Fastvue

America’s Two Largest School Districts Are Restricting Student AI Use

Image of a yellow school bus in the foreground of the Brooklyn Bridge

by

Bec May

America’s two largest school districts are drawing a line around student AI use. The bigger story is what comes after the line is drawn.

What this means for school AI policy

On 2 September 2026, New York City announced a one-year moratorium on student-facing generative AI for students from 2-K through eighth grade. Nearly 600,000 students are covered. Companion-style chatbots are prohibited, while high schools will focus on AI literacy and a small number of tightly supervised, approved AI pilots.

Los Angeles Unified has gone further at the device layer. LAUSD has restricted generative AI on all district-owned laptops and tablets across all grades while its Generative AI Ad Hoc Committee develops longer-term rules.

While NYC and LA are at the center of the headlines, the questions and concerns behind these decisions are being asked by school districts across the country: which AI tools should students be allowed to use, where should access be restricted, how can districts tell whether those policies are actually working, and what technologies need to be in place to ensure they are.

Student AI use is already mainstream

Schools are no longer trying to get ahead of AI use; they are scrambling to catch up.

A 2026 Pew Research Center Survey found that 54% of US teens had used AI chatbots for schoolwork, while more recent research from Common Sense Media put broader AI use for schoolwork at 70%.

The concern is not as simple as 'students are using AI ’. It is how they are using it. Common Sense Media found that 63% of teen AI users were using it to answer academic questions directly—and herein lies the real heart of the matter. Where does useful assistance end and replacement of learning begin?

A study of nearly 1,000 high school math students found that unrestricted GPT-4 access improved performance while students were using it, but students performed 17% worse than the control group once that access was removed.

More recent research found that an AI math tutoring model configured to coach rather than provide the modern equivalent of back-of-book answers (which my friends and I used to affectionately call "BOB") significantly improved math outcomes.

So what is my point here?

First, we still don't have enough evidence to know the long-term impact of sustained AI use on how students learn, retain information, and develop critical skills and independent thinking.

Secondly, the research we do have suggests the outcome depends heavily on how AI is used. Tools that simply hand over the answer risk replacing the learning. Tools designed to coach, prompt, and challenge can support it.

For districts, that means the answer is not simply to allow AI or block it. It is to keep testing, keep measuring, invest in digital literacy, and make sure students remain in the driver’s seat of their own learning.

NYC's approach to controlled Artificial Intelligence use 

NYC's high school pilots provide a useful example of controlled AI use. NYC Public Schools also prohibits AI use for grading and behavior monitoring. Quill is capped at 15 minutes per week; Edia at 20 minutes; Brisk Boost is limited to short teacher-created activities; Playlab is restricted by assignment; and Intel AI-Ready Schools is tied to supervised project work.

This model shows how quickly AI governance becomes more granular than a simple allow-or-block decision. Access varies by age, tool, purpose, and supervision, and district-specific rules and local context shape that guidance, with different rules for different parts of the school system.

On the technical side, this is a completely different proposition from maintaining a blocked application list. Districts need controls that reflect those distinctions, along with enough visibility to see whether they are holding up in practice.

Why blocking AI is not enough

Among students who used AI for schoolwork, 44% said an AI service had been blocked on their school network or device. Unsurprisingly, 59% of these students said they responded by switching to a personal device.

The lesson is not 'filtering has failed' (cue doom-filled voiceover). The lesson is that filtering was never designed to carry the whole burden of responsible use.

The same layered principle already exists elsewhere in school technology governance. Under CIPA, filtering sits alongside internet safety policies, monitoring of minors’ online activity, and education about appropriate online behavior. AI introduces different risks, but it similarly cannot be governed by a blocked list alone. 

A district may decide that certain tools should be blocked entirely, others should be available only to staff, and certain applications should be approved for specific grades, subjects, or activities.

The technical controls are only one layer. Firewalls and web filters can restrict access to known AI services, while account, identity, and device controls can further narrow access. But students may still switch services, use personal devices, or encounter AI inside approved platforms.

That is why districts also need visibility into what happens after the controls are applied, alongside AI literacy and clear expectations for appropriate use.

A layered approach is stronger: policy sets the rules, technical controls enforce them where possible, monitoring shows what is actually happening, and AI literacy and human oversight help students use these tools responsibly.

A layered approach to responsible AI use

No single control can guarantee student AI use will be 'safe', appropriate, or educationally valuable. Districts need several layers working together, with each doing a different job across the wider education system.

Policies and AI governance set the boundaries

District AI policy defines which tools are approved, who can use them, for what purposes, and under what conditions. As NYC's pilot demonstrates, those rules can vary by age, tool, subject and level of supervision.

Technical controls put policy into practice

Firewalls, web filters, account controls and device management can restrict prohibited AI services, apply different access to different users and disable AI features where these controls are available. This enforcement layer turns district policy into something operational across the network and managed devices.

For schools still setting up these controls, you can check out our guide on how to block ChatGPT.

Visibility shows whether the controls are working

Monitoring and reporting give districts evidence of what is actually happening after controls are applied. That can include which AI services are being accessed, where blocked attempts continue, whether use shifts to other platforms, and how behavior changes after policy updates.

Tools such as Fastvue Reporter for Education use data already captured by supported firewalls and web security platforms to make those patterns easier to see by user, group, and application.

AI literacy builds critical thinking 

Technical controls and monitoring can provide increasingly detailed visibility into AI use. In some environments, that can extend to prompts students enter into Generative AI tools. For example, FortiGate and Fastvue Reporter can monitor AI prompts across supported AI applications.

