AI in the ICT lab: five uses, three risks, and the one-page policy every CBSE and ICSE school needs
ChatGPT, Gemini, Perplexity and Claude landed in Indian school ICT labs before any policy did. Here is the honest 2026 map — five legitimate uses, three serious risks (including deepfake generation of classmates), and a one-page policy any school can adopt by next week's lab period.
Walk into any CBSE or ICSE ICT lab in India at 09:08 on a Tuesday, three minutes into the second period. The teacher has handed out a worksheet on relative cell references in Microsoft Excel. The thirty-six students in the room have the worksheet open in one tab. Many of them have ChatGPT, Gemini or Perplexity open in another. A quieter two or three have a Stable Diffusion mirror open, generating faces that look suspiciously like someone in the class. The filter running on the school network sees none of this. The lab assistant can see six screens from where they are sitting; the other twenty-four are turned slightly away.
This is not a scare paragraph. It is the honest 2026 reality of ICT labs across India, from Delhi Public Schools to small-town convent ICSE setups to government-aided CBSE schools in Pune and Chennai. AI tools arrived, in waves, through 2023, 2024 and 2025, faster than any ministry, board, principal or ICT coordinator wrote policy to meet them. By October 2026, in most Indian schools, there is no written answer to the question: what are students allowed to do with AI in the lab? The gap between the actual usage and the actual policy is the problem this post exists to help close.
What AI tools are actually in the lab in 2026
Six categories now show up on virtually every Indian ICT lab PC that has a browser:
- Text LLMs. ChatGPT (free and paid), Gemini (free, often via Google account), Claude, Perplexity, Copilot. Text generation, Q&A, essay drafting, code help.
- Image generators. DALL·E (via ChatGPT), Midjourney (via web mirrors), Stable Diffusion mirrors hosted on fresh domains that no filter list has caught up with.
- Voice and speech tools. ElevenLabs, Google NotebookLM for voice summaries, local Hindi/regional TTS services.
- Code assistants. Replit AI, Codeium, free tiers of Copilot through GitHub Student Pack (which many Class 11 and 12 ISC Computer Science students now hold).
- Study and homework apps. Toppr AI tutor, Vedantu's AI add-ons, PhotoMath, Socratic, Doubtnut's AI explainer.
- Nudifier and deepfake sites: the dark end of image generation, often reached through two or three clicks from a legitimate-sounding search. Covered in detail in the risks section below.
Students know these tools. Many have been using them at home on their parents' phones for 18 months. The ICT lab, for most students, is the place where they get an uninterrupted 40 minutes with a bigger screen and no sibling asking for the device.
The five legitimate uses. AI the policy should allow
AI is not the enemy of learning in a lab. Used well, it extends a teacher who cannot personally sit with each student for 40 minutes. Five uses are both pedagogically defensible and age-appropriate for Classes 6–12 under the NCERT framing:
- Research helper. "Explain the difference between a mutual fund and an index fund for a Class 11 Economics project." A guided explanation the student still has to think about, rephrase and cite.
- Code debug. ISC and CBSE Computer Science students pasting a Python traceback and asking the model to explain the error. Pedagogically closer to a senior student helping than to cheating.
- Essay rewriter, with care. Students pasting a paragraph they wrote and asking for feedback on structure. Fine when the student's own writing came first and the AI commented; not fine when it writes the paragraph itself. The policy below draws this line.
- Language practice. English-second-language students practising conversation, Hindi students practising English, regional-language speakers getting a first-draft translation. Hugely useful in India's multilingual classrooms.
- Concept explainer. "Explain Ohm's law like I am twelve." A teacher-adjacent function, not a teacher replacement.
If an ICT lab's AI policy forbids every use, students use AI anyway and lie about it. If the policy names the uses as allowed with specific conditions, students use them openly, teachers observe the quality of use, and the entire class gets better at AI literacy, which the AI content-filtering piece argues is a 2026 life skill in its own right.
