Policy Statement
SelfDesign Learning Foundation is committed to the responsible development, procurement, and relational use of artificial intelligence (AI) systems and tools in ways that advance our mission while protecting the dignity, privacy, and equity of learners, families and the communities we serve.
We recognize that AI tools are already present and often used informally by contractors, including educators, and board members. Rather than prohibit experimentation and usage, this policy establishes clear, values-aligned parameters that enable safe, ethical, confident use of AI within our organization.
We understand that good governance is an act of care, protecting relationships and those we serve, between leadership, contractors and our families, and between efficiency and human dignity.
All AI policies are governed by the Overarching AI Principles found in the AI Governance Framework. For information and clarity, an AI Glossary of Terms is available.
Policy
SelfDesign Learning Foundation (SDLF) will allow the responsible use of artificial intelligence (AI) tools to enhance learning, creativity, accessibility, and engagement while maintaining authentic learning, critical thinking, and human connection. These tools augment human capacity and do not replace human judgement or automate critical decisions.
Contractor and Educator Responsibilities
Specific AI tools and functions change regularly. Individual contractors may want to use AI tools to support their work; others may want to experiment with developing their own tools. If contractors choose to use AI tools, they are responsible for ensuring the tools and their usage meet the principles in this policy.
Human review is mandatory for all AI outputs regardless of the tool used. Human review requires active critical engagement. No AI output goes directly to learners, families, contractors, or public channels without this step. This human-first approach protects our personalization model, prevents trust erosion, and upholds our mission.
Every contractor must personally ensure outputs comply with:
- Privacy Policy
- AI Governance Framework and this AI Policy
The individual user/creator bears full accountability to:
- Read, verify, edit, and fact-check for accuracy, hallucinations, and bias
- Assess equity impact and values alignment
- Ensure no personally identifiable information (PII) or sensitive data is disclosed to AI tools or included in AI-generated outputs unless expressly permitted under organizational policy
- Refer to the AI Use Cases list for examples
Prohibited Uses
It is strictly prohibited to utilize AI systems to:
- Impersonate individuals
- Emulate a person’s writing style, voice, likeness, or video without explicit consent
- Create synthetic media that plausibly replicates an individual
- Infringe copyright or reproduce protected materials
- Mislead leadership, contractors, learners, families, partners, or stakeholders
These prohibitions protect authenticity, trust, and legal compliance while upholding our SelfDesign value
Training Requirements
All contractors who access SelfDesign-managed infrastructure will complete data literacy and AI orientation training where available and according to established timelines.
Data Governance and Privacy
SelfDesign Learning Foundation will follow all applicable laws, including but not limited to PIPA, BC government policy requirements, emerging provincial and federal AI legislation, and intellectual property laws.
AI tools use a lot of data. The tools themselves are trained from different data sources, and when SelfDesign contractors use them to do their work, the AI tools will use SelfDesign’s data as well. It is important to know what data is being shared with these tools.
SelfDesign uses a 4-tier sensitivity classification for organizational data. Only Tier 1 data is acceptable for use with AI tools without additional approval from your Foundation contact. Tier 2, Tier 3, and Tier 4 data should not be entered into AI tools due to the risk of data exposure, as AI providers may use submitted data for model training. This sharing of information with AI providers would classify as a privacy breach and/or a security breach.
- Tier 1 Public / Low Sensitivity. This includes publicly available program names and descriptions, high-level strategic planning information, and internal draft documents (such as communications drafts, grant applications, etc.) that do not contain intellectual property as defined in the Terms and Conditions of contracts.
- Tier 2 Internal / Medium Sensitivity. This includes personally identifiable information (PII) (e.g. individual family names, personal education numbers, phone numbers, email addresses) or intellectual property both as defined in Terms and Conditions of contracts and information covered under non-disclosure agreements or other data-sharing agreements.
- Tier 3 Confidential / High Sensitivity. This includes sensitive personal information, proprietary business data, strategic plans under development, and information whose unauthorized disclosure could result in moderate financial loss or reputational damage to an individual, the organization, or its partners.
- Tier 4 Restricted / Critical Sensitivity. This includes data whose unauthorized disclosure could result in loss of life, major economic impact, serious personal injury, terrorism/sabotage risk, or severe legal/regulatory consequences.
Incident Management
SelfDesign Learning Foundation recognizes that AI-related incidents may occur despite safeguards. When sensitive data is inadvertently shared with AI tools, inaccurate and harmful outputs are published, or legal/privacy obligations are potentially violated, users must immediately follow existing SelfDesign Learning Foundation incident management procedures, including:
- Privacy Policy (privacy breach protocols)
- Notifying your designated SelfDesign contact immediately, ensuring that enough detail is provided to support investigation and remediation steps.
Incidents involving AI tools will also be escalated to the Chief Information Officer or delegate prompting a review of tools, platform usage patterns, and organizational suitability. Users will be contacted for additional details to understand a timeline of events, what data or tools were involved, and any immediate actions taken to contain the impact.
Security Practices
When selecting new vendors, we will require vendors to share, in writing, their data management guidelines for their products.
SelfDesign will adopt the following key security practices in the use of AI in our organization, which include but are not limited to:
- Anonymity: We will limit the use of sharing personally identifiable information in AI tools.
- Confidentiality: We will abide by key confidentiality policies by not inputting confidential information into AI tools.
- Limit data disclosure: When we use LLMs, we will use tools that allow us to opt out of sharing organizational data for the purposes of training their model.
Related Documents
- AI Governance Framework
- AI Glossary of Terms
- Educator AI Guidelines
- Privacy Policy
- Acceptable Use
- Software and Application Policy