Advertisement

Safe AI help · Updated 9 September 2026

Your University Just Gave You a Free AI Account. What to Know First

Whole campuses switched on ChatGPT Edu and Microsoft Copilot this term. The account is a licence, not a permission — and the privacy answer is not the one either the optimists or the panickers are giving you.

Advertisement

Log in, then change two settings and answer one question. Your university almost certainly is not reading your chats — campuses that publish this say they do not monitor individual conversations — but most of them reserve an audit right, and with Microsoft Copilot your prompts and replies are stored as activity history that administrators can retrieve through standard compliance tools. The genuine upgrade over your free account is the contract, not the model: your institution's agreement normally stops the vendor training on what you type. And the licence changes nothing about your coursework rules. Your module's policy still decides what you are allowed to hand in.

Illustration of a student in glasses working at a wooden desk with an unmarked laptop, an open book, a desk lamp, a stack of books, a mug and potted plants, in front of tall arched windows

What actually happened this term

Institution-wide rollouts stopped being pilots. The University of Leicester announced in June 2026 that it would give full Microsoft 365 Copilot access to its whole community — more than 21,000 students and 4,000 staff — from September, as one of the first UK Microsoft Frontier universities.

In the US, the pattern is ChatGPT Edu with a training gate. UCCS opened student access on 14 August 2026, but only after you finish an AI literacy course in Canvas — five modules and two quizzes — with existing staff users given a deadline to complete it or lose access. The California State University system runs its own ChatGPT Edu deployment across campuses.

Two things follow. First, if your inbox has an unread message about an AI account, it is probably real and probably free to you — UCCS student paper The Scribe reported that only around 230 students had claimed theirs shortly after launch. Second, having the account settles nothing about using it, which is where students get into trouble.

For scale: the Lumina Foundation-Gallup 2026 State of Higher Education study (fieldwork 2–31 October 2025, non-probability web panel) found 57% of US college students use AI in coursework at least weekly and about 20% daily, while 42% said their school discourages AI use and 11% said it is prohibited outright. The gap between those numbers is the whole problem: routine use, unclear permission.

Can your university see your chats?

This is the question everyone asks and almost nobody answers precisely, because the honest answer differs by product. Here is what the operators actually publish.

ChatGPT Edu: not monitored, but auditable

The University of Colorado, which runs the UCCS deployment, states in its ChatGPT FAQ that "CU will not monitor individual users' interactions with ChatGPT Edu" and will "collect basic use statistics to better understand adoption and use patterns." It then adds the sentence students skim past: "CU will retain the right to audit individual user interactions in isolated and limited cases."

Cal State LA's FAQ uses near-identical language — individual conversations "are not monitored," only basic use statistics are collected — and confirms that the system's agreement with OpenAI "ensures your ChatGPT interactions and data are not used to train their underlying large language models or improve their services." On deletion, CU is specific: a deleted chat is "removed from your view immediately and scheduled for permanent deletion from OpenAI systems within 30 days, with limited exceptions (e.g., legal or security obligations)."

Microsoft Copilot: stored by design

Microsoft's own documentation is blunter, and this is where campus guidance most often misleads. Microsoft's data and privacy page for Copilot says that when you interact with Copilot, "we store data about these interactions," that the stored data "includes the user's prompt and Copilot's response," and that this record is your "Copilot activity history." It then states that "to view and manage this stored data, admins can use Content search or Microsoft Purview."

The enterprise data protection page says the same thing from the administrator's side: Copilot "applies your retention policies, supports audit of interactions, and follows your administrative settings," with the caveat that "the specific controls and policies will vary depending on the underlying subscription plan."

You will find university IT pages saying prompts and responses are not saved and nobody can see your chat. That describes one specific configuration, not the licensed product your university just bought for everyone. When a campus page and the vendor's documentation disagree, assume the more conservative reading applies to you.

QuestionChatGPT EduMicrosoft Copilot
Routine monitoring of your chatsNo, per CU and CSUNot stated as routine
Retrievable by administratorsAudit right reserved for limited casesYes — Content search or Purview
Used to train the vendor's modelsNo, per campus agreementsNo, per Microsoft
You can delete your historyYes, 30 days to permanent deletionYes, via the My Account portal

The practical rule that survives both columns: write as if a reasonable administrator could one day read it. That is not paranoia, it is just how institutional accounts work — and it is the same standard you already apply to your university email.

Three things a free account does not change

It is not permission. Your university buying a licence is a procurement decision. Your module handbook is the rule. CU says it directly: the institution has policies "that bar academic dishonesty in all its forms," and "nothing about the use of generative AI changes that foundational policy," while faculty "retain control of their curriculum and learning environment." A tutor can ban AI on an assignment the same week the university switches it on for 20,000 people. If you are unsure where a specific task falls, work through the AI help versus cheating decision tree before you start, not after you submit.

