Research Article
SSAIL: A Design Framework for Safe and Sound AI for Learning
Synthesis: Rahimi (2026) proposes SSAIL (Safe and Sound AI for Learning), a conceptual design framework responding to a "learning paradox": generative AI can help learners produce better work while simultaneously performing the cognitive work those learners need to do to build their own competencies. He argues this creates a learning-safety problem that conventional concerns about accuracy, bias, privacy, or harmful outputs do not capture. SSAIL begins from the competencies humans should develop, maintain, and exercise: Learning Safety protects those competencies from foreseeable harm, while Learning Soundness supports their intended development. Using evidence-centered design, it operationalizes safety through two coupled questions — whether the learner is developing the intended competencies and whether the environment supports and protects that development — answered via stealth assessment of the learner and AI evaluation of the system, informing adaptive decisions about tasks, supports, Guardrails, Learner Agency, and cognitive responsibility. The goal is not dependence on a well-guarded system but the capacity to regulate AI use through internal guardrails built through guided practice.
The Learning Paradox Beyond Conventional AI Safety
Generative AI poses a distinctive design problem that accuracy, bias, privacy, and harmful-output concerns miss: it can not only support human thinking but perform substantial portions of that thinking — formulating arguments, solving problems, interpreting evidence, and revising explanations. In learning contexts, particularly early in development, learners must carry out such cognitive work themselves to form the intended competencies. The central question is therefore whether AI assistance strengthens or undermines long-term learning, not merely whether it boosts immediate performance — a distinction that matters when learning is inferred from performance, since a strong essay or correct solution may reflect cognition supplied by the tool rather than competencies developed by the learner. The paper frames this as an instance of the "deskilling" risk anticipated decades ago: intelligent tools may quietly erode the very skills society wants to retain. Emerging evidence supports the concern — for example, students using an unrestricted AI interface performed worse later without the tool, while learning-oriented safeguards largely mitigated the effect, even though learners using unrestricted AI did not realize they were worse off without it.
Learning Safety, Learning Soundness, and Adaptive Responsibility
Within SSAIL, the framework names two complementary obligations. Learning Safety protects human competencies from foreseeable harm — the cases where AI performs cognition a learner still needs to practice. Learning Soundness supports the intended development or maintenance of those competencies. Together they frame the central design problem: determining what learners should do themselves, what AI can support or perform, and how those responsibilities should shift as learners develop. The framework is deliberately competence-first — it starts from the human capabilities a system aims to protect and develop rather than from assumptions about what the AI can or cannot do.
Operationalizing Safety with Evidence
Because safety claims need evidence, SSAIL borrows evidence-centered design to make the framework operational through two coupled evidentiary questions: (a) is the learner developing the intended competencies, and (b) does the AI-powered learning environment support and protect that development? Once implemented:
- Stealth assessment provides evidence about learner competencies as they work, without interrupting the activity.
- AI evaluation and verification provide evidence about system behavior — whether the tool is performing cognition that should stay with the learner.
These two evidence streams jointly inform adaptive decisions about task selection, supports, guardrails, learner agency, and cognitive responsibility. The ultimate objective is not a maximally guarded system the learner depends on, but the development of internal guardrails — the capacity to regulate one's own AI use — achieved through guided practice over time.
What the work contributes
For AIED designers, SSAIL reframes safety from a property of model outputs to a property of the human-development trajectory a learning environment supports or erodes, aligning with scholarship on Cognitive Offloading and productive struggle. It positions Human AI Collaboration design — deciding which cognitive tasks the tool performs versus the learner — as the central safety lever, and it argues that as AI capabilities evolve, safe and sound learning must keep the human competencies it aims to protect at the center. Its evidence-centered pairing of learner and system measurement offers a concrete path for Learning Analytics and assessment communities to evaluate not just what AI produces but what it lets learners become able to do on their own.
What this means for practice
- Designers. Specify what cognition must remain with the learner before specifying what the AI will do, and treat that allocation as the central safety lever rather than accuracy, bias, privacy, or harmful outputs alone.
- Designers. Instrument two coupled evidence streams — stealth assessment of the learner's emerging competencies and AI evaluation and verification of the system's behavior — because deciding what is safe requires both a learner judgment and a system judgment.
- Instructional designers. Judge safety on durable learning rather than immediate performance: an AI-assisted essay or a correct solution can reflect cognition supplied by the tool rather than a competency the learner has developed.
- Designers. Audit the evaluators themselves: the paper notes that LLM-based evaluators can exhibit position, verbosity, and self-enhancement biases, and that unreliable evaluators create false assurance.
- Researchers. Treat the framework's competence-first stance as a hypothesis to test — what learners should carry out themselves, what AI may perform, and how that allocation should shift as competency develops.
Limitations
- SSAIL is a conceptual and design framework, not an empirical test: the author states it adopts the design logic of safety-by-design architectures "without claiming formal safety guarantees," and that its constructs, facets, indicators, and mechanisms require empirical validation.
- The observable examples in Figures 1 and 2 are presented as an initial specification to be refined through expert review, learner studies, process analysis, and empirical modeling; the paper reports no study of whether SSAIL-informed orchestration improves durability, transfer, agency, or self-regulation.
- The human–AI performance expression, Observed performance = f(human contribution, AI contribution, human–AI interaction, task/context), is explicitly conceptual rather than a psychometric decomposition, so the framework supplies no method for separating the human contribution from the AI contribution.
- The framework's own evidence layer is unvalidated: the paper identifies as open questions whether cognitive labor can be classified reliably as protected, shared, or delegated, and whether coupled learner and system evidence supports more valid inferences than either stream alone.
Connected Concepts
- Generative AI
- Cognitive Offloading
- Pedagogical Safety
- Learner Agency
- Human AI Collaboration
- Learning Analytics
- Formative Assessment
- AI in Education
Connected Articles
- The Safety Gap: Restoring Productive Struggle Through Pedagogically Aligned Generative AI — The Safety Gap: Restoring Productive Struggle Through Pedagogically Aligned Generative AI
- Cognitive Offloading in the Age of Generative AI: What Does It Mean for Students With Learning Disabilities? — Cognitive Offloading in the Age of Generative AI and Students With Learning Disabilities
- Cognitive Offloading in Student–AI Collaboration: A Longitudinal Analysis of Prompting Strategies — Cognitive Offloading in Student–AI Collaboration: A Longitudinal Analysis of Prompting Strategies
- Metacognitively Discordant Completion and the Aware Pass-Through of Non-Understanding in Generative AI Learning — Metacognitively Discordant Completion in Generative AI Learning
- EduZone: A Framework for Evaluating LLM Safety for K-12 Students and Teachers — EduZone: A Framework for Evaluating LLM Safety for K-12 Students and Teachers
Citation
Rahimi, S. (2026). SSAIL: A Design Framework for Safe and Sound AI for Learning. EdArXiv preprint.