How We Used AI to Write Our School Digital Strategy (and Why It Will Never Be Finished)
- Adam Sturdee

- Aug 7
- 12 min read

This year I led the writing of a five-year digital strategy for the secondary school where I work.
I want to share the process, because the way we built it changed my view of what a school strategy document can be.
We used AI throughout. Not to invent the strategy for us, but as a research assistant, drafting partner, critical friend and institutional memory.
The result is a strategy that is more evidence-based, more coherent and dramatically easier to keep up to date than anything I could have produced alone.
And that last point matters.
We deliberately chose a five-year horizon. Not because we believe anyone can predict what school technology, let alone artificial intelligence, will look like five years from now. They plainly cannot. We chose five years because schools still have to make long-term decisions about infrastructure, budgets, devices, contracts, staffing, curriculum and professional development.
The trick is to plan five years ahead without pretending the fifth year is already known.
Our strategy therefore describes where we are now, the direction in which we want to travel and the decisions we can reasonably foresee. It is reviewed at least annually and can be adjusted sooner when technology, guidance, safeguarding risks or the needs of the school change.
The Department for Education actually supports this principle. Its digital leadership and governance standard says schools should have a digital technology strategy covering a minimum of two years and should revisit and review it annually at a minimum, amending it as circumstances change.
For us, five years provides the horizon. Annual review provides the discipline. In some areas, particularly AI, safeguarding and cyber security, I suspect termly review will make more sense.
That apparent contradiction — planning further ahead at precisely the moment when technology is changing faster than ever — is not really a contradiction at all.
It is the reason schools need a strategy.
Start with compliance: what schools are actually expected to do
Before you write a word of a digital strategy, you need to understand the landscape of expectation.
There is no single statutory document called a "digital strategy" that every school in England is legally required to produce. But the combination of statutory safeguarding duties, data protection law, assessment regulations and the Department for Education's increasingly explicit digital standards means that schools now operate within a substantial framework of expectations.
The DfE's current digital and technology standards make the direction particularly clear. Schools and colleges should be working towards six core standards by 2030: broadband internet, wireless networks, network switching, digital leadership and governance, filtering and monitoring, and cyber security. Filtering and monitoring is expected to be met now.
The digital leadership and governance standard is especially relevant. It says schools need a member of the senior leadership team with strategic oversight of digital technology, responsible for creating and managing a digital technology strategy led by the needs of staff and pupils rather than by the technology itself. The strategy should be based on teaching and learning outcomes and organisational need, aligned with the school development plan, and supported by governors or trustees.
That is a significant shift from the old model in which "IT strategy" could mean little more than deciding when the laptops needed replacing.
The core reference points we worked from included:
the DfE's digital and technology standards for schools and colleges, including digital leadership and governance, broadband, wireless networking, network switching, filtering and monitoring, cyber security, cloud, servers, devices, accessibility and IT support;
Keeping Children Safe in Education, particularly the expectations around online safety, filtering and monitoring;
the DfE's Generative artificial intelligence in education policy and its supporting safe-use materials;
the DfE's Generative AI product safety standards;
current DfE and ICO material on data protection in schools, including the implications of AI and the changes flowing from the Data (Use and Access) Act 2025, on which the DfE has said further education-specific detail will follow;
the NCSC's cyber security guidance and resources for schools, including its questions for governors and trustees;
JCQ guidance on AI use in assessments, which matters directly to secondary schools delivering regulated qualifications;
the Prevent duty, the Equality Act 2010 and relevant accessibility requirements;
There are a couple of important timing points here.
At the time of writing, Keeping Children Safe in Education 2025 remains the version in force until 31 August 2026. KCSIE 2026 has already been published but comes into force on 1 September 2026. That is exactly the sort of version change a living strategy needs to cope with rather than silently carrying an outdated reference for another year.
The mobile-phone position has changed too. Revised guidance became statutory on 29 June 2026 and schools are expected to begin following it from 1 September 2026. It expects schools to implement a policy prohibiting mobile-phone use throughout the school day, subject to the adaptations and reasonable adjustments described in the guidance.
That is why compliance research cannot be a one-off exercise completed at the beginning of a five-year strategy.
The ground moves.
