Short answer
It depends on what the material is, whether it identifies you, what your university’s policies and agreements say, and whether an appropriate legal basis exists. There is no blanket rule that lets a university use your coursework, recordings or messages to train or test an artificial intelligence system without regard to your rights. Two separate legal frameworks are usually engaged at the same time: data protection law, which protects you as an identifiable individual, and intellectual property law, which protects your work as a creation. On top of those sit the university’s own contractual terms, IP policy, privacy notices and academic regulations.
Data protection: personal data in your work, recordings and messages
If the material contains information about you as an identifiable person, it is your personal data and is protected by the UK GDPR and the Data Protection Act 2018. Recordings of your voice or image, messages you have sent, and coursework that identifies you will normally count as personal data. Some categories, such as anything revealing health, ethnicity, religion, sexual orientation or biometric identifiers, are special category data with stronger protection.
The Information Commissioner’s Office treats using personal data to train or test an AI system as a distinct processing operation that needs its own lawful basis. The university must identify a valid basis for that specific use, for example consent, legitimate interests, or the performance of a task in the public interest, and it cannot simply reuse a basis it relied on for a different original purpose. It must also comply with the fairness and transparency principles, which means it should have told you at the point of collection, or before this new use, that your data might be used in this way. If it wants to use special category data, it needs an additional condition under Article 9, and consent is often the realistic route there.
Purpose limitation is central. Data you gave for one purpose, such as submitting an assessment, attending a recorded lecture or seminar, or messaging staff through a learning platform, cannot automatically be repurposed for AI training. The university must show the new purpose is compatible with the original one or obtain a fresh lawful basis. In practice, universities that do this properly update their privacy notices, carry out a Data Protection Impact Assessment, and often anonymise or pseudonymise data so it no longer identifies individuals. If the data is genuinely and irreversibly anonymised so that no one can be identified, data protection law stops applying to that anonymised dataset, which is one common lawful route universities take.
Intellectual property: who owns your work
Copyright in original work such as essays, dissertations, code, designs, images and creative pieces normally belongs to you as the author, unless you created it as an employee in the course of employment, or you have assigned or licensed it to the university. Many universities include in their student contract, IP policy or assessment regulations a licence allowing them to use, copy, store and process submitted work for specified purposes such as marking, quality assurance, plagiarism detection and academic administration. Whether that licence stretches to AI training or testing depends on the exact wording. A narrow licence limited to assessment and administration would not obviously cover feeding your work into a machine learning model, whereas a broadly drafted licence might.
You should read the specific terms you agreed to on enrolment and any IP policy referenced in them. If the university wants to use your copyright work for something outside the scope of the licence you granted, it needs your permission or a further licence.
Recordings of you
Recordings raise both issues at once. A recording of you speaking or on camera is your personal data, and any original spoken content you produced can also attract copyright and performers’ rights. Universities usually record lectures, seminars and online sessions under a specific recording policy with its own stated purposes, commonly teaching, revision and accessibility. Using those recordings to build or test an AI product is a different purpose and would generally require its own lawful basis and, for special category content or voice biometrics, likely explicit consent.
Messages and communications
Messages you send through university email, virtual learning environments, chat tools or support services are personal data, and the content may also be confidential. Reusing message content to train an AI system is again a separate processing purpose. The fact the university holds the messages for administration or support does not entitle it to mine them for model development without an appropriate basis and transparency. Confidential or sensitive exchanges, for example with counselling, wellbeing or disability services, attract particularly strong protection.
Your rights and how to exercise them
You have a set of practical rights you can use.
1. Right to be informed. The university must tell you, usually through a privacy notice, what data it uses, for what purposes and on what lawful basis. You can ask directly and request to see the relevant privacy notice and any AI-specific policy.
2. Right of access. You can make a subject access request to find out what personal data the university holds about you and how it is being used, including for AI purposes.
3. Right to object and to withdraw consent. If the processing relies on legitimate interests, you can object, and the university must stop unless it shows compelling grounds. If it relies on consent, you can withdraw it at any time, and consent must have been freely given, specific and informed to be valid in the first place. Bundled or pre-ticked consent is not valid.
4. Rights around automated decisions. If an AI system makes or heavily influences a decision that produces legal or similarly significant effects on you, you have additional rights under Article 22, including the right to human involvement.
Practical next steps
Start by gathering the documents that govern your relationship with the university: your enrolment or student contract, the IP or copyright policy, the student privacy notice, any AI or data ethics policy, and any recording policy. These will usually answer whether the university claims a right to do this and on what basis.
Ask the university’s data protection officer, in writing, three specific questions: what personal data of yours is being used to train or test any AI system, what the lawful basis is for that specific use, and whether the data is anonymised before use. A clear written enquiry often resolves the matter, because a properly run scheme will have documented answers ready.
If you are content in principle but want limits, you can ask that your data be anonymised, excluded from training datasets, or that you be given an opt-out. Many universities operate opt-outs for lecture capture and similar uses.
If you object to a use you consider unlawful, put your objection or consent withdrawal in writing and keep a copy. If the university continues without a satisfactory explanation, you can raise a formal complaint through its internal complaints procedure, and then escalate to the Information Commissioner’s Office for the data protection aspects. For copyright misuse, the remedy is a civil matter and you would raise it as a breach of the licence terms or infringement, though internal resolution is almost always the sensible first route.
Where the answer could change
The outcome turns heavily on facts I do not have. If the data is fully anonymised, most data protection objections fall away. If your student contract contains a broad IP licence covering research and system development, the copyright position shifts in the university’s favour. If the AI use is confined to internal testing on anonymised data rather than building a product or making decisions about students, the risk profile is lower. Conversely, if the material includes special category data, confidential support communications, or biometric voice or facial data, the protections are stronger and explicit consent is far more likely to be required. It is also worth keeping in mind an ordinary explanation may apply: some universities use AI-assisted tools purely for plagiarism detection or marking support under existing, disclosed policies, which is different from using your work as training data for a new model. Confirming exactly what the university is doing is the key first step before treating it as any kind of wrongdoing.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
How do we ensure lawfulness in AI? | ICOico.org.ukUse of personal data in AI models policy (UK and EU)kent.ac.ukIntelligence (AI)imperial.ac.ukHow do we ensure individual rights in our AI systems?ico.org.ukKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.