Wednesday, September 16, 2026
Microsoft Signs AI Privacy Standard That Bans Training on Student Data

Microsoft Signs AI Privacy Standard That Bans Training on Student Data



Microsoft signs an AI privacy standard that prevents covered school data from being used to train generative models and gives U.S. districts contractually enforceable protections. The agreement with the American Federation of Teachers and United Federation of Teachers was announced September 9 and becomes available nationally on November 1.

 

The 31-page standard governs AI products designed and marketed for authenticated educational use, placing limits on data collection, automated decisions and product changes. Its ten principles establish four especially consequential safeguards:

  • No model training on student or educator data, apart from a narrow safety exception.
  • No AI companions and no unreviewed high-risk decisions.
  • Schools control data retention, deletion and product changes.
  • Providers must report qualifying breaches within 72 hours.

 

Microsoft Signs AI Privacy Standard With Enforceable Terms

The National AI Safety & Privacy Standard is a binding memorandum between the AFT’s National Academy for AI Instruction and participating AI providers. Microsoft is the first announced technology company to adopt it, turning the document’s requirements into obligations rather than voluntary guidance.

 

Beginning November 1, any U.S. school district can ask Microsoft to incorporate the protections into a new or existing customer agreement. Microsoft says districts will not need to wait for renewal or renegotiate the entire contract, and the added commitments can be enforced if the company fails to meet them.

 

The agreement remains in force for two years and must be renewed in writing to continue. A material breach that is not corrected within the specified cure period can end a provider’s participation in the standard, while affected schools retain contractual remedies.

 

This structure is important because federal student-privacy laws were written before generative AI systems began processing prompts, uploaded files, generated answers and persistent memories. The standard does not replace FERPA, COPPA or state rules; it adds stronger contractual protections where the law permits.

 

Student Prompts and Outputs Cannot Train General Models

The standard defines student data broadly. It includes names, grades and disciplinary records, but also prompts, AI-generated outputs tied to a student, behavioral patterns, device identifiers, location data, memory files, audio, visual material and related metadata.

 

Covered data cannot be used to train, fine-tune, benchmark or otherwise improve an AI model. The prohibition also applies to de-identified, aggregated or transformed derivatives and continues after the contract ends, closing routes that could otherwise turn classroom interactions into future training material.

 

A narrow exception permits the minimum necessary processing for safety and security functions, including detecting self-harm risks, grooming, bullying, threats, malicious activity or unauthorized access. Data handled under that exception cannot be reused for advertising, profiling, unrelated product development or general model improvement.

 

Providers must collect only what is necessary for the contracted educational service. Continuous location monitoring, keystroke logging, passive attention tracking, long-term profiling and biometric collection are restricted unless a documented need and explicit school approval satisfy the agreement’s conditions.

 

Schools retain control over export, retention and deletion. Covered data cannot be sold or used for advertising, and persistent memory features must be manageable so eligible users can see stored information, erase it or turn memory off without losing access to the service.

 

Further Reading

 

Human Review and AI Companion Restrictions Set Deployment Limits

The standard states that AI should support educators and students rather than replace their judgment. High-risk decisions require meaningful human review or prior approval, preventing a covered system from independently determining consequential outcomes for a learner or teacher.

 

AI companion products are prohibited under the agreement. That restriction targets systems designed to simulate an ongoing social relationship, a category attracting scrutiny because children may disclose sensitive information, form emotional dependence or misunderstand whether they are interacting with a person.

 

Providers must explain in plain language how educational AI generates outputs, summarize its training data and identify known limitations and failure modes. Products also need clear indicators when a student or educator is interacting with AI, making the technology visible rather than hiding it inside a conventional interface.

 

Security obligations include encryption, access controls, independent testing and incident-response planning that extends to subprocessors. Qualifying breaches must be reported within 72 hours, and unresolved violations can lead to the affected AI use being paused or terminated.

 

The rules also address accessibility and discrimination. Providers must identify and correct gaps, offer equal features and support an independent study, adding an evaluation requirement beyond ordinary promises that a product was designed to be fair.

 

School District Adoption Will Determine the Standard’s Reach

The agreement arrives after New York City and Los Angeles adopted one-year limits on student-facing AI tools for many pupils. Those policies give school systems time to decide where generative tools belong and which technical and contractual controls must precede broader classroom use.

 

The Microsoft standard offers districts a route between unrestricted adoption and a complete ban. Administrators can permit selected educational products while establishing rules for data ownership, human oversight, incident reporting, transparency and the ability to leave a provider without losing access to exportable records.

 

Its scope has boundaries. The definition covers products primarily designed and marketed for education under an authenticated school agreement, while general-purpose productivity, communication, search, cloud and workplace-assistance tools are excluded when they are not education-specific products.

 

Microsoft has said it will extend the protections nationwide, but district uptake will show whether the standard becomes a common procurement requirement. Other AI vendors would also need to sign and implement comparable terms for schools to apply the same rules across a mixed technology environment.

 

The November rollout creates a practical test: whether enforceable contract language can move faster than legislation while still producing measurable compliance. Districts, teachers and families will be able to judge the standard by audits, breach notices, deletion controls and the provider’s response when a safeguard fails.

THEFLGHT
author

THEFLGHT

Elevating narratives from the heart of London's intellectual epicentre.

0 Comments:

Leave a Reply

AI Agent Data Breach: Spain Discloses Its First Report
Google Launches Gemini 3.8 Live and Extended Thinking Voice Models
Meta Launches Meta One AI Subscriptions Across Instagram, WhatsApp and Facebook
Axelera Launches Europa AI Chip for Dell and Supermicro Systems
Einride Autonomous Truck Launches Into Daily Lidl Service in Germany
DeepSeek IPO Plan Taps Yan Wentao as First CFO