Jump to content

Recommended Posts

Posted

Hi all,

 

Does anyone have a staff AI policy that we could look at, please?

 

I'm noticing staff here are starting to use AI (ChatGPT) to write letters - Although they aren't filling it with confidential information, or uploading spreadsheets loaded with data, I feel it's only a matter of time that someone (Innocently) feeds an non IT controlled AI system with information - Causing all sorts of GDPR issues.

 

Don't want to block them from a useful tool, but looking at forcing them to use only Copilot, as that at least is on a system we control & already have our data in.

 

 

 

 

  • Like 1
Posted

Wouldn't this fall under an existing policy? There must be one that covers uploading PII to unauthorised third party systems. Maybe expand that policy as it should be broadly covered already.

Posted
57 minutes ago, FN-GM said:

Wouldn't this fall under an existing policy? There must be one that covers uploading PII to unauthorised third party systems. Maybe expand that policy as it should be broadly covered already.

 

It will (even the most basic data protection / AUP will cover "don't give data about people to random companies without proper authorisation and due diligence") and that'll cover you in court, but if you want employees to do the right thing and avoid dealing with the fallout of them not doing so, you need to be more explicit.

 

Even if the "AI Policy" link goes to appendix 3 of the data protection policy, it's easier to put that link there than hope they look in the policy and scroll to appendix 3 unprompted.

Posted

Regardless of the individual policy wrangling - one sure fire way to remain saf(er) would be to only use copilot/gemini on your own MS/google tennancies which are already in EU/UK and already comply with GDPR.

 

As soon as you pick a.n.other AI comany to use you're putting yourselves at greater risk of GDPR shinanegans.

  • Like 1
Posted (edited)

Hi all,

 

Thanks for the links above, useful starting points.

 

Aye - A lot of "Don't upload data to unauthorised systems" stuff is covered under existing GDPR policies, which is what I've used to force staff to use Copilot at this stage. 

I sold it as a "Look at this really powerful feature you now have & hey, it's GDPR compliant!" rather than a STOP USING AI FULL STOP, which I feel would have been kneejerk.

 

Asking for policies has come from staff asking what is safe to upload to it and what isn't, as they are aware that other organisations have policies around this.

 

Some quick examples

  • Asking it to rewrite a CPOMS entry for clarity before submitting it
  • Asking it to come up with recommendations for SEN provision using detailed information about a student.
  • Uploading a picture of an item brought in school & asking it what it is (Is this an X knife?)
  • Student X has displayed X/Y/Z - Would this information require a PREVENT referral?

 

Now in theory, yes, because it's all on our M365 tenant & we as an organisation can view all the prompts & data that come as a result.

Of course, our data is already on Sharepoint/Onedrive/Outlook as it stands, but it's not being used to train AI.

 

I am keen to get stuck in on the paid versions of Copilot for key staff, but there's a awful lot of work that needs to be done first around data classification/tagging. 

Edited by DrCheese
  • Like 1
Posted

^ Given (IME) Copilot can barely* provide an accurate answer without a follow-up "please check your answer", the "hey, does student X need a prevent referral?" and the SEN recommendations query are a bit WTF.

 

*and not complex or nuanced stuff either.  It gets basic percentage calculations wrong.

  • Like 1
Posted
On 06/06/2025 at 18:24, pete said:

if you want employees to do the right thing and avoid dealing with the fallout of them not doing so, you need to be more explicit.

 

Training would be a better option than a dedicated policy.

  • Like 1
Posted
On 14/06/2025 at 05:33, FN-GM said:

 

Training would be a better option than a dedicated policy.

 

 100% this!

 

Who on here has read 100% of all of their companies/academies/schools/trusts policies and can remember them all?  As far as I'm concerned they're there to discipline people when they get it wrong.

 

Training, training, training is the answer and I've yet to hear of any of our Teachers being offered training.  In fact in our AI policy (that we had nothing to do with) it states the Network Manager would provide training - this was news to him and no such training has taken place or has been arranged!!

Posted
On 16/06/2025 at 17:52, Fazza said:

Who on here has read 100% of all of their companies/academies/schools/trusts policies and can remember them all? 

 

I can't remember where I park my car half the time!

  • Haha 1
Posted
On 16/06/2025 at 09:22, Fazza said:

 

 100% this!

 

Who on here has read 100% of all of their companies/academies/schools/trusts policies and can remember them all?  As far as I'm concerned they're there to discipline people when they get it wrong.

 

Training, training, training is the answer and I've yet to hear of any of our Teachers being offered training.  In fact in our AI policy (that we had nothing to do with) it states the Network Manager would provide training - this was news to him and no such training has taken place or has been arranged!!

Before AI one person read the policies, me, before I uploaded them, to check for mistakes like "do you want to leave <insert school name here> in the policy?". Now I just ask AI to find mistakes and contradictions, so 0 people read them

  • Haha 2
  • 2 weeks later...
Posted
On 11/06/2025 at 18:01, DrCheese said:

Hi all,

 

Thanks for the links above, useful starting points.

 

Aye - A lot of "Don't upload data to unauthorised systems" stuff is covered under existing GDPR policies, which is what I've used to force staff to use Copilot at this stage. 

I sold it as a "Look at this really powerful feature you now have & hey, it's GDPR compliant!" rather than a STOP USING AI FULL STOP, which I feel would have been kneejerk.

 

Asking for policies has come from staff asking what is safe to upload to it and what isn't, as they are aware that other organisations have policies around this.

 

Some quick examples

  • Asking it to rewrite a CPOMS entry for clarity before submitting it
  • Asking it to come up with recommendations for SEN provision using detailed information about a student.
  • Uploading a picture of an item brought in school & asking it what it is (Is this an X knife?)
  • Student X has displayed X/Y/Z - Would this information require a PREVENT referral?

 

Now in theory, yes, because it's all on our M365 tenant & we as an organisation can view all the prompts & data that come as a result.

Of course, our data is already on Sharepoint/Onedrive/Outlook as it stands, but it's not being used to train AI.

 

I am keen to get stuck in on the paid versions of Copilot for key staff, but there's a awful lot of work that needs to be done first around data classification/tagging. 

 

Have you had a quote yet for the full CoPilot licence?

 

I had one and nearly choked!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...