Skip to main content
Cyberfirst Wales what happens to the data in AI systems

AI tools can generate text, write code and even take action. But they also rely on data. Every prompt, file or connection to a system involves information being processed, and sometimes stored. Understanding how data flows through AI systems is essential for teachers and students using these tools safely.

AI is not just a tool, it is a data processor

Artificial intelligence tools are often presented as simple assistants. You ask a question and receive an answer. However, behind this interaction is a more important reality. AI systems process and sometimes store the information they are given.

When a user enters a prompt, uploads a document or connects an AI system or agent to another platform, they are sharing data. This might include personal information, school work or sensitive organisational details.

Every interaction with an AI system is also a data exchange.

Guidance from the Information Commissioner’s Office makes clear that organisations must understand how personal data is used when adopting AI tools. This includes knowing where data is processed, how long it is stored and who has access to it.

Where the risks come from

The risks associated with AI and data do not always come from deliberate attacks. In many cases, they arise from everyday use.

For example, a student might paste coursework into an AI tool to improve it. A teacher might upload a document to generate a summary. In both cases, information is being shared with an external system.

Research has shown that sensitive data can sometimes be reproduced or inferred from AI systems under certain conditions, particularly where safeguards are limited. While modern systems have improved, the risk has not disappeared entirely.

There is also the possibility of accidental exposure. If AI tools are connected to documents, emails or shared drives, they may access more information than the user expects.

Guidance from the National Cyber Security Centre highlights that connecting AI systems to wider services increases the potential impact of data exposure, especially where permissions are not carefully controlled.

The difference between public and managed tools

Not all AI tools handle data in the same way. This is an important distinction for schools and educators.

Publicly available AI tools may:

  • Process data outside uk

    A teacher using a free AI tool to summarise student work may be unknowingly sending that data to servers hosted in another country, where different data protection rules apply.
  • Retain inputs for system improvement

    If a student pastes coursework into an AI chatbot, that content may be stored and used to improve the system, meaning it is no longer entirely private to the student or school.
  • Have limited visibility over how data is used

    School leaders may not be able to see exactly what happens to data once it is entered into a public AI tool, making it difficult to assess risk or meet safeguarding responsibilities.

In contrast, managed or enterprise tools are more likely to:

  • Offer clearer data handling policies

    A school-approved AI platform should explain how data is processed and stored, helping teachers make informed decisions about what is appropriate to use in lessons.
  • Restrict how data is stored or reused

    Enterprise tools should ensure that student data is not used to train models, reducing the risk of that information appearing elsewhere.
  • Provide administrative controls

    School IT teams can control who can use the tool, what data can be accessed and how it is used, allowing leaders to manage risk more effectively across the organisation.

The Information Commissioner’s Office advises organisations to carry out data protection impact assessments when introducing AI systems, particularly where personal data is involved.

Understanding this difference helps schools make informed decisions about which tools are appropriate in an educational setting.

How this connects to other risks

The risks associated with data do not exist in isolation. They connect directly to the issues explored in other articles in this series.

If AI generated code is not fully understood, it may expose data unintentionally. If an AI system is vulnerable to prompt injection, hidden instructions could lead to sensitive information being revealed. If an AI agent has access to systems and data, it may act on that information in ways that were not intended.

The more access an AI system has to data, the greater the potential impact if something goes wrong.

This means that data risk is not a separate issue. It is part of a wider picture where AI capability and access combine to create new forms of exposure.

Why this matters for students

It is easy to see AI tools as private or personal, particularly when they are accessed through individual accounts. However, the information entered into these systems may be processed in ways that are not immediately visible.

Students need to develop simple but important habits. They should think carefully about what they share, particularly when it involves personal information or work that has not yet been submitted.

The Information Commissioner’s Office emphasises the importance of data minimisation. This means only sharing the information that is necessary for a specific task.

Why this matters for teachers and schools

For teachers and school leaders, the use of AI raises broader considerations around safeguarding and data protection.

Schools are responsible for protecting student data and ensuring that systems are used appropriately. This includes understanding how AI tools interact with student information, internal systems and external services.

Guidance from the National Cyber Security Centre recommends taking a cautious approach to integrating AI with existing systems, particularly where sensitive data is involved.

This may involve selecting and subscribing to approved AI tools, limiting integrations and providing clear guidance and training to staff and students.

Reducing the risk in practice

Reducing data risk does not require avoiding AI altogether. Instead, it involves using it in a controlled and informed way.

A key principle is to limit what is shared. Users should avoid entering sensitive or personal information unless they are confident in how it will be handled.

It is also important to understand permissions. AI tools should only have access to the data and systems they need to perform a specific task.

Human oversight remains essential. Outputs should be reviewed, and any actions taken by AI systems should be checked, particularly in educational contexts.

These approaches align with broader UK guidance on secure and responsible use of technology in education.

Looking ahead

As AI becomes more integrated into education, questions about data will become increasingly important. The benefits of these tools are clear, but they rely on access to information.

There has been progress. Many AI providers are improving transparency, offering better controls and reducing how data is retained. At the same time, regulators such as the Information Commissioner’s Office are providing clearer guidance.

However, the underlying challenge remains. AI systems depend on data, and the way that data is used is not always visible to the user. By helping students understand how data flows through AI systems, and by encouraging responsible use, schools can ensure that these tools are used safely.

Used well, AI can support learning and creativity. The key is to ensure that this is balanced with awareness of how data is shared, processed and protected.

Become a CyberFirst School

If you’re a school or college in Wales and want to enjoy the benefit of CyberFirst, there’s no better time than now to start your award application.

News

CybereFirst News Empower girls into tech post event Featured Image

Empower: Girls into Tech showing real impact across Wales 

CyberFirst Wales celebrates the success of its pan-Wales Empower: Girls into Tech event series, which engaged nearly 800 Year 9 and Year 10 girls through hands-on technology workshops, industry-led activities and inspiring career…
Read more Empower: Girls into Tech showing real impact across Wales 

Co-producing a Strong Future for AI and Frontier Tech with techfirst Wales 

At CyberFirst Wales, we know that the strongest programmes are shaped by the people they serve. That means listening to learners, teachers, industry partners and the wider education community across Wales. Our…
Read more Co-producing a Strong Future for AI and Frontier Tech with techfirst Wales 
Radyr High School Cyberfirst Award Image

Celebrating a standout term for New CyberFirst Schools in Wales 

As the summer term unfolds and welcome the (hopefully) warmer weather, we have some brilliant news to share from across the nation. More schools are being recognised for the…
Read more Celebrating a standout term for New CyberFirst Schools in Wales