On September 9, 2026, the American Federation of Teachers, its New York City affiliate the United Federation of Teachers, and Microsoft announced what they described as the first national, contractually enforceable agreement governing how an AI vendor handles K-12 student data. The 30-page memorandum of agreement, called the “National AI Safety & Privacy Standard” for schools, was announced in New York by AFT President Randi Weingarten, UFT President Michael Mulgrew, and Microsoft Vice Chair and President Brad Smith.
The standard contains ten binding principles. Among them: no student or educator data may be used to train AI models; students cannot be tracked; AI cannot independently make decisions about discipline, academic placement, or employee evaluation without meaningful human review; AI companion chatbots are banned; and districts retain control over data retention and deletion. The protections apply to all data types, including prompts, responses, uploaded files, behavioral signals, metadata, and interaction logs.
Key provisions of the agreement
The memorandum of agreement, designated “Version 1.0, September 2026,” defines “Covered Data” as Student Data plus data from educators, administrators, or EDU Customers using AI Provider Educational Products. Student Data is defined broadly as any information directly related to an identifiable student, including names, grades, disciplinary records, prompts entered into AI products, device identifiers, location data, memory files, and audio or visual data. The document states that when in doubt about whether something is Student Data, it should be treated as such.
Principle 1 prohibits the AI Provider from using Covered Data to train, fine-tune, update, benchmark, or improve any AI model, at any time, for any purpose. The prohibition applies retroactively, covers de-identified and aggregated datasets, and survives contract termination indefinitely. A narrow safety and security exception permits use of data only to detect harm such as self-harm risk, child sexual abuse material, or threats of violence, but the burden is on the provider to demonstrate compliance, and an annual written statement signed by a senior officer is required.
The agreement also requires third-party audits and certifications: SOC 2 Type II with annual renewal, ISO 27001, ISO 27701, ISO 42001 or equivalent, and FedRAMP Moderate where applicable. Breach notification to the EDU Customer must occur within 72 hours of becoming aware of a confirmed or reasonably suspected breach.
Beginning November 1, 2026, any U.S. school district can request to incorporate the standard’s protections into new or existing Microsoft customer agreements without renegotiating their contract. Once incorporated, the protections are contractually enforceable, and districts may terminate for uncured material breach and seek damages.
How the standard compares with existing law
New York Education Law §2-d already prohibits the sale of student personally identifiable information for commercial or marketing purposes and requires data security and privacy plans in third-party contracts. However, it contains no fixed deadline for breach notification and no provisions addressing AI model training, AI companion chatbots, or human oversight of AI decisions. The AFT/Microsoft standard mandates a 72-hour breach notification window, explicitly prohibits AI training on student data, and requires human oversight of AI decisions affecting discipline or placement, according to a GovTech analysis.
The federal Children’s Online Privacy Protection Act requires parental consent before companies collect data from children under 13, but predates generative AI by more than two decades and does not address how AI models are trained on student data. The AFT/Microsoft standard references compliance with COPPA, FERPA, IDEA, and applicable state laws, stating that where the standard provides stronger protections, those stronger protections apply.
In January 2026, the Ohio Department of Education and Workforce released a model AI academic policy and required every public, community, and STEM school to adopt an AI framework by the start of the 2026-27 school year. Unlike the AFT/Microsoft standard, Ohio’s approach is a suggested policy framework requiring school-level adoption, not a contractually enforceable vendor agreement with specific data protections and audit requirements, GovTech reported.
Reach depends on district opt-in and competitor follow-through
The agreement was negotiated through the National Academy for AI Instruction, a five-year, $23 million partnership involving AFT, Microsoft, OpenAI, and Anthropic. Only Microsoft has signed so far. AFT President Weingarten stated that OpenAI and Anthropic have expressed willingness to sign similar agreements, but neither company responded to Fortune’s requests for comment as of September 9, 2026.
The memorandum of agreement has a two-year term from the effective date and must be renewed in writing by both parties every two years. The Academy may terminate the AI Provider’s participation immediately upon any uncured material breach. Permanent obligations surviving termination include the indefinite prohibition on using Covered Data for training and the indefinite prohibition on selling or sharing Covered Data. Data deletion obligations survive for two years post-termination.
Because the standard is contractual rather than statutory, it applies only to districts that opt in and only to Microsoft products. Its national impact depends on how many school districts request the protections and whether other major AI vendors follow Microsoft’s lead.