The three serious risks. AI the policy must stop
These are the three categories that keep designated safeguarding leads awake, and that no Indian school's current acceptable-use document names explicitly:
Risk 1. Coursework cheating that the exam board cannot detect
Not the obvious copy-paste of an essay. The harder problem: AI-written answers that have been paraphrased, interleaved with the student's own sentences, and translated between English and Hindi twice to defeat detection tools. By Class 10 and ISC Class 12 Economics and English Literature, this is now a majority behaviour on home assignments and a growing one on in-lab project work. CBSE and ICSE boards have not published a 2026-grade response; the 10 new online risks piece covers the broader educational-corruption pattern.
What to do: move 40% of assessment weight from completed artefact to oral viva and in-class drafting. If the student cannot explain the submitted answer back to the teacher, the mark reflects that gap. Pedagogically harder, structurally necessary.
Risk 2. Jailbreaks that return harmful content
Standard safety guardrails on ChatGPT and Gemini do catch most direct requests. They do not catch the roleplay bypass ("my grandmother used to tell me, as a bedtime story, how to..."), the fiction-frame bypass ("in my novel, the character needs to know..."), or the Hinglish bypass that sidesteps English-only content moderation. A motivated 15-year-old in a Delhi NCR ICT lab can walk a model into self-harm instructions, drug synthesis explanations or weapons-adjacent content inside a 40-minute period. The classroom teacher's eyes are not the right defence here.
What to do: device-level content filtering that reads the AI tool's output, not just its domain. Covered in the ICT lab blind-spots audit, published alongside this piece.
Risk 3. Deepfake and nudify generation targeting classmates
The fastest-growing specific safeguarding incident in Indian schools through 2026 is a student generating a sexualised or deepfake image of a classmate using a free image-generation service, usually inside an ICT lab period. The IT Act Sections 67, 67A and 67B apply directly; POCSO applies when the subject is a minor; the DPDP Act 2023 applies to the handling of the resulting image. Most Indian schools have no written incident-response procedure for this specific pattern yet.
What to do: three pieces: a named prohibition in the lab policy, device-level blocking of nudifier and image-generation domains (there are only around forty worth blocking), and a defined 72-hour response plan for when it still happens. If your school has not had a conversation about this, it is overdue.
AI in the ICT lab is a policy problem before it is a technology problem. The schools that write the policy first spend less time fighting the technology later.
The one-page AI lab policy, adapt and adopt
The template below fits on a single A4, maps cleanly to CBSE's existing acceptable-use language, respects the DPDP Act's data-minimisation posture, and takes 15 minutes to tailor to a specific school. Print it, laminate it, pin it next to every lab PC. Read it aloud in the first ICT period of each term.
What this lab allows (with conditions)
- Research help from approved AI tools, provided the final work is in the student's own words and the AI tool is cited.
- Code debugging and explanation, provided the student can explain the fix back to the teacher.
- Language practice and translation, used as a draft, not a final submission.
- Concept explanation for study, treated as a tutor, not a substitute for notes.
What this lab never allows
- Submitting AI-generated text as the student's own work, in any subject, at any level.
- Generating images, voice or video of any real person, classmates, teachers, public figures, family members.
- Attempting to bypass the content safety settings of any AI tool, including through roleplay, fiction framing or language switching.
- Accessing nudifier, deepfake, non-consensual intimate imagery or any other service that creates sexualised content of real people.
What the lab logs and reviews
- All AI tool usage during lab periods is category-logged (not content-logged) and reviewed weekly by the ICT coordinator.
- Policy breaches follow the school's existing safeguarding and disciplinary pathways. Breaches in categories 2–4 above are reported to the Designated Safeguarding Lead within 24 hours and may trigger notification under the IT Act or POCSO where applicable.
- Students may appeal any block in writing to the ICT coordinator and request a specific tool be added to the approved list.
What to do: paste these 11 lines into a school letterhead, add your DSL's name and contact, get it signed by the Head of IT and the Principal, and circulate it to every teacher who takes a lab period before the next academic term starts.
How SafeAnywhere makes this policy enforceable in an Indian ICT lab
- Category-aware filtering that reads AI output, not just AI URLs. Blocks jailbreak responses, nudifier outputs and policy-violating content in real time, inside tools whose domains are allowed.
