1.4.5 AI Policy – Governance, Security and Operations

POLICY TYPE: 1.0 Administrative Policies \ 1.4 Using Technology at SDLF
EFFECTIVE DATE: 2026-07-08 LAST REVISED:
THIS POLICY APPLIES TO:

Policy Statement

SelfDesign Learning Foundation is committed to the responsible development, procurement, and relational use of artificial intelligence (AI) systems and tools in ways that advance our mission while protecting the dignity, privacy, and equity of learners, families and the communities we serve.

We recognize that AI tools are already present and often used informally by contractors, including educators, and board members. Rather than prohibit experimentation and usage, this policy establishes clear, values-aligned parameters that enable safe, ethical, confident use of AI within our organization.

We understand that good governance is an act of care, protecting relationships and those we serve, between leadership, contractors and our families, and between efficiency and human dignity.

All AI policies are governed by the Overarching AI Principles found in the AI Governance Framework. For information and clarity, an AI Glossary of Terms is available.

Policy

SelfDesign Learning Foundation will ensure the responsible evaluation, procurement, implementation, monitoring, and governance of AI technologies in support of organizational effectiveness, security, privacy, and alignment with vision, mission and values.

AI Governance Responsibilities

Tools for organization-wide use will be approved on a case-by-case basis, guided by the Software and Application Policy paired with an equity and values assessment to address the following.

  • Does it reduce the sense of self-authoring or personal agency of a learner?
  • Does it risk our approach to personalized learning?
  • Does it reduce essential human connection?
  • Could bias in LLM training data disadvantage certain groups of individuals?
  • Does it enhance accessibility or create barriers?
  • Does non-mandatory adoption widen equity gaps between users and non-users?
  • Does it create legal or legislative compliance to risks?
  • Could it introduce proprietary vendor lock-in, data retention issues, or unfavourable terms?

Data Governance and Privacy

SelfDesign Learning Foundation will follow all applicable laws, including but not limited to PIPA, BC government policy requirements, emerging provincial and federal AI legislation, and intellectual property laws.

AI tools use a lot of data. The tools themselves are trained from different data sources, and when SelfDesign contractors use them to do their work, the AI tools will use SelfDesign’s data as well. It is important to know what data is being shared with these tools.

SelfDesign uses a 4-tier sensitivity classification for organizational data. Only Tier 1 data is acceptable for use with AI tools without additional approval from your Foundation contact. Tier 2, Tier 3, and Tier 4 data should not be entered into AI tools due to the risk of data exposure, as AI providers may use submitted data for model training. This sharing of information with AI providers would classify as a privacy breach and/or a security breach.

  • Tier 1 Public / Low Sensitivity. This includes publicly available program names and descriptions, high-level strategic planning information, and internal draft documents (such as communications drafts, grant applications, etc.) that do not contain intellectual property as defined in the Terms and Conditions of contracts.
  • Tier 2 Internal / Medium Sensitivity. This includes personally identifiable information (PII) (e.g. individual family names, personal education numbers, phone numbers, email addresses) or intellectual property, both as defined in Terms and Conditions of contracts and information covered under non-disclosure agreements or other data-sharing agreements.
  • Tier 3 Confidential / High Sensitivity. This includes sensitive personal information, proprietary business data, strategic plans under development, and information whose unauthorized disclosure could result in moderate financial loss or reputational damage to an individual, the organization, or its partners.
  • Tier 4 Restricted / Critical Sensitivity. This includes data whose unauthorized disclosure could result in loss of life, major economic impact, serious personal injury, terrorism/sabotage risk, or severe legal/regulatory consequences.

Security Practices for AI

When selecting new vendors for organization-wide AI tools, we will require vendors to share, in writing, their data management guidelines for their products.

SelfDesign will adopt the following key security practices in the use of AI in our organization, which include but are not limited to:

  • Anonymity: We will limit the use of sharing personally identifiable information in AI tools.
  • Confidentiality: We will abide by key confidentiality policies by not inputting confidential information into AI tools.
  • Limit data disclosure: When we use LLMs, we will use tools that allow us to opt out of sharing organizational data for the purposes of training their model.

Additional responsibilities include:

  • Vendor due diligence
  • AI platform security review
  • Data retention and data quality review
  • Monitoring of AI tool usage patterns
  • Ongoing risk assessment

Incident Management

SelfDesign Learning Foundation recognizes that AI-related incidents may occur despite safeguards. When sensitive data is inadvertently shared with AI tools, inaccurate and harmful outputs are published, or legal/privacy obligations are potentially violated, users must immediately follow existing SelfDesign Learning Foundation incident management procedures, including:

  • Privacy Policy (privacy breach protocols)
  • Notifying your designated SelfDesign contact immediately, ensuring that enough detail is provided to support investigation and remediation steps.

Incidents involving AI tools will also be escalated to the Chief Information Officer or delegate prompting a review of tools, platform usage patterns, and organizational suitability. Users will be contacted for additional details to understand a timeline of events, what data or tools were involved, and any immediate actions taken to contain the impact.

Monitoring and Review

AI tools and governance practices will be reviewed annually, and more frequently following:

  • Security incidents
  • Privacy incidents
  • Significant regulatory changes
  • Adoption of new organization-wide AI systems

Related Documents