use.
The pattern isn’t unique to education: a 2025 MIT study found that employees in over 90% of companies regularly use personal AI tools for work, even though just 40% of companies have purchased AI subscriptions.
These data points confirm a simple reality: AI is already in the building, whether districts have sanctioned it or not, and that gap between use and oversight is where risk lives.
Out of this gap, a new phenomenon has emerged: “shadow AI,” or AI tools not reviewed, approved or secured by an IT team. And it comes at a time when districts are amassing more data than ever before, when grades, attendance logs and health records have turned K-12 institutions into mines of sensitive information.
Yet as AI becomes a bigger part of the learning experience, these mines are in danger of being exploited in ways that pose profound risks. When unapproved tools are used, IT teams lose the ability to track where data flows, how long it’s retained or if it’s shared with third parties. Compromised tools can be leveraged by bad actors to launch phishing campaigns, impersonate users or gain access to school systems.
Moreover, K12 districts are attractive targets because they operate with limited budgets and lean cybersecurity infrastructure, and because many can be backed by public funding in times of crisis, as when personally identifiable information of minors may be at stake.
As a project leader who has managed strategy, implementation and learning experiences across more than 15 K-12 districts, I’ve seen shadow AI emerge as one of the most acute threats for this technology. Here are three steps that districts can take to combat this rising risk.
1. Establish technology governance
A first action to protect against shadow AI is to survey a district’s technology landscape, classify all AI-related tools and establish guidelines for what tools can continue to be used:
- Create an inventory. First, conduct a district-wide survey and deploy audit tools, such as Lightspeed Digital Insight, to identify all AI tools being accessed.
- Evaluate AI tools based on three criteria. Assess how effective each tool is in achieving learning outcomes, how strongly each tool is protecting data privacy and how each tool is integrating with a district’s current technologies. Districts can do this by using standards such as those by the 1EdTech TrustEd Apps program.
- Build AI literacy among stakeholders. Train educators and students to understand how AI tools collect data, how to interpret AI outputs critically and how to avoid inputting sensitive information. Organizations like aiEDU and the MIT Media Lab offer useful resources for these AI literacy best practices.
2. Implement training
A second move to address shadow AI is to equip district members with the knowledge and tools to understand and use AI effectively.
According to a report by the Center for Democracy and Technology, less than half of teachers (48%) have participated in AI training provided by their schools, and less than half of students (48%) say they have received information on how to use AI.
Teachers, especially, must be empowered to integrate AI tools in classrooms and teach how to use these technologies responsibly in their work. The best way for districts to address this is by establishing a focused, relevant and accessible professional development program for teachers.
Several technology companies and educational organizations have created AI training guides to help with this, including Nvidia, Microsoft, Google, Coursera, the ISTE+ASCD and the American College of Education.
3. Create an early-adopter community
A third step for combating shadow AI is to cultivate a group of tech-savvy educators that can test new AI tools in partnership with a formal IT vetting team.
Developing this informal group allows a district to gain buy-in, model best practices for safe use of tools and get quick wins, such as using AI to analyze test scores for parent communications without exposing full student datasets to new tools.
Ultimately, these local experts offer a district three advantages:
- They can try out AI tools specific to a district’s day-to-day uses.
- They can catalog a tool’s pros and cons in relation to a district’s precise needs.
- They can apply an insider’s knowledge to conduct quality assurance before rollout.





