Shadow AI in NZ Education: What Schools Don't Know Is Happening | NSP

Dayna-Jean Broeders

02 August 2026

14 min

Read

Shadow AI in Education: What Your Staff and Students Are Using - And What You Don't Know About It

 

New Zealand schools and tertiary institutions are navigating AI adoption at a pace that has overtaken almost every governance framework put in place to manage it. The Ministry of Education issued guidance to schools in 2023 and NZQA has published specific direction for assessment contexts. Yet as the NZ Herald reported in March 2026, schools across the country are still working through what AI governance looks like in practice - while staff and students are making their own decisions about which tools to use and how, often without any formal guidance applying to their specific situation.

NZQA's response to AI in assessment contexts has been concrete: submitted reports were removed as an external assessment format for several NCEA standards from 2025, due in part to authenticity concerns. Schools are shifting toward in-class, supervised tasks and oral assessments to ensure students demonstrate their own understanding. The message from the regulatory side is clear. What hasn't kept pace is the governance of how AI is being used - by staff and students - outside formal assessment contexts.

That gap is where shadow AI lives in education. And in an environment where student data, staff information, and institutional intellectual property are all in play, the consequences of getting it wrong are specific to education in ways that generic AI governance frameworks don't account for.

 

Why Education Staff and Students Are Turning to AI - With or Without Approval

The pressures driving AI adoption in education are real and well-documented. Teachers are managing larger classes with more diverse needs, more administrative requirements, and less preparation time than they had five years ago. Leaders are producing reports, managing compliance, and navigating ministry requirements alongside operational responsibilities that haven't shrunk.

Students, meanwhile, are living in an environment where AI tools are freely available, increasingly capable, and used routinely outside school hours. Expecting them not to reach for those tools in an academic context requires either effective restriction - which most schools can't fully achieve - or effective education and governance that gives them a framework for using AI appropriately.

Into both of these environments, AI tools have arrived. Teachers have found AI useful for lesson planning, assessment design, parent communication, and report writing. Students have found it useful for research, drafting, and working through concepts. Support staff have found it useful for administrative tasks, correspondence, and documentation.

The challenge is that most of them are happening without any formal institutional decision about which tools are approved, what information can be used with them, and what oversight applies to the output.

 

What Shadow AI Looks Like in a School or Tertiary Institution

Shadow AI in education doesn't look like a deliberate policy violation. It looks like this:

A teacher using ChatGPT to draft end-of-year reports, entering student names, assessment results, observed behaviours, and personal notes about each student's progress and challenges. The reports are reviewed and edited before they're sent to parents. The student information - including names, academic performance, and personal observations - has been entered into an external AI system with no data processing agreement with the school.

A head of department using a public AI tool to design an assessment rubric, entering the course objectives, student cohort context, and previous assessment approaches. The output is reviewed and adapted. The institutional curriculum information is now in an external system.

A school leader using an AI tool to draft a communication to parents about a sensitive student welfare issue, entering relevant background context to help frame the message appropriately. The welfare information - involving a specific student's circumstances - has been processed through an external platform.

An administrator using an AI transcription tool added to Teams to produce notes from a staff meeting where student pastoral care cases were discussed. The transcript includes student names, welfare concerns, and staff commentary on individual students. It's stored on a server the school doesn't control.

A student using ChatGPT for an internal assessment in a context where their school's policy is unclear about whether that's permitted. They submit the work. The teacher doesn't recognise it as AI-assisted. The school's academic integrity policy has just been breached in a way nobody detected.

A tertiary lecturer using a public AI tool to generate first-pass marking feedback across a large student cohort, entering student submissions to produce draft comments. The student submissions - which contain intellectual property belonging to the students - are now in an external system.

Each found a tool that addressed a real pressure point in their work. The issue is that in each case, information about students - or belonging to students - moved outside the institution's governed environment without a deliberate decision having been made.

 

Where AI Is Genuinely Creating Value in Education

The opportunity AI presents for education is substantial - and the institutions that use it well will be better placed to support their staff and students than those that don't.

