AI Safety Policy (Template)
Policy template describing AI model usage, advisory-feedback safeguards, staff visibility, and school-owned escalation.
Outleap AI Safety Policy (School-Facing Template)
Status: Approved baseline template. Adapt through your school safeguarding and governance process before local adoption.
1. Purpose
This policy defines how AI-assisted feedback in Outleap is governed so that student outcomes, fairness, and safeguarding are protected.
2. Scope
Applies to Outleap usage by:
- outleap_admin
- school_admin
- teacher
- student
3. Operating Principles
- Human accountability: School and authorised staff remain responsible for decisions and published guidance.
- Safeguarding first: Any welfare concern takes priority over workflow speed.
- Transparency: AI assistance is used as part of a supervised educational process.
- Minimum necessary data: Only required context is sent for feedback generation.
- No hidden student profiling: No automated high-stakes decisions are made solely by AI output.
4. Intended Use
Current intended use (the processing in place today):
- Help students structure their own evidence into reusable Evidence Bank records.
- Generate structured, advisory feedback on UCAS three-question statements. Feedback is bounded to the student's own draft and is visible to staff through normal product views; automated safeguarding alert delivery, staff routing and review holds are not active in the launch product.
- Support consistency and efficiency across feedback rounds.
- Provide CV/application support where enabled for the school. This is student-owned support on the student's own work unless the workflow is submitted for staff review.
- Provide staff with context for coaching conversations.
Reference Studio (AI-assisted reference drafting for staff review and finalisation) and Opportunity Radar are coming September 2026. They are not part of current intended use or current processing unless activated by written agreement.
5. Prohibited Use
- Treating AI output as final without authorised review.
- Using AI output as the sole basis for safeguarding judgments.
- Entering unrelated sensitive personal data into prompts/workflows.
- Sharing student statements or feedback outside approved school/supplier systems.
- Presenting AI feedback as approved school guidance; it is AI-assisted support, not school-authored advice.
6. Safety Controls in Service Operation
- Role-scoped access controls and school-level tenancy boundaries.
- Audit logging for key admin and publication actions.
- Logging policy that avoids student statement text and AI output content in application logs.
- Statement feedback is advisory and visible to staff through normal product views. Safeguarding escalation remains owned by the school's usual route; automated alert delivery and routing are not active in the launch product.
- Student-facing drafting suggestions, where used, must stay bounded to the student's own material and must not be presented as approved school guidance.
7. Current Rollout Model
- Student: own records only.
- Teacher: assigned-student workspaces only.
- School admin: school-scoped settings, cohorts, and compliance.
- Outleap admin: provisioning, cohort setup, support and recovery operations in the current first-school product. Outleap staff are not the normal educational release owner.
8. Safeguarding Handling
If content raises concern (for example self-harm, violence, hate, or safeguarding risk):
- Follow the school's safeguarding policy and DSL route.
- Record handling actions in approved staff systems.
- Restrict safeguarding notes to authorised staff only.
- Do not expose safeguarding-only notes in student-facing views.
9. Quality and Bias Review
- Review sample outputs regularly for quality and fairness.
- Record incidents, near misses, and corrective actions.
- Update prompts/processes through controlled change and testing.
10. Roles and Accountability
- School policy owner:
[Name + role] - School safeguarding lead:
[Name + role] - Supplier contact: Jesse Merrigan (Director, Outleap Limited). General contact: hello@outleap.io. Privacy and data-rights contact: info@outleap.io
- Last review date:
[YYYY-MM-DD] - Next review date:
[YYYY-MM-DD]
11. Related Documents
- Data Processing Agreement
- DPIA
- Data Retention Policy
- School safeguarding policy
- School acceptable use policy