One of the most-searched AI questions in UK schools right now. Here is the honest answer on what your school can see, what is protected, and where the real risk actually sits.
Want your school's AI documents written for you — free?
I'm a school governor and I've built the full KCSIE-2026-ready set for my own school: AI policy, staff acceptable use agreement, governor briefing and parent letter. I'm doing the same free for a small number of schools while I build case studies. No catch, nothing to buy.
Email me and say "send me the AI documents" — I'll reply with what I need to know. Takes you two minutes.
Email neil@askcolin.uk Or call 07971 775986Neil Kidd · Governor, Worple Primary School · Prefer the detail first? Keep reading.
This is one of the most-searched questions by school staff in the UK right now, and it deserves a straight answer rather than a shrug. If you sign into Microsoft Copilot with your school account, your school's IT administrators can see that you used it, and in many configurations they can retrieve what you typed. Not in real time, not casually, and not usually by choice — but the capability exists, and staff should know that before they paste anything sensitive.
What your school can actually see
When you use Copilot signed in with a school (Microsoft 365 Education) account, your prompts and responses are treated as your organisation's data — not your personal data. In practical terms that means:
- Usage is visible. Admins can see which accounts are using Copilot and how often, through the Microsoft 365 admin centre reports.
- Content can be retrievable. Copilot interactions are stored in the school's tenant and can be surfaced through eDiscovery and audit tools — the same mechanisms that cover email and Teams messages.
- Retention policies apply. If your school has retention rules configured, Copilot interactions can be kept under those rules like any other record.
What that does not mean is that your headteacher is reading your prompts over coffee. These tools exist for legal, safeguarding and compliance reasons — a subject access request, a safeguarding investigation, a disclosure requirement. Nobody is browsing for entertainment. But "nobody is looking" and "nobody can look" are very different statements, and staff deserve the accurate one.
Is what I type used to train the AI?
This is the reassuring part, and the distinction that matters most. With a properly licensed Microsoft 365 Education account, prompts and responses in commercial-data-protected Copilot are not used to train the underlying models. That protection is the whole point of the education and enterprise licensing: your data stays inside your tenant's boundary.
The risk sits elsewhere — in staff using free, personal AI accounts for school work. A teacher pasting pupil information into a free consumer tool on a personal login has no such protection, and that is where most schools' real exposure lies. It is also, incidentally, what KCSIE 2026 now expects schools to have understood and managed.
The short version: school-account Copilot is the safer place to work. Free personal AI accounts used for school tasks are the actual problem — and the one your policy needs to address by name.
What this means for staff
- Assume your school-account AI use is a school record. Write in it as you would in a school email — because in compliance terms, that is roughly what it is.
- Never put identifiable pupil information into a free or personal AI account. Names, SEN details, safeguarding notes, behaviour records. This is the line that turns a productivity habit into a potential UK GDPR breach.
- Don't use AI for anything you wouldn't want quoted back. Venting about a colleague or a parent in a prompt is a bad idea for the same reason it is in email.
- Ask what your school has actually enabled. Most staff have no idea whether their school has Copilot licensed, what version, or with which protections — and it is a fair question to ask.
What this means for school leaders
If staff are asking this question — and the search data says they are, in numbers — the honest read is that your school has AI use happening without a shared understanding of the rules. That is not a discipline problem; it is a communication gap, and it is straightforward to close.
- Tell staff plainly what is monitored and why. Silence gets filled with rumour, and rumour makes staff either reckless or fearful. Neither helps.
- Give them a sanctioned tool. Staff who have a safe, approved option stop improvising with free accounts. This single step removes most of your risk.
- Put it in an acceptable use agreement. One page, signed, covering what may and may not go into AI tools, which accounts to use, and who to ask when unsure.
- Cover it in safeguarding training. KCSIE 2026 now expects AI to sit inside your safeguarding arrangements, not beside them.
For the wider picture of what the new guidance requires, see our summary of the KCSIE 2026 AI changes, and our guide to writing an AI policy for a UK school. If you're weighing up the platform itself, our Microsoft Copilot for schools review covers what it's actually good at.
Not sure where your school stands?
I write AI policies, staff agreements, governor briefings and parent letters for UK schools — currently free for a small number of schools building case studies.
Frequently asked questions
Can my school see my Copilot chats?
Your school's administrators can see that you used Copilot and, in many configurations, retrieve the content of your interactions through audit and eDiscovery tools. It is not casual monitoring, but the capability exists because Copilot interactions with a school account are treated as school records.
Does Microsoft use school Copilot data to train its AI?
With a properly licensed Microsoft 365 Education account, prompts and responses in commercial-data-protected Copilot are not used to train the underlying models. The same protection does not apply to free, personal AI accounts used for school work.
Is it safe to put pupil names into Copilot?
Only where your school has licensed a data-protected version and your AI policy explicitly permits it. Identifiable pupil data should never go into free or personal AI accounts, which risks a UK GDPR breach.
Can my school see what I do in Copilot on my personal account?
No — a personal account outside the school tenant is not visible to school administrators. But using a personal account for school work removes the school's data protections and is exactly the practice most AI policies prohibit.
Should staff be told what is monitored?
Yes. Transparency is both a data protection expectation and the practical way to stop staff drifting to unmonitored free tools. A short acceptable use agreement covering AI is the usual way to do it.