What the district actually passed
On July 28 the Orange County Public Schools board approved its first formal AI policy, effective August 11 when students return. OCPS is one of Florida's largest districts, so this is a policy governing a population comparable to a mid sized enterprise. The substance is more carefully constructed than the summaries suggest. Students may use AI for background research ahead of an assignment. They may not submit AI generated work for assessment without written permission from the teacher. They are required to notify parents before using AI. Only district approved platforms are permitted, which is framed explicitly as a data protection measure rather than a quality one.
On the staff side, the constraints run in the other direction. Teachers decide whether and how AI is used in their classroom, and must communicate those guidelines in writing at the start of the year to both students and parents. Staff remain accountable for high stakes decisions including grading and cannot rely solely on an AI system to make them. The policy also bans the use of chatbots for emotional support, which is a specific and sensible carve out. The whole thing is subject to annual review as tools and state standards change. Board member Maria Salamanca of District 2 described the core mechanism: "What we ask the teachers to do is, at the beginning of the year, in a written form, provide their guidelines for how they expect to interact with students and AI."
The consultation is the part worth copying
The process behind this policy deserves more attention than its contents. The district began drafting guidance in 2025, when it blocked consumer platforms including ChatGPT on its network while it studied classroom applications. It then ran the proposal through board discussions in April, May, and July. Along the way it collected 20,000 survey responses from teachers and parents, and each board member held a separate town hall with students. By the time the vote happened, the constituencies who would have to live with the policy had been asked, repeatedly, in forums where their objections were on the record.
Compare that with how AI acceptable use policies typically arrive in enterprises. Legal drafts a document, security adds an approved tools list, it is published to the intranet, and adoption is measured by completion of a mandatory training module. Nobody asked the people doing the work what would help them or what would drive them to shadow usage. The result is a policy that is technically in force and widely ignored, which is a worse position than having no policy at all because it creates the appearance of governance without the substance. A Gallup and Walton Family Foundation survey released in May found that 82 percent of teachers had received no formal guidance on using AI in their jobs. That vacuum is what unenforced policy actually produces.
Rules set at the point of use, guardrails set centrally
The architectural choice here is the delegation of specific rules to teachers while holding the guardrails centrally. The district decides which platforms are approved, that human staff own high stakes decisions, and that parents must be informed. The individual teacher decides what AI use looks like in a ninth grade chemistry class versus an advanced placement literature seminar, and has to write it down and communicate it. That division recognises something central policy authors resist admitting: the correct rule genuinely differs by context, and the person closest to the work knows the context.
This maps directly onto the problem enterprises are failing to solve. A single organisation wide rule on AI generated code, or AI drafted client communications, or AI assisted analysis, will be simultaneously too permissive for the regulated business line and too restrictive for the internal tooling team. The productive structure is the one OCPS chose: the centre owns the tool allowlist, the data boundaries, and the accountability principle, and the accountable local leader publishes the specific working rules for their team in writing. The written and published requirement is what stops delegation from becoming abdication, because a rule nobody wrote down is a rule nobody can be held to.
Refusing to buy the detection tools
The most striking commitment in the policy is that the district will not use AI detection tools. Teachers assess work through other means. This is a district with real budget pressure choosing to forgo a category of product that vendors have been selling hard into education for three years, on the reasonable grounds that the tools do not work reliably and that false accusations of cheating do lasting damage to students. It is a decision to accept a known enforcement gap rather than paper over it with a technology that produces confident wrong answers.
We would like to see considerably more of this reasoning in enterprise security and compliance. The AI detection market has an enterprise analogue in tools that claim to identify AI generated content in code review, in vendor submissions, and in hiring. They carry the same fundamental problem: the false positive rate is high, the consequences of a false positive fall on an individual, and the vendor's accuracy claims are not independently verifiable. Buying one converts an unsolved policy problem into an automated decision that feels rigorous. OCPS made the harder and more honest choice, which is to state the expectation clearly, hold people accountable through judgement, and decline to pretend the problem is technically solved.
The dissent named the real gap
Stephanie Vanos of District 6 voted against the policy despite supporting most of it, on the grounds that it contains no opt out for parents who do not want their children using AI at all. That is a substantive objection rather than a procedural one. The policy requires students to notify parents before using AI, which gives parents information without giving them a decision. Vanos also placed the question in a wider frame: "I think it's important because AI is changing. There are institutions of higher education that are not allowing AI at all."
The same gap runs through nearly every enterprise AI policy we have reviewed. Organisations notify employees that AI systems are used in their workflow, in performance analytics, in scheduling, in candidate screening, and provide no mechanism to decline. Notification without a decision right is a weak form of consent, and it is exactly the arrangement that emerging regulation in Europe and several US states is moving to constrain. An organisation that builds an opt out pathway now, while the population choosing it is small and the accommodation is cheap, will be in a considerably better position than one that has to retrofit it under a compliance deadline.
What we would take into an enterprise policy
Four elements from this policy transfer cleanly. First, an approved platform allowlist justified explicitly on data protection grounds, which is a far easier argument to win internally than one based on output quality. Second, a clear statement that named humans remain accountable for high stakes decisions and cannot delegate them to a system, which is the single most important sentence in any AI policy. Third, delegated rule setting at team level with a written publication requirement. Fourth, a scheduled annual review, so the policy has a maintenance owner rather than becoming a document nobody dares reopen.
The element we would add is the one Vanos identified. Build the opt out, define what accommodation looks like, and decide in advance who approves it. Beyond that, the process lesson stands on its own: this district spent roughly a year consulting before it published, and it will get compliance because the people bound by the rules helped write them. Enterprises that want their AI policy to survive contact with the organisation should budget for that consultation rather than treating the drafting as the work. The document is the cheap part.


