Artificial Intelligence (AI) Policy

Organisation: Nested Learning Ltd
Policy owner: Managing Director
Applies to: employees, contractors, partners, clients, learners, apprentices and users of Nested Learning AI systems
Review frequency: annual, or sooner where law, regulatory guidance, product scope or risk profile materially changes

1. Purpose and scope

This policy sets out how Nested Learning uses, governs and reviews artificial intelligence.

The policy applies to all AI systems designed, supplied, configured, tested or used by Nested Learning. This includes learner-facing AI tutors, staff-facing tools, analytics dashboards, administrative workflows, feedback tools, AI-supported reports, pilots, demonstrations and client deployments.

The policy applies to all employees, contractors, consultants, partners, institutional clients, learners, apprentices and other users who access or use Nested Learning AI systems.

The purpose of this policy is to ensure that AI is used in ways that are:

  • educationally purposeful;
  • safe, secure and proportionate;
  • transparent and accountable;
  • compliant with data protection law;
  • aligned with academic integrity;
  • supportive of equality, accessibility and inclusion;
  • subject to human oversight where decisions affect people.

Nested Learning uses AI to support learning, reflection, formative feedback, teaching insight and professional practice. It does not use AI to replace human judgement in consequential educational, safeguarding, employment, disciplinary or institutional decisions.

2. Policy statement

Nested Learning recognises AI as a powerful educational and operational tool. Used well, AI can support learning, feedback, reflection, revision, accessibility, staff productivity and institutional insight.

AI must support human learning and professional judgement. It must not replace them.

AI outputs are advisory. They must not be treated as inherently accurate, complete, unbiased, current or suitable for high-stakes decisions without appropriate human review.

Nested Learning recognises that responsible human-AI co-creation is now part of educational practice. The policy therefore governs responsible, transparent and accountable AI use rather than pretending that AI can be excluded from learning.

Users remain responsible for the integrity, accuracy and consequences of AI-assisted work.

Nested Learning distinguishes between AI use that supports learning and AI use that bypasses learning. AI may support brainstorming, revision, reflection, feedback, language development, accessibility, planning and checking understanding. AI must not be used to misrepresent authorship, fabricate evidence, bypass required cognitive work, or replace required human demonstration of learning.

3. Definitions

Artificial intelligence means software or systems that perform tasks normally associated with human cognitive activity, including generating text, analysing information, classifying data, summarising content, recommending actions, supporting decisions or responding conversationally.

Generative AI means AI that can produce new content, including text, images, audio, code, summaries, feedback, explanations, plans, questions or other digital artefacts.

Learner-facing AI means AI used directly by learners, students, apprentices or trainees.

Staff-facing AI means AI used by staff, tutors, administrators, managers, developers or institutional users.

AI-supported analytics means outputs derived from AI processing, classification, summarisation or clustering of learner activity, feedback, engagement, themes, support needs or progress signals.

Human oversight means meaningful review, interpretation and control by a competent person with authority to question, amend, reject, suspend or escalate AI-supported outputs.

Consequential decision means a decision that may materially affect a person’s education, employment, assessment outcome, progression, access to services, disciplinary status, safeguarding response or legal rights.

AI literacy means the knowledge and skill needed to use AI appropriately, including understanding limitations, risks, privacy duties, bias, hallucination, disclosure, attribution and safe prompting.

4. Core principles

Nested Learning AI systems must follow these principles.

Human-centred use
AI must support people. It must not displace human responsibility, educational judgement or institutional accountability.

Educational purpose
AI use must be connected to a legitimate learning, teaching, feedback, accessibility, administrative or insight purpose.

Safety and proportionality
AI use must be proportionate to the intended benefit. Higher-risk uses require stronger controls.

Transparency
Users should know when they are interacting with AI, when AI has contributed to feedback or reports, and what the system can and cannot do.

Accountability
There must be an identifiable person or role responsible for each AI system, deployment, use case and review process.

Privacy and data minimisation
AI systems must process only the data needed for the stated purpose. Personal data must not be entered into unapproved tools.

Fairness and inclusion
AI use must be assessed for bias, accessibility barriers, unequal access, differential impact and possible disadvantage.

Security and robustness
AI systems must be designed, configured and operated securely, including appropriate access controls, logging, testing and incident response.

Contestability and redress
Where AI contributes to outputs about a person, there must be a way to question, correct, review or escalate the matter.

Professional judgement
AI may inform professional judgement. It must not replace it.

5. Approved uses

The following uses are generally approved where they are properly configured, proportionate and compliant with this policy.

AI may be used to support learners with:

  • formative feedback;
  • revision and practice;
  • reflective learning;
  • checking understanding;
  • planning study activity;
  • improving clarity of expression;
  • language support;
  • accessibility support;
  • confidence-building and preparation for discussion, assessment or practice.

AI may be used to support staff with:

  • drafting learning materials;
  • generating formative prompts;
  • summarising non-sensitive materials;
  • preparing feedback structures;
  • identifying common learning themes;
  • reviewing learner support patterns;
  • administrative productivity;
  • creating training resources;
  • improving accessibility of materials.

