top of page

Proving Your Thought: Turnitin Clarity and the Surveillance of Academic Cognition

Chirkankshit Bulani and Anjali
3 hours ago
9 min read

This piece is written by Chirkankshit Bulani (5th Year Student at Rajiv Gandhi National University of Law) and Anjali (1st Year Student at MS Ramiah College of Law)


I. The Question Clarity Forces Us to Ask


When a student submits an essay written completely on his own, no AI-generated paragraph in sight or any plagiarism flags. However, a misconduct notice still comes up. It wasn’t because of what was written but how you wrote it. What was flagged was drafting in short bursts and another paragraph which you had written elsewhere but was pasted in one go. It was flagged by a system monitoring each tap of yours, and to it, the behaviour seems anomalous.


This example is a real scenario of Turnitin Clarity,  a tool launched at SXSW EDU in March 2025 and made generally available in July 2025. Turnitin’s product documentation mentions that Clarity captures “the writing process from the first keystroke to final submission,” recording active writing time, paste events, revision history, and AI tool interactions. Additionally, this data can be exported by the administrators as CSV files at the institutional level.


Turnitin pitches Clarity as a learning tool as well as an integrity mechanism, highlighting the AI chat assistant and citation feedback features. However, this deserves much deeper scrutiny, since the very infrastructure which provides AI-assisted revision suggestions also logs every keystroke, and on top of all that, allows exporting this behavioural record to institutional administrators. The learning and surveillance functions come as a bundle. 


This makes it distinct from what conventional plagiarism did. Conventional plagiarism worked on what was submitted, while Clarity works on the process of making the work itself. This shift, from analysis of text to behavioural profiling under garb of learning integrity is exactly what this piece examines. 


The piece doesn’t argue that AI-assisted misconduct is a genuine problem, which it is, even according to Turnitin’s own data, which shows that, as of Turnitin's February 2026 data release, approximately 15% of essay submissions now have over 80% AI-generated writing, up from 3.3% in 2023. The core query here is that if the requisite legal and normative justifications are met when student cognition is monitored as a way of authenticating authorship. This piece argues that, in its current form, the answer is a resounding no. 


II. From Text to Process: What Clarity Does and Why It Matters


Clarity cannot be called a plagiarism detector in the conventional sense. According to its product page, it is a ‘composition environment’ in which students can draft assignments within an institutional learning drafting system. Accordingly, the platform logs the full drafting of the student in real time, including evert addition, deletion and paste event, which are recorded and timestamped. This timeline can be played by instructors, along with the ability to view AI interactions. Further, in November 2025, introduction of bulk CSV export of this data establishes that measurement of student cognition is available at the institutional level for aggregation and comparison. 


This system creates a behavioural record of the individual using it, which Turnitin calls as a ‘proof of process’ of authentic authorship. Traditionally, integrity was inferred from results of finished products against established benchmarks. Clarity, however, turns the table to generate a record of writing conduct, which can be used by instructors to then draw inferences from it. This phenomenon of behavioural tracking is part of a broader wave, which includes remote proctoring platforms such as Proctorio which rely on behavioural monitoring to maintain integrity in education. However, the question arises when a system treats behavioural deviations as misconduct, and to what extent is this justified on yardsticks of proportionality, data protection and broader umbrella of evidentiary validity. 


III. The Proportionality Problem


Before application of proportionality, it is crucial to establish threshold such that proportionality can be applied. When applying the proportionality standard under Puttuswamy, it’s crucial to note that it only binds the state under Article 12. In this regard, Turnitin is registered in the US, while the universities deploying Clarity might or might not fall under definition of state. Further, the horizontal application of fundamental rights to private actors is unsettled under current Indian jurisprudence, whether it is the court’s cautious treatment in Indian Medical Association vs Union of India or the broader debate in Puttuswamy. 


