Microsoft Adds Contract Rules for Student Data and School AI

The National AI Safety & Privacy Standard sets data limits, human-review requirements and breach duties, but its framework is tied to Microsoft’s school agreements.

By 2 min read
Microsoft Adds Contract Rules for Student Data and School AI
Microsoft Adds Contract Rules for Student Data and School AI

Listen to this story

The audio brief

About 1:36
0:001:36
Read transcript
Microsoft is adding binding rules for student data and school AI to its district agreements, with the protections taking effect November first. The National AI Safety and Privacy Standard bars Microsoft from training AI models on student data, tracking students, selling their data, or using it for advertising. It also prohibits AI companion chatbots for students and requires human review before AI makes decisions. The standard is not a ban on classroom AI. Districts still decide when AI is used, and how student data is collected, stored, deleted, and disclosed. They must also receive clear information about AI use, data practices, and safeguards so families and educators can understand what is happening. What makes this more than a policy statement is the contract machinery behind it. Districts can audit compliance, require annual certification, and demand security fixes by set deadlines. A breach must be reported within seventy-two hours. If Microsoft violates the terms, districts can terminate agreements and seek damages. Microsoft announced the framework on September ninth alongside American Federation of Teachers President Randi Weingarten and United Federation of Teachers President Michael Mulgrew. The move followed New York City’s one-year moratorium on AI in public schools. But the protection currently travels with Microsoft’s school relationships. Union leaders want OpenAI and Anthropic to adopt comparable rules, but neither has committed to them. The key question is whether this becomes a broader education-industry standard—or remains a Microsoft-specific contract promise.

Story brief

3 key points

Microsoft will apply a school-focused contract standard on November 1, giving districts protections that go beyond a data-use promise: no training on student data, tracking, advertising, or student companion chatbots, plus human review for AI decisions. The terms also require 72-hour breach notification, annual certification, audit rights, and remediation deadlines, with termination and damages available for...

  1. 01

    Districts retain control over when AI is used and how student data is collected, stored, deleted, and disclosed.

  2. 02

    The standard’s enforcement tools include contract termination, damages, audits, annual certification, and security-fix deadlines.

  3. 03

    Microsoft’s announcement followed New York City’s one-year moratorium on AI use in public schools.

Microsoft says school districts it works with will receive new protections for student data and AI use on November 1. The National AI Safety & Privacy Standard prohibits training AI models on student data and requires human review before AI makes decisions.

The announcement came September 9 from Microsoft Vice Chair and President Brad Smith, American Federation of Teachers President Randi Weingarten, and United Federation of Teachers President Michael Mulgrew. It followed New York City’s announcement of a one-year moratorium on AI in public schools.

Rules written into the vendor relationship

The standard is not a ban on classroom AI. Districts can add its provisions to Microsoft customer agreements, while retaining control over when and how AI is used and how data is used, kept and deleted. It also calls for clear information to families and educators about AI use, data collection and safeguards.

Limits on data, tracking and companion bots

  • Companies cannot train AI models on student data or track students.
  • AI cannot make decisions without human review.
  • Student data cannot be sold or used for advertising.
  • The standard prohibits AI companion chatbots for students.

The agreement also requires a 72-hour breach report, annual certification, audit rights and deadlines for fixing security problems. Those operational requirements turn the standard from a list of data-use limits into continuing obligations for Microsoft under the arrangement.

A wider pledge remains unsettled

Microsoft said the protections will take effect November 1 for every school district it works with, whether or not a district acts to adopt them. Union leaders want OpenAI and Anthropic to take on similar protections; Fortune reported that neither company responded to its requests for comment.

That leaves Microsoft’s standard as a concrete protection for its own school relationships, rather than a requirement for the full education-technology market. Whether rival providers adopt the same approach is the next open question.

Editorial analysis

Our Read

Microsoft’s choice to put the safeguards in customer agreements is more consequential than another set of school-AI principles: it gives districts a stated route to enforce terms against a vendor. But it also leaves the model bounded by the companies that choose it. New York City’s announced moratorium took a different route, limiting student AI use by age. The next useful test is whether other education-technology providers adopt comparable terms, especially OpenAI and Anthropic, which union leaders said they hope will join.

Sources

  1. news.microsoft.comAFT, UFT and Microsoft announce ‘National AI Safety & Privacy Standard’ for schools to protect students, families and educators - Source
  2. fortune.comMicrosoft's move in the AI school debate: controls over how student data gets used | Fortune

Loading discussion...