Info Gov

The University of Southampton is to cease its use of the Turnitin plagiarism-detection and academic-integrity service over proposed changes to its end user agreement that would allow it to use student submissions to train AI services.

In a statement, the university said that would not renew its contract with Turnitin beyond the end of the 2026/27 academic year and will begin phasing out the service ahead of the contract’s expiry.

A University of Southampton spokesperson said: “We have a responsibility to protect the data, intellectual property and academic work of our students and the University.

“While we understand Turnitin has postponed changes to the end user license agreement that would have allowed it to use student submissions to train AI services, it has not fully clarified what future changes may be imposed.

“As a result, we have decided not to renew our contract beyond the end of the 2026/27 academic year and will begin phasing out the use of this service immediately.

“We will continue to evaluate other options to ensure that academic integrity standards are maintained.”

Turnitin software compares the text against a vast index of web pages, published journals and, crucially, every other student paper previously submitted to Turnitin anywhere in the world. It returns a "similarity report" highlighting matching passages with a percentage score, which markers then interpret; a high score is not itself proof of plagiarism, since quotations and bibliographies match too.

Since 2023 it has also offered an AI-writing detection feature that estimates how much of a submission was machine-generated. It is owned by Turnitin LLC, a US company.

"We do not use customer or student work to train the AI assistant within Turnitin Clarity,” a spokesperson for Turnitin told Info-Gov.

“We may use anonymised student submissions to improve our detection and assessment tools. We train a machine learning classification model for our AI detection tool that identifies likely AI-written text.

“Classifier models categorise or label existing data, returning a numeric prediction about AI writing. They do not write, rewrite, or produce text like generative AI models. We do not train any generative AI models. Further, we do not sell any student data to third-parties, including third-party LLMs. You can learn more about our approach to building AI tools in our AI design principles."

"We recognise the great responsibility that comes with our customers’ trust to protect their data, which we have prioritised for nearly 30 years. We acknowledge that the introduction of AI in education raised new questions and concerns about data use and privacy. We are committed to being transparent around AI product design and data use.”

"As Turnitin has expanded the in-product use of AI, and as we assist customers in navigating their own AI use, our institutional agreements were updated to reflect current data practices. To give us time to discuss any changes with customers, we are not updating it any earlier than September 1, 2027.

Also in this section

Sep 23, 2026

Hospital trust reports personal data breach to ICO after reused database script wipes maternity access logs

Nottingham University Hospitals NHS Trust has reported a personal data breach to the Information Commissioner's Office after a script intended to copy a radiotherapy database was run against its legacy maternity system instead, overwriting records for women and babies treated between September 2011 and November 2022 and permanently destroying most of the audit trail showing who accessed them.
Sep 22, 2026

Section 166 offers no route to challenge ICO decisions not to investigate under new complaints framework, tribunal rules

The First-tier Tribunal has struck out an application seeking to force the Information Commissioner to investigate a subject access complaint, in a decision that confirms the ICO's harm-based complaints prioritisation framework can dispose of a complaint without any engagement with the data controller and still count as an outcome beyond the reach of section 166 of the Data Protection Act 2018.
Sep 11, 2026

ICO opens investigation into Police Scotland's handling of subject access requests

The Information Commissioner's Office has opened an investigation into Police Scotland's handling of subject access requests, seeking to establish whether the force has failed, or is failing, to comply with its obligations under Articles 12 and 15 of the UK GDPR and section 45 of the Data Protection Act 2018, including responding to requests within the statutory timescale.

InfoGov Masthead Newsletter 800