School Connection / Analysis
The AI register is not enough: when assurance must be reopened
An inventory makes AI visible. It does not prove that each use remains safe, lawful, effective or understood by the people responsible for it. The next maturity step is linking the register to material-change triggers and evidence.
The answer in brief
The register becomes valuable when it tells leaders what needs attention next.
DfE's data-protection guidance expects schools to understand what personal data an AI service processes, why it is used, the relevant roles, security and transparency. That information can become a live register, but only if the record has an owner, a review date and an event that reopens the judgement.1
The review clock should move when the service or its context changes. A new model, a wider pupil group, a new data field, a changed retention term or an incident can make the original approval stale even if the product name is unchanged.134
- Record the decision behind the entry, not only the product and owner.
- Attach review triggers to changes in purpose, data, people, service and harm.
- Use the register to create a work queue for leaders, DPOs, DSLs and IT teams.
01 / From list to control
A register should answer a leadership question without another investigation.
For each use, retain the purpose, users, age group, data categories, provider role, access model, human reviewer, safeguards, evidence of benefit, review date, owner and exit route. Record what the school decided not to do as well as what it approved when that boundary matters.12
02 / Five reopen triggers
The same product can become a different risk.
Reopen the review when the purpose changes; new or more sensitive data enters; a new pupil or staff group is included; the service, model, subprocessor or retention changes; or an incident, complaint, unexpected output or monitoring result changes the risk picture.134
- Product: model, feature, interface, access, subprocessor or terms change.
- Purpose: the use moves from assistance into recommendation, decision or pupil-facing interaction.
- Data and people: new identifiers, special-category data, ages, roles or scale enter the use.
- Harm: an incident, complaint, safeguarding concern, bias signal or poor outcome appears.
- Context: a new device, platform, network or policy changes how the service operates.
03 / Assurance in practice
The review should end in a decision that someone can implement.
A reopened review can continue, restrict, redesign, pause or stop the use. Record the evidence considered, who decided, what changed, what communication is required and when the decision will be checked again. This is a governance loop, not a compliance document stored out of sight.23
Leadership questions
Questions that turn the development into a governing conversation.
Board test
Which AI entries have no named review owner, evidence threshold or exit route?
Board test
What change in a product, purpose, data set or user group would reopen each approval?
Board test
How do DSL, DPO, IT, curriculum and governance roles see the information they need?
Board test
What is the route from a complaint or unexpected output to a pause and a recorded decision?
School Connection intelligence lens
What the national Observatory can add, and where it must stop.
The programme treats an AI register as a signal system: it identifies where a decision exists, what could make it stale and which role needs to act. It does not treat the presence of an entry as proof of safety or effectiveness.12
Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.
Evidence boundary
What this analysis does not prove.
- A register is only as complete as the discovery process that feeds it, including informal or free tools.
- A review trigger does not predict harm; it creates a disciplined opportunity to investigate.
- The legal and technical depth required varies with the use, data, users and potential impact.
What we are monitoring next
Publication is the beginning of the watch.
- DfE and ICO updates on AI, data protection and EdTech assurance.
- Material product, model, subprocessor, retention, user or purpose changes.
- Complaints, incidents, monitoring results and independent evidence that alter a local decision.
Approved public intelligence
What the live evidence is showing now.
Gigabit is coming to more schools. The connection is only the beginning.
The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.
A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet.
This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.
Sources and methodology
Evidence used in this analysis
School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.
- 01
Department for Education · Current guidance checked 14 September 2026
Generative artificial intelligence and data protection in schools
Guidance on personal data, purpose, lawful basis, transparency, security, human oversight and reviewing AI uses as they change. - 02
Department for Education · Updated 19 May 2026
Using AI in education: support for school and college leaders
Implementation support for leaders; it does not certify a product or replace local safeguarding, privacy or professional judgement. - 03
Department for Education · Updated 8 September 2026
Filtering and monitoring: core standard
Current safeguarding and technical expectations, including dynamic, personalised and AI-generated content and event-triggered review. - 04
National Cyber Security Centre · Published 20 August 2026
Managing the cyber risk of agentic AI
Interim cross-sector guidance on threat modelling, restricted authority, human oversight, logs, monitoring and emergency shutdown.