AI In Schools: 2026 Is the Year Schools Need to Ask Not Just What AI Can Create, But What It Can Do?
- The White Hatter

- 9 hours ago
- 13 min read

CAVEAT - A special thank you to our friend Julia Helenger, a professional educator and subject matter expert in AI pedagogy, for taking the time to review this article and provide her thoughts and expertise. Here at The White Hatter, our subject matter expertise focuses on the privacy, security, and safety challenges surrounding artificial intelligence. Julia brings a complementary area of expertise as a professional educator specializing in AI pedagogy, including how AI can be thoughtfully and responsibly integrated into classroom learning, teaching practices, and school policy. Together, these areas of expertise allow us to approach AI in education from both a safety and educational perspective. We are honoured to have Julia working alongside us as part of The White Hatter team.
As schools prepare for the 2026/27 academic year, there are plenty of familiar priorities competing for the attention of administrators and educators. Staffing, budgets, curriculum, student well being, classroom technology, cybersecurity, academic integrity, and parent engagement will all continue to matter. However, we believe artificial intelligence needs to move much closer to the top of that list this year. Not because AI suddenly appeared in education, but because the technology itself is changing in ways that significantly alter the conversation surrounding its use in schools. For the past several years, much of the discussion has centred on generative AI and what students or educators can create with it. Today, schools increasingly need to think about something different, “What can AI access, what can to connect to, and ultimately, what can it be allowed to do.
Throughout much of 2024 and 2025, the educational conversation surrounding artificial intelligence understandably focused on prompt generation. Could a student use AI to write an essay? Could it answer homework questions, solve math problems, summarize a textbook chapter, generate computer code, create an image, produce a presentation, or complete an assignment? Educators also began experimenting with AI to create lesson plans, rubrics, quizzes, parent communications, classroom activities, and other educational materials. These were, and continue to be, important conversations, particularly when it comes to academic integrity, privacy, copyright, critical thinking, and determining what authentic student learning should look like in an AI enabled world. However, focusing primarily on what AI can generate risks preparing schools for where artificial intelligence has been rather than where it is increasingly going.
Artificial intelligence is quickly moving beyond the traditional chatbot model where a person enters a prompt, the AI generates a response, and the interaction essentially ends there. Newer AI systems can increasingly browse the internet, search and analyze multiple sources, access documents, connect with applications, interact with software, retrieve information, remember context, and complete multi-step tasks. When granted the appropriate permissions, some AI systems can also take actions on behalf of the person using them. This evolution toward what are commonly referred to as AI agents or agentic AI represents an important shift. We are moving from AI that primarily creates something for us toward AI that can increasingly do something for us, and those are two very different risk environments.
Consider the difference between asking an AI system to help draft an email and allowing an AI system to access an email account, read incoming messages, determine which ones are important, retrieve additional information from other connected systems, draft responses, and potentially send those responses. Similarly, there is an important difference between asking AI to help an educator create a lesson plan and connecting that same AI to systems containing student information so that it can automatically personalize educational content. There is also a significant difference between a student asking AI to explain a difficult concept and allowing an AI agent to interact with educational platforms, documents, accounts, calendars, cloud storage, or other parts of the school’s digital environment. In each example, the AI is no longer simply generating content, it’s being given some degree of access, authority, and agency.
This distinction should matter greatly to schools because educational institutions have responsibilities that many ordinary businesses and organizations do not. Schools are entrusted with children and youth, including some of society’s most vulnerable students. They collect and maintain significant amounts of personal information, communicate confidentially with families, assess academic performance, manage behavioural and accessibility information, maintain educational records, and increasingly rely upon interconnected digital infrastructure to perform many of these functions. Parents and caregivers reasonably expect schools to protect this information and to exercise professional judgment when making decisions that affect their children. For these reasons, AI cannot simply be treated as another productivity tool that staff or students can connect to institutional systems because doing so is convenient.
The Permission Question May Become More Important Than the Prompt
Over the past few years, a great deal of attention has been given to “prompt engineering,” essentially teaching people how to communicate effectively with generative artificial intelligence. Knowing how to formulate a useful prompt can certainly be helpful, but we believe schools now need to expand AI literacy beyond prompting and begin teaching what we might call permission literacy. Instead of only asking, “What should I ask this AI?” students, educators, and administrators should increasingly be taught to ask, “What have I given this AI permission to see, access, remember, connect to, and do?” As AI becomes integrated into browsers, operating systems, productivity suites, educational platforms, smartphones, wearable technology, and other digital environments, understanding permissions may become every bit as important as understanding prompts.