The piece doesn’t deny this difficulty, but argues that the argument is simultaneous on two distinct tracks. Firstly, the Digital Personal Data Protection Act, 2023 (DPDPA), which is set to enter enforcement in 2027, obligates data fiduciaries to respect data minimization, and such obligations must be interpreted in light of the constitutional right to privacy established in Puttuswamy. As per the definition, institutions processing student behavioural data would be data fiduciaries. Secondly, institutions, even if privately owned, but serve a significant public function, such as education, would find that proportionality as a principle of administrative fairness binds them. Either way, the argument stands as such: intrusion is a necessity, is connected to a legitimate aim and is proportionate to the objective it seeks to achieve.


When this is applied to Clarity, the first element of legitimate aim is satisfied. Institutions do hold an obligation to maintain academic integrity and preventing misconduct. The second element, which is of the rational connection, is also satisfied to some extent since behavioural monitoring might be considered appropriate in the age of AI. However,  the last element, which is of proportionality in relation to the objective is where Clarity’s justification runs into a snag.


As per Puttuswamy, proportionality translates to that the means adopted should be necessary, not just convenient. However, surveillance of every continuous keystroke of the writing process, which includes every pause, every alphabet, every word pasted, right from when the assignment is synthesized to when it submitted, that too exportable at the institutional scale, demands that we ponder if the move is maximalist compared to a targeted concern. It could be argued that less stringent alternatives such as oral examinations and submission-stage interviews exist. This onus has not been satisfactorily discharged by institutions using Clarity, who must demonstrate why overall round-the-clock surveillance is the only options left. Further, the institutional level data exporting is hard to justify. The point is that when comparing the interest being protected with the means being used to achieve it, which is catching a subset of students using AI for misconduct, compared to continuous surveillance of all students while creating their assignment. This brings a partial benefit on a near-universal cost.


The DPDPA doesn’t fully resolve this problem. While it obligates data fiduciaries to obtain valid consent before processing of personal data, and the data in question, including behavioural data such as keystrokes and AI detection outputs would fall within category of personal data. However, that by itself doesn’t resolve the problem due to lack of ed-tech specific provisions. The act doesn’t exactly address the issue of structural coercion by a university, atleast not explicitly. Further, the DPDPA provides a broad exemption for research and statistical purposes, which could be theoretically invoked as a defence if this were to be examined by the DPBI. Hence, until targeted amendments are made to the DPDPA, this regulatory gap must be bridged by Puttuswamy’s proportionality standard. 


For comparison, the General Data Protection Regulation governs institutions in the European Union. Articles (1)(b) and 5(1)(c) mandate that personal data collection must be specified, for a legitimate purpose and limited to what is necessary. Any reasonable reading of the articles won’t be able to satisfy collection of keystroke level data which records every editing decision over the entire process of creation of the assignment, which further, is available for bulk export. The relevance of GDPR here is it is an illustration of a what rigorous data protection demands, and how DPDPA hasn’t been able to keep up. 


If understood together, Puttuswamy’s proportionality standard and DPDPA’s regulatory silence on Edtech regulation mean that the burden to justify use of Clarity falls squarely on institutions deploying it. 


IV. The Evidentiary Gap: Can Behavioural Data Prove Authorship?


While the question of proportionality remains unanswered, moving one step forward, the concern of the evidentiary validity of the data produced by Clarity remains. The software essentially generates a behavioural profile, which is distinct from determining authorship. At the end of the process, the inference is drawn by a human educator, and difference between what data implies and what would be inferred from it is greater than what educators would acknowledge. 


The problem of false positives of AI detectors already holds empirical validation. A Stanford study, which tested around seven leading AI detectors, found that essays by non-native English speakers were misclassified as AI-generated 61% of time, and at the same time, nearly none of the native-English essays were falsely flagged. A 2025 study by Sarah Eaton, published in Teaching in Higher Education showed that neurodivergent and non-native writers were affected disproportionately by false positives, which lead to psychological and material harm. The institutional response also makes the picture clear: Universities like Yale, Vanderbilt and Johns Hopkins have blocked Turnitin’s AI detection entirely, citing bias and inaccurate detection. This risk increases further when applies to Indian Universities multilingual composition. 


