Partnerships

Microsoft Signs Binding AI Safety and Privacy Standard for US Schools

mm
Add Unite.AI to your preferred sources on Google

AFT President Randi Weingarten, United Federation of Teachers President Michael Mulgrew and Microsoft Vice Chair and President Brad Smith announced the National AI Safety & Privacy Standard for schools on September 9, 2026, a signed agreement that lets US school districts add contractually enforceable AI privacy and safety protections to their Microsoft customer agreements.

The announcement, made in New York, framed the standard as a response to what it called the absence of meaningful federal and state rules governing AI in schools, and described it as the first agreement of its kind following months of negotiations. The protections are set out in a binding Memorandum of Agreement between the National Academy for AI Instruction and Microsoft Corporation, with open slots for additional AI providers to sign. Weingarten and Smith signed the agreement on September 7, 2026.

Weingarten said the agreement secures three foundational goals: protecting the privacy and data of children, giving schools real control over AI tools in the classroom, and providing transparency and information to parents. She said the unions acted because no one else, including the federal government, had stepped up. “HIPAA and FERPA never envisioned the advent of AI,” she said in Microsoft’s announcement, “and in the absence of those protections, tech companies need to take responsibility for the products they create and market to students, educators and communities.”

Smith said the standard sets a high bar for child privacy and AI safety and said Microsoft will extend the agreement to every school district across the country. Mulgrew, who leads the 200,000-member New York City AFT affiliate, said it gives families and districts the information and privacy protections they have been demanding and empowers districts to end agreements and seek damages from providers that break the rules.

Ten Binding Principles

The memorandum sets out ten core principles and states that each is a binding commitment; complying with some but not all of them is not compliance. The first principle bars the provider from using any Covered Data, defined to include prompts, AI outputs, uploaded files, behavioral signals and metadata, to train, fine-tune, benchmark or otherwise improve any AI model. The ban applies retroactively to previously collected data, binds the provider’s subsidiaries, subprocessors and third-party partners, and survives the agreement’s termination indefinitely. A narrow exception permits processing only for safety and security purposes, expressly forbids general model improvement, and requires, on request, an annual statement signed by a senior officer confirming that no Covered Data was used for training outside the exception and that nothing derived from it crossed from safety systems into other models or products.

The second principle limits data collection to what is strictly necessary to deliver the contracted product and prohibits precise geolocation tracking, behavioral tracking, keystroke logging, long-term profiling and biometric collection. Collecting data from students under 13 requires verifiable parental consent compliant with COPPA, the federal children’s online privacy law, where that consent is legally required. Under the third principle, the district and its students own all Covered Data exclusively. The provider may never sell it or use it for advertising, must provide exports in standard machine-readable formats, must delete data from active systems within 180 days of a deletion request, and must store Covered Data solely in the European Union or North America. De-identified telemetry data is carved out for security, reliability and product improvement, but the agreement forbids using it for generative-model training, profiling, personalization or advertising.

Human Oversight, Security and Enforcement

The fourth principle requires meaningful human review before any covered AI system makes decisions for educators or students. It prohibits companion-style or relationship-oriented features designed to foster emotional attachment or dependency, and it requires externally consequential agentic features, meaning capabilities that take action on a student’s behalf outside the provider’s own systems, to be disabled by default unless an authorized district administrator enables them. Providers must also maintain crisis-level protocols for high-risk content involving self-harm or violence. The Academy will instruct educators that they cannot use AI for automated grading without human review, automated disciplinary or placement decisions, emotional or psychological assessment, or behavioral surveillance.

The fifth principle requires current independent certifications, including SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001 or an equivalent, plus FedRAMP Moderate authorization where required. Providers must notify a district of a confirmed or reasonably suspected breach no later than 72 hours after becoming aware of it, and must maintain a public trust page listing certifications, audit summaries and known past security incidents affecting education customers, updated at least quarterly. If a material breach goes uncured, the Academy or AFT may revoke the provider’s participation and publicly announce the revocation.

The remaining principles require security controls including encryption and multi-factor authentication, backed by annual independent penetration testing; plain-language guides and FAQs for families within 90 days; accessibility features and fairness testing across diverse student populations, including a provider-funded independent equity analysis within 12 months; controls against feature creep and vendor lock-in, with data exportable at no cost; and permanent prohibitions on using Covered Data for training or selling it, with deletion and breach-reporting duties that outlive the contract.

The agreement runs for two years from signing and must be renewed in writing to continue; a provider may withdraw with 60 days’ written notice. An addendum records that Microsoft has not completed an independent ISO 42001 assessment for its education AI products and is targeting certification by December 31, 2027, and that the tracking prohibitions do not apply to Speaker Coach or Speaker Progress, two public-speaking coaching tools, during user-initiated speaking activities.

Availability and Union Background

The standard extends earlier AFT work. In 2024 the union released its Commonsense Guardrails for Using Advanced Technology in Schools, built around nine core principles, and in 2025 it announced the National Academy for AI Instruction to train educators in the use and misuse of AI tools. In a May speech titled “Devices Down, Eyes Up, Hands-On,” Weingarten called for a screen ban from kindergarten through second grade, a ban on student-facing AI in elementary school and a ban on social companion chatbots for students under 16. According to the announcement, similar frameworks have been adopted by the Los Angeles Unified School District and the New York State United Teachers, and, in the week preceding the announcement, by New York City Public Schools and Mayor Zohran Mamdani.

Under the agreement, each participating provider must make the standard’s substantive protections available to education customers on request within 90 days of the effective date, incorporated into an existing data privacy agreement, license or addendum. Microsoft’s fact sheet says the company will also give education leaders and families plain-language information about how its AI products work in classrooms, and states that beginning November 1, 2026, Microsoft will make the protections available to every school district in the United States, addable to new or existing agreements with no contract renegotiation or renewal required.

Sophie Denar is an AI-generated journalist at Unite.AI, covering artificial intelligence policy, regulation, and governance across global markets. Her work focuses on how national and international regulatory frameworks shape the development, deployment, and commercialization of AI technologies over the long term.

With a diplomatic and globally informed perspective, Sophie tracks policy initiatives from governments, multilateral institutions, and standards bodies, analyzing how differing regulatory approaches affect innovation, competition, and market access. She pays particular attention to cross-border implications, compliance challenges, and the balance between risk management and technological progress.

Articles authored by Sophie Denar are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, neutrality, and responsible coverage of AI policy and regulatory developments worldwide.