Safeguarding is not an IT subsection
One of the clearest conclusions from doing the research was that online safety cannot sit somewhere near the back of the strategy under "IT".
Filtering and monitoring are safeguarding responsibilities.
The DfE's filtering and monitoring standard says schools have a statutory responsibility to keep children safe online as well as offline, and governing bodies and proprietors should make sure appropriate filtering and monitoring systems are in place.
The expectation that the effectiveness of filtering and monitoring arrangements is reviewed at least annually is well established, and KCSIE 2026 maintains and sharpens that emphasis.
Cyber security increasingly belongs in the same conversation. A compromised account, inaccessible safeguarding system or breach of sensitive pupil information is not merely a technical inconvenience. It can become an immediate safeguarding and operational problem.
The NCSC provides specific cyber-security resources for schools and questions for governors and trustees precisely because this requires strategic oversight, not just technical competence.
Any digital strategy that separates technology from safeguarding too neatly has misunderstood the problem.
AI needs a vision, not just a policy
Compliance gives you boundaries. It does not give you ambition.
A school also needs a view of what it thinks AI is for.
My own view is that schools should be bold about this.
Ignoring generative AI is not a sustainable strategy. Nor is blocking it, writing a policy about misuse and assuming the job is done.
This technology is already changing the way knowledge work happens outside school. It is changing administration, communication, software development, research, design and many other professions. Our pupils will enter a world in which working intelligently with AI is likely to be an ordinary part of professional life.
Schools should therefore be asking a much bigger question than, "How do we stop pupils using ChatGPT for homework?"
What do we want young people to understand about AI? When should they use it? When should they deliberately not use it? How do we protect the development of knowledge, writing, reasoning and independence while also teaching pupils how to use powerful new tools critically and responsibly?
And what should teachers themselves be able to do with it?
The DfE's position is deliberately enabling rather than prohibitive. It says education settings should make the most of the opportunities technology provides while using it safely and effectively. It identifies potential benefits in areas such as resource creation, planning, feedback, revision and administrative work, while stressing that professional judgement remains essential and that AI-generated material must be checked for appropriateness and accuracy.
That is a much more useful starting point than either enthusiasm without safeguards or safeguarding without ambition.
A digital strategy therefore needs a bold educational vision for AI as well as rules for its safe use.
The two belong together.
Why we did not just write a document
Most school digital strategies die the same death.
Someone writes a heroic thirty-page document. It gets discussed, approved, saved somewhere sensible and gradually becomes a description of a school that no longer exists.
The devices change. Contracts change. Guidance changes. Staff change. AI changes every other Tuesday.
Three years later, someone opens the strategy because a governor has asked for it and discovers that half the links are dead.
We wanted the opposite.
So instead of starting with a blank Word document, we started with an AI project.
I used Claude Projects, although the principle matters much more than the particular product. Other AI platforms provide similar project or workspace approaches.
A project gives you something a single chat does not: a persistent working environment containing the source material, project instructions, drafts, evidence and accumulated decisions behind the strategy.
That changes the job completely.
The strategy is no longer just one document.
The document is the published expression of a much larger maintained evidence base. I have written before about why schools need learning systems rather than a collection of AI tools, and this project was that idea put into practice.
What we put into the project
The quality of the system depends heavily on what sits behind it.
Our project grew to contain more than seventy documents.
At its centre was a research memory seed: a carefully prepared document setting out the school context, the national expectations we had identified, the intended architecture of the strategy and explicit rules governing how the AI should behave.
Among other things, it was told not to invent legal requirements, not to fill gaps with plausible guesses and to flag statements that depended on guidance that should be checked against the current published version.
Around that sat the national source material: the DfE digital standards, current KCSIE material, filtering and monitoring guidance, NCSC resources, DfE data-protection guidance, AI policy and safe-use material, JCQ assessment guidance, Prevent and accessibility material.
Then came the internal evidence base.
That included our AI policy; mobile-phone policy; safeguarding and online-safety arrangements; filtering and monitoring documentation; cyber-security and incident-response plans; disaster-recovery and business-continuity plans; data-protection policies and privacy notices; records-management policy; SEND, equality and accessibility policies; the school improvement or development plan; curriculum and teaching-and-learning priorities; device-replacement plans and costings; contracts and licensing information; the existing IT management plan; staff-training plans; and relevant procurement documentation.
