In the first, AI is blocked at the firewall and the district considers the matter handled. It is not handled. Staff are using personal accounts on their phones, pasting in whatever they need to get through the afternoon, and from a student data standpoint this is the worst available outcome. There is no log, no agreement, no retention setting anyone has reviewed, and no way for the district to know what left the building. Blocking the tool did not stop the usage. It moved the usage somewhere nobody can see.
In the second, AI is permitted because someone decided being forward-looking was the right posture, and it was permitted without a policy, without training, and without monitoring. Teachers are using it well in some rooms and badly in others. A principal has started drafting discipline documentation with it. Nobody has told anyone what may not be pasted in, and nobody has checked what the vendor agreement says about whether that content trains a model.
Underneath both is the same gap. Most districts have neither a written acceptable use policy for staff AI use nor any practical training on de-identification, which is the one habit that makes everything else safe. There is usually a board policy about student devices written before any of this existed, and a technology agreement nobody has reread. What there is not is a document that says which tools are approved, who approves the next one, and what a teacher is supposed to do when they want to use one that is not on the list.
The last piece is organizational rather than technical. The technology director and the curriculum and instruction director are usually not in the same conversation. One is being asked about data processing agreements and network filtering. The other is being asked about instructional quality and professional development days. The decision that actually needs making sits between them, and it tends to sit there until a board member asks a question nobody has a written answer to.