top of page

Should You Tell Students When an AI Is Watching Their Progress?


There is something quietly unsettling about a system that knows more about a student's study habits than they do. Learning analytics platforms can now track when a learner opens a module, how long they linger on a page, how many attempts they make before getting a question right, and whether their engagement patterns suggest they are about to disengage entirely. The insight is genuinely valuable. The question institutions often skip is: does the student know any of this is happening?


This is not a hypothetical concern. AI-powered monitoring tools are being deployed across universities and online learning platforms at significant scale, often introduced through terms of service that few students read and fewer still understand. The conversation about student data privacy in education tends to settle quickly into legal compliance — GDPR in Europe, the Personal Data Protection Act (PDPA) in Singapore and across Southeast Asia, FERPA in the US. Meet the legal threshold, check the box, move on.


That framing misses something important. Transparency in AI monitoring is not just a legal obligation. It is a pedagogical one.

What the Law Actually Requires


The legal baseline is worth understanding clearly, because it is more demanding than many institutions realise.


Singapore's Personal Data Protection Commission issued updated Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems in March 2024, covering the use of personal data to train, test, and monitor AI models, as well as AI-driven recommendations or decisions about individuals (PDPC, 2024). For educational institutions in Singapore, this means that student data used to power learning analytics or early-alert systems falls squarely within PDPA obligations — collection must be for a notified purpose, and students must be informed of how their data is being used.


Across the region, similar frameworks are tightening. Malaysia's amended PDPA, in effect from mid-2025, moves closer to GDPR-level requirements (Future of Privacy Forum, 2024). Thailand, Indonesia, and Vietnam have each enacted data protection legislation in recent years, reflecting a regional trend toward stronger individual rights over personal data.


The minimum, then, is notification: tell students their data is being collected and explain the purpose. But notification is not the same as understanding — and understanding is where the real work begins.


A buried clause in an enrolment agreement is technically disclosure. It is not transparency. And the difference matters enormously in an educational context.


Research into learning analytics consent mechanisms has consistently found that students who genuinely understand how their data is being used respond differently — and better — than those who are simply subject to monitoring without comprehension. A 2019 model for informed consent in higher education learning analytics, still widely cited in current literature, argued that meaningful consent requires more than opt-in checkboxes: it requires students to understand what data is collected, how it informs decisions about them, and what recourse they have (Sclater & Mullan, International Journal of Educational Technology in Higher Education, 2019).


More recent research extends this argument to the age of generative AI. A 2024 arxiv preprint on human-centric explainable AI in education found that students who receive explanations of AI-generated feedback — not just the feedback itself — develop stronger metacognitive awareness and engage more productively with personalised learning systems (arxiv, 2024). In other words, the transparency itself becomes a teaching tool.


There is also a trust dimension that institutions underestimate. Predictive analytics and algorithmic profiling, when opaque, breed suspicion. Students who sense they are being monitored without understanding why often interpret AI flags — "you may be at risk of falling behind" — as surveillance rather than support. The result is disengagement, the very outcome the system was designed to prevent. The World Economic Forum's 2025 analysis of responsible AI in higher education makes this point plainly: institutions that move from policing AI use to partnering with students report stronger outcomes on both trust and academic integrity (WEF, 2025).

What "Transparency by Design" Looks Like


Transparency by design means building legibility into the system from the start — not as an afterthought, not as a legal disclaimer, but as a core feature of how AI monitoring tools are introduced and sustained.


This is distinct from what most institutions currently do. A 2025 review of institutional AI policies in higher education found that while many universities have released AI guidelines, these are frequently disjointed, hard to enforce, and quickly outdated (Azevedo, New Directions for Adult and Continuing Education, 2025). Transparency by design requires something more structural.


A responsible AI framework for learning analytics in higher education, developed by researchers in 2024, proposes that ethical obligations should be embedded across the full software development lifecycle — from data collection requirements through to ongoing monitoring and review (arxiv, 2024). For institutions deploying off-the-shelf tools, this means demanding that vendors meet the same standard, not just signing their data processing agreements and assuming compliance flows downstream.

A Proposed Framework: Four Elements


Institutions serious about transparency by design in AI monitoring should build around four concrete elements.


1. Plain-language data notices at point of use. Not in the privacy policy. Not in the enrolment handbook. At the moment a student first encounters a learning analytics dashboard or AI-driven feedback tool, they should receive a clear, brief explanation: what data is being collected, what the system does with it, and who has access. This should be integrated into the onboarding of any digital learning environment — a one-screen explainer, not a legal document.


2. Visible AI reasoning for any consequential output. When an AI system flags a student as at-risk, generates a personalised recommendation, or contributes to a grade, the student should be able to see the basis for that output. This does not require exposing model weights — it requires a human-readable rationale. "You are being recommended additional support resources because your quiz submission patterns over the last two weeks differ from your earlier engagement" is meaningful. A generic "based on your learning data" is not.


3. Meaningful consent, not just notice. Institutions should distinguish between data collection that is necessary for a service to function (where informed notice suffices) and uses that go beyond that — predictive profiling, data sharing with third parties, use in institutional research. The latter should require genuine opt-in consent, with no penalty for students who decline. This is already required under PDPA and GDPR frameworks; the gap is in implementation.


4. Regular student-facing reviews. Once a semester, students should be given access to a summary of the data held about them, an explanation of how it has been used, and a mechanism to raise concerns or correct inaccuracies. This is standard practice in corporate data governance. In education, it would also function as a data literacy exercise — helping students develop the skills to interrogate AI systems they will encounter throughout their careers.

The Bigger Picture


None of this diminishes the genuine value of AI monitoring in education. Early-alert systems, when implemented well, have real evidence behind them — identifying students who might otherwise quietly withdraw, enabling timely intervention, reducing equity gaps for students who lack informal support networks. A 2025 study in Nature Scientific Reports found that AI-based monitoring in student management systems meaningfully improved academic intervention outcomes when paired with human follow-through (Scientific Reports, 2025). The technology is not the problem.


The problem is the assumption that students are passive recipients of AI-driven support rather than active participants in it. When students understand how a system is reading their behaviour, they can engage with it deliberately — adjusting their study patterns, interpreting AI feedback critically, and developing the kind of reflexive AI literacy that higher education should be cultivating in the first place.


Platforms that take this seriously build it in from the start. Noodle Factory, for instance, operates under ISO 27001-aligned security standards and SOC 2 compliance, and takes an explicit position that student and institutional content remains owned by the institution — not repurposed or used outside the account. Its deployment model is structured around co-implementation with institutions rather than a licence handover, which means the questions of how data is used, who has access, and how students are informed are worked through with schools rather than left to them. That is not a complete answer to the transparency challenge — but it is the right architecture for one.


Transparency, in this framing, is not about giving students something to worry about. It is about giving them something to work with.


Institutions that treat AI monitoring as a background operation — something done to students rather than with them — are not just taking a legal risk. They are missing a pedagogical opportunity. The question is not really whether to tell students when an AI is watching their progress. The question is why we have waited this long to ask it.

Sources


bottom of page