What Is an AI Use Case Inventory for K-12 Districts?
A practical guide to documenting AI tools across instructional, administrative, and operational functions so districts can see, govern, and audit AI use with confidence.
An AI use case inventory is a maintained record of every AI tool, system, or agent in use across a district, documenting its purpose, vendor, deploying department, data access, integration method, and risk classification. It is the foundational artifact districts need to see, govern, and audit AI use across instructional, administrative, and operational functions.
Core Elements of a District AI Use Case Inventory
Discovery
Surface tools in use, including those adopted outside formal procurement.
Data Access Mapping
Document what student and staff data each tool can reach.
Risk Classification
Tier tools by sensitivity of data and function.
Ownership and Review
Assign accountable owners and a recurring update cadence.
What an AI Use Case Inventory Is
An AI use case inventory is a structured record of every AI system, tool, or agent in active use across a district's instructional, administrative, and operational functions. It differs from a general software list in what it captures: not just that a tool exists, but what it is used for, what data it can access, who deployed it, and which user groups interact with it.
NIST's AI Risk Management Framework frames this as part of its Map function, which recommends characterizing AI systems as a prerequisite to identifying risk. A district cannot assess or manage risk in a tool it has not formally documented, and it cannot answer basic oversight questions, such as which systems touch student PII, without a consolidated record to check against.
Why Districts Need One
AI tools enter districts through many channels at once: curriculum teams piloting instructional apps, administrative staff adopting scheduling or grading assistants, individual teachers signing up for free tools without going through procurement. Each of these introduces a system with its own data access footprint, but without central tracking, no single office has a complete view of what is running or what data it touches.
This creates specific exposure. FERPA obligations attach whenever a tool accesses student personally identifiable information, regardless of whether the tool went through formal procurement. A vendor tool that added generative AI features after initial approval may now process data in ways the original review never considered. During a data privacy audit, vendor risk review, or public records request about AI use, a district without a maintained inventory has no reliable way to respond.
Fields a Use Case Inventory Should Capture
At minimum, each entry should document the attributes that make AI systems governable rather than merely catalogued:
- Purpose of the use case (instructional, administrative, or operational)
- Vendor or provider, and whether generative AI features are present
- Deploying department and accountable owner
- Data access scope, including student and staff PII
- Integration method (LMS, SSO, API, standalone signup)
- User population and groups that interact with the system
- Risk classification based on data sensitivity and function
Building the Inventory in Practice
Ownership, governance, and scope
District IT or data governance leaders typically own the inventory, since it intersects directly with existing IT asset management, procurement, and vendor data privacy agreement processes. NIST AI RMF's Govern function calls for organizations to assign clear accountability for AI risk decisions, and districts should reflect this by naming a single owner responsible for sign-off on new entries rather than leaving the inventory to informal, department-by-department tracking.
This ownership question also determines scope. An inventory limited to procured software will miss tools adopted directly by staff. Extending discovery to LMS and SSO connected-app logs, and reviewing what data an integration is actually permitted to access at runtime rather than what a vendor claims, gives a more accurate picture of exposure than a static list of approved vendors alone.
Guidance from groups like TeachAI and CoSN increasingly points districts toward maintaining registries of approved AI tools, though the required level of detail varies by state and is not uniformly mandated.
Frequently Asked Questions
Is an AI use case inventory legally required for K-12 districts?
No federal regulation specifically mandates an AI use case inventory. Recommendations derive from general frameworks like NIST AI RMF and voluntary toolkits like TeachAI's. State-level guidance varies significantly, so districts should verify current requirements for their specific state.
How is this different from a standard IT asset inventory?
A standard IT asset inventory typically tracks licenses and devices. An AI use case inventory adds data access scope, integration points, user population, and a risk classification specific to how the AI system behaves and what it can act on.
How often should the inventory be updated?
At minimum, review annually. Updates should also be triggered by new procurement, contract renewal, or when a vendor adds generative AI capability that changes what data a tool can access.
What about AI tools staff adopt outside procurement?
This is often called shadow AI. Districts surface it through department surveys, procurement record review, and LMS or SSO connected-app logs, then bring it into the same inventory and risk review process as formally procured tools.
Extend Your Inventory Into Ongoing Governance
A use case inventory establishes what AI systems are in use and what data they touch. Trussed AI provides runtime governance and security for AI agents, including tool approval workflows, agent permissions, and audit logging, to help sustain oversight after the inventory is built.
Talk to an Expert