However, in most environments, that visibility is still limited. Seeing that an AI service was accessed, or even seeing the prompt itself, does not necessarily tell you whether the use was appropriate, educationally valuable, or consistent with the intent of an assignment.

Clear expectations, digital literacy, and academic integrity guidance remain essential to helping students understand where useful assistance ends and replacement of learning begins.

Human review still matters

Network activity, blocked requests, and even AI prompts can provide useful context, but they do not tell the whole story. Teachers, IT teams, and school leaders still need to consider the student, the assignment, and the circumstances before deciding whether AI use was appropriate or whether the policy itself requires further iteration.

School AI policy needs clear ownership

Creating an AI policy for schools is one thing. Ensuring it exists as a coherent, usable framework is another.

When we first talk with schools, we often find pieces of relevant policy scattered across acceptable use, academic integrity, digital citizenship, data privacy, and IT security documents. Each tends to cover part of the problem, but together they do not necessarily give staff a clear answer on what AI use is allowed, who is responsible for enforcing it, or what should happen when something falls outside the rules.

AI policy cuts across technology, teaching and learning, academic integrity, student privacy and school operations, so fragmented ownership quickly becomes fragmented implementation. IT may be responsible for technical controls and visibility, but it cannot decide what appropriate AI use looks like inside an assignment. Teachers and curriculum leaders are better placed to make those judgments, but they need clear guidance on approved tools and acceptable use. Privacy and security teams need to understand student data AI vendors collect, and how it is handled.

For district leaders, the goal should be a shared governance model with clear ownership over policy, technical enforcement, professional learning, vendor approval, and ongoing review.

Every approved AI tool creates a new governance decision

For school leaders who decide against blanket bans on AI systems, deciding whether an AI tool belongs in your school is only the first step.

The more complicated questions come next. Approval is not simply a matter of whether the platform works or whether teachers want to use it. District leaders need to understand both the risks the tool introduces and the educational value it is expected to deliver.

That means assessing two things in parallel: whether the tool is safe and governable enough for student use, and whether its use is genuinely improving learning.

Data, privacy and safeguarding

  • What student data does the tool collect?

  • How is that data stored, protected and retained?

  • Are prompts or outputs used to train AI models?

  • What safeguards are built in?

  • Does the vendor meet the district’s privacy, security and safeguarding requirements?

Educational value and impact

  • What problem is the tool supposed to solve?

  • Does it support student learning, critical thinking, and independent work?

  • Does it risk bypassing the thinking the task was designed to develop?

  • How will the district measure its impact on student learning outcomes?

  • What evidence would justify continuing, expanding, or restricting its use?

As AI technologies evolve, districts need to revisit those questions alongside technical controls. An application that passed review last year may introduce new AI capabilities, new data practices or a very different role in student learning this year.

  1. Turn AI policy into operational rules. Define which tools are approved, which are restricted, who can use them, and under what conditions. That may vary by age, grade, user group, subject, assessment type, or approved pilot. NYC’s model is useful precisely because access is bounded by tool, time, purpose, and supervision.

  2. Build technical controls around those rules. Use controls across identity, accounts, firewalls, web filtering, and managed devices to enforce the policy as consistently as possible. A blocked list still matters, but it becomes less sufficient as AI functionality appears inside otherwise approved platforms and everyday software. Student-facing AI is increasingly showing up inside mainstream education technology, not just standalone chatbot sites.

  3. Measure what happens after the controls are applied. Look beyond the number of blocked requests. Are students moving to other AI services? Are repeated attempts continuing after a policy change? Are new applications appearing? Is VPN or proxy activity changing? That evidence can show where controls are holding and where policy may need further iteration.

  4. Treat AI literacy as part of the control model. Policy and filtering can influence access, but they cannot make every judgment for the student. Districts need clear guidance around appropriate AI assistance, academic integrity, critical thinking, and how students should evaluate AI outputs, with ongoing support for educators as practice evolves. The research report specifically found evidence that AI-literacy instruction can improve how critically students engage with AI.

  5. Make every approved tool or pilot an evidence-and-privacy exercise. Approval should consider not only whether a tool has educational value, but what student data it collects, whether prompts or outputs are retained or used for model training, what vendor security controls exist and what evidence would justify expanding or continuing its use.

  6. Build review and iteration into the policy from the start. The strongest model from the research is not “write policy, enforce policy, done.” It is: set the policy → educate → apply controls → observe what happens → review with human judgment → adjust.

The next phase of school AI policy

The question for districts is no longer whether students will use AI. They already are.

The harder question is what responsible use should look like, how those expectations will be enforced, and how leaders will know whether school AI policy is working in practice.

NYC and LAUSD are taking different approaches, but both point to the same reality: school AI policy cannot sit in isolation. It needs to connect curriculum, technology, privacy, academic integrity, technical controls, monitoring, and human judgment.

The districts that get this right will not be the ones with the longest blocked list. They will be the ones that set clear boundaries, apply the right controls, see what is actually happening, and keep refining their approach as the technology, evidence, and student behavior change.

Your school AI policy is only as useful as your ability to see how it is working in practice.

Fastvue Reporter helps districts turn existing firewall and web security data into clearer evidence of AI use, blocked activity, and changing network behavior.

Don't take our word for it. Try for yourself.

Download Fastvue Reporter and try it free for 14 days, or schedule a demo and we'll show you how it works.

  • Share this story
    facebook
    twitter
    linkedIn