Student learningfor Grades 9–12, Higher Ed
Data Trail Audit
Teams read an AI study app's privacy policy like investigators, map where their data could travel, and choose settings and habits that shrink their trail.

All activities Student learning
Teams sort fourteen texts, emails, and game-chat messages into safe, scam, or check-another-way, and learn why AI-polished scams make spelling mistakes a useless clue.
Many of us were taught that scams are easy to spot because they're full of typos. Now anyone can use AI to write a polished, friendly, perfectly spelled scam in seconds. In this gallery-walk sort, teams visit a "tank" of fourteen realistic messages, decide which are safe, which are scams, and which need to be checked another way, and name the red flags that still work. They leave with a SLOW DOWN routine they can use on any message.
Hook
Show or read two versions of the same message side by side. Version 1: "URGENT!! you acount is lockd. click hear to fix now". Version 2: "Hi! We noticed unusual activity on your PixelPlay account. To keep your progress safe, please confirm your login within 24 hours using the secure link below." Ask: "Which one is the scam?" Reveal: both are. Say: "Scammers can now use AI to fix the spelling and make it sound friendly. So we need better clues."
Facilitator noteIf you have a district-approved chatbot, paste Version 1 and ask it to "make this sound professional" live on the projector. Don't send anything anywhere; the point is how fast the polish appears.
Explore
Teams rotate through the 14 messages (about one minute per station, or work through the strips at their desks). At each one, they place a colored sticky note: green = Safe, red = Scam, yellow = Check another way, and write one flag that convinced them. Teams may not click, call, or reply to anything; they may only notice.
Facilitator noteListen for "It has no typos, so it's fine." Bring that reasoning to the debrief.
Debrief
Go to the three messages with the most split votes. Ask teams to defend their color. Reveal the key and build a class list titled "Flags that still work": urgency, secrecy ("don't tell anyone"), a request for passwords, codes, or money, a link or sender that doesn't match the real company, an offer that's too good to be true, and a message you didn't expect. Then ask: "Why is 'check another way' sometimes the smartest answer?"
Facilitator noteStress that asking for a verification code is a major flag. A login code is meant only for you; a real friend or company will not ask you to send it to them in a message.
Model
Hand out Handout B and model it on Message 5 (the "friend" asking for a code in game chat). Think aloud: "Stop. I feel rushed. Look at the sender... it's a new account using my friend's name. Open nothing. Who can I check with? I'll ask my friend in person or through our usual chat. Don't share codes or passwords, ever. Own it: tell an adult. Warn others. Note what happened so I recognize it next time."
Facilitator noteStudents under 13 may not have accounts of their own; frame it as protecting a family phone, a game console, or a school account.
Apply
Teams complete Handout C. They choose one scam from the tank and write the safe action they'd take, the trusted route they'd use to check, and what they'd say to a younger sibling or friend who got the same message. Then each team writes one new flag the class didn't list.
Facilitator noteLook for trusted routes that don't use the message itself: the official app, a number from the back of a card, a teacher or parent, the real website typed in by hand.
Reflect
On an exit sticky note, each student writes the one flag they'll remember and one person they'd tell if something felt off. Collect them at the door.
Facilitator noteIf a student shares a real scam they or their family experienced, thank them and follow your school's reporting process if there's any ongoing risk.
Designed for paper: the message tank is taped to the walls, sticky notes record votes, and the SLOW DOWN card goes home. Read Version 1 and Version 2 of the hook aloud if you have no projector.
Post the messages as slides or a form so students vote Safe, Scam, or Check another way and see the class results as a chart. The teacher alone may demonstrate how a district-approved chatbot polishes a clumsy message; students never paste real messages or personal information into an AI tool. Grades 6–8 can review their school account's security settings with the teacher afterward.
Does it need a screen? A live AI polish demo proves in seconds that good spelling means nothing, which shifts students to flags that still work. The core sorting and reasoning is stronger on paper, where every vote and flag is visible on the wall.
What you should be able to see or collect if it worked.
Students sort realistic messages as safe, scam, or check another way and name red flags that still work, the phishing and security part of digital citizenship.
Students take the SLOW DOWN card home and walk a family member through one message from the tank. Next class, invite volunteers to share one scam flag their family recognized.