How Skolkoll uses AI

Where AI is actually used on Skolkoll, what controls are in place — and, just as importantly, what the AI does not do. We describe only what is actually built.

Skolkoll uses AI in a few, well-defined places — chiefly the assistantKollen, but also to stylise school images and as internal drafting aids behind the scenes. Journalist email is instead handled manually and is not part of the AI flow.The AI never sets any published numbers. Data extracted from documents requires a human decision before use. The former AI-assisted support-triage and private Desk-note pilot is retired and not active. For school images the human review comes before the model: editors approve the source image, licence and absence of identifiable people, after which stylisation and display are automatic. Kollen is an AI assistant you actively choose to talk to and that is clearly labelled as AI. It receives Skolkoll source data as context, but a language model generates the response and may therefore make mistakes — always verify important information. This page lists every place openly, what safeguards exist and where the limits are. We would rather understate than overstate: a control that is not built is not listed here, and a place where we use AI is not hidden away.

1. Where we use AI

Kollen — the assistant that answers questions about schools

Kollen is an AI-based chat for questions about a school or school statistics in general. A legal stop applies to new requests to Anthropic while evidence of the processing country is missing. The code stops the request when the evidence is missing, but we have not yet confirmed that this block is deployed and working in the production environment; this page therefore does not claim that the active production instance is technically paused. The provider states storage in the United States and selected processing locations in Europe, Asia and Australia but does not publish a complete country list. Before the feature may be used, dated provider/account evidence must show that processing outside the EEA is limited to the United States, covered by the DPF or SCCs with a country- and recipient-specific TIA, and we must have confirmed that the block is deployed in the production environment. Another country requires a new code and annex review before any request. Once both conditions have passed, the question and relevant page context are sent to Anthropic through its Claude API; the model is Claude (Sonnet). Before the chat starts, you are shown processing information and the instruction not to enter private or sensitive data. Processing relies on legitimate interest (Article 6(1)(f) GDPR) underKollen LIA version 1.3, but that legal basis does not replace the requirement for valid, dated evidence of the processing country and transfer safeguard. The feature does not require a blanket ZDR agreement.

When Kollen is legally approved and we have confirmed that the block in the production environment permits the flow, Anthropic processes the messages as Skolkoll's direct data processor. For commercial API services, Anthropic states that inputs and outputs are normally deleted within 30 days. Material flagged for Usage Policy violations may be retained for up to two years and related trust-and-safety classification scores for up to seven years; legal requirements may require longer retention. API content is not used for model training unless Skolkoll explicitly opts in or submits feedback. Skolkoll does not write message content to its server-side audit log or operational database. See alsoAnthropic's current retention description, the privacy policy andData protection and subprocessors.

School images — source material is human-reviewed before automatic stylisation

The image at the top of a school page is not a photograph of the school but anAI-stylised illustration in a chalkboard style. The source — often a façade photo — is sent to an image model at OpenAI that transforms it into the stylised version; the image is processed under OpenAI's own safety and content policies. The source material is reviewed before model processing: an editor verifies the licence/rights basis and that the image contains no identifiable people. After that control, the image is stylised and becomes available for serving automatically; no separate post-review of the model output is claimed. The source is either submitted through the contribution form with the applicable consent or a licensed, credited photo — for example from Wikimedia Commons — and provenance is always shown in the image's (i) panel. Only the image file and a static style instruction are sent to the model; contact details, attribution, rights metadata and form text are not sent. This bounded flow does not require a blanket ZDR agreement, and images that already satisfy the controls do not need to be regenerated. The illustration is just an illustration — itnever affects grades, numbers or ranking. More on the data protection is inData protection and subprocessors.

Email — automated outreach is closed; journalist email is handled manually

The automated outreach track is closed. The former Layer 1 remains only asmanual, deterministic data support: predefined placeholder fields in a text template can be filled with data from our own registers, but a person selects the material, assembles and sends any communication. This is neither an active pilot outreach nor an outreach automation, and no language model is involved. Campaigns and newsletters are handled in Zoho Campaigns outside the site's server flowand remain stopped until the manual evidence required before sending is complete. When a journalistgets in touch, a person assesses, drafts and sends the reply manually. Message content is not sent automatically to Anthropic, OpenAI or another AI service.

Internal drafting aids — reviewed by a human, never reach the outside world on their own

In a couple of places behind the scenes, Skolkoll uses AI as a working tool, never as something that publishes or sends on its own. The conditional document extraction may, only after its flow-specific assessment and only once we have confirmed that it is deployed and working in the production environment, extract data from official documents into a review queue where a human approves before anything is used — automatic publishing is disabled. The former pilot for AI-assisted support triage and private Zoho Desk notes is retired; no such automated triage or note is active. A permitted document extraction is a suggestion on a human's desk — none of it reaches a family, a school or a published number without a human decision.

