MICKAI®ArticlesCan schools use AI without sendin…
Article · 21 July 2026

Can schools use AI without sending pupil data to the cloud?

Yes, when the AI runs on infrastructure the trust controls and pupil data never leaves the school's own boundary.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aieducationdata sovereigntyon-premise aiaudit trail

Yes. Schools and multi-academy trusts can use AI for lesson planning, marking support, report drafting and administration without sending pupil data to the cloud, by running the AI on infrastructure the trust controls. The dividing line is pupil identifiability: generating general lesson content is low risk on any service, but SEND reports, safeguarding notes and behaviour logs are pupil-identifiable data and belong inside the trust's own boundary, with every access logged in a record the designated safeguarding lead and governors can inspect.

The question matters in 2026 because DfE guidance encourages schools to use generative AI to reduce workload, while pupil data is children's data under UK GDPR and safeguarding records are among the most sensitive files any organisation holds. Teachers already use AI daily; the governance question is where the pupil data goes when they do.

Why is pupil data treated differently under UK GDPR?

Because it is children's data, and the regime treats children as meriting specific protection. UK GDPR applies with heightened expectations where children are concerned, and the ICO's age-appropriate design code sets out how online services likely to be accessed by children are expected to handle their data. A school's records go further than most organisations hold: SEND assessments, safeguarding notes, health information and family circumstances sit among the most sensitive categories of personal data. Sending such records to an external AI service the trust cannot answer for creates risk that the trust, as controller, continues to carry.

What does DfE guidance actually say about AI in schools?

The DfE's position on generative AI is encouraging on workload and clear on data. Schools are supported in using AI for planning, resource creation and administrative drafting, and are expected to protect personal data and uphold safeguarding duties while doing so, alongside the expectations set out in KCSIE. The guidance does not prescribe architecture. It leaves trusts to answer the practical question of how a teacher can use AI on real work without pupil data leaking into services never designed to hold it, and that answer is architectural.

Which school tasks are safe on any AI service, and which are not?

The line is identifiability, and it is worth writing down for staff.

  • Low risk on any service: lesson plans, worksheets, quiz questions, model answers, and policy drafting with no pupil details.
  • Boundary only: report drafting from pupil records, SEND documentation, behaviour log analysis, safeguarding case summaries, and anything naming or describing an identifiable pupil.

A one-line staff rule works: if a pupil could be identified from the prompt, the prompt stays inside the boundary.

Why are consumer AI accounts the wrong place for safeguarding records?

Safeguarding files exist to protect children, and their handling is part of the protection. A safeguarding note pasted into a personal account on a public service such as ChatGPT, Claude or Gemini leaves the school's control entirely: the school cannot show where it went, who could access it, or how long it persists, and a contractual assurance from any provider is not a technical guarantee. KCSIE expects safeguarding information to be held securely and shared on a need-to-know basis. The workable position is architectural: safeguarding data is processed only where the trust can account for every access.

What should the designated safeguarding lead be able to inspect?

A complete, tamper-evident record of every AI interaction with pupil data. Inside Mickai, our Sovereign Intelligence Operating System, every action writes to a post-quantum signed audit ledger: who queried what, which documents were read, what was produced, and which staff member accepted it, with identity hardware-attested and bound to the chain. The record is verifiable offline, so the safeguarding lead or a governor can inspect it without reference to any external service. Model weights are versioned and hashed, and a zero-egress inbound perimeter means pupil data cannot reach the internet from the AI at all.

What does a trust-controlled deployment look like in practice?

A multi-academy trust runs the deployment centrally on operator-owned hardware, and its schools use it through the existing network. Teachers get drafting, marking support and summarisation against real pupil records, because the records never leave the trust. The data protection officer gets one processing location to govern instead of hundreds of personal accounts. Governors get an inspectable record. The alternative most trusts currently live with is unofficial: staff using personal AI accounts with no visibility at all, which is precisely the risk profile a controlled deployment exists to replace.

General lesson content is low risk anywhere; pupil-identifiable data is what forces the sovereign pattern.

How the boundary, the ledger and the studios fit together is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Can teachers use ChatGPT for lesson planning?

Yes, for lesson content that contains no pupil information. Plans, worksheets and quiz questions are low risk on any public service because no personal data is involved. The rule to give staff is about the prompt rather than the task: the moment a prompt could identify a pupil, the work must stay on infrastructure the trust controls.

Is it a data protection breach to put pupil names into an AI service?

It creates risk that the school carries as data controller, and whether a specific incident amounts to a breach depends on the facts and the service involved. Pupil data is children's data, which UK GDPR treats as meriting specific protection, and the school remains accountable wherever the processing happens. The safer position is architectural: pupil-identifiable prompts should only run on systems inside the trust's boundary.

Can we use AI to write school reports?

Yes, when the drafting runs where the pupil records live. Report writing is one of the strongest workload cases for AI in schools, and it necessarily involves pupil-identifiable data, so it belongs on trust-controlled infrastructure rather than a consumer service. The teacher reviews and owns every report; the AI produces the first draft, and the ledger records both steps.

What should a trust ask an AI supplier about safeguarding data?

Four questions expose most of the risk. Can the system run with no outbound connection at all? Is pupil data ever used to train any model, and is that enforced by architecture or only by contract? Can the designated safeguarding lead inspect a complete record of every access without the supplier's help? Are model versions hashed, so the trust knows exactly what processed its data? Suppliers with strong answers will put them in writing.

Does the DfE ban cloud AI in schools?

No. DfE guidance encourages schools to use generative AI for workload while protecting personal data and maintaining safeguarding duties. The constraint comes from data protection law and safeguarding practice rather than a ban: general content work is fine on public services, and pupil-identifiable work needs infrastructure the trust can answer for. Trusts that write that line into policy give staff clarity instead of prohibition.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/sovereign-ai-for-schools-and-multi-academy-trusts-safeguarding-data. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles