Security1 publisher3 min readPublished
AFT deal puts Microsoft's classroom AI under third-party privacy audits from November 1
The American Federation of Teachers got Microsoft to bar training on student data, ban companion features built for emotional attachment and accept outside audits. District buyers now have a written term sheet to put to every other vendor.
The Watch · Security desk

What happened
- Microsoft announced last week that it had agreed to adopt guardrails and privacy standards for its AI in schools, negotiated with the American Federation of Teachers, the second-largest US teachers union.
- Microsoft says it will not use student or educator data to train AI systems, apart from a narrow exception for data that could help protect students, and that collected data cannot be sold, advertised against or used for product development.
- The agreement prohibits AI companions or features designed to foster emotional attachment or dependency, or to keep students engaged for longer than a learning task requires.
- Brad Smith said the standards apply to all schools Microsoft holds contracts with starting Nov. 1.
- OpenAI and Anthropic said they are discussing similar pacts with the union, while Google, the dominant provider of education technology to American schools, has not said whether it will offer comparable protections.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability School buyers can now cite signed, itemised language on training data, resale, advertising and product development instead of drafting privacy terms from scratch against a vendor's own paper.
- exposure Districts running on Google's education stack sit outside this floor, so the largest installed base of school software still handles student data on whatever its existing contracts allow.
- contradiction The AFT presents the deal as a possible industry standard while Fairplay's Golin warns schools will read a data-handling floor as clearance to deploy, which are two different purchasing conclusions from the same document.
- precedent With no federal or state law on AI in schools, per Weingarten, the terms that govern student data are being set at a bargaining table, so the next vendor commitments will be won the same way.
Enforcement runs through contract law and an outside auditor. The AFT says the agreement is legally binding and requires third-party audits for compliance, and that it could set an industry standard [2]. The Associated Press account of the announcement does not name the auditors or say what happens if Microsoft fails one.
The transparency clauses require Microsoft to tell families, in plain language, how its tools work [6]. "This standard sets a high bar for child privacy and AI safety, and we'll extend this agreement to every school district across the country," Brad Smith, Microsoft's vice chair and president, said in a statement [7].
Randi Weingarten, the AFT president, called the agreement the "first of its kind" and an important step toward an industry standard in the absence of federal and state legislation on AI in schools [9]. "We want parents to have control of their kids' education. We want educators to have control of kids' education, not ed tech. And that's what this agreement is," Weingarten said [10].
The three companies engaged with the union are the three that fund its teacher training arm. The AFT's National Academy for AI Instruction, housed at the union's New York City affiliate, launched a year ago with $23 million from Microsoft, OpenAI and Anthropic [21]. All three are now inside the union process: Microsoft has signed, and OpenAI and Anthropic said they are discussing their own safety and privacy pacts [23]. Google is not among the academy's named backers [22]. Weingarten said she contacted Google directly before making the agreement public, hoping the company would become a signatory [14]. Google has not responded to an AP request for comment on whether it plans similar protections [13].
Josh Golin, executive director of the online safety nonprofit Fairplay, said the safety provisions are meaningful but will only be effective if all the AI companies sign on, and that the agreement sidesteps whether AI products belong in classrooms at all, or at what age they should be introduced [15]. "I worry that a high-profile framework like this will be misunderstood and schools will think, 'If they're doing a good job on data privacy and safety, then that means we should be using the tool,'" Golin said [16]. On the missing signatory he was blunter: "Is Google going to embrace this framework? That is a huge question" [17].
That question is live in the two districts with the most purchasing leverage. New York City and Los Angeles paused student use of AI for a year as the school year started [18], and both plan extensive audits of their education technology contracts and AI tools with a focus on data privacy, transparency and accountability [19]. The New York City ban applies to all elementary and middle school students; Los Angeles extends it through high school [20].
What to watch
- Whether OpenAI or Anthropic signs, and whether their texts match Microsoft's wording on training data and companion features.
- Google's answer to Weingarten, and whether its school contracts pick up equivalent clauses.
- What the New York City and Los Angeles contract audits produce when the one-year pause ends.