All insights
Industry newsSep 11, 2026Source: National Academy for AI Instruction, AFT, UFT and Microsoft

School AI agreement turns safety and privacy rules into contract terms

A school district contract links student data controls, human review and AI provider accountability

The American Federation of Teachers, the United Federation of Teachers and Microsoft announced a National AI Safety & Privacy Standard for Schools on 9 September 2026. The 31-page memorandum is more than a voluntary list of principles. It is binding between the National Academy for AI Instruction and a participating AI provider, and it gives US school districts a route to request equivalent protections in their own contracts.

The standard covers educational AI products used by authenticated students, educators and administrators. It does not automatically cover every general-purpose productivity or cloud product bought by a school. A district must request the protections and incorporate applicable terms into its agreement before it can rely on contractual enforcement.

The publication matters because it turns familiar AI governance goals into testable procurement requirements. It addresses data use, retention, human oversight, agentic authority, privacy assessments, security incidents, audit records and remedies. Microsoft and the unions call the terms legally enforceable. Independent education coverage confirms the contract mechanism, while the exact scope comes from the signed memorandum.

What the agreement requires

The memorandum contains ten mandatory principles for covered educational AI products. It prohibits using covered student or educator data for general model training, with a narrow exception for specified safety and security functions. It requires data minimization, customer control over retention and deletion, security controls, incident response, transparency and meaningful human review.

The standard defines an agentic or action-taking feature as a capability that can initiate, approve, transmit, modify or execute actions on behalf of a user. Before a material new feature or data practice is activated, the provider must complete a privacy impact assessment when the change could increase student privacy or safety risk. The examples include new agentic authority, biometrics, profiling and significant retention changes.

The agreement also requires records that can demonstrate compliance. Participating providers must support audits, document certain safety and security processing, and provide plain-language information about data handling and product changes. Those duties make the standard operational rather than purely aspirational.

Human review is tied to consequential decisions

The memorandum says AI may support decisions, but it cannot independently make high-stakes determinations about discipline, academic placement, disability accommodations, employee evaluation or other protected outcomes. A qualified person must review relevant information and retain responsibility for the decision.

That boundary is useful beyond education. Human oversight is strongest when it is connected to a defined action, evidence package and responsible owner. A generic statement that a person remains in the loop is weaker than a rule that identifies which decisions require review, what information the reviewer sees and how the final outcome is recorded.

Maetra's guide to human approval for high-risk AI agents explains how to attach review to the exact consequence instead of an entire application. School districts can apply the same pattern when translating the memorandum into local procurement controls.

Districts still need implementation evidence

Adding clauses to a contract does not by itself prove that a vendor or school is following them. Districts need an inventory of covered products, configured features, connected data sources, users, subprocessors and retention settings. They also need owners for privacy assessments, incident notices, access reviews and renewal decisions.

A practical evidence set should include the signed addendum, the provider's current product scope, data-flow records, admin settings, deletion tests, privacy impact assessments, human-review procedures, incident reports and remediation records. Evidence should be refreshed when a product adds memory, new connectors or action-taking capabilities.

The AI compliance evidence checklist offers a starting structure for assigning owners and checking freshness. The AI audit log guide explains how event records can preserve what happened after a policy or contractual rule is applied.

Important limits

The standard is not a federal law and does not automatically bind every technology company. It applies to providers that sign the agreement and to eligible educational products within its definitions. District-level protections become enforceable through the relevant customer agreement.

The memorandum also allows limited processing of covered data for necessary safety and security functions, subject to purpose, minimization, retention and audit conditions. Teams should not summarize the rule as an absolute ban without that qualification.

Neither the announcement nor the agreement proves that every participating product already satisfies each control in practice. Schools should verify implementation before deployment and again after material changes.

Maetra analysis

The agreement is a useful model for turning AI principles into accountable operations. Its strongest feature is not a slogan. It is the connection between defined scope, mandatory controls, evidence, contractual remedies and renewal.

For governance teams, the next step is to map each clause to a product owner, technical control, evidence item and review date. For agentic features, districts should separately inventory what the AI can read, decide and change. They should require human review for protected decisions, verify data and retention boundaries, and preserve enough evidence to show whether the contract was followed.

Sources

school AI safetystudent privacyhuman oversightAI procurement