An AI system that only receives information deliberately typed into a prompt presents one level of privacy and security risk. An AI system that has permission to access email, cloud storage, calendars, learning management systems, documents, contacts, student information, or other applications creates a very different risk profile. Every additional permission potentially expands what the AI can see and what it might be capable of doing with that information. This does not mean these integrations are inherently unsafe or should automatically be prohibited. It does mean schools should understand them before enabling them. Convenience should not become the default justification for giving an AI system broad access to information or institutional infrastructure.
This is also where a long standing cybersecurity principle becomes extremely relevant to AI, “Only provide the access necessary to perform the required task.” Schools already understand that not every employee should have access to every student record, database, administrative system, or network resource. The same thinking should increasingly be applied to artificial intelligence. If an AI tool only needs access to a specific document to complete a task, why should it have access to an entire cloud drive? If it only needs to draft a response, why should it automatically have permission to send that response? If an educational application does not require personally identifiable student information to function, why provide it? These are governance questions that schools need to begin asking before AI agents become commonplace throughout educational environments.
Safeguarding, Privacy, Assessment, and Security Are Becoming Connected
One of the challenges surrounding AI in education is that it does not fit neatly into a single administrative category. This is not simply an information technology issue, a curriculum issue, a privacy issue, or an academic integrity issue. It intersects with all of them. Safeguarding is one obvious example. Schools need to consider whether an AI system could expose students to inappropriate material, provide unsafe or misleading guidance, facilitate harmful behaviour, or make recommendations about a student without sufficient human oversight. As students increasingly interact with conversational AI systems that can appear remarkably human in their responses, educators should also understand issues such as anthropomorphism, emotional reliance, sycophancy, persuasion, and the possibility that some students may place more trust in an AI generated response than the technology actually deserves.
Student privacy and data protection are equally important. Before adopting an AI platform, schools should understand what information the system collects, where that information is processed, how long it is retained, whether it is shared with third parties, whether it can be used to train or improve AI models, and what happens to the information when an account is deleted. These questions become even more important when an AI system is connected to other applications because the information available to the AI may extend far beyond what a student or educator intentionally types into a chatbot. Schools therefore need to think about both the information deliberately provided to an AI and the information an AI may be able to retrieve because of permissions granted to it.
Assessment integrity will also need to evolve. Much of the early educational response to generative AI focused on determining whether a student used ChatGPT to write an assignment. However, as AI becomes capable of researching information, analyzing sources, interacting with software, generating multimedia, completing multi-step workflows, and potentially working across different applications, the question of what constitutes authentic student work becomes increasingly complicated. Rather than relying primarily on AI detection tools or attempting to police every possible use of artificial intelligence, schools may need to rethink some assessment practices so that educators can better evaluate the student’s understanding, reasoning, process, and ability to defend or explain their work. The presence of AI does not eliminate the need for assessment, but it may require us to reconsider what meaningful assessment looks like.
Cybersecurity must also become part of the conversation. Every connection between an AI system and another digital platform potentially creates another pathway to information. An AI tool with access to email, documents, calendars, contacts, cloud storage, or administrative systems could become far more consequential if an account is compromised, permissions are misconfigured, or the AI performs an unintended action. As AI is increasingly integrated into all aspects of the world around us, including employment and education, there is an increasing need to move from fear based approaches to AI to informed and conscientious AI integrations. It means AI needs to be treated with the same seriousness schools already apply to cybersecurity, identity management, access controls, and protection of sensitive information. Educators, and schools in general, we believe have a moral and professional responsibility to provide conscientious oversight over integration of AI that impact students.
Human-in-the-Loop Cannot Simply Mean Clicking “Approve”
Another phrase educators and administrators are likely to hear increasingly is “human-in-the-loop.” In simple terms, this means keeping a human involved in reviewing, approving, or making important decisions rather than allowing artificial intelligence to operate completely autonomously. We believe this principle is particularly important in education, but it can easily become meaningless if schools do not clearly define what meaningful human oversight actually looks like. A person technically being present somewhere in an automated process does not necessarily mean they are exercising professional judgment.