Lesson planning and resource development - AI-assisted development of lesson plans, learning resources, and differentiated materials can significantly reduce teacher preparation time. Within a governed environment where student-specific information doesn't leave the institution's control, this is a high-value, relatively low-risk application.

Assessment design - Developing assessment tasks, rubrics, and exemplar responses is an area where AI genuinely accelerates work that used to take significant time. The key distinction is whether institutional curriculum information and existing student work are being entered into external systems.

Report writing support - AI-assisted drafting of student reports - using pre-approved, governed tools rather than public AI - can compress one of the most time-intensive administrative demands in teaching. The requirement is that student personal information stays within the institution's governed data environment.

Administrative efficiency - Parent communications, meeting agendas, policy document drafting, and routine correspondence are all areas where AI can reduce administrative workload substantially without requiring access to sensitive student information.

Microsoft Copilot within the institution's environment - For schools and tertiary institutions on Microsoft 365 - which describes a significant proportion of NZ education institutions - Microsoft Copilot provides AI capability within the institution's existing data governance structure. It doesn't send student information to external AI models. It works within the institution's existing permissions and access controls. For institutions that haven't yet activated it in a governed way, this is the alternative that already exists within many existing licences.

Personalised learning support - AI-assisted identification of learning patterns, resource recommendations, and adaptive content delivery represent significant long-term opportunities for improving student outcomes. These applications require purpose-built, governed AI tools - not public AI platforms used informally.

 

The Specific Risks for NZ Education Institutions

Education sits at a particular intersection of risk: student privacy, academic integrity, institutional reputation, and regulatory obligation - all in an environment where the people whose information is at stake include children.

Student privacy and the Privacy Act 2020 - Student information - names, academic performance, welfare records, behavioural observations, personal circumstances - is personal information subject to the Privacy Act 2020. Processing that information through external AI tools without adequate data governance creates Privacy Act obligations that most schools haven't fully assessed. For students under 16, the privacy considerations are heightened further by the obligations around collecting and using information about children.

The Education and Training Act 2020 - Schools have obligations around the management of student information under the Education and Training Act. These obligations apply regardless of the tools being used to process that information - a school that processes student information through an external AI tool without appropriate safeguards doesn't escape those obligations because the processing happened through AI.

Academic integrity - NZQA's position is clear: AI is not permitted for external assessments, and schools are required to have an authenticity policy covering AI use for standards-based assessment. Shadow AI in a student context creates academic integrity risk that is difficult to detect and, once detected, difficult to address fairly without clear prior guidance having been given. NZQA specifically warns against over-reliance on AI detection software, noting false positives have unfairly flagged high proportions of second-language students - which means detection isn't a reliable substitute for clear governance.

Institutional IP and curriculum content - Teaching resources, assessment designs, curriculum frameworks, and pedagogical approaches developed within an institution represent intellectual property. When those materials are entered into public AI tools - for refinement, adaptation, or benchmarking - the data handling terms of most AI platforms are incompatible with those materials remaining exclusively the institution's.

Staff and student wellbeing information - Pastoral care discussions, welfare records, mental health support notes, and behavioural incident documentation are among the most sensitive information that schools hold. When that information is processed through AI tools - even for legitimate purposes like generating draft communications or summarising case notes - it creates governance risk that the sensitivity of the information warrants.

Reputational risk - A school that processes student information through unmanaged AI tools, or that has an AI-assisted academic integrity breach become public, faces reputational consequences that affect community trust in ways that are difficult and slow to rebuild. In the NZ education context, where community relationships are central to how schools operate, that reputational dimension matters significantly.

 

The NZ Regulatory Context

New Zealand's education sector has more AI-specific regulatory guidance than most industries - and it's still evolving.

The Ministry of Education has published guidance on generative AI for education professionals, covering what educators should consider when using AI and how schools should think about assessment policy in an AI context. NZQA has provided specific direction on AI in assessment, including the removal of submitted reports as an external assessment format for several NCEA standards.

Both the Ministry and NZQA make clear that the obligation is on schools to develop their own institutional AI policy - they provide frameworks and guidance, but the governance decisions sit with each school's leadership. That means the quality of AI governance across NZ education institutions varies significantly - from schools with detailed, well-communicated policies to those still working through what a policy should cover.

For tertiary institutions, the Privacy Act and the Education and Training Act sit alongside institutional academic integrity obligations and, increasingly, contractual arrangements with research partners and funding bodies that have their own data governance requirements.

The consistent direction across all of this guidance is the same: schools and institutions need to make deliberate decisions about AI use rather than letting adoption happen informally. That's exactly what shadow AI represents - adoption that happened before the deliberate decisions were made.

 

The Visibility Problem

Shadow AI in education refers to AI tools that staff or students begin using independently, without involvement from school IT departments or administrators. Many of these tools are unvetted, untracked, and unaccounted for.

The visibility challenge in education is more complex than in most industries because it has two distinct dimensions: staff shadow AI and student shadow AI. Both need to be understood before governance can be built around either.

Staff shadow AI follows the same pattern as other industries - tools adopted individually, AI features activated through software updates, and a gap between what's in use and what's governed. In education, this is complicated by the relatively flat technology governance structure of many NZ schools, where IT oversight is limited and individual teachers have significant autonomy over their classroom tools.

Student shadow AI is a different category entirely - and one that requires a different kind of governance response. Students using AI tools for academic work presents an academic integrity question as much as a data governance one. The institution needs visibility into what students are using AI for, what guidance they've been given, and whether that guidance is being followed - not to catch students doing something wrong, but to ensure the governance exists to address it fairly if and when something does go wrong.

The patterns are so consistent across sectors, geographies, and school sizes that it is no longer useful to treat shadow AI as an exception or a failure of compliance. It is, instead, one of the defining governance challenges of this moment in AI adoption.

Visibility comes before policy. Understanding what AI tools are in use - across staff and students - before building governance around assumptions is the foundation that makes everything else work.

 

What Good AI Governance Looks Like for Education Institutions

Education institutions that have approached AI governance well share a consistent pattern: they treat visibility and education as parallel starting points, not sequential ones.

They gain technical visibility into what AI tools are connecting to their institutional environment - including AI features embedded in existing software and Microsoft 365 tools activated through updates. And they start the educational conversation with staff and students at the same time - not waiting until governance is complete to begin educating, but treating education as part of the governance process.

From that foundation:

A clear, tiered AI policy that distinguishes between AI use by staff, AI use by students in non-assessment contexts, and AI use in assessment contexts. The policy should be specific enough to address the scenarios that actually occur in the institution - not a generic document that doesn't map to the questions teachers and students are actually asking.

An approved tool list covering AI tools that have been assessed for data governance compliance, with clear guidance on what institutional and student information can be used with each tool. The list should be maintained and communicated - not a one-time document that goes out of date.

Student-facing AI education that addresses academic integrity, appropriate use, and the specific obligations that apply in assessment contexts. NZQA's guidance is explicit that this education is the institution's responsibility - AI detection tools are not a reliable substitute for clear prior guidance.

Staff professional development on AI use - including the data governance dimensions that most professional development programmes don't cover, and specific guidance on what student information can and can't be used with AI tools.

Microsoft Copilot as the governed staff AI alternative. For institutions on Microsoft 365, Copilot provides staff AI capability within the institution's existing data governance structure - lesson planning, report drafting, administrative correspondence, meeting summarisation - without student information leaving the institution's governed environment. Positioning this clearly as the approved tool for staff reduces the incentive to reach for public AI tools for the same tasks.

Governance that covers both staff and students. Most AI governance frameworks focus on one or the other. Effective education AI governance needs to address both dimensions explicitly - because the risks and the appropriate responses are different.

 

Gaining Visibility Before Building Policy

If your institution hasn't yet taken a structured approach to AI governance, the starting point is understanding what's actually happening - across staff and students - before building policy around assumptions.

Most NZ education institutions that begin this process find more AI use than they expected, in more contexts than they anticipated, with less consistency than their existing acceptable use policies assumed. That's not a failure - it's a reflection of how quickly AI tools have arrived and how slowly governance frameworks typically move.

NSP's approach starts with visibility - mapping the current state of AI adoption across the institution's Microsoft 365 environment, identifying shadow AI exposure across staff use cases, and reviewing configuration and governance posture before any policy work begins. For education institutions specifically, that exercise surfaces the student privacy, academic integrity, and regulatory obligations that generic AI governance frameworks don't account for.

For institutions ready to build a more comprehensive programme, NSP's Secure AI Accelerator provides a structured approach covering AI enablement, security, governance, and ongoing optimisation - with executive reporting that gives leadership a documented, evidenced picture of AI governance maturity. For schools presenting to boards of trustees, that documentation is the kind of evidence governance conversations require.

The education institutions that will navigate AI most effectively aren't the ones that banned it - students and staff will use it regardless, just less visibly. They're the ones that understood what was already happening, built governance that reflected the real picture, and used that governance as a foundation for genuine AI education rather than a substitute for it.

If you're not sure how much AI is already in use across your institution's Microsoft 365 environment, that's the question worth starting with. NSP can help you understand your current shadow AI exposure and governance readiness before you begin building policies or wider AI initiatives.

Talk to NSP about AI for your institution →

Or call us: 0508 010 101

 

Frequently Asked Questions

What is shadow AI in schools and education institutions? Shadow AI in education refers to AI tools being used by teaching staff, support staff, or students without formal approval or oversight from the institution's leadership or IT function. This includes public AI tools used for lesson planning, report writing, student communications, assessment design, and student academic work, as well as AI features embedded in existing educational software activated without review. In NZ education, shadow AI is particularly significant because of student privacy obligations under the Privacy Act 2020, NZQA academic integrity requirements, and the Education and Training Act 2020.

What are the main risks of shadow AI for NZ schools? The primary risks are student personal information - including academic performance, welfare records, and personal observations - being processed through external AI tools without adequate data governance; academic integrity breaches in assessment contexts where AI use hasn't been clearly governed; institutional IP in teaching resources and curriculum materials being processed through external systems; and compliance obligations under the Privacy Act 2020 and Education and Training Act being breached through unmanaged AI processing of student information.

What does NZQA say about AI use in assessments? NZQA's position is that AI is not permitted for external assessments, and schools are required to have an authenticity policy covering AI use for standards-based assessment. NZQA also warns against over-reliance on AI detection software, noting false positives have unfairly flagged second-language students, and recommends schools take an educative rather than punitive approach to AI-related academic integrity issues. Submitted reports were removed as an external assessment format for several NCEA standards from 2025, due in part to AI authenticity concerns.

What should NZ schools do about shadow AI? Start with visibility - understand what AI tools are actually in use across staff and students, including AI features embedded in existing educational software and Microsoft 365 tools. Develop a clear, tiered AI policy that addresses staff use, student non-assessment use, and assessment use separately. Provide student-facing AI education that addresses academic integrity and appropriate use. Implement Microsoft Copilot as a governed staff AI alternative within the institution's existing Microsoft 365 environment.

How does Microsoft Copilot help NZ education institutions manage AI risk? Microsoft Copilot operates within the institution's existing Microsoft 365 data governance environment - it doesn't send student information to external AI models, and it respects the institution's existing permissions and access controls. For NZ schools and tertiary institutions on Microsoft 365, Copilot provides staff AI capability for lesson planning, report drafting, administrative correspondence, and meeting summarisation without student information leaving the institution's governed environment. This makes it a fundamentally different proposition from public AI tools in terms of student privacy risk.

 

Continue Reading

Let’s stay in touch!

Enter your details below to stay up-to-date with the latest IT solutions and security measures.