Can Our Staff Put Student Work Into an AI Tool?

Short answer: into an assessed, contracted institutional tool, yes, with conditions. Into a member of staff’s own account, no. Student coursework is personal data and unpublished work the institution holds in trust, so a marker pasting a chapter into a consumer chatbot has made a disclosure, not a productivity decision.

Every institution has spent two years writing rules for students. Almost none has written the mirror rule, and the staff side is the one where the institution — not the student — is the party at fault when it goes wrong.

Why is this a different question from student AI use?

Because the roles reverse. When a student uses AI on their own work, the student is the author, the risk is academic, and the institution is the judge. When a member of staff uses AI on a student’s work, the institution is the controller of someone else’s personal data, the risk is legal, and there is no one to judge the institution but a regulator.

The student-side visibility problem is real and separate; it is described in what your students are already using that you cannot see. This piece is about the same gap on the staff side, where the consequences land differently.

Is a student’s coursework personal data?

Yes, and treating it as merely “a document” is the root error.

An assignment is attributable to an identified individual and is usually submitted with a name, a student number and a module code attached. It frequently contains a great deal more: a reflective piece naming a placement, a dissertation whose methods section describes the author’s own health condition, a case study about a family member. Special category data arrives in student writing routinely and without warning.

A thesis chapter adds a second problem on top of the first. It is unpublished scholarly work whose author has not yet decided where it will appear, and in some cases it contains research participants’ data collected under a separate ethics approval that says nothing about a language model.

Who is the controller when a marker pastes a chapter into a chatbot?

The institution is, and the tool provider is not your processor — which is the part that surprises people.

A processor relationship does not arise from a company having your data. It arises from a contract. Article 28(3) of the GDPR requires processing by a processor to be governed by a binding contract setting out subject matter, duration, nature and purpose, and stipulating in particular that the processor “processes the personal data only on documented instructions from the controller” and “ensures that persons authorised to process the personal data have committed themselves to confidentiality”.

A member of staff signing up with a work email address has none of that. And Article 28(10) settles what the counterparty then is: “if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.” A consumer account is not a defective processor arrangement. It is a disclosure to a second controller.

Two document folders linked by a broken chain, representing an absent processor contract
No contract, no processor. What you have instead is a second controller you never chose.

What makes staff use lawful?

The same three things every other institutional processing operation needs, in the same order.

  1. A lawful basis that survives contact with the facts. For a publicly funded university acting in its public task, the honest answer is Article 6(1)(e), and Article 6(3) requires that basis to be laid down in Union or Member State law. Legitimate interests is not the fallback people assume: Article 6(1) states expressly that “point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks.” Consent is worse still, for the reasons in whether a university can rely on student consent, and staff consent carries the same imbalance problem in an employment relationship.
  2. A contract with the provider. An Article 28 agreement, with the training and retention position settled in writing rather than inferred from a marketing page — the four clauses to establish are set out in is student work used to train AI models.
  3. An assessment that covered this purpose. Marking support is a different purpose from student writing support. If your data protection review scoped the student-facing deployment, it did not authorise the staff-facing one. The sequence is in how to run a data protection review before deploying an AI writing tool.

Does an enterprise licence solve it?

It solves most of it, and you should still read the documentation rather than the reassurance.

Microsoft’s published privacy documentation for Microsoft 365 Copilot is a useful worked example because it is unusually specific. It states that the service grounds on tenant content within each user’s existing permissions plus a query sent to Bing Search; that optional customer feedback may improve the service but “we don’t use this feedback to train the foundation LLMs”; and that the Copilot services are opted out of the abuse monitoring, including human review, available in Azure OpenAI. All three are the answers you want.

The same page also carries a sentence a European institution has to read carefully: “Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.” That is not a reason to avoid the product. It is a reason to know which of your suppliers’ subprocessors sit outside the boundary you told your data protection officer you were staying inside, and to say so in the record rather than discover it at an audit.

Can AI write the feedback?

It can draft language. It cannot hold the academic judgment, and the difference has to be visible in your regulations rather than assumed.

Three lines are worth drawing explicitly. The mark is the marker’s and must be arrived at by the marker. Feedback that a student will act on must be checked line by line by the person whose name is on it, because a fluent, confident and wrong comment costs a student a term. And anything that goes to a student as the institution’s view of their work must be capable of being defended at an appeal by the human who issued it.

There is a disclosure duty running the other way too, and it is the one staff-facing policies most often omit. The European Code of Conduct for Research Integrity (2023 revised edition), which the European Commission recognises as the primary standard for EU-funded research, requires that assessors “disclose the use of AI and automated tools”, and lists hiding the use of AI or automated tools in the creation of content among violations of research integrity. An institution that requires disclosure from candidates and stays silent about assessors has published a standard it does not apply to itself.

What about external examiners?

They are the sharpest version of the problem, and almost no examiner brief mentions it.

