Microsoft’s new AI privacy rules for schools are a contract standard, not a federal mandate. On Sept. 9, Microsoft, the American Federation of Teachers and the United Federation of Teachers announced a National AI Safety & Privacy Standard that U.S. districts can ask to add to their Microsoft agreements.
The arrangement is a binding memorandum between Microsoft and the AFT’s National Academy for AI Instruction. Its protections become contractually enforceable for a district when the relevant terms are incorporated into that district’s own data-privacy, licensing or addendum agreement. The memorandum does not automatically rewrite every school’s Microsoft contract, and it does not create a new law.
Microsoft said it would extend the arrangement nationwide. Politico reported that districts could begin adding the protections to new or existing agreements on Nov. 1, without reopening their entire contracts. The memorandum says participating providers must make the standard’s substantive protections available to U.S. education customers that request them within 90 days of its effective date.
What do Microsoft’s AI privacy rules for schools cover?
The agreement has 10 mandatory principles for participating providers and applies to an opted-in customer’s covered educational AI products. It bars use of covered student and educator data to train, fine-tune or otherwise alter AI models. It also says that data cannot be sold or repurposed, while schools retain control over its use, retention and deletion.
Covered data is defined broadly in the memorandum. It includes identifiable student information, prompts, student-linked AI outputs, behavioral patterns, device identifiers, location data, memory files, audio or visual material, metadata, and data belonging to educators and administrators.
- Providers must limit data collection and cannot track students, according to Microsoft’s announcement.
- AI cannot make school decisions without human oversight.
- Providers must give families and educators accessible, plain-language information about tool operation, data collection and safeguards.
- The standard prohibits companion-style or relationship-oriented features intended to create emotional attachment or dependency.
- Security, accountability and responsible-use safeguards are required under the agreement.
The deal does allow a narrower category of data: de-identified telemetry. The memorandum permits it for security, reliability, debugging, capacity planning, service-health monitoring, aggregate performance monitoring and product improvement. It specifically bars that telemetry from generative-model training, student profiling, individual AI-output personalization, advertising, marketing and behavioral inference.
Which Microsoft products are included?
That boundary matters. The memorandum covers generative-AI services or features primarily designed and marketed for students, educators or administrators, used through authenticated educational agreements. It excludes general-purpose productivity, collaboration, communication, search, cloud, development and workplace-assistance products, even when schools license or use them.
Districts therefore need to check which education-specific AI products and contract terms are actually being incorporated. The language need not match the memorandum word for word, but the agreement says the substantive protections must be made available on request.
The standard lasts two years unless renewed in writing. Microsoft, AFT and UFT described the agreement as a response to what they called a lack of meaningful federal and state rules for AI in schools. That is their characterization; the announced standard is private contract machinery, with consequences when a district chooses to put it in the contract.
This story draws on original reporting from The Verge.