Responsible use
The first three modules answered "how do I use it". This module answers "where do I stop". You will clean the data leak out of a real-looking prompt with your own hands, hunt the bias in a model's output, rank how much scrutiny each kind of task deserves, and finish by generating a one-page AI policy you can take to your department.
Knowing how to use the tool is not enough.
Module 2 showed you that a good prompt is the route to a good output. But a good output is not automatically a usable output. Three separate questions, three separate areas of responsibility.
What leaked in this prompt?
The prompt below is the kind a real teacher would write. The intent is entirely good, the problem is serious. Click the phrases that carry risk, then check your answer. Every underlined fragment is clickable and some of them are completely harmless.
The same prompt can be rewritten and still do the job: "Write notes for a parent meeting about a Year 9 pupil who struggles with reading. Suggest three activities to build reading fluency that can be done at home. Keep the language plain and respectful." Without a single name, number or diagnosis, the model still does its work. The rule is simple: describe the task to the model, not the person.
Where does the data go?
The word "cloud" hides this question. What you type travels to a server, is processed there and is usually retained for some period. Which account you signed in with changes that entire chain. Click the tabs.
On free and individual plans, most providers reserve the right to use conversations to improve their services and train their models. There is usually a setting to turn this off, but it is rarely off by default.
On enterprise and education plans, providers typically commit not to use your data for model training, sign a data processing agreement and define a retention period. The difference is not marketing, it is legal: the school now has a lawful basis for processing.
Setups where the data never leaves the institution. Strongest on privacy, heaviest on cost and maintenance. Rarely realistic for a single school to run alone.
Practical advice: if you do not know which account your school works under, make that the first question at your next department meeting. Working with pupil data without knowing the answer is like driving off without checking the brakes.
Same task, two environments
The practical consequence of this distinction: some of what you learned as "never put that into AI" actually means "never put that into a general-purpose assistant on your personal account". On a platform your school has a contract with, one that does not train on your data and has a defined retention period, the same task can become workable. The only thing that never changes is who signs the decision.
| Task | Personal account, general-purpose assistant | Platform your school contracts with |
|---|---|---|
| Lesson plan, sample question, material idea | Fine. No personal data involved. | Fine |
| Feedback on a pupil's work, with their name attached | No. Name plus work identifies the pupil directly and the school has no legal basis for it. | Workable. Inside a school account, a defined workflow and a data processing basis; the teacher still edits the output. |
| Class-wide marks and progress analysis | No. That means carrying your class list outside the school. | Workable. If the data already sits on that platform, no new transfer is created. |
| Rubric-bound scoring and feedback drafts | Risky. With no rubric to anchor it, output is inconsistent and its reasoning cannot be audited. | Workable. Each score maps to a criterion and the draft comes back to the teacher for revision. |
| EHCPs, educational psychologists' reports, diagnoses, health data | No. | Not automatically cleared. Special category data needs its own consent and purpose assessment; a contract alone is not enough. |
| Fixed in both environments | Data minimisation still applies, output still gets verified, and a human still signs any decision that affects a pupil | |
Six questions to ask of any platform
Which column a tool belongs in is decided by the answers to these six questions, not by its marketing copy. If you cannot find an answer in writing, the tool sits in the first column.
Madlen produces this course, so answering the six questions for our own platform is on us. Teacher and student data is not shared with third parties, not sold, and not used to train AI models; only teachers and school administrators can access restricted content. The platform meets GDPR requirements, and for international school partnerships we work to meet local regulation too, data is processed on Infercom infrastructure on servers in Germany within EU borders and is not transferred to the US, and the infrastructure is certified to ISO 27001:2022.
None of that means "use Madlen and the privacy question is settled". A contracted platform does not cancel out data minimisation, and a human still signs any decision that affects a pupil. Ask us those six questions, and ask them of every tool you use; if you cannot find the answers in writing, do not put pupil data into it.
Data protection in four sentences.
The UK GDPR and the Data Protection Act 2018 run on the same logic, and the ICO's guidance for schools spells out what that means in practice. You do not need to be a lawyer; there are four principles a teacher needs to hold.
1 Purpose limitation ›
You may use data only for the purpose you collected it for. Information gathered for attendance cannot be uploaded to an AI tool with "analyse my class for me". The question to ask: if the person who gave me this data knew I was using it for this, what would they say?
2 Data minimisation ›
Work with the least data needed to do the job. That is the whole point of the redaction exercise above. The model produces the same set of activities without knowing the pupil's name, so leaving the name out is not only safer, it is the legally correct behaviour.
3 Consent and special category data ›
Health status, diagnoses, ethnicity, beliefs and biometric data are special category data and carry the highest level of protection. They cannot be processed or passed to a third-party service without an explicit lawful basis. Copying a sentence from an educational psychologist's report into a prompt is exactly such a transfer.
4 Retention and deletion ›
Data cannot be kept indefinitely; once the purpose is gone, it goes. Chat histories are a storage location too. Make it a habit to delete conversations about a pupil once the work is done. That serves both the spirit of the law and plain common sense.
Am I allowed to enter this?
Instead of memorising a rule list, ask three questions in order. The tree below builds a reflex you can use every day. Pick an option and move to the next question.
A model repeats the world it was trained on.
In Module 1 you saw the model predict the next word by probability. Probability comes from frequency in the training data. If engineers in that data are mostly men and nurses mostly women, the model repeats that as if it were a fact. There is no malice, only statistics. But the classroom effect is the same: some pupils never see themselves in the material you hand out.
In the names it picks, the occupations it assigns, the families it describes, the life it treats as "normal", the skin tones and disability representation in generated images, and the economic assumptions inside word problems.
Write diversity into the prompt explicitly. Before you hand an output out, ask "who is missing from this". Have your pupils ask the same question; a bias hunt is a strong critical thinking activity in its own right.
Bias hunt.
The text below is a realistic output for the prompt "write three word problems about fractions for Year 6 maths". Click the problematic assumptions.
How much scrutiny does each output need?
Checking every output with the same rigour is unrealistic; checking none is dangerous. The dividing line is the size of the risk: how directly does an error touch a pupil? Choose a level of scrutiny for each task below.
Copyright, attribution and open declaration.
The legal status of AI-generated material differs by country and is changing fast. The professional stance, however, has settled: if you used it, say so.
Name the tool and the stage you used it at. This is not a confession, it is professional ethics. It also models the behaviour you want: pupils see an adult who does not hide their sources.
As Module 3 showed, detection tools are unreliable. The fix is not to punish concealment but to normalise declaration: which prompt did they write, how did they change the output.
Who can use it, at what age, and how?
The answer to this does not start with age, it starts with the tool. For a pupil of any one age there are two entirely different situations: on one side a free-form conversation with a general-purpose assistant on their own account, on the other a school-provided education tool with its subject and content bounded, assigned by the teacher. The first column's answer changes as pupils get older; the second is already constrained by design, so it can open earlier.
General-purpose assistant (raw interaction): The conversation is open to any subject, nobody bounds the output in advance, the history accumulates in the pupil's own account, and the provider is the processor. This is where provider terms typically exclude under-13s entirely and require parental permission under 18.
School-provided education tool (bounded interaction): The task and subject are defined up front, output is produced inside the frame the teacher sets, the school opens the account, and the contract names the school as controller. Here what governs is less an age limit than the contract the school signed and the information given to parents.
The gap between the two is pedagogically real as well: a primary-age pupil holding a conversation with an unbounded assistant is not the same thing as that same pupil working on an exercise their teacher assigned. The table below keeps the two in separate columns.
| Key Stage | General-purpose assistant, pupil's own account | School-provided bounded tool | Parent communication |
|---|---|---|---|
| Primary, KS1-2 | No. The terms do not allow it and pedagogically there is no need. | From the teacher's screen, one screen at the front; where content is assigned, under teacher supervision and in class | Information is enough |
| Secondary, KS3 | Usually no. Even where terms open up above 13, individual use should be tied to school policy. | On a school account, group work under supervision; outputs reviewed together in class | Written information and permission |
| Secondary, KS4-5 | Yes, within stated rules. Use is declared and task design is explained with an AIAS level. | Individual use can open up; the teacher defines the task and the assessment criteria up front | Written information |
| Fixed at every Key Stage | Whichever the tool: no personal data entered, outputs verified, a human signs any decision that affects a pupil | Policy shared | |
Work out for yourself which category your tool falls into: is the conversation open to any subject, whose account holds the history, who does the contract name as controller? Terms change often, so always confirm the current rule on the tool's own page; the table above is a pedagogical recommendation.
Five situations without a clean answer.
Some of the questions in this module have no single right answer; it depends on your school's context. Pick a side in each of five situations and see that side's strength and its weakness. The aim is not to talk you into a position, it is to prepare the discussion you will open with your department.
Five common ethical mistakes.
1 "I only used the initial, so it is anonymous" ›
2 "The model gave a source, so it must be right" ›
3 "I ran the essay through a detector and it flagged AI" ›
4 "I left the final grade to the AI, that is more objective" ›
5 "Nobody at school said anything, so it must be allowed" ›
Fill in the blanks.
- data minimisation
- purpose limitation
- explicit consent
- ordinary
- special category
- anonymous
- the model
- a human
- the detector
- used as it is
- verified one by one
- counted only
You want to build an individual support plan using the wording of an educational psychologist's report a parent sent you. In a general-purpose assistant you signed into with your personal account, what is the right thing to do?
Module 4 complete.
You now know which data never goes in, how much scrutiny each output deserves and which rule you will defend at your school. One module left: we have drawn the boundaries, now we bring the pupil to the table.
Module 5: AI in the classroom → All modules