An external examiner is at another institution, under another IT estate, with their own habits and their own subscriptions. You have sent them an unpublished thesis, often under an expectation of confidentiality that was never written down. If they upload it, the disclosure has happened outside every control you have, and your only instrument is the brief you gave them.

A bound thesis and a confidential envelope on an external examiner's desk
The thesis leaves your estate the moment you post it. The appointment letter is the only control that travels with it.

Two sentences in the appointment letter resolve most of it: state that the thesis is confidential unpublished work and must not be entered into any AI service that is not covered by the examiner’s own institutional agreement, and state that any AI assistance used in preparing the report must be disclosed in it. Both are ordinary professional expectations once written down and unenforceable while they are not.

What about references and recommendation letters?

Higher risk than marking, and usually governed by nothing at all.

A reference is written about an identifiable person, it is often decisive for them, and it commonly contains exactly the material that needs the most care — an explanation of interrupted study, a mitigating circumstance, a disability adjustment. Drafting one in a personal AI account discloses special category data about a student to a company with no relationship to the institution, for a purpose the student has never been told about.

The rule that works is short: references may be drafted only in an institutionally approved tool, and never with the mitigating detail pasted in. Write the letter’s substance yourself and let the tool help with the prose, not the other way round.

What should the institution actually do?

Five provisions, all of which are policy rather than technology.

  1. Name the approved tools for staff use on student work, and state plainly that anything not on the list is prohibited for that purpose. A list of two is worth more than a principle.
  2. Separate the purposes in your record of processing. Student-facing writing support and staff-facing marking support are different operations and should appear as such.
  3. State that academic judgment is non-delegable, in the assessment regulations rather than in guidance.
  4. Extend the disclosure requirement to assessors and examiners, in the examiner brief and the appointment letter.
  5. Give staff a usable alternative. A prohibition with no approved route produces the same shadow usage on the staff side that it produced on the student side, and it will be harder to see.

If you would like to work through the staff-side position — approved tools, the record of processing, and the examiner brief wording — against your own regulations, request an institutional evaluation and we will go through it with your integrity and data protection leads.

Frequently asked questions

Can staff use AI to mark student work?

Only in a tool the institution has assessed and contracted for that purpose, and only as drafting support. The mark and the academic judgment behind it cannot be delegated to the tool, and the person whose name is on the feedback must be able to defend every line of it at an appeal.

Is pasting an assignment into a personal chatbot account a data breach?

It is at minimum an unauthorised disclosure of personal data to a party with no contract, and it should be handled through your incident process rather than quietly. Whether it becomes a notifiable breach depends on the risk to the student, but the assessment has to be made rather than skipped.

Does it matter if the student’s name is removed first?

Less than people hope. A dissertation is often identifiable from its content alone — the supervisor, the cohort, the placement site, the topic — and removing a name from the header does not anonymise a document that describes one person’s project in detail.

Which lawful basis applies to staff use?

For a public university acting in its public task, Article 6(1)(e), with the basis laid down in Union or Member State law as Article 6(3) requires. Article 6(1) expressly removes legitimate interests from public authorities performing their tasks, and consent is not a sound basis in a relationship with this much imbalance.

Is a work email address enough to make it an institutional tool?

No. A processor relationship comes from a contract under Article 28, not from the domain in the address used to sign up. Without that contract the provider is determining the purposes and means itself, which under Article 28(10) makes it a controller rather than your processor.

Do staff have to disclose their own AI use?

Where they are acting as assessors, yes under the European Code of Conduct for Research Integrity, which requires assessors to disclose the use of AI and automated tools and treats hiding such use as a violation of research integrity.

What should we tell external examiners?

That the thesis is confidential unpublished work and must not be entered into any AI service outside their own institution’s agreement, and that any AI assistance used in preparing the report must be disclosed in the report. Put both in the appointment letter, not in a conversation.

Can a member of staff use AI to draft a reference?

Only in an approved tool, and never with the sensitive detail included. References routinely carry health, disability and mitigating-circumstance information, which is the last category of data that should reach an unassessed service.

Does an enterprise agreement remove the need for a review?

No. It changes the answers, it does not remove the questions. Read the provider’s own privacy documentation for the grounding, training, retention and subprocessor position, and record where a subprocessor sits outside the boundary you have committed to.

Should we monitor what staff paste into tools?

Deploying surveillance of staff to fix a policy gap creates a second and larger problem. Name the approved tools, provide one that works, and treat non-compliance as a management matter rather than a technical one.

Who owns this policy internally?

It sits across three owners and fails when it has only one. The data protection officer settles the lawful basis and the contract, the academic registrar settles the non-delegable judgment rule, and the graduate school settles the examiner brief.

What is the most common mistake?

Writing a student AI policy and assuming it governs staff. It does not, and the staff-side gap is the one where the institution is the party a regulator would be looking at.

Bring Tesify to your institution

Scope a departmental pilot: one cohort, one term, and your own measures of what worked.

Request an evaluation We reply within 2 business days

Categories