
AI is changing how we learn, create and interact with technology. From generating code to acting on our behalf, these systems introduce new risks as well as new opportunities. As AI becomes more embedded in education, the key question is not just what these systems can do, but what skills people need to use them safely, critically and securely. AI SAFE, a new framework for students and teachers, aims to help simplify the transition to this new way of working and learning.
A shift in what it means to be digitally skilled
Digital skills have traditionally focused on using tools effectively. Students learned how to search, create and communicate, while teachers focused on integrating technology into learning.
AI changes this.
These systems do more than support tasks. They generate outputs, influence decisions and increasingly act on behalf of users. Using technology safely is no longer just about operating it. It is about understanding how it behaves, where it can fail and how it can be influenced.
This introduces a new dimension of cybersecurity, shaped as much by human behaviour as by technology itself as discussed in this series of articles below.
CyberFirst Wales’ Guide to the Cyber Secirty Risks of AI in Education
I’ll read the detail later. Take me direct to the AI SAFE Framework
AI Is Writing the Code. Attackers Are Reading It: The Security Risks of Vibe Coding
What Happens to the Data? Understanding AI and Information Risk
When AI Can Be Tricked: Understanding Prompt Injection Risks
When AI Takes Action: Understanding the Security Risks of AI Agents
From awareness to action
Across the topics explored in this series, a consistent pattern emerges. The risks are different, but the behaviours needed to manage them are closely related.
Students and teachers do not need to understand every technical detail of AI systems. What they do need is a clear set of habits that can be applied consistently across different tools and contexts.
Building on what we know so far, and as discussed in this series, one way to think about this is through a simple framework:
AI SAFE: A framework for students and teachers
Sense Check
AI systems can produce outputs that appear confident and complete, even when they are incorrect.
Generated code may contain hidden flaws. Responses may be influenced by manipulated inputs. Agent-based systems may act on incomplete or inaccurate information.
Developing the habit of checking, questioning and verifying outputs is essential. For students, this means not accepting answers at face value. For teachers, it means creating space for explanation and reasoning.
From a cybersecurity perspective, this reduces the risk of acting on incorrect or manipulated information.
Assess data
AI systems depend on data. What is entered into them may be processed, stored or passed between services.
Students need to understand that information shared with AI tools is not always private, particularly when using publicly available systems. Teachers and school leaders need to consider how tools handle data and what safeguards are in place.
This awareness helps prevent accidental data exposure and supports responsible use.
Follow the flow
AI systems are increasingly connected, interacting with other systems and agents to complete tasks.
This means that a single outcome may depend on multiple systems working together. In many cases, one AI system may rely on another, passing information along a chain of interactions that is not visible to the user.
Understanding this flow helps students and teachers recognise that outcomes may be shaped by systems they cannot see. It also introduces the idea that trust is shared across systems, not contained within one tool.
From a cybersecurity perspective, this highlights that risk can exist beyond the immediate system being used.
Evaluate actions
AI is increasingly moving from tools to agents.
When systems take action on behalf of users, such as sending messages or interacting with services, the user is no longer involved in every step. This creates new risks if actions are taken without full understanding or oversight.
Students need to recognise that automation does not remove responsibility. Teachers need to ensure that the use of such systems includes appropriate oversight and reflection.
Maintaining awareness, even when systems act independently, is now a key skill.
Building habits for safe use
The strength of the AI SAFE framework is that it turns complex risks into simple, repeatable habits.
Students can apply it whenever they use AI:
Teachers can reinforce it through everyday classroom practice, embedding these behaviours into how technology is used rather than treating them as separate topics.
This aligns with guidance from organisations such as the National Cyber Security Centre, which emphasise that cybersecurity depends as much on people as it does on systems.
Looking ahead
AI will continue to evolve, and with it, the skills required to use it safely.
The focus for education should not be on keeping pace with every new tool, but on developing the underlying capabilities that remain relevant. These include critical thinking, awareness of risk and an understanding of how systems behave and connect.
The AI SAFE framework will help make these skills visible and practical. They provide a shared language for students and teachers, linking everyday behaviour to cybersecurity.
Used well, AI can support learning and creativity. The goal is to ensure that this is balanced with the awareness needed to use it safely and responsibly.

We’ve created a FREE A3 Bilingual Poster for your school. This can be printed and placed anywhere in your school or college. It doesn’t have to be the computing lab. In fact, we suggest where there’s a high footfall to help increase awareness.
Become a CyberFirst School
If you’re a school or college in Wales and want to enjoy the benefit of CyberFirst, there’s no better time than now to start your award application.