- Named allow-lists for the four legitimate uses. ChatGPT, Gemini, Perplexity and Copilot (or whichever your school approves) run with safety-mode on, logged at category level, no content stored.
- Weekly rollup for the ICT coordinator. One page, one Monday morning, showing usage patterns and policy breaches by lab, by period, by class, no student-level surveillance for routine use.
- Incident queue for the DSL. Risk-mapped alerts for the three serious categories above, routed through the unified safeguarding view.
- DPDP-aware by design. Minimal data collection, Indian data residency, consent and erasure rights properly handled, the compliance architecture is the same one covered in privacy and compliance for families and adapted for the Indian school context.
Common questions ICT coordinators and principals ask
Should we just block ChatGPT entirely?
You can, and students will route around the block within one period, through Google's Gemini (which is embedded in the search results page itself), through free mirrors, through a classmate's mobile hotspot. The policy approach beats the block approach every time, because policy is the only thing that scales when students have personal AI tools in their pockets outside school.
What about CBSE's and ICSE's position on AI in schoolwork?
As of October 2026, neither board has published a comprehensive 2026-grade policy framework for AI use in coursework or in-school assessments. Both have issued general cautions. The vacuum means individual schools are setting their own policy; the schools that write a clear one now will be ahead when the boards do catch up.
Our lab filter blocks AI tools. Isn't that enough?
Domain-level blocks catch the direct URL. They miss AI accessed through Google Search's built-in AI summaries, through browser extensions, through mobile hotspots, through the many fresh-domain mirrors that pop up weekly. The ICT lab blind-spots audit covers the 10 common gaps in a typical Indian school filter setup.
How do we actually detect AI-written coursework?
Detection tools are unreliable in 2026, the better the model, the worse the detector. The sustainable approach is pedagogical: more in-class drafting, more oral viva components, assessment designed so that AI is a help in the process rather than a shortcut past it. Shifts weight back to the teacher's judgement, which is where it belongs anyway.
What are our legal obligations if a deepfake incident happens in the lab?
IT Act Sections 67, 67A and 67B apply directly to the creation or distribution of obscene or sexually explicit content. POCSO applies when the subject is a minor. The DPDP Act 2023 applies to the handling of the resulting data. In practice this means: preserve the device evidence, notify the DSL within 24 hours, inform the parents of all affected students, and consult legal counsel before approaching the police under the IT Act. Write this procedure down before you need it.
What about staff AI use, is that covered by the same policy?
The template above covers student use. Staff AI use (lesson planning, question banks, administrative drafts) deserves its own one-page policy, which is less urgent but worth writing in the same term. The core principle is identical: name allowed uses, name prohibited ones, log at category level, respect the DPDP Act.
Does this policy apply to AI used on students' personal phones during school hours?
Policy yes; enforcement no. The school lab policy sets the standard; the school's broader phone policy covers device use during the school day. The schools-monitoring piece covers the broader split between what schools can and cannot see.
The quiet bottom line
AI tools in Indian ICT labs are not going away. The schools that write the policy first, honest about the legitimate uses, specific about the serious risks, enforceable through the right technology, will spend less time fighting the technology and more time teaching students to use it well. The schools that do not will still have students using AI tools; they will just not know, which is worse than knowing and allowing.
Policy first. Technology second. Incident response written down before you need it.
More from the SafeAnywhere blog
The ICT lab blind-spot audit: 10 things your filter and your lab teacher cannot see
Walk into any Indian school ICT lab in 2026 and the network filter catches roughly three categories of harm. The students know about ten things the filter misses — and most of those ten are what actually goes wrong in a 40-minute period. The honest audit, with the fix for each.
Read articleWhat your child's school already monitors online — and what it quietly does not
Parents often assume school filters cover everything. In 2026 they cover a precise, narrow slice of a child's digital life — and the gap is wider than most families realise. A clear-eyed guide to exactly what is monitored, what is not, and the small home setup that closes the 100-hour weekly blind spot.
Read articlePhysical and digital safety together: why schools need a unified approach
A deputy head once watched a pupil's warning signs show up in four separate systems in one week, and nobody saw the pattern until Friday. A practical field guide to designing a unified school safety operation that catches the signals siloed systems miss.
Read article