Ohio Made AI Policies Compulsory. The Deadline Passed. Now What?
Ohio became the first US state to force every school district to adopt an AI policy by law. The deadline has passed, but having a policy and having a good one are not the same thing.
On 1 July 2026, every public school district, community school and STEM school in Ohio was legally required to have an artificial intelligence policy on the books. Ohio Revised Code 3301.24, part of House Bill 96, made it the first US state to mandate that every district, not just the willing ones, formally decide what AI use looks like on its watch.
The state didn't leave districts to write from scratch. The Ohio Department of Education and Workforce, working with the Ohio AI in Education Coalition, published a model policy and toolkit at the end of 2025 covering acceptable use, academic integrity, data privacy and FERPA compliance, vendor evaluation, and professional development. Districts could adopt it word for word or adapt it locally. Either way, the box had to be ticked by July.
For readers in England, where the Department for Education's AI guidance remains non-statutory and school-level policy is still patchy eighteen months after the technology went mainstream in classrooms, Ohio's approach is worth watching closely. It answers a question UK policymakers keep dodging: what happens when you actually legislate the requirement rather than just recommend it.
What the mandate did and didn't do
The law is narrow by design. It requires a policy to exist. It does not require schools to teach AI, does not require them to use AI tools in the classroom, and does not dictate specific content beyond a handful of mandatory elements. As legal analysis from the firm Kohrman Jackson Krantz put it plainly: adopting the state's model policy makes a district compliant. It does not, by itself, make the district safe.
That distinction is already showing up in practice. A Forbes analysis published on 24 July, the day before this piece, found districts racing to meet the deadline were leaning heavily on the template's data privacy language without necessarily building the vendor-vetting infrastructure to enforce it. Naming FERPA compliance in a policy document is not the same as auditing which AI tools a school actually has running with student data behind them.
The gap is more pronounced in special education. Coverage from education outlets tracking the rollout notes the state model addresses special education chiefly by seating a special-education representative on its drafting workgroup and pointing districts toward reviewing their existing IEP-related policies separately, rather than setting out specific safeguards for how AI tools should or shouldn't be used with students who have individualised education plans. For a state betting that a single template can serve districts as different as Columbus City Schools and a 400-pupil rural STEM school, that's a meaningful blind spot.
A law that requires a policy document is not the same as a law that requires good judgement. Ohio has proven you can legislate the former in months. The latter still depends entirely on what happens in individual staffrooms.
Why this matters beyond Ohio
FutureEd's legislative tracker counted 77 AI-in-education bills moving through 27 US state legislatures this year alone, and Ohio's mandate is already being cited by lawmakers elsewhere as a template worth copying, according to reporting from EdWeek Market Brief. If other states adopt similar compulsory-policy laws, school leaders everywhere should expect the same pattern: a rush to compliance, a state-issued template that gets adopted with minimal local editing, and a widening gap between the paperwork and what's actually happening in classrooms.
That pattern should sound familiar to UK school leaders navigating KCSIE's new AI safeguarding duties and the patchwork of trust-level policies that have emerged in the absence of a statutory push. Ohio shows both the upside and the limit of forcing the issue by law: it guarantees a document exists everywhere, but it can't guarantee anyone read it critically before signing off.
What to do
If you lead a school or trust, don't wait for a legal mandate to test your own policy against Ohio's gaps. Check whether your policy names specific safeguards for SEND pupils and vulnerable learners, not just a general nod to existing procedures. Check whether "we address data privacy" means an actual list of vetted tools, or just a sentence borrowed from a template. A policy that reads well but hasn't been stress-tested against your actual EdTech procurement list is decoration, not governance.
What to watch
Watch whether Ohio publishes any follow-up audit of what districts actually adopted, verbatim template versus meaningfully customised policy, and whether that correlates with anything measurable in classrooms. Watch which other states copy the compulsory-policy model in their 2027 legislative sessions. And watch whether England's DfE, having so far resisted a statutory duty, treats Ohio's experience as a case for legislating or as a cautionary tale about what a legal deadline actually buys you.