It is not more accurate. The enterprise tier changes the contract, not the model. Microsoft says plainly that responses "aren't guaranteed to be 100% factual" and that users "should still use their judgment when reviewing the output." Institutional branding makes fabricated citations feel more official, which makes them more dangerous. Keep verifying answers before you study from them.

It does not make other people's data yours. Copilot only surfaces organisational content "to which individual users have at least view permissions," which protects the university's files. It says nothing about the group chat transcript, the placement notes or your supervisor's unpublished draft that you were about to paste in. The privacy checklist for class materials still applies, and arguably applies harder now that the account has your real name attached to it.

Set it up properly in ten minutes

  1. Find your campus AI page. Search your university site for "ChatGPT Edu" or "Copilot" and read the FAQ, especially the monitoring and retention wording. This is the document that governs you, not anything in this article.
  2. Check whether training is mandatory. Several institutions gate access behind a short course and suspend accounts that skip it.
  3. Confirm you are signed in with the university account. Enterprise protections apply to the institutional login, not to your personal one in the same browser. If you cannot see your university name in the account menu, you are in the consumer product with none of the contract benefits.
  4. Learn where the delete button is. For Copilot, activity history is removable from the My Account portal at myaccount.microsoft.com; for ChatGPT Edu, delete individual chats or all chats from settings.
  5. Save your module's AI clause somewhere you will see it — the class AI policy checklist turns a vague paragraph into a decision you can actually apply.

Three prompts worth having on day one

Paste these into whichever account your university gave you. The first is the one to run before anything else.

I am going to paste the AI policy from my course handbook and one assignment brief. Do three things. 1) List exactly what is permitted, what is forbidden, and what is unclear. 2) For anything unclear, write the one-sentence question I should email my tutor. 3) Give me a short disclosure line I could include if I use AI in a permitted way. Do not guess at anything the text does not say — mark it as unclear instead. Here is the text: [PASTE]

Act as a tutor for [TOPIC] who never gives me the answer. Ask me one question at a time, starting from what I already know. When I get something wrong, tell me which specific idea I have confused and ask a follow-up that helps me spot it myself. When I get something right, make the next question harder. Keep going for ten questions, then summarise the two weakest points in my understanding.

Below is a paragraph from my notes. For each factual claim, tell me: is this something I could verify in my course materials, is it something you are inferring, or are you not confident about it? List anything I should check against a primary source before I revise from it. Do not add new facts. Here are the notes: [PASTE]

Building a full revision system on top of these is a separate job — the exam prep system with practice tests and flashcards and the guide to Socratic AI tutors both take the second prompt further.

FAQ

Can my university see my ChatGPT Edu conversations?

Not routinely, but the right is usually reserved. CU states plainly that it will not monitor individual users' interactions with ChatGPT Edu and collects only basic use statistics, and then adds that it retains the right to audit individual user interactions "in isolated and limited cases." The California State University system uses near-identical wording. So nobody is reading your chats over your shoulder, but they are not sealed either. Read your own campus FAQ, because the wording is what governs you.

Are my Microsoft Copilot chats at university private?

They are stored. Microsoft documentation says that when you interact with Copilot it stores the "content of interactions," meaning your prompt and the response, as your "Copilot activity history," and that admins can use Content search or Microsoft Purview to view and manage that stored data. Some campus IT pages say prompts are not saved, which describes one particular configuration rather than the licensed product. You can delete your own activity history from the My Account portal at myaccount.microsoft.com.

Does using the university AI account count as cheating?

The account is a licence, not a permission. Your assignment brief and your module policy still decide what is allowed, and they can be stricter than the university-wide position. CU puts it directly: nothing about the use of generative AI changes the foundational policy barring academic dishonesty. Treat a campus rollout as the university paying for the tool, not as your tutor approving its use on a specific piece of work.

Is the university version better than the free one?

The contract is better, and that is the main thing you gain. Your campus agreement typically prevents the vendor training its models on what you type, which the free consumer tiers do not promise by default. You may also get higher limits and access to newer models. The model itself is not more accurate: Microsoft notes that responses are not guaranteed to be 100% factual, so every citation and calculation still needs checking.

What should I not paste into my university AI account?

Other people's information and anything restricted by someone else. Group project chats, interview transcripts, medical or placement notes and unpublished work belonging to a supervisor are not yours to upload, whatever the contract says about training. The account being institutional protects the university from the vendor. It does not make you the owner of everyone else's data.

Bottom line

Claim the account — the contract behind it is genuinely better than what you had, and it costs you nothing. Then spend ten minutes on the three things that matter: read your campus FAQ rather than trusting a summary of it, find the delete control before you need it, and check your module policy separately from the university announcement. The licence answers the question of what you can access. It does not answer the question of what you are allowed to submit, and only one of those gets you in front of a panel.

Advertisement
Free download: Grab the one-page AI Study Safety Checklist — everything to check before you upload, trust, or submit anything involving AI.
Advertisement