SchoolDecisionby Formative Spaces, Inc.
School DecisionThe Newsroom
SATURDAY, SEPTEMBER 12, 2026
Beyond the headline
SCHOOLDECISION.COM/NEWSROOM

AFT and Microsoft announce first national enforceable AI privacy standard for K-12 schools

The agreement bars AI training on student data, bans companion chatbots, and requires human oversight; districts can opt in starting November 1.

On September 9, 2026, the American Federation of Teachers, its New York City affiliate the United Federation of Teachers, and Microsoft announced what they described as the first national, contractually enforceable agreement governing how an AI vendor handles K-12 student data. The 30-page memorandum of agreement, called the “National AI Safety & Privacy Standard” for schools, was announced in New York by AFT President Randi Weingarten, UFT President Michael Mulgrew, and Microsoft Vice Chair and President Brad Smith.

The standard contains ten binding principles. Among them: no student or educator data may be used to train AI models; students cannot be tracked; AI cannot independently make decisions about discipline, academic placement, or employee evaluation without meaningful human review; AI companion chatbots are banned; and districts retain control over data retention and deletion. The protections apply to all data types, including prompts, responses, uploaded files, behavioral signals, metadata, and interaction logs.

Key provisions of the agreement

The memorandum of agreement, designated “Version 1.0, September 2026,” defines “Covered Data” as Student Data plus data from educators, administrators, or EDU Customers using AI Provider Educational Products. Student Data is defined broadly as any information directly related to an identifiable student, including names, grades, disciplinary records, prompts entered into AI products, device identifiers, location data, memory files, and audio or visual data. The document states that when in doubt about whether something is Student Data, it should be treated as such.

Principle 1 prohibits the AI Provider from using Covered Data to train, fine-tune, update, benchmark, or improve any AI model, at any time, for any purpose. The prohibition applies retroactively, covers de-identified and aggregated datasets, and survives contract termination indefinitely. A narrow safety and security exception permits use of data only to detect harm such as self-harm risk, child sexual abuse material, or threats of violence, but the burden is on the provider to demonstrate compliance, and an annual written statement signed by a senior officer is required.

The agreement also requires third-party audits and certifications: SOC 2 Type II with annual renewal, ISO 27001, ISO 27701, ISO 42001 or equivalent, and FedRAMP Moderate where applicable. Breach notification to the EDU Customer must occur within 72 hours of becoming aware of a confirmed or reasonably suspected breach.

72 hoursRequirement for breach notification to the EDU Customer after becoming aware of a confirmed or suspected breach, according to the MOA. [3]

Beginning November 1, 2026, any U.S. school district can request to incorporate the standard’s protections into new or existing Microsoft customer agreements without renegotiating their contract. Once incorporated, the protections are contractually enforceable, and districts may terminate for uncured material breach and seek damages.

How the standard compares with existing law

New York Education Law §2-d already prohibits the sale of student personally identifiable information for commercial or marketing purposes and requires data security and privacy plans in third-party contracts. However, it contains no fixed deadline for breach notification and no provisions addressing AI model training, AI companion chatbots, or human oversight of AI decisions. The AFT/Microsoft standard mandates a 72-hour breach notification window, explicitly prohibits AI training on student data, and requires human oversight of AI decisions affecting discipline or placement, according to a GovTech analysis.

The federal Children’s Online Privacy Protection Act requires parental consent before companies collect data from children under 13, but predates generative AI by more than two decades and does not address how AI models are trained on student data. The AFT/Microsoft standard references compliance with COPPA, FERPA, IDEA, and applicable state laws, stating that where the standard provides stronger protections, those stronger protections apply.

In January 2026, the Ohio Department of Education and Workforce released a model AI academic policy and required every public, community, and STEM school to adopt an AI framework by the start of the 2026-27 school year. Unlike the AFT/Microsoft standard, Ohio’s approach is a suggested policy framework requiring school-level adoption, not a contractually enforceable vendor agreement with specific data protections and audit requirements, GovTech reported.

Reach depends on district opt-in and competitor follow-through

The agreement was negotiated through the National Academy for AI Instruction, a five-year, $23 million partnership involving AFT, Microsoft, OpenAI, and Anthropic. Only Microsoft has signed so far. AFT President Weingarten stated that OpenAI and Anthropic have expressed willingness to sign similar agreements, but neither company responded to Fortune’s requests for comment as of September 9, 2026.

The memorandum of agreement has a two-year term from the effective date and must be renewed in writing by both parties every two years. The Academy may terminate the AI Provider’s participation immediately upon any uncured material breach. Permanent obligations surviving termination include the indefinite prohibition on using Covered Data for training and the indefinite prohibition on selling or sharing Covered Data. Data deletion obligations survive for two years post-termination.

Because the standard is contractual rather than statutory, it applies only to districts that opt in and only to Microsoft products. Its national impact depends on how many school districts request the protections and whether other major AI vendors follow Microsoft’s lead.

Analysis

By the School Decision Newsroom, written after the reporting above was filed.

Nothing changes unless your district asks for it.

The standard is opt-in. No district automatically receives these protections. Starting November 1, a district must request that Microsoft incorporate the terms into its existing contract. EdWeek confirmed the protections will not be applied automatically. If your district never asks, your child's data stays under whatever terms the district already signed. There is no notification system and no requirement that districts tell parents whether they have opted in. A parent's first question to their superintendent should be simple: have we requested this standard?

OpenAI and Anthropic already say they don't train on student data. The fight is over de-identified data.

Both companies already state they do not train on data from their education products. Anthropic's Claude for Teachers page says 'training is off' for verified teacher accounts. OpenAI says it does not use ChatGPT Edu or ChatGPT for Teachers data for training or improving models. What the AFT standard adds: a permanent, retroactive ban on using even de-identified or aggregated data for any model improvement, plus mandatory third-party audits. An OpenAI student DPA disclosed through a CU Boulder FOIA request shows the company reserves the right to create and own de-identified data and use student data for 'improvement of OpenAI's products or services.' That gap is the real negotiation point.

The November 1 date covers only Microsoft. Watch for whether the other vendors sign.

Weingarten built this through the $23 million National Academy for AI Instruction, which lists Microsoft, OpenAI, and Anthropic as partners. Anthropic's own site quotes her about working with the company on a 'Gold Standard' for K-12 safety and privacy. If OpenAI and Anthropic do not sign, the standard applies only to Microsoft products, leaving districts using ChatGPT or Claude without these protections. The MOA has a two-year term and must be renewed in writing. A parent should watch for two things: whether the other vendors sign on, and whether their own district requests the terms.

Sources

  1. American Federation of Teachers. AFT, UFT and Microsoft Announce ‘National AI Safety & Privacy Standard’ for Schools to Protect Students, Families and Educators View
  2. EdWeek. Microsoft Agrees to New Student Privacy Protections for AI. How Ironclad Are They? View
  3. American Federation of Teachers. AI Safety & Privacy Standard for Schools: Memorandum of Agreement View
  4. K-12 Dive. Teachers unions announce AI safety agreement with Microsoft View
  5. Fortune. Microsoft's move in the AI school debate: controls over how student data gets used View
  6. New York State Education Department / FindLaw. Frequently Asked Questions About Data Privacy and Security / New York Consolidated Laws, Education Law - EDN § 2-d View
  7. GovTech. Microsoft, AFT, UFT Set Precedent for District AI Governance View
  8. OpenAI. Business data privacy, security, and compliance View
  9. Anthropic. Introducing Claude for Teachers View
  10. AAUP / CU Boulder FOIA Return. CU Boulder OpenAI Contract FOIA Return (Student DPA) View