Microsoft Commits to Sweeping AI Privacy Rules for Students
Beginning Nov. 1, every U.S. school district can add contract terms barring Microsoft from using student data for AI training, advertising, or product development.
Microsoft signed a binding agreement that bars the company from using student and educator data collected through its education AI products for AI training, advertising, or product development.
The AI Safety & Privacy Standard for Schools applies directly to Microsoft’s work with the National Academy for AI Instruction, an educator-training initiative led by the American Federation of Teachers. The agreement also requires Microsoft to offer equivalent terms to every U.S. school district.
Other districts are not automatically covered. A district must add the terms to its Microsoft contract before it can enforce them. Adopting the terms does not create new duties for school districts or require them to change how they use Microsoft’s products.
The rules cover Microsoft services or features that use generative AI and are developed and marketed primarily for students, educators, or school administrators. They do not cover general-purpose Microsoft products a school uses.
Microsoft restricts use of student data
Microsoft cannot use student or educator information collected through its education AI products to train or improve its AI models. The same restriction applies to data belonging to educators and school administrators who use those products.
A narrow exception allows Microsoft to process the minimum data needed to detect threats to students or the security of its education products. Microsoft may use that data only for the specific safety or security purpose, not to improve its general AI models or develop unrelated products.
Microsoft also cannot sell the data or use it for advertising. Its education AI products may collect only the information needed to provide the service a school purchases.
Participating schools can decide how long Microsoft retains the data, order its deletion, and export it when changing providers. Without a school’s written approval, Microsoft cannot continuously track students’ locations or attention, create long-term profiles, or collect biometric information.
Schools control how the products are used
Microsoft’s covered education AI products cannot make decisions for students or educators unless an educator or authorized school administrator reviews or approves the decision. For the National Academy, the agreement prohibits AI from making disciplinary decisions and bars automated grading without review.
Microsoft also cannot offer students features intended to form emotional relationships or encourage dependence. Features that can send messages, submit work, make purchases, or take other actions outside Microsoft’s systems must be turned off by default unless a school administrator approves their use.
Microsoft must give families plain-language information explaining how its education AI products work, what information they collect, and how schools can restrict their use. The company must notify an affected district within 72 hours after learning of a confirmed or reasonably suspected breach involving student or educator data.
Microsoft announced the standard with the American Federation of Teachers and the United Federation of Teachers. Microsoft and the National Academy for AI Instruction signed the agreement.
In a Sept. 16 statement, Microsoft invited other technology companies to adopt the same rules. The company did not identify another provider that had signed the standard.