Microsoft Adds Contract Rules for Student Data and School AI
The National AI Safety & Privacy Standard sets data limits, human-review requirements and breach duties, but its framework is tied to Microsoft’s school agreements.
Loading page…
The National AI Safety & Privacy Standard sets data limits, human-review requirements and breach duties, but its framework is tied to Microsoft’s school agreements.
Listen to this story
Microsoft will apply a school-focused contract standard on November 1, giving districts protections that go beyond a data-use promise: no training on student data, tracking, advertising, or student companion chatbots, plus human review for AI decisions. The terms also require 72-hour breach notification, annual certification, audit rights, and remediation deadlines, with termination and damages available for violations.
Districts retain control over when AI is used and how student data is collected, stored, deleted, and disclosed.
The standard’s enforcement tools include contract termination, damages, audits, annual certification, and security-fix deadlines.
Microsoft’s announcement followed New York City’s one-year moratorium on AI use in public schools.
Microsoft says school districts it works with will receive new protections for student data and AI use on November 1. The National AI Safety & Privacy Standard prohibits training AI models on student data and requires human review before AI makes decisions.
The announcement came September 9 from Microsoft Vice Chair and President Brad Smith, American Federation of Teachers President Randi Weingarten, and United Federation of Teachers President Michael Mulgrew. It followed New York City’s announcement of a one-year moratorium on AI in public schools.
The standard is not a ban on classroom AI. Districts can add its provisions to Microsoft customer agreements, while retaining control over when and how AI is used and how data is used, kept and deleted. It also calls for clear information to families and educators about AI use, data collection and safeguards.
The agreement also requires a 72-hour breach report, annual certification, audit rights and deadlines for fixing security problems. Those operational requirements turn the standard from a list of data-use limits into continuing obligations for Microsoft under the arrangement.
Microsoft said the protections will take effect November 1 for every school district it works with, whether or not a district acts to adopt them. Union leaders want OpenAI and Anthropic to take on similar protections; Fortune reported that neither company responded to its requests for comment.
That leaves Microsoft’s standard as a concrete protection for its own school relationships, rather than a requirement for the full education-technology market. Whether rival providers adopt the same approach is the next open question.
Editorial analysis
Microsoft’s choice to put the safeguards in customer agreements is more consequential than another set of school-AI principles: it gives districts a stated route to enforce terms against a vendor. But it also leaves the model bounded by the companies that choose it. New York City’s announced moratorium took a different route, limiting student AI use by age. The next useful test is whether other education-technology providers adopt comparable terms, especially OpenAI and Anthropic, which union leaders said they hope will join.
Loading discussion...
Join the conversation
Which safeguard would you refuse to compromise on?
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.