Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - When Innovation Meets Education: Caution Before Celebrating ‘OpenAI for Greece’
Articles Artificial Intelligence Future, Trends and Insight Security

When Innovation Meets Education: Caution Before Celebrating ‘OpenAI for Greece’

Anastasios ArampatzisBy Anastasios ArampatzisSeptember 10, 2025Updated:September 10, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
OpenAI for Greece
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Generative AI (GenAI) has clear potential in low-risk contexts—such as enhancing productivity, supporting research, and aiding professional workflows. Where it can serve as a powerful, time-saving tool.

But this begins to change dramatically when we enter high-risk arenas, particularly education, where minors are involved and formative learning, trust, and their rights need safeguarding. Any steps must be firmly anchored in the rule of law, regulatory compliance, and rigorous oversight—not wishful thinking or classical rhetoric.

The “OpenAI for Greece” rollout: groundbreaking or reckless?

On 5 September 2025, the Greek government formally inked a Memorandum of Understanding with OpenAI to pilot ChatGPT Edu in 20 secondary schools, alongside an AI-accelerator program for local startups.

In promotional remarks, OpenAI’s Chris Lehane evoked Greece’s legacy as the cradle of Western thought, citing “from Plato’s Academy to Aristotle’s Lyceum” as justification for introducing this untested tool into public education.

While the classical references are symbolic, they cannot substitute for the due diligence required when children’s development is involved.

Accountability, transparency, and children’s rights

Greece is a party to the UN Convention on the Rights of the Child. Article 12 obliges states to consult children, meaningfully consider their views when policies affect them, and conduct Child Rights Impact Assessments (CRIA). Before deploying GenAI in schools, the state should have conducted and published:

  • A clear Child Rights Impact Assessment.
  • A Data Protection Impact Assessment (DPIA) under GDPR.
  • Transparent information about participation rights, oversight, and grievance mechanisms for parents, students, and educators.

However, until the time I write this article, we have seen no evidence of this crucial documentation.

Data-driven oversight, not slogans, must come first.

The elephant in the room: OpenAI’s regulatory track record

This is no mere hypothetical worry. In December 2024, Italy’s data protection authority (Garante) fined OpenAI €15 million for processing personal data without a proper legal basis, violating transparency principles, failing to disclose a March 2023 data breach, and lacking age verification to protect minors. OpenAI now faces regulators worldwide who demand absolute compliance with regulatory requirements.

What measures will Greek authorities take to prevent similar mistakes from occurring in Greece? And how will students and parents respond if they discover that the tools introduced into classrooms fail to fully protect children’s rights?

Is this pilot building on oversight or ignoring it?

Positioning high-risk tools as a pilot may risk repeating past EdTech missteps, where untested systems were introduced directly into classrooms. As Dr. Ioanna Noula, a childhood and education expert, clearly says, education cannot be a field trial. We must demand:

  • Evidence of regulatory compliance under GDPR and the upcoming EU AI Act—including DPIA and child-rights assessments where applicable.
  • Clear protocols for human oversight: Are educators trained to detect hallucinations, biases, and psychological risks? What fallback exists when ChatGPT fails or misleads?
  • Independent oversight and audits are assessing early results, not glossy PR.

It is disheartening that the government appears not to have learned from past missteps—when the Greek DPA “identified significant violations of legislation on personal data protection” during the WebEx rollout to support e-learning during the pandemic. Once again, and quite ironically, it was our children who were placed at the center of experimentation.

That episode highlighted the dangers of rushing untested digital solutions into classrooms without proper safeguards. The current initiative raises concerns that similar challenges could arise again.

Contradiction of values: Protecting minors vs exposing to bias and hallucinations

As a society, we rightfully strive to shield minors from harmful online content—hate, disinformation, and explicit material. The Greek government had heavily advertised Kids Wallet over the previous months as a step to protect children from online risks, and they seem to have led the introduction of age verification across all platforms.

Yet, by introducing GenAI into classrooms without safeguards, we risk hallucinations, embedded biases, and misinformation. This tension isn’t just regrettable—it’s contradictory.

If we don’t equip teachers and students to question AI outputs critically, we may be enabling the very problems we aim to prevent.

Where is the digital and data-sovereignty angle?

The European Union champions digital and data sovereignty. Digital sovereignty and privacy are critical—especially for minors in public education.

However, if ChatGPT Edu operates under a U.S.-based provider, student data—even if stored in Europe—may still be subject to U.S. law enforcement requests under the CLOUD Act. The law compels U.S. companies to disclose data irrespective of location, and no storage location can completely insulate against such access.

Moreover, a thriving European AI ecosystem offers more sovereign, privacy-minded alternatives. Companies such as Mistral AI deliver generative AI in line with European values and regulations.

Did the government explore these European options? If not, why endorse a U.S. model vulnerable under U.S. jurisdiction instead of nurturing homegrown or European AI that better supports digital and data sovereignty?

Conclusion: Respect for innovation, respect for citizens

Let me be clear: I believe generative AI can enhance education—but only under the right conditions. Low-risk support tools are welcome; curriculum design and teacher productivity are valid use cases.

But deploying ChatGPT Edu in schools without visible impact assessments, data-sovereignty clarity, or mechanisms to protect and inform minors crosses into experimenting on children. That is a line that must not be crossed.

Performance optics such as celebratory emojis, nostalgic references, and AI as “the calculator of our time,” should not substitute for transparency and accountability. Transparency isn’t optional; it’s the cure to techno-utopianism.

If Greece wants to be a pioneer, authentic leadership means leading with caution, evidence, and ethics, not nostalgia and hype. Let’s insist on accountability, protection of minors, and real oversight before we applaud.

Anastasios Arampatzis
Anastasios Arampatzis

Anastasios Arampatzis is a cybersecurity content strategist, writer, and consultant with expertise in cybersecurity, digital identity, and regulatory compliance. Tassos has a strong background in creating thought leadership content, marketing materials, and strategic communications tailored to CISOs, security professionals, and business leaders. He has contributed to various cybersecurity publications and collaborates with organizations to develop compelling, insightful content that addresses industry challenges. He is a privacy advocate and a member of the ISC2 Hellenic Chapter. Before joining Bora, Tassos was an Hellenic Air Force Officer with a solid background on IT and Infosec.

  • Anastasios Arampatzis
    The quiet revolt: what the world happiness report 2026 tells security professionals
  • Anastasios Arampatzis
    Cybersecurity and the Power of Words: Why Security Must Be in Our DNA
  • Anastasios Arampatzis
    Have You Read the F***ing Policy?
  • Anastasios Arampatzis
    Cybersecurity’s Greatest Threat Isn’t AI—It’s Us

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read

AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

June 19, 20265 Mins Read

From AI hype to operational reality: A practitioner’s framework for securing agentic systems

June 5, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}