The DfE's current digital leadership standard also expects schools to maintain information such as contracts, asset and information-asset registers and to keep these current. Those became useful parts of the project evidence base too.
Finally, we added working documents: an evidence log showing the owner, version, source and review date of key documents; a digital risk register; a gap-analysis checklist; and a record of decisions.
This is the bit I would urge schools not to skip.
A folder full of PDFs is not institutional memory.
A managed evidence base is.
The project format is what makes a five-year strategy possible
This is where the five-year planning issue comes back in.
It would be absurd to write a detailed technology roadmap today and assume that the decisions in Year Five should simply be carried out because someone typed them into a table five years earlier.
That is not strategy. It is fortune telling.
A five-year strategy should instead establish a direction of travel and a set of principles, priorities, dependencies and likely investment needs based on what is known now.
Each review then asks: what has changed?
That review can happen annually as a minimum, because that is the DfE expectation. In rapidly moving areas, a lighter termly review may be sensible too. And the point is that this is easily and rapidly done using an AI project architecture.
Suppose KCSIE changes.
Upload the new version. Remove or archive the superseded version. Ask the project which statements, risks, actions and policies are affected.
Suppose the DfE updates its digital standards.
Replace the source document and rerun the gap analysis.
Suppose the school changes its mobile-phone arrangements, appoints a new IT provider, replaces its filtering system or adopts a new AI platform.
Update the evidence base and ask what else now needs to change.
Suppose an old policy is withdrawn or ceases to be relevant.
Remove it from the active evidence set.
Suppose completely new guidance appears.
Add it.
The project can then compare the new evidence with the strategy that already exists.
That is the crucial difference.
You are not beginning again every time something changes.
You are maintaining a system.
Guardrails before cleverness
Using AI on material involving children, safeguarding and data protection demands discipline.
Our rules were simple.
Safeguarding comes first.
Nothing identifying individual pupils or staff goes into the project merely because doing so would be convenient. Any school using an AI platform also needs to understand its own data-protection responsibilities, the terms and data handling of the product it is using and the organisation's approved processes.
The DfE now has specific guidance on generative AI and data protection in schools, covering personal-data risks and relevant data-protection law.
AI does not get to invent compliance.
If a requirement cannot be traced to a reliable source, it should not appear in the strategy as though it were law.
Humans decide.
AI can draft, compare, summarise, interrogate and challenge. Senior leaders, DSLs, DPOs, technical staff and governors remain accountable for the decisions.
This closely matches the DfE's own position: generative AI cannot replace professional judgement, and responsibility for the quality and content of final work remains with the professional and organisation producing it.
Where information is missing, use a placeholder rather than a confident invention.
And every recommendation needs a workload test.
If the strategy assumes staff have unlimited time to carry out new checks, create resources, learn platforms, rewrite curricula and run audits, it is not an ambitious strategy.
It is fiction.
AI and assessment needs its own attention
For secondary schools, assessment is another reason AI cannot simply be bolted onto an existing digital plan.
JCQ maintains specific guidance on AI use in assessments and the responsibilities of centres, teachers and assessors. The current guidance covers areas including candidate misuse, acknowledgement of AI use, centre responsibilities, prevention and identification of misuse, marking and reporting.
That needs to connect directly to school decisions about homework, coursework, non-examination assessment, staff training, pupil AI literacy and academic integrity.
An AI policy sitting in isolation from assessment practice will not do the job.
The strategy becomes a capability
This is the part I most want other school leaders to understand.
Because the strategy lives in a project rather than only in a file, it behaves differently.
When guidance is updated, we can ask what it changes.
When a new AI product is suggested, we can assess it against our own policies, safeguarding requirements, data-protection expectations and the DfE's generative-AI product safety standards, which cover areas including filtering, monitoring, privacy, security, intellectual property, governance and risks to children.
When governors ask a question, we can create a briefing grounded in the evidence base but written for a governance audience rather than a technical one.
When budget planning begins, we can connect strategic ambitions with device replacement, contracts, infrastructure and likely costs.
When the annual review comes around, the evidence log tells us which source documents have changed and the risk register tells us where the assumptions have moved.