AI never sets any published numbers

All statistics on Skolkoll — merit scores, SALSA results, eligibility rates, the Skolkoll score and every other key metric — are calculated deterministically from source data from agencies such as Skolverket, SCB and Kolada. The AI never produces, alters or selects any of these metrics. The one case where an AI reads numbers out of official documents (see the internal drafting aids above) lands in a review queue where a human decides — nothing is published automatically. When Kollen states a number, the model is instructed to use the verified source data, but even a grounded AI response can be wrong. How the numbers are calculated is documented openly on themethod page.

2. What controls are in place

Several layers of safeguards surround Kollen. Some are hard guarantees; others are deliberately described as "best-effort" because they can let something through in edge cases — we would rather be honest about the limits than promise more than the code delivers.

Grounding in verified data

On a school page, the server injects the school's verified Skolkoll data as context before the question reaches the model. The system prompt explicitly tells the model to answer "I don't have data for that right now"rather than guess, and to never invent statistics or school names that are not in its context. The source data is the source of truth; the model is expected to stay within it.

Input sanitisation

All fields in the school context are sanitised before being built into the prompt, so that content in the data cannot be interpreted as instructions to the model.

Scoped to school questions

The prompt includes an instruction to ignore attempts to inject new instructions and to answer only questions about schools and school statistics. This is a mitigation, not a guarantee — it reduces the risk of manipulation but cannot rule it out entirely.

Best-effort topic screening

Before a question is answered, it is first classified by a faster model (Claude Haiku) as on-topic or off-topic. This is a best-effort control: if the classification fails, the question is allowed through rather than wrongly blocked. We therefore never describe it as a safeguard that blocks everything inappropriate. Separately, a circuit breaker can temporarily disable the whole AI chat if the main model fails repeatedly — an availability safeguard, not part of the topic screening.

Request integrity (HMAC signing)

The assistant's messages are signed with HMAC and re-verified on subsequent requests. If a message has been tampered with, the request is rejected. This means the conversation history cannot be forged in transit.

Rate limits

Requests are limited in several ways: a short-term per-IP burst limit, a daily limit and — for signed-in users — a monthly quota. This protects the service against overload and abuse.

Audit logging with a keyed IP pseudonym

For each eligible processed Kollen request, the server makes at most one asynchronous write attempt to the Kollen audit log in our database (Google Cloud Firestore). The response does not await that write, failures are logged, and storage is therefore not guaranteed. A stored record contains a domain-separated HMAC-SHA-256 pseudonym of the IP address, truncated to 16 hexadecimal characters (not the full address), the length of the question and answer (not the content), school context as an exact eight-digit school-unit code or no value, status and a timestamp. The record receives a deletion date stored on the record, 90 days ahead. A check of the production environment on 2026-07-30 showed the deletion rule for the audit log's deletion date as active; this proves policy state, not deletion of a particular expired sample. Firestore's automatic deletion (TTL) is asynchronous after expiry. No message content is logged.

An always-visible "AI can be wrong" disclaimer

Every answer from Kollen is automatically appended on the server with a source-and-fallibility disclaimer —"AI-generated summary based on data from Skolverket, SCB and Kolada via Skolkoll.se. Kollen may make mistakes — verify important information." In addition, the chat interface shows a permanent disclaimer carrying the same call to verify:

"Kollen drivs av AI (Claude, Anthropic). Kan göra fel — verifiera viktig information."(Kollen is powered by AI (Claude, Anthropic). It can make mistakes — verify important information.)

The disclaimer is deliberate and permanent. The numeric reasonableness check we run internally is alog — it does not correct or block answers. So the disclaimer stands as the visible safeguard: the source data is the source of truth, the model is grounded on it, and you are always asked to verify important information.

Clear information, local acknowledgement and the right to object

Before first use, Kollen shows information about recipients, data types, retention, risks and the legal basis. When you continue, a local information acknowledgement is stored in the browser; it is not consent as the legal basis. The browser's local copy of the conversation lasts only for the session and disappears when you close the tab; provider and audit-log retention are described above. "Clear AI data" clears both the local conversation and acknowledgement, and you may object at any time through the data-protection contact.

3. What the AI does not do

We keep this page honest about the limits: the topic screening lets a question through rather than blocking it by mistake, and the instruction to answer only school questions is a mitigation rather than a guarantee. If a safeguard is improved or added, this page is updated accordingly.

Transparency · Privacy policy · Method · Security