These findings are similarly applicable to the writing report generated by Clarity. Normal human behaviour such as irregular keystroke patterns and substantial pasting, which is fairly common for multilingual writers who often think in one language and then translate, for students with dyslexia and ADHD, who draft externally and then paste. The writing report creates no distinction for between these practices and AI-generated text. It can only flag deviation from a behavioural norm likely calibrated against neurotypical, native-English writing behaviour.


Data from Centre for Democracy and Technology has shows that automated proctoring systems, which are based on the same underlying logic as Clarity, often place student with disabilities at a higher risk  of misidentification because of the behavioural divergence from encoded norms. In February 2026, a federal judge ruled that Adelphi University's finding against Orion Newby, a student with documented learning differences, was 'without valid basis and devoid of reason'. Turnitin had flagged his paper as 100% AI-generated even though two independent detectors found it human-written and the original similarity score was only four percent, and the university penalized him without ever sharing the underlying report. Further, research has shown that more than often, there are less than adequate safeguards present when behavioural data is translated into misconduct findings. Clarity’s application of these to long form writing, coupled with exporting of bulk data risks that individual scrutiny will become even more inconvenient.


Hence, the picture appears as such: While Clarity produces behavioural data consistent with AI assistance, the same data can also be consistent with human writing practices, which are particularly common among multilingual, neurodivergent and non-normative writers. When the outputs are treated as presumptive evidence of misconduct, the lack of safeguards is both a legal and epistemic error.


The Missing Procedural Safeguard


A further difficulty arises when Clarity’s behavioural record is converted from an instructional signal into evidence of misconduct. Indian law has long treated academic-discipline decisions as requiring procedural fairness. In Board of High School & Intermediate Education, U.P. v. Ghanshyam Das Gupta, the Supreme Court held that an examination authority deciding allegations of unfair means performs a quasi-judicial function because its determination can seriously affect a student’s career; natural justice therefore requires an adequate opportunity to answer the material relied upon. That principle becomes more—not less—important when the “material” is a behavioural inference drawn from writing time, paste events, revisions or AI activity. Turnitin itself cautions, in relation to its AI Writing Report, that detection may misidentify human and AI writing and “should not be used as the sole basis for adverse actions against a student.” Clarity’s process data should logically attract at least the same caution. A defensible institutional framework must therefore guarantee disclosure of the complete report, identification of the specific behaviour triggering concern, an opportunity to contextualise drafting practices, and meaningful human review before any penalty follows. Otherwise, “proof of process” risks becoming proof by process.  


V. Conclusion


When we go back to the story of the student at the beginning, where he was flagged not for what he wrote by how he wrote it. This is the model Clarity is built upon. Academic integrity is a product of monitored cognition; authorship is authenticated through behavioural data and any deviation from norms is academic misconduct. Turnitin calling Clarity a learning tool doesn’t mean that these concerns do not carry weight anymore. The infrastructure of support has conflated with that of surveillance, and any legal or normative assessment must evaluate the entire picture, not move towards the easiest function to justify.


The constitutional jurisprudence places the burden of justification upon the institutions. The statutory mechanism, the DPDPA, contains no EdTech-specific provisions, leaving the constitutional doctrine to fill that gap. The empirical literature discussed provides insights on analogous surveillance technologies, coupled with the withdrawal decision by various international universities poses a question on discriminatory distribution of false positives, which would only multiply in India’s multilingual context.


Now the question which Indian institutions must answer is one which law hasn’t clearly provided an answer for. The question is about what kind of a relationship do they envision with their students, and what are the constitutional constraints? A model that monitors every keystroke to authenticate every thought is not a neutral integrity mechanism. It is a choice about the nature of education. The Puttuswamy framework exists to demand justification for that choice. Whether Indian institutions and regulators will be required to provide it is now the urgent question.


Recent Posts

See All

Comments


bottom of page