What the record is — and isn't
Does Phloem mark or grade student work?
No — and it never will. Phloem doesn't score writing, grade it, or judge its quality. The report describes how a document came to be: which sentences were typed, which were pasted in, which came from an AI suggestion taken whole — and which came from a suggestion the writer read, thought about, and rewrote in her own words. What a teacher makes of that description is the teacher's call, within the context of everything they already know about the student.
The Ministry of Education's guidance on AI and marking puts its first principle this way: "AI must support — not replace — teachers' professional judgements." That principle is Phloem's design premise, not a constraint it works around. The report gives a teacher more to exercise judgement on, and takes none of it away.
Marking work with AI tools, Ministry of Education / Te Poutāhū Curriculum Centre, October 2025 (education.govt.nz).
Is this an AI detector? Why not just use one?
No. A detector reads a finished text and guesses where it came from. Phloem doesn't guess, because it doesn't need to: the record was kept while the writing happened, event by event, in a sealed log the writer owns.
The guessing turns out to matter. In a study by Perkins and colleagues (samples tested September–October 2023, published March 2024), seven major detectors — Turnitin, GPTZero and Copyleaks among them — averaged 39.5% accuracy on unmodified AI-generated text. When the text was lightly disguised, by asking the model to add spelling errors or vary its sentence lengths, accuracy fell to 22%. The errors ran in both directions: human-written control samples were correctly identified only 67% of the time, and 15% of all results falsely accused a human writer. The authors' conclusion was that these tools "cannot currently be recommended for determining whether violations of academic integrity have occurred." They are careful to say the results are a snapshot and the tools keep evolving — so are we, and the date above is there so you can weigh it.
Those false accusations don't land evenly. Research the study builds on found detectors misread the writing of non-native English speakers as AI-generated more than half the time — a finding some detector vendors dispute, which is exactly the kind of argument a student can't win from inside it. The honest writer accused by a percentage score has no way to answer. A writer with a Phloem record does: she hands it over, sealed, and says — here's how it came to be.
None of this replaces your plagiarism checker. It runs over the finished text exactly as it did yesterday; Phloem neither replaces it nor obstructs it.
Perkins, Roe et al., GenAI Detection Tools, Adversarial Techniques and Implications for Inclusivity in Higher Education (preprint, March 2024) · Liang et al., GPT detectors are biased against non-native English writers (2023; contested by Turnitin and GPTZero in their own published research).
Isn't this just surveillance with better manners?
Opposite polarity. Surveillance takes evidence from the student; this is evidence she offers. The record is hers — shared by her consent. She keeps her own copy.
Although, it is fair to say that the moment an assignment brief says "attach your Phloem report", consent becomes compliance. We don't pretend otherwise. What survives that moment is still hers — her own copy of the record, and a description rather than a score.
Couldn't a student pass copied work off as her own typing?
Yes — by retyping it, and the report will not catch her. The report never uses the word "original", because it can't know: it records typed, pasted, offered-and-taken, offered-and-declined — facts about how the document came to be, never certificates of where a sentence was born. I found the limit myself, writing a test essay with Wikipedia open in the next window: my transcription went down as my own typing, because it was my own typing. No tool can see the second screen — including the keystroke-watchers whose scores imply they can.
What the record does close off is the cheap version. A paste wears its own mark. AI help is on the ledger along with what she did about it. The deception that remains costs her hours of reading and retyping at human speed — which is, not coincidentally, the very time-on-task the assignment was asking for.
But she could type it all herself and learn nothing.
So could I, forty years ago — cram for three days, write the essay, lose ninety-five percent of it within the week. The finished paper has never proved learning; it only ever proved its own existence. What's changed is where the facts live: a date or a formula is seconds away, so education has moved to what it was always really about — how to think, how to learn, how to work with sources.
A truthful account of the process serves that; what the margin offered, what she took, what she declined, what she reworked in her own words. It isn't proof of learning — nothing is — but it is more than the finished paper ever told you.
The writing, the law, and the machine
Is students' writing used to train the AI?