For example, if an AI system generates a recommendation about a student’s academic performance, behaviour, accessibility needs, or educational pathway and an educator simply clicks “approve” without understanding what information was considered, how the recommendation was generated, or whether the output could be inaccurate, biased, incomplete, or inappropriate, the human may technically be “in the loop” while contributing very little meaningful oversight. The greater the potential consequence for a student, the more important genuine human review becomes. AI can assist professional decision making, but responsibility for consequential decisions affecting students should not quietly migrate from qualified educators and administrators to an algorithm simply because automation is faster or more convenient.
This is particularly important when we consider automation bias, the human tendency to place too much trust in recommendations generated by automated systems. If an AI system repeatedly produces useful information, it can become easy for people to stop critically evaluating its output. Over time, the AI’s recommendation may begin to feel like the correct answer rather than one source of information that still requires professional judgment. Educators need to remain intellectually engaged in the process. The goal should be to use AI to augment human expertise rather than slowly allowing human expertise to become subordinate to AI-generated recommendations.
The Questions School Leaders Should Be Asking Before September
Rather than beginning the conversation with, “Which AI platform should our school or district purchase?” we believe administrators should first be asking governance questions. What student, staff, and institutional information can an AI system access? What information is leaving the school’s digital environment? Where is that information being processed and stored? What other applications can the AI connect to? Can it read documents, access cloud storage, interact with calendars, retrieve emails, send messages, modify files, submit information, or perform other actions? Most importantly, where must a human explicitly approve an action before the AI is permitted to proceed?
School leaders should also be asking which AI tools are developmentally appropriate for students and whether different ages require different levels of access, supervision, and instruction. A tool that may be appropriate for a Grade 12 student conducting research may not necessarily be appropriate for a Grade 4 student. Schools also need clear processes for determining what happens when AI gets something wrong, exposes information it should not, produces inappropriate content, or performs an unintended action. Who is responsible? Who investigates? Who communicates with parents? How is the incident documented? How are permissions revoked? These are questions that are much easier to answer before an incident than during one.
Professional development will also need to evolve. If staff training continues to focus primarily on how to write prompts, generate lesson plans, summarize documents, or create classroom resources, educators may understand only one part of the emerging AI environment. Teachers and administrators increasingly need to understand AI agents, permissions, privacy, data governance, cybersecurity, hallucinations, automation bias, anthropomorphism, persuasion, and the limitations of AI-generated reasoning. Educators do not need to become computer scientists, but they do need enough AI literacy to understand what these systems are capable of doing and where professional caution is warranted.
Perhaps one of the simplest tests for any school’s AI strategy is whether administrators can explain it clearly to parents and caregivers. If a school is using artificial intelligence involving student information, families should be able to understand what the technology is being used for, what information it can access, why that access is necessary, what safeguards are in place, whether humans remain responsible for consequential decisions, and what options exist when concerns arise. If explaining an AI system requires pages of technical language that an average parent cannot reasonably understand, transparency has probably not yet been achieved. Parental trust will increasingly depend not simply on whether schools use AI, but on whether they can demonstrate that they are using it responsibly.
AI Literacy Must Now Include AI Agency
We have consistently argued that AI literacy should not simply teach students how to use artificial intelligence. It should teach youth how to interrogate it. Who created the system? What information was it trained on? What data am I providing it? Where might that information go? Why did the AI produce this particular answer? What might it have missed? Can I independently verify what it is telling me? Could bias, commercial interests, personalization, or persuasive design be influencing what I am seeing? These questions help students understand that AI output should not automatically be treated as neutral, authoritative, or correct simply because it is presented confidently.
We now believe another question needs to become part of that literacy: “What authority have I given this AI to act on my behalf?” This question will become increasingly important as AI is integrated into operating systems, browsers, productivity platforms, educational software, smartphones, smart glasses, and other devices. Students need to understand that granting an AI permission to access their email, photos, documents, contacts, calendar, location, or cloud storage is not simply turning on a useful feature. They may be granting software access to significant parts of their digital lives and, increasingly, permission to take actions using that information. Understanding the difference between asking AI for assistance and authorizing AI to act is going to become an important component of onlife literacy.