The strategy stops being a document you wrote.
It becomes a capability you maintain. It is also, I think, the antidote to the pattern I have described elsewhere, where schools perform AI readiness instead of building it.
Five years ahead, one year at a time
There is something slightly paradoxical about writing a five-year digital strategy in 2026.
Artificial intelligence is moving at extraordinary speed. Products that dominate conversation today may disappear. Capabilities that seem experimental may become routine. New safeguarding, data-protection and assessment questions will emerge that we have not yet thought of.
That is precisely why the school still needs a long-term view.
Someone has to think about infrastructure.
Someone has to think about budgets.
Someone has to think about staff capability, curriculum, safeguarding, equity of access, cyber resilience and the skills pupils will need when they leave us.
Five-year planning does not mean pretending you know the future.
It means deciding, from where you stand today, what direction you believe the school should travel in and what foundations will give you the ability to respond intelligently when the world changes.
Then you revisit that judgement.
Every year at minimum.
Perhaps every term for the fastest-moving areas.
You keep what still makes sense.
You change what does not.
And you keep the evidence underneath it current.
What I would tell another school starting tomorrow
Do the compliance work first. Know which requirements are statutory, which are DfE standards and which are recommendations or your own strategic choices.
Then develop the vision.
Do not allow the strategy to become a defensive document about cyber attacks, inappropriate content and pupils cheating with AI. Those things matter enormously, but they are not the purpose of educational technology.
Ask what excellent digital provision would make possible for teaching, learning, inclusion, communication and staff workload.
Ask what pupils need to understand about AI if they are to leave school able to use it intelligently rather than either fear it or trust it blindly. I have written separately about how school leaders should already be using AI in their own work, because leaders who use it thoughtfully themselves make far better decisions about it.
Then build the evidence base.
Put the real documents into a managed project environment. Keep versions and review dates. Add new guidance when it appears. Remove or archive superseded material. Maintain the evidence log and risk register alongside the strategy itself.
And choose a horizon long enough to make serious decisions.
For us, that is five years.
Not because we know what 2031 will look like.
Because we know we need to be thinking about it.
The five-year horizon gives us direction. The annual review keeps us honest. The project keeps the knowledge underneath it alive.
And AI makes maintaining that system feasible in a way that simply was not practical before.
The strategy will never be finished.
That is not a failure of the approach.
It is the entire point.
Further reading
Meeting digital and technology standards in schools and colleges, DfE: https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges
Keeping Children Safe in Education, DfE: https://www.gov.uk/government/publications/keeping-children-safe-in-education--2
Generative artificial intelligence in education, DfE: https://www.gov.uk/government/publications/generative-artificial-intelligence-in-education
Mobile phones in schools, DfE: https://www.gov.uk/government/publications/mobile-phones-in-schools
Cyber security for schools, NCSC: https://www.ncsc.gov.uk/section/education-skills/schools
AI use in assessments, JCQ: https://www.jcq.org.uk/exams-office/malpractice/artificial-intelligence/
Appropriate filtering and monitoring, UK Safer Internet Centre: https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring
On this blog
Schools need more than AI tools. They need learning systems: https://www.adamsturdee.com/post/schools-need-more-than-ai-tools-they-need-learning-systems
Four Ways School Leaders Should Be Using AI Already: https://www.adamsturdee.com/post/four-ways-school-leaders-should-be-using-ai-already
We have been here before: AI and the edtech graveyard: https://www.adamsturdee.com/post/ai-readiness-has-become-a-performance
Adam Sturdee is a senior leader and co-founder of Starlight, the UK’s teacher-first AI-powered transcript-based coaching platform for educators.
His work sits at the intersection of dialogic practice, instructional leadership and responsible AI strategy for schools and trusts.
He recently presented his research on AI-supported coaching at the BERA TEAN Conference 2026: https://www.bera.ac.uk/conference/bera-tean-conference-2026
If you would like to explore these ideas further:
Learn more about Starlight: https://www.starlightmentor.com
Read more on AI and coaching: https://www.coaching.software
Connect on LinkedIn: https://www.linkedin.com/in/adam-sturdee-b0695b35a/
Enquire about speaking or consultancy: https://www.adamsturdee.com/consulting



Comments