No. The margin runs on Anthropic's Claude through their commercial API, and the Commercial Terms say it in one clause: "Anthropic may not train models on Customer Content from Services." We can put that clause in front of you.
The Ministry of Education's own guidance warns about precisely this: many AI tools reuse what's typed into them as training data, and putting student work into a tool that isn't information-protected "may be in breach of NZ Privacy Law" (October 2025). That warning is the right test to apply — to Phloem as much as to anything else. It is the test Phloem was built to pass: the terms forbid training on the writing, and the data-processing agreement that governs it is a document we can hand you, not a reassurance.
Anthropic Commercial Terms of Service §B and the Data Processing Addendum incorporated into them, as read August 2026 · Marking work with AI tools, Ministry of Education, October 2025.
The writing goes to a model in the United States. Doesn't that need consent?
When the writer summons the margin, the relevant writing goes to Anthropic's servers in the United States, under the terms above.
In law, that is processing, not disclosure. Anthropic processes the information on the school's behalf, so under section 11 of the Privacy Act 2020 the school never stops holding it — which makes this a security question under IPP 5, not a cross-border disclosure under IPP 12. That isn't our reading alone: it's the Privacy Commissioner's published position.
Privacy Act 2020, s 11 · OPC — Sending information overseas: an agency using a cloud provider remains responsible for the information; holding under IPP 5, not disclosure under IPP 12.
If something goes wrong, is that on you or on the school?
On the school — the information never leaves the school's hands legally, the school carries the responsibility, including breach notification. Which is exactly why a school should hold its providers to a contract that makes that safe, rather than to a reassurance.
Can a student have her record deleted?
Anything a student writes into Phloem belongs to the student, and stays with the student until she chooses to share a report. There is no copy held anywhere else for her to ask deleted. When she does choose to share one, the copy she hands over is the school's to hold, and any privacy obligations that come with it rest with the school from that moment — governed by the school's own rules, not ours.
What if a student writes about somebody else — a sibling, a teacher?
That's IPP 3A, which came into force on 1 May 2026 — new law about collecting personal information indirectly. Our reading is that the exceptions carry most of the school writing case, but it is new law and our reading is marked as exactly that: a school's privacy officer should reach their own view rather than take ours.
Privacy Act 2020, IPP 3A, in force 1 May 2026.
Running it in a school
Do we have to install anything? Does IT need to approve it?
No. The student writes, exports her report — one file, the readable report carrying its own sealed record — and attaches it to the assignment she already submits. Nothing installed, no tenant administration, no procurement, no new account for the school to govern.
Are you a Ministry-approved vendor?
No, and we're not asking to be. The Ministry holds cloud agreements with Microsoft and Google; Phloem isn't on that list, and that is precisely why the pilot attaches a file to an assignment you already run instead of asking the school to adopt a new cloud service holding student writing. The report travels inside the systems you've already approved.
Has a lawyer reviewed any of this?
No. Everything on this page is our own reading of published guidance and primary sources, written up with the gaps marked in the documents themselves. We'd rather hand you that than a confident answer nobody has checked. The two working documents behind these answers — the Privacy Act analysis and the school-as-agency analysis — exist, are dated, and mark what we don't know; if fifteen minutes with them would help your privacy officer, write and we'll send them.
What's your data-breach process?
Owed, not built. Anthropic is contractually obliged to notify us of a breach; nothing yet obliges us to notify a school. Meanwhile it is the school, as the agency holding the information, that carries the legal duty to report a serious privacy breach to the Privacy Commissioner and the people affected — and the Commissioner's published expectation is notification within 72 hours of learning of it. A breach-notification agreement is a short document, and it's the first one we'd sign before a single student writes under a school's roof.
What we haven't done yet
- No practitioner has reviewed the legal analysis. It is our own reading of published guidance.
- No breach process and no school agreement exist yet. Both are short documents, both owed before any student writes in a school pilot.
- The sources are dated, deliberately. Terms of service and government guidance change without announcing themselves; every claim above says when we read it, so it can be checked rather than trusted.