Schools Don’t Need to Fear AI, But They Do Need to Be Ready for It
None of this means that schools should panic about artificial intelligence or attempt to prohibit every emerging AI technology. There are extraordinary opportunities associated with these tools when they are implemented thoughtfully. AI can support accessibility, assist educators with administrative workloads, help differentiate learning, provide translation, support brainstorming, make information more accessible, and allow students to explore ideas in ways that were difficult or impossible only a few years ago. We believe schools should be exploring these opportunities. Embracing the benefits of AI, requires conscientious adoption, including identifying potential risks and mitigating them
The goal should be to ensure that capability does not move faster than responsibility. Schools should understand which AI systems are being used, what information those systems can access, what permissions they have been granted, what actions they can perform, where meaningful human approval is required, and who remains accountable when something goes wrong. Policies, professional development, cybersecurity practices, privacy assessments, student education, and parent communication all need to evolve alongside the technology rather than several years behind it. all need to evolve alongside the technology rather
than several years behind it.” + this requires a fundamental shift in how schools deal with policies. The time of one and done versions of any technology policy, but especially AI related policies, is over. Schools need to shift to a dynamic model, which means that technology policies will need to constantly be reviewed and updated in light of new capabilities and potential risks
This is why we believe the AI conversation heading into the 2026/27 school year needs to change. 2025 was largely about asking, “What can AI generate?” In 2026, the more important question is becoming, “What should AI be allowed to do?” That is not simply a technology question. It is a safeguarding question, a privacy question, a cybersecurity question, an assessment question, a professional accountability question, and ultimately an education question.
Schools that begin having these conversations now will be far better positioned than those that wait until increasingly capable AI agents are already deeply embedded throughout their classrooms and digital infrastructure. Artificial intelligence is evolving quickly, and our approach to AI literacy, governance, professional development, and education needs to evolve with it.
Being ready for AI no longer means simply understanding what it can create. It means understanding what it can access, what it can influence, what it can do, and where we as humans need to remain firmly in control.
Digital Food For Thought
The White Hatter
Facts Not Fear, Facts Not Emotions, Enlighten Not Frighten, Know Tech Not No Tech
POST SCRIPT:
Here at The White Hatter, our approach to artificial intelligence education goes well beyond simply teaching people how to use an AI tool or write an effective prompt. We provide evidence informed programs for students, educators, parents, and caregivers that focus on the privacy, safety, security, ethical, and critical-thinking considerations surrounding AI, which we believe should form an important foundation for meaningful AI literacy.
However, as AI becomes increasingly embedded in education, we also recognize that awareness and literacy are only part of what schools now need. Educators and administrators are being asked to determine not only whether AI should be used in the classroom, but when its use is appropriate, why it is being used, how it supports learning, and where reasonable boundaries need to exist. This requires thoughtful pedagogy, clear expectations, professional development, and policies that can evolve alongside a technology that is changing extremely quickly.
To support this next stage, The White Hatter now teamed up with an educator who is a subject matter expert on the use of AI to help schools and educators develop the pedagogical framework surrounding the responsible and purposeful use of AI in teaching and learning, as well as assist with the development and review of school based AI policies. This includes helping schools think through issues such as student and staff use, privacy and data protection, academic integrity, age and developmental appropriateness, AI agents and permissions, human oversight, assessment practices, transparency with families, and professional accountability.
Our goal is not to tell schools that they must embrace AI, nor is it to suggest that they should prohibit it. Rather, our goal is to help educational communities develop the knowledge, skills, pedagogy, and governance needed to make informed decisions about AI based on purpose, evidence, context, and educational outcomes.
If you are looking for an evidence based presentation on artificial intelligence that moves beyond the hype, fear, and headlines, we can help. The White Hatter offers engaging programs for students, parents and caregivers, as well as professional development for educators, focused on the safety, privacy, security, ethics, and responsible use of AI. Our goal is to provide practical knowledge grounded in current research so people can better understand both the opportunities and the challenges AI brings to today’s onlife world. To learn more or bring one of our AI presentations to your school or organization, connect with us at www.thewhitehatter.ca














