Securing AI in Education: Safe Adoption of Google Workspace & Microsoft 365

As Cyber Security Awareness Month continues, we consider the risks of AI in education, and the practical steps schools can take to stay safe and keep their data secure.
AI in education
Share Post:

During Cyber Security Awareness Month, it’s worth taking the time to reflect on how emerging technologies and artificial intelligence (AI) is changing the way schools navigate online systems, safeguarding, and security.

AI in education is contantly evolving, moving beyond experimental teaching tools to becoming part of the everyday platforms schools use. With Microsoft 365 Copilot and Google Workspace Gemini, staff and students now have generative AI capabilities built into their daily tools. While these platforms offer the opportunity to reduce administrative workload and create resources more effectively, they also present unique data protection, governance, and safeguarding challenges.

For Executive Principals, Trust CEOs, CFOs, School Business Managers, and Headteachers, ensuring that AI can be used safely requires a proactive, strategic approach aligned with the latest DfE Generative AI Product Safety Standards and KCSIE statutory guidance.

The Risks of AI in Education

Integrating AI into the cloud platforms that schools already use fundamentally changes how data can be accessed and shared across the organisation. Without the right safeguards in place, these tools can introduce significant security and data protection risks.

Free or unmanaged consumer AI accounts may use user prompts to improve or train AI models, depending on the service and its settings. This means staff could inadvertently expose sensitive information, such as pupil records, Education, Health and Care Plans (EHCPs) or staff disciplinary notes, by entering it into an unconfigured AI tool. This can lead to a severe GDPR breach.

Furthermore, tools such as Microsoft 365 Copilot and Google Workspace Gemini can also access information based on a user’s existing permissions. If internal site permissions, shared drives, or SharePoint libraries are misconfigured, an AI prompt can easily surface restricted executive or safeguarding data to unauthorised users. This makes regular permission reviews and good access management essential.

Beyond access controls, traditional web filtering may not fully address the risks associated with AI features built into everyday applications. Simply blocking these tools, without providing approved alternatives and clear guidance, can encourage staff to use personal AI accounts or unapproved services instead. This is often referred to as shadow AI and can make it harder for schools to manage how information is used and shared.

Keeping AI Safe, Secure and Compliant

The regulatory framework surrounding AI in education requires active oversight from school and trust leaders, rather than relying on technical teams alone. The DfE sets explicit benchmarks requiring absolute assurance that pupil personal data and intellectual property remain private and unharvested. These standards reinforce a “human-in-the-loop” model where AI-generated content, such as lesson plans or pupil reports, must be checked by a qualified member of staff to ensure it is accurate, appropriate, and suitable for its intended purpose.

KCSIE also provides an important framework for understanding the safeguarding risks associated with AI. The guidance explicitly addresses interactions with AI chatbots, as well as the creation and sharing of AI-generated images, videos and deepfakes. Designated Safeguarding Leads (DSLs) and Senior Leadership Teams must review how web filtering and monitoring arrangements address AI features within office applications, search engines and other online services. Putting strong policies and staff training programmes in place can help to ensure that AI is used safely, responsibly and in line with the school’s wider data protection and safeguarding responsibilities.

How to Use AI Safely in Schools

To maintain a secure environment, school leaders must verify that technical administrators have properly configured the appropriate security and data protection settings across Microsoft 365 and Google Workspace.

In Microsoft environments, this includes confirming that the relevant Enterprise Data Protection (EDP) protections are in place and understanding how prompts and data are handled within the organisation’s environment. Meanwhile, regular Microsoft Purview access reviews can help to identify and correct excessive permissions on SharePoint sites and files before these are surfaced through Copilot.

In Google Workspace, leaders should check that their licences, subscription terms and service settings provide the intended data protection safeguards, including how prompts and data are used for model training. Google Admin Console settings can also help administrators manage access to Gemini, allowing schools to apply different rules for staff and students, or different age groups where appropriate.

Across both ecosystems, putting Data Loss Prevention (DLP) policies in place is essential to block sensitive information, such as personal data and UPNs, from being submitted in AI prompts. These policies should be configured to reflect the school’s specific requirements and reviewed regularly as AI capabilities evolve.

How One Education Can Help

Carrying out a safe, secure AI rollout requires the right technical expertise alongside a clear understanding of the requirements and challenges facing schools and trusts. One Education helps bridge this gap through our Strategy & Assurance Discovery Framework.

Our specialist team works directly alongside Headteachers, CEOs, SBMs, and DSLs to review existing systems, assess access permissions and identify potential risks before AI tools are widely adopted. This helps schools understand where sensitive information could be exposed and what steps are needed to address any weaknesses. We also assist safeguarding teams in drafting clear AI Acceptable Use Policies (AUPs), configuring filtering for dynamic AI content, and establishing auditable records for regulatory compliance.

Beyond initial audits, our engineers provide hands-on technical support to enforce strict data boundaries and prevent public model training. We turn complex technical findings into clear, actionable reports, helping Governing Bodies and Multi-Academy Trust (MAT) Boards understand the risks, prioritise improvements and make informed decisions about the safe use of AI.

Contact One Education IT Services today to schedule your M365 and Google Workspace AI Readiness Review.

Enquiry Form

Please complete the form below and we will get in contact as soon as we can to help you with your query.

In other news

Login to your account

Search our website

Request a brochure

Please fill in your details below to receive our free brochure.

Sign up to our Newsletter

Please fill in your details below to sign up to our newsletter.

Request a call back

Please fill in your details below to receive a call back from a member of our team.