"What am I allowed to do with AI?" is a simple question with a complex answer... AI tools change quickly, so detailed guidance soon becomes outdated.
Instead, use these two simple rules to recognise what is safe:
The ‘Know your tools’ guidance focuses on stand-alone AI tools such as Copilot Chat, ChatGPT, Claude and Gemini. AI features enabled by WeST or your school within systems such as Arbor will already have gone through the appropriate data-protection checks.
WeST classifies its data into four categories: Public, Internal, Confidential, and Highly Confidential. Most files and emails will not have a visible classification label; their classification is implied by their nature, source and content.
Across WeST, we mostly use Internal or Confidential data. Information about identifiable individuals, including names, personal information and performance or assessment data, will normally be Internal or higher. The same applies to commercially sensitive information, including financial information, unless it has been explicitly approved for public release by an authorised person.
We also use a lot of Public data. This includes material intended for release, such as newsletters, curriculum and teaching resources we have created and are entitled to share publicly, and information deliberately published for unrestricted public use such as national statistics.
Highly Confidential is reserved for the most sensitive information we hold, such as safeguarding records or HR grievance case notes.
The higher the classification, the greater the harm a data breach could cause. Putting Confidential or Highly Confidential information into an unapproved tool is against WeST policy and may result in a personal data breach.
Only some AI tools are safe for non-public data. WeST has enterprise data-protection agreements with suppliers such as Microsoft, Google and Arbor. Before adopting any new system that may access our more sensitive data, we must complete a Data Protection Impact Assessment (DPIA). This includes adopting new features of existing systems that were not covered by the original DPIA.
AI tools used for work across WeST must be legal, suitable for business use and fulfil the following minimum requirements. These requirements do not make a tool approved for pupil, staff or other non-public information, but they help protect the Trust’s reputation by setting reasonable minimum expectations.
All AI tools used for any work purposes across WeST must fulfil all the following criteria:
You can ask an AI tool to direct you to its Privacy Information and Terms pages. Always check the actual provider’s published information, rather than relying on the AI to tell you. If you are unsure, ask ICT or the DPO.
For lesson plans and resources that contain no pupil or staff information, or when working with any Public data, you may use any reputable AI tool that meets WeST’s basic requirements.
For any other use, the tool and purpose must be covered by a completed and approved DPIA.
(click the headings to expand)
The email may contain personal or sensitive information. Use only an AI tool approved for that data and purpose, such as Copilot while logged into your WeST account. Do not paste it into a public AI tool. Removing the pupil’s name may not be enough if they could still be identified from the details.
QLA data may include pupil information and unpublished school performance data. Use an approved tool, such as Copilot within Excel.
Do not upload identifiable or school-level QLA data to an unapproved AI tool. An unapproved tool should be used only where the data has been reduced to question- or topic-level information and contains nothing that could identify a pupil, class or school.
This is usually acceptable where the resource contains no personal or confidential information and you have the right to upload it. Do not upload commercially purchased resources or pupil work unless the approved process specifically allows it. Check the output for accuracy before using it.
AI may support these tasks only where an approved tool and process are in place. It must not make important decisions by itself. A member of staff remains responsible for checking the information, applying professional judgement and making the final decision.
Meeting notes may contain personal, safeguarding, staffing or commercially sensitive information. Use only an approved tool, such as Copilot within Microsoft Teams. Do not paste confidential notes into a public or unapproved AI tool, even if the meeting itself was routine.
A Data Protection Impact Assessment (DPIA) is similar to a health and safety risk assessment, but for data. Before a new system is bought or used, it checks what information it may access, how and why that information will be used, who can access it, how it will be stored, shared and deleted, and what safeguards are needed. UK GDPR requires DPIAs for higher-risk uses of personal information, and WeST requires one for every new platform that may access our data. Our pupils and staff trust us with their personal information. DPIAs help us make sure we use it responsibly and keep it safe.
We are also required to update a DPIA if a platform we are currently using introduces new functionality not covered by the original DPIA.
The person proposing the platform must write or update the DPIA, with advice from the supplier. The DPO must review and approve it before any agreement is made or features used.
Learn more from the Information Commissioner’s Office – Data Protection Impact Assessments.
At present, no. Do not install any software that can access files, applications or other data on your work device unless it has been approved and made available by WeST.
Microsoft is introducing additional AI functionality within Microsoft 365. We will make approved tools available when we are satisfied that they are sufficiently mature and safe. We do not recommend installing unapproved agentic AI tools on personal devices used for work either.
Agentic tools are AI tools that can take actions rather than only provide answers. For example, they may be able to open or create files, edit documents, manipulate spreadsheet data, access other applications or send messages on your behalf.
This can make AI much more useful, but it also increases the risk of the tool accessing the wrong information or taking an incorrect or unintended action. Agentic tools must therefore be specifically approved before being installed or used with WeST data.
Once an image or video is uploaded to an AI tool, we may lose control over how it is stored, analysed or reused. It could be used to identify someone, create convincing false or altered content, imitate their appearance or voice, or reveal information about their identity, location or circumstances.
Misuse could cause distress, embarrassment, reputational damage or serious safeguarding concerns. Children may be particularly vulnerable, and the effects can be difficult or impossible to reverse once content has been shared or reproduced.
No. A person may still be identifiable from other details, such as their school, year group, role, circumstances or the content itself.
Removing names also does not make confidential information Public. Internal assessment results, behaviour information, staffing matters or unpublished school data could still cause harm, embarrassment or reputational damage if disclosed. Only use the information with an AI tool approved for that type of data and purpose.
Only if the information is Public, or the tool has been specifically approved for that type of data and purpose. Removing the sender’s or pupil’s name may not be enough if they can still be identified from the content.
Pupil work may also be protected by copyright, so do not upload it unless the approved process specifically permits this.