AI may be used to support institutions with:

  • non-graded learning analytics;
  • cohort-level teaching insight;
  • identification of common themes and support needs;
  • evaluation of engagement patterns;
  • pilot reporting;
  • evidence generation for improvement activity.

Approved use does not remove the need for human review. AI-generated content must be checked before being relied upon.

6. Restricted uses

Restricted uses require approval, risk assessment and, where relevant, data protection review before use.

Restricted uses include:

  • processing personal data through AI;
  • processing special category data;
  • use of third-party AI tools;
  • AI use in client systems or institutional environments;
  • AI use in assessment design;
  • AI outputs that may influence institutional decisions;
  • AI use involving children, vulnerable adults or safeguarding contexts;
  • AI use involving intellectual property, unpublished materials or confidential client information.

Restricted uses must be recorded in the AI use-case register.

Each restricted use must have:

  • a named owner;
  • a clear purpose;
  • a risk rating;
  • data protection consideration;
  • human oversight arrangements;
  • user transparency arrangements;
  • review date;
  • fallback process.

7. Prohibited uses

Nested Learning does not permit AI to be used as the sole or determining basis for:

  • grades, marks or formal assessment outcomes;
  • admission or access decisions;
  • progression, withdrawal or exclusion decisions;
  • disciplinary findings;
  • safeguarding decisions;
  • employment, recruitment or dismissal decisions;
  • legal, medical, psychological or financial advice;
  • automated judgement about a person’s character, credibility, motivation or intent;
  • covert monitoring of learners or staff;
  • emotion recognition in education or workplace settings;
  • biometric identification or surveillance;
  • generating fabricated evidence, citations, references, testimonials, learner records or compliance evidence;
  • impersonating a learner, tutor, staff member or institution;
  • bypassing required human demonstration of learning.

AI must not be used to create or support deceptive, manipulative, discriminatory, unsafe or unlawful activity.

AI must not be used with unapproved tools where personal, confidential, client, learner or commercially sensitive data is involved.

8. Academic integrity and responsible human-AI co-creation

Nested Learning recognises that AI can form part of legitimate learning activity. The key distinction is whether AI supports learning or bypasses learning.

AI may be appropriate where it helps a learner to:

  • ask better questions;
  • understand feedback;
  • practise explanations;
  • test their understanding;
  • improve clarity;
  • plan revision;
  • compare approaches;
  • reflect on their work;
  • prepare for discussion or oral explanation.

AI is inappropriate where it is used to:

  • conceal lack of understanding;
  • submit work that misrepresents authorship;
  • fabricate sources or evidence;
  • avoid required reading, reasoning or practice;
  • generate assessed work where the assessment requires unaided performance;
  • replace required human argument, judgement or defence of ideas.

Nested Learning supports proportionate disclosure of AI use. Users should be able to explain how AI contributed to their work where this is relevant to learning, feedback, assessment or institutional policy.

Disclosure should not be reduced to a punitive or unrealistic declaration process. AI use may occur across many stages of learning, and users may not always remember every interaction. Policy and guidance should therefore focus on meaningful transparency, responsibility and evidence of learning.

Assessment and integrity practice should place greater weight on process evidence where appropriate. This may include drafts, reflective commentary, oral explanation, tutor discussion, version history, learning logs, feedback response and evidence of decision-making.

Nested Learning does not support over-reliance on AI detection tools. Detection tools may be technically limited and may create unfairness, especially for neurodivergent learners, multilingual learners and users of accessibility tools. Integrity should be supported through assessment design, transparency, dialogue, process evidence and professional judgement.

9. Transparency, disclosure and explainability

Users must be told when they are interacting with AI.

Where AI contributes to feedback, reports, summaries, analytics or recommendations, this should be made clear to the relevant user or institution.

AI systems should explain their role in plain language. Learners and staff should be told:

  • what the AI system is for;
  • what it can help with;
  • what it cannot do;
  • whether outputs are advisory;
  • what data is processed;
  • whether human review is involved;
  • how to report a concern;
  • how to challenge or correct an output where appropriate.

Nested Learning should provide module-, assessment- or deployment-specific guidance where generic guidance is insufficient.

Learners should receive concrete examples of acceptable and unacceptable AI use in context. General “you may” and “you may not” statements are not enough where learners need to make decisions in real assessment or learning situations.

Transparency must be mutual. If learners are expected to disclose AI use, staff and institutions should also be transparent where AI is used to prepare learning materials, generate feedback, summarise learner evidence or produce analytics.

10. Data protection, security and supplier controls

Nested Learning must process personal data lawfully, fairly and transparently.

Personal data must be limited to what is necessary for the stated purpose. Sensitive, confidential or special category data must not be entered into AI tools unless the tool, purpose, legal basis, safeguards and approval route have been, legal basis, safeguards and approval route confirmed.

AI systems that process personal data must be assessed for:

  • lawful basis;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • retention;
  • deletion;
  • security;
  • processor and sub-processor arrangements;
  • international transfers;
  • individual rights;
  • risks to vulnerable users;
  • need for a DPIA.

AI systems must be designed and operated securely. Controls should include appropriate authentication, access control, logging, secure configuration, monitoring, testing, incident handling and supplier review.

Third-party AI tools must not be adopted without approval. Supplier review should consider data processing terms, security posture, training-data use, retention, sub-processors, export controls, model behaviour, availability, auditability and exit routes.

AI systems should not reveal sensitive, personal, client or institutional data to unauthorised parties.

Where AI is used in client deployments, responsibilities between Nested Learning and the client institution must be documented.

11. AI literacy, equality and accessibility

Nested Learning treats AI literacy as part of digital capability.

Staff, contractors and relevant users should receive role-appropriate guidance on:

  • safe and effective AI use;
  • privacy and data protection;
  • prompt safety;
  • output checking;
  • hallucination and inaccuracy;
  • bias and fairness;
  • academic integrity;
  • attribution and disclosure;
  • accessibility;
  • escalation and incident reporting.

Learners should receive clear guidance that helps them use AI critically rather than passively. Guidance should focus on judgement, responsibility and learning, not only on compliance.

AI use should be assessed for equality and accessibility impact. Particular attention should be paid to:

  • disabled learners;
  • neurodivergent learners;
  • multilingual learners;
  • learners with lower digital confidence;
  • learners with limited access to paid tools;
  • socio-economic disadvantage;
  • unequal institutional access;
  • accessibility tools that may include AI-like features.

Blanket AI bans may create unfairness where AI supports accessibility, language development or reasonable adjustment. Any restriction must be justified by the intended learning outcome and supported by alternative access arrangements where needed.

AI systems and guidance should be designed to support inclusion, not widen gaps.

12. Human oversight, governance, monitoring and review

Nested Learning will maintain governance arrangements for AI use.

Governance must include:

  • a named policy owner;
  • an AI use-case register;
  • a risk assessment process;
  • a data protection review route;
  • supplier approval controls;
  • incident reporting;
  • user feedback routes;
  • periodic review;
  • withdrawal or suspension process.

Restricted and higher-risk uses must have named human oversight. The person providing oversight must have enough competence, authority and support to question, amend, reject, escalate or suspend AI-supported outputs.

AI outputs must be monitored for:

  • accuracy;
  • unsafe responses;
  • bias;
  • accessibility issues;
  • privacy risk;
  • user misunderstanding;
  • inappropriate over-reliance;
  • unintended educational effects;
  • technical failures;
  • drift in model behaviour.

Nested Learning will review this policy annually, or sooner where:

  • legal or regulatory requirements change;
  • product functionality changes materially;
  • a new high-risk use is proposed;
  • a serious incident occurs;
  • client deployment changes the risk profile;
  • evidence shows user harm, unfairness or misuse.

13. Alignments with other frameworks

FrameworkNested Learning alignment
UK AI regulation frameworkThe policy reflects the UK’s five principles: safety, security and robustness; transparency and explainability; fairness; accountability and redress. See https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach/white-paper
UK Government AI PlaybookThe policy follows the Playbook’s practical emphasis on knowing AI’s limits, safe and secure use, governance, human control, assurance, and adoption processes. See https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html
DfE generative AI in education guidanceThe policy requires AI use in education to be carefully assessed, with clear benefits that outweigh risks, and with learner use in mind. See https://www.gov.uk/government/publications/generative-artificial-intelligence-in-education/generative-artificial-intelligence-ai-in-education
ICO AI and data protection guidanceThe policy builds in accountability, DPIA triggers, controller/processor awareness, fairness, transparency, data minimisation, accuracy and security. See https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection
NCSC secure AI system development guidanceThe policy requires secure design, secure operation, access control, monitoring, testing and protection against security of sensitive data. See https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development
EU AI Act: high-risk education and vocational training usesThe policy prohibits AI-only grading, progression, admission and other consequential educational decisions, reducing the risk that Nested Learning’s normal formative tools move into high-risk educational decision-making. The EU AI Act treats certain education and vocational training systems as high-risk where they determine access, evaluate learning outcomes in consequential ways, assess education level or attainment. See https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
EU AI Act: AI literacyThe policy requires role-appropriate AI literacy for staff and users, aligned with Article 4’s requirement for providers and deployers to take measures to ensure sufficient AI literacy in using. See https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
EU AI Act: transparency and human oversightThe policy requires transparency, explainability, human oversight, challenge routes and competent review for AI-supported outputs, aligning with the AI Act’s transparency and human oversight requirements. See https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-13
UNESCO Recommendation on the Ethics of AIThe policy reflects UNESCO’s human-rights-centred approach, including proportionality, safety and security for individual users. See https://www.unesco.org/en/articles/recommendation-ethics-artificial-intelligence  
UNESCO guidance on generative AI in education and researchThe policy adopts a human-centred approach to generative AI in education, including privacy protection, ethical and pedagogic validation and institutional educational use. See https://www.unesco.org/en/articles/guidance-generative-ai-education-and-research
UNESCO AI Competency Framework for TeachersThe policy treats AI literacy as part of professional capability and aligns with UNESCO’s five teacher competency dimensions: human-centred mindset, ethics of AI, AI foundations and applications, AI and professional learning. See https://www.unesco.org/en/articles/ai-competency-framework-teachers