This week, the principle that student data should not be fed to AI models moved from request to enforceable reality on two fronts. Microsoft signed a first-of-its-kind national standard with the two largest teachers' unions that lets school districts bake privacy protections into their Microsoft contracts and seek damages if the company misuses student data. Two days later, California made the same no-training rule state law, as Governor Newsom signed Assembly Bill 1159, which also bars selling student data and closes loopholes in the state's decade-old student-privacy statute. But the harder question, adoption, split into view immediately: OpenAI and Anthropic said they are in talks to sign comparable pacts, while Google, the dominant provider of school technology, which just expanded its Gemini chatbot to K-12 students, has said nothing. The throughline is that enforceable protection is arriving through law and contract, but it reaches only the vendors that actually sign, and the platform most students use every day is, so far, the conspicuous holdout.
1
Breaking
Microsoft and the two largest teachers' unions sign a first-of-its-kind enforceable student data standard, letting districts seek damages if it misuses student data
Microsoft, American Federation of Teachers · September 9, 2026
What happened
On September 9, 2026, the American Federation of Teachers, the United Federation of Teachers, and Microsoft announced a National AI Safety and Privacy Standard for U.S. schools, described as the first agreement of its kind and reached after months of negotiation. The core of the agreement is that its protections are legally enforceable: districts can incorporate them directly into new or existing Microsoft customer agreements, with no renewal or renegotiation required, making them contractual terms Microsoft can be held to. The standard rests on three priorities. On privacy, student and educator data will not be used to train AI models, sold, or repurposed, and schools retain control over how data is used, retained, and deleted. On safety, AI systems must include human oversight, avoid harmful or manipulative design, and meet security standards. On transparency, companies must give parents and educators clear, plain-language information about how tools work, what data they collect, and what protections apply. According to reporting that reviewed the underlying agreement, a district that determines Microsoft has materially violated the terms can terminate its agreement and pursue damages, and the protections become available to districts on November 1, 2026. The protections are set out in a binding memorandum of agreement between the National Academy for AI Instruction and Microsoft, with open slots for other AI providers to sign. Microsoft said it would extend the agreement to every school district in the country.
Who's affected
Every district that uses Microsoft products, and, as a template, every district negotiating with any AI vendor. The significance is less the specific terms, many of which mirror what careful districts already seek, than the enforceability: this converts a set of privacy principles into contract terms with a remedy attached, so that a violation is a breach a district can act on rather than a broken promise it can only complain about. It directly answers the problem this bulletin flagged last week, when a Utah audit found that signed privacy agreements often go unverified and unenforced; here the enforceability, including the right to seek damages, is built into the agreement itself. The open invitation for other AI providers to sign the same standard is the part worth watching, because it could establish a portable, district-favorable baseline that pressures the rest of the market.
Compliance Exposure
The agreement reduces exposure for districts that adopt it, but only if they actually do, and only if they understand what it does and does not cover. A district that assumes it is protected without incorporating the standard into its Microsoft agreement gets none of the enforceability. Federal and state monitors, and parents, would ask: Has your district actually added the National AI Safety and Privacy Standard to its Microsoft customer agreement, or merely noted that it exists? Do you know which of your other AI vendors have not signed a comparable enforceable standard, and what your remedy is if they misuse student data? Does your team understand the material-violation threshold and how you would document and act on a breach? The exposure is no longer only whether protections exist on paper, but whether a district has taken the step to make them enforceable and knows how to use the remedy.
Recommended Action
If your district uses Microsoft products, treat November 1 as an action date: confirm with your team and counsel how to incorporate the National AI Safety and Privacy Standard into your existing Microsoft customer agreement, since the protections and the right to seek damages only attach if you take that step. Then use the standard as a benchmark for every other AI vendor: ask which of them will agree to the same enforceable terms, no training on student data, no selling or repurposing, human oversight, transparency, and a remedy for material violations, and treat a vendor's refusal as information. Make sure the people who manage vendor relationships understand the material-violation threshold and know how to document and escalate a suspected breach, because an enforceable right is only worth what a district is prepared to enforce.
Workflow Impact
Vendor Management: Incorporate the enforceable standard into your Microsoft agreement by November 1, benchmark every other AI vendor against the same terms, and train staff on the material-violation threshold and how to act on a breach2
California makes the no-training rule state law: AB 1159 bars companies from using student data to train AI or selling it, closing loopholes in the state's decade-old privacy statute
Office of Governor Gavin Newsom, CalMatters · September 10, 2026
What happened
On September 10, 2026, Governor Gavin Newsom signed Assembly Bill 1159, by Assemblymember Dawn Addis, as one of thirteen laws in a package aimed at protecting children from technology-related harms. AB 1159 prohibits technology companies from using student data to train or develop AI models, and provides that any company that knows its products are used in schools, and whose products are designed or marketed to students, is barred from selling the data it collects or using that information for anything beyond the student's education. This bulletin flagged AB 1159 as it advanced through the legislature earlier this session; it is now law. The measure expands California's landmark 2014 education technology privacy statute, which limited how companies use data from students in prekindergarten through twelfth grade but applied only to companies that "primarily" serve students and were "designed and marketed" for them. That wording created a loophole that let widely used products, such as general-purpose tools that happen to be popular in classrooms, argue they were not covered. AB 1159 closes that gap by reaching any company that knows its products are used in schools, and it extends the same protections to the data of college students. The new rules take effect next year. Unions representing California teachers, nurses, and college professors supported the bill; the technology group TechNet and the California Chamber of Commerce opposed it.
Who's affected
Every education technology company operating in California, and every district that relies on them, along with districts nationally that will feel California's gravitational pull on vendor behavior. Because California is the largest market and its 2014 law became a de facto national standard, a company is unlikely to build one data practice for California students and another for everyone else, which means the no-training and no-selling rules are likely to propagate well beyond the state. For districts, the most important shift is that the law reaches products that previously escaped the old statute by claiming they were not primarily designed for students, the same general-purpose and embedded tools that are hardest to inventory. The extension to college data also signals that student-privacy protection is no longer treated as a K-12-only concern.
Compliance Exposure
For California districts, AB 1159 raises the floor and, with it, the expectation that districts know which vendors are now covered. A district that cannot say whether a widely used tool falls under the expanded law, or whether its vendors use student data to train AI, will struggle to demonstrate compliance once the rules take effect next year. Federal and state monitors would ask: Which of the tools your district uses are now covered by the expanded statute, including general-purpose products that were previously excluded? Have you confirmed, in writing, that your vendors do not use student data to train AI models or sell it, as the law now requires? For districts outside California, the question is whether you are relying on vendor practices that California is now moving to prohibit, and whether your contracts would meet the standard California has set. The law converts a widely recommended contract term into a legal requirement, and the exposure is being unable to show you meet it.
Recommended Action
California districts should inventory their edtech tools against the expanded law before it takes effect next year, paying particular attention to general-purpose and embedded products that the old statute let off the hook, and confirm in writing that each covered vendor neither trains AI on student data nor sells it. Districts everywhere should treat AB 1159 as the direction of travel: the no-training and no-selling terms are becoming legal requirements, not just good practice, and writing them into your contracts now positions you ahead of the regulation that California tends to spread nationally. Pair this with the enforceable Microsoft standard from this week's lead item, because together they show the same principle arriving through two doors at once, law and contract, and a district that builds both into its vendor management will be covered whichever door its state walks through.Workflow Impact
Compliance & Reporting: Inventory edtech tools against the expanded California statute, confirm in writing that covered vendors do not train AI on or sell student data, and align contracts to the no-training standard before it takes effect3
The standard's real test is adoption, and it split at once: OpenAI and Anthropic move to sign comparable pacts while Google, which just expanded Gemini to K-12 students, stays silent
Associated Press · September 14, 2026
What happened
An Associated Press report published September 14, 2026, examined whether the Microsoft privacy standard would spread across the AI industry, and found the answer already dividing. OpenAI and Anthropic both said they were in talks with the American Federation of Teachers to reach their own safety and privacy pacts. OpenAI called the Microsoft agreement an important milestone for AI safety and privacy in schools and said it looked forward to finalizing its own agreement; Anthropic said it was working with the union to shape a gold standard for safety and privacy. AFT President Randi Weingarten said she had contacted Google directly before the announcement, hoping it would become a signatory. But Google, which the report described as the dominant provider of education technology for America's schools, had not said whether it would offer similar protections and did not respond to the Associated Press. The context sharpening the question is recent: in August, Google turned on its Gemini chatbot for many K-12 students using Google Classroom, which the company says is used by 150 million teachers and students worldwide, reversing its prior policy of allowing Gemini only for students 18 and older. Josh Golin of the online safety nonprofit Fairplay warned that the standard will only be effective if the tech giants sign on, and that a high-profile framework risks being misread by schools as a signal that a tool is safe to use.
