Microsoft is drawing a firm line around school data. Its new agreement with teachers' unions says student and educator information cannot be used to train or improve AI models, aside from narrow safety and security exceptions.
The National AI Safety & Privacy Standard, negotiated with the American Federation of Teachers and United Federation of Teachers, sets 10 legally enforceable protections for Microsoft AI products used in schools. Beginning Nov. 1, US districts can add the terms to new or existing Microsoft customer agreements, covering data use, tracking, security, transparency, and human oversight.
For schools, the important part is that the rules can become contract terms, not just product promises. The agreement also reaches beyond model training, setting limits on how data can be collected, used, retained, and shared.
Microsoft’s agreement adds 10 enforceable protections
Politico reported that Microsoft agreed not to track students and not to let its AI make decisions in schools without human oversight. The company must also publish reports, provide annual certifications, and meet deadlines for fixing security issues.
Microsoft said schools will retain control over how their data is used, kept, and deleted. Families and educators must also receive clear information about what data is collected, how AI tools work, and what safeguards are in place.
AFT President Randi Weingarten said the union wanted protections with “real teeth,” arguing that voluntary commitments were not enough. If Microsoft violates contract terms that include the standard, schools could pursue remedies for breach of contract.
The standard covers more than names and grades
The agreement uses a broad definition of student data. According to Education Week, it can include names, grades, behavioral records, writing prompts, memory files, work outputs, keystrokes, and eye-tracking data when that information could reasonably identify or be linked to a student.
The standard also calls for encryption and access controls, independent security testing, breach-response plans, and additional review for higher-risk uses such as biometrics, memory, profiling, and tracking. AI companions designed to simulate ongoing social or emotional relationships with students are banned, and breaches must be reported within 72 hours.
What eWEEK found: Microsoft still allows some data use
Microsoft’s promise does not make all school-related data off-limits. Education Week reported that de-identified telemetry cannot be used to train AI models, create advertising, build student profiles, or infer student behavior, but it can still be used for debugging, security, or product improvement.
| Data use | Status under the agreement |
| Training