Home / Blog / AI & LLM
AI & LLM Spec analysis + hands-on review

Analyze and review: Microsoft releases new AI privacy rules for schools

Microsoft and teachers' unions AFT and UFT struck a contractually enforceable AI privacy standard for US schools, rolling out nationwide on Nov 1, 2026.

Microsoft has teamed up with two of the largest US teachers’ unions, the American Federation of Teachers (AFT) and the United Federation of Teachers (UFT), to announce a “National AI Safety & Privacy Standard” on September 9, 2026, after months of negotiation. What sets this apart from a typical policy announcement is that school districts can write the standard directly into their Microsoft customer agreements, turning it into a contractual obligation that’s enforceable under contract law if breached.

The core commitments are that Microsoft will not use student or educator data to train AI models, will not sell or use that data for advertising, will not use AI to track student behavior, and will always require a human to review AI-generated decisions before they’re acted on. Microsoft also committed to plain-language guides that parents and teachers can actually understand.

Brad Smith, Microsoft’s Vice Chair and President, said the company will make the standard available to every school district across the US starting November 1, 2026. The AFT says it’s holding similar talks with OpenAI and Anthropic.

How the New Standard Changes AI Use in Schools

The standard rests on four pillars: no using student or educator data to train or fine-tune AI models, no selling or using data for advertising, no using AI to track student behavior, and mandatory human review before an AI-generated recommendation or decision is acted on. These commitments are tied to the contract itself, not just a policy statement.

Microsoft logo with Cloud and AI icons, representing the services covered by the new privacy standard

Teachers still need to review AI-generated answers before using them and avoid entering unnecessary personal information. Administrators must configure permissions, monitor usage, and provide a channel for reporting problems when data is used outside the agreed terms.

Why This Deal Is Happening Now

The negotiations followed mounting concerns: teachers let students use AI to help review assignments, but some students accidentally entered names, grades, or family details without knowing how long the data would be kept or who could access it. Some districts, including New York City, had already imposed their own restrictions on classroom AI use before this deal.

Parents worried their children’s data could be used beyond classroom activities, while students themselves often had no idea whether personal information they entered could later be corrected or deleted. That pressure is what pushed the teachers’ unions to negotiate directly with Microsoft rather than leaving each district to write its own rules.

Which Microsoft Services the Standard Covers

The standard covers the services schools actually use, such as Microsoft 365 Education and Copilot, with Azure providing the underlying data and processing infrastructure. Districts that want these protections need to request that the terms be added to their Microsoft customer agreement, which is what makes the commitments legally enforceable — and puts Microsoft on the hook for breach of contract if it violates them.

The launch of Microsoft Copilot, one of the services covered by the new AI privacy standard

Even so, Microsoft isn’t setting a school’s education policy directly. Districts still have to decide which tasks Copilot can be used for, who gets access, and when parental consent is required. The standard is a floor that guarantees data won’t be used beyond what’s agreed — not a full education policy.

Before and After: What Actually Changed

Factor Before the standardAfter the standard
Use of data for training Governed by general terms of useStudent/educator data barred from training AI models
Behavioral tracking No explicit prohibitionAI may not be used to track student behavior
AI-driven decisions Varied by districtHuman review required before acting on them
Transparency to parents Left to each school to communicatePlain-language guides required
Enforcement Guidance, not contractually bindingWritten into customer contracts, enforceable by law

The shift from guidance to a contractual term is the most important change here — it gives districts real legal leverage instead of relying on a provider’s goodwill.

When Privacy Rules Have to Work in a Real School Day

Teachers can use AI to help design lessons by selecting only necessary information and excluding identifying student data. The standard reduces risk but adds a step for reviewing content before use.

Students can more comfortably ask AI to summarize assignments, knowing their data won’t be used to train models — but schools still have to teach them not to over-share personal information in the first place, since the standard prevents misuse of data, not students entering too much of it to begin with.

A laptop displaying a security monitoring dashboard, representing administrators auditing AI usage

Administrators can inspect usage history in greater detail, making it easier to trace problems, though the monitoring workload grows too. If sensitive data is entered by mistake, the school still has to suspend usage, assess the impact, and notify relevant parties — the standard doesn’t remove the need for an incident response process.

Microsoft Compared with Google and Other Providers

Factor MicrosoftGoogle Workspace for EducationOther providers
Bar on using data for training Explicit, via this standardActual policy must be reviewedActual policy must be reviewed
Contractual enforceability Can be written directly into customer contractsActual policy must be reviewedDepends on the provider
Partnership with teachers' unions Negotiated directly with AFT and UFTNo confirmed partnership of this kindNo confirmed partnership of this kind
Rollout timeline Nationwide from Nov 1, 2026Actual policy must be reviewedActual policy must be reviewed
Ease of compliance Depends on each district's processDocumentation must be reviewedMust be assessed case by case

Microsoft is currently the first to turn a deal like this with teachers’ unions into a contractual term. Google Workspace for Education and other providers haven’t confirmed whether they’ll follow suit. The AFT says it’s in talks with OpenAI and Anthropic, but no agreement has been announced yet — schools should check each vendor’s official documentation before committing.

Strengths and Limitations That Still Require Attention

The new standard gives districts real legal leverage when Microsoft breaches the terms, and it sets a clearer framework for protecting minors’ data than before. But the real-world impact still depends on whether each district actually asks to have the terms added to its contract.

Pros

  • +A contractual term that's actually enforceable, not just a pledge
  • +Explicit bar on using student/educator data to train AI models
  • +Available to every US district starting Nov 1, 2026

Cons

  • −Districts must proactively request the addendum for it to apply
  • −No detail yet on how compliance will actually be audited
  • −Doesn't cover other AI vendors schools may use alongside Microsoft

Costs That Do Not Appear on the Quote

The standard itself doesn’t add cost — it’s a term added to an existing customer contract. But the real cost doesn’t end there. Schools still need to train teachers, review data, and adjust internal policies to match the new terms — work that takes staff time and needs periodic review.

IT teams also have to manage user permissions, request the contract addendum, and monitor whether actual usage complies with the standard. Misconfigured permissions can expose data to people who shouldn’t see it, so the budget should account for review time, documentation, and on-the-ground troubleshooting — not just license fees.

What the Standard Still Doesn’t Fully Address

The standard sets a clearer privacy framework, but it doesn’t say how accurate AI has to be, or who’s responsible when a wrong answer affects a student’s education or opportunities. Schools still need people reviewing important answers and a way for students to challenge them.

Another gap is how compliance with Microsoft’s commitments will actually be verified, and how it applies to other AI tools schools may use alongside Microsoft, which fall outside this deal entirely. It also remains to be seen whether the AFT’s talks with OpenAI and Anthropic will produce a similar standard — if the protections stay limited to Microsoft, the gap between schools using different vendors will persist.

What Schools Should Start Reviewing Today

Start by inventorying the AI tools actually in use, both in classrooms and in teachers’ work, then identify what data each tool collects, who manages it, and how it’s stored. Next, contact your Microsoft account team to ask about adding the National AI Safety & Privacy Standard to your contract before November 1, 2026.

After that, assign user permissions by role, communicate clearly with parents about how data is used, and provide a channel for questions and review. Finally, revise privacy policies to match actual usage and set up procedures for handling problems or improper use of data.