Who's affected
Every district, because the standard's protections reach only the vendors that actually sign it, and the vendor most students use every day has not. Google Workspace and Classroom are ubiquitous in American schools, which means a district running on Google does not automatically receive the no-training, no-selling, audit, and transparency protections in the Microsoft standard. Google's August decision to enable Gemini for K-12 students, where it had previously been limited to those 18 and older, puts more student interaction with AI on precisely the platform that has made no comparable enforceable commitment. The risk Golin names is concrete: a district could see the Microsoft standard, conclude the privacy problem is being solved, and overlook that its own dominant AI exposure, Google, sits outside it. The standard is a meaningful floor, but only for the companies that adopt it.
Compliance Exposure
The exposure is a false sense of coverage. The Microsoft standard binds Microsoft, and, if they follow through, OpenAI and Anthropic, but not Google or the thousands of smaller AI vendors districts use. A district that treats one vendor's strong commitment as protection across its whole AI footprint is exposed exactly where it is largest. Federal and state monitors would ask: For the AI tools your students use most, especially Google Gemini through Classroom, what enforceable privacy commitments actually exist? Have you confirmed whether Gemini is turned on for your students, and at what ages, given Google's August change? Are you using the Microsoft standard as a floor to demand from every vendor, or mistaking it for coverage you do not have? The gap between the tools that have signed and the tools students actually use is the exposure.
Recommended Action
Do not let one vendor's strong standard become a blind spot for the rest. First, determine whether Google Gemini is enabled for your students in Classroom and at what ages, since Google's August change turned it on for K-12 where it had been limited to 18 and older; decide deliberately whether to leave it on. Then use the Microsoft standard as a benchmark you demand from every AI vendor, Google included: no training on student data, no selling or advertising use, third-party audits, and plain-language transparency. Track which vendors sign the AFT standard or offer equivalent enforceable terms, and treat silence, as from Google so far, as a gap to manage rather than assume away. The standard's value to your district depends entirely on which of your vendors actually adopt it, so map your real AI exposure to the commitments that actually cover it.Workflow Impact
Vendor Management: Confirm whether Gemini is enabled for your students and at what ages, benchmark every AI vendor including Google against the Microsoft standard, and track adoption rather than assuming coverageMicrosoft and teachers’ unions announce an enforceable National AI Safety and Privacy Standard for schools
[1] Microsoft (Source Newsroom). “AFT, UFT and Microsoft announce ‘National AI Safety & Privacy Standard’ for schools to protect students, families and educators.” September 9, 2026. https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/
[2] American Federation of Teachers. “AFT, UFT and Microsoft Announce ‘National AI Safety & Privacy Standard’ for Schools.” September 9, 2026. https://www.aft.org/press-release/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-schools-protect
California enacts AB 1159, barring use of student data to train AI and closing edtech privacy loopholes
[1] Office of Governor Gavin Newsom. “Governor Newsom signs the strongest child safety chatbot and social media laws in the nation.” September 10, 2026. https://www.gov.ca.gov/2026/09/10/governor-newsom-signs-the-strongest-child-safety-chatbot-and-social-media-laws-in-the-nation/
[2] CalMatters (Adam Echelman). “Tech companies are selling kids’ data. A new California law aims to protect their privacy.” September 11, 2026. https://calmatters.org/economy/technology/2026/09/students-data-california/
The enforceable standard’s real test is adoption: OpenAI and Anthropic in talks, Google silent
[1] Associated Press (Jocelyn Gecker), via KSAT. “Microsoft commits to sweeping AI privacy rules for students. Will other tech giants follow?” September 14, 2026. https://www.ksat.com/business/2026/09/15/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/
[2] Associated Press (Jocelyn Gecker), via WHIO. “AI in schools leads to pressure on tech companies around data privacy.” September 14, 2026. https://www.whio.com/news/business/microsoft-commits/QKTFBC242Q27FDOCA6JZ4LR444/