AI Governance
Ensures AI use aligns with law, policy and humanitarian principles. Covers risk management and data security, creating a safe, orderly and controlled digital environment.
What this domain contains p.10
- Protect the personal data of students and educators.p.10
- Understand and comply with cybersecurity policies and acts at institutional and national level.p.10
- Establish clear reporting channels for AI incidents or misuse.p.10
- Internalise the roles and responsibilities of each individual — student, educator, school leader.p.10
- Interpret AI misuse — assignment cheating, spreading false information — as misconduct subject to disciplinary action.p.10
How the six practices land in this domain p.34
Figure 4 maps every practice onto every domain. This is the column for AI Governance.
1. Understanding AI
Comply with the institution's data security policy when interacting with AI systems.
2. Evaluating Critically
Know the reporting channels if you encounter harmful or policy-violating AI output.
3. Using AI Tools
Use approved AI tools aligned with the institution's device-use policy.
4. Managing the AI Workflow
Manage AI workflows that comply with institutional rules; allocate tasks between human and AI efficiently.
5. Creating with AI
Ensure creations do not breach cyber-security policy or institutional guidelines.
6. Innovating for Problem Solving
Propose innovations aligned with institutional policy, goals and humanitarian principles.
Legal instruments named here
Education Act 1996
Act 550Sections 134 and 135 set student conduct, discipline and the powers of the headmaster. AI-related misconduct can be treated as a breach of school rules.p.10
Education (School Discipline) Regulations
1959School discipline regulations.p.10
Personal Data Protection Act 2010
Act 709Regulates personal data in commercial transactions. Section 3 exempts the Federal and State Governments — but Ministry staff must still ensure awareness of the limits of personal data use, especially with third-party AI platforms.p.10
Cyber Security Act 2024
Act 854A comprehensive cybersecurity legal framework: protection of critical infrastructure, regulation of cybersecurity services, incident-reporting procedures and continuous threat monitoring.p.11
MOE Cyber Security Policy v2.0
June 2024Ministry-specific policy binding on all Ministry staff, vendors and third parties using Ministry ICT assets — explicitly including AI technology.p.11
Online Safety Act 2025
Act 866Obligations on online application service providers to protect children — safe design and operation of online services.p.11
Government Contracts Act 1949
Act 120Any cooperation with strategic partners must comply with this and the 2024 Cabinet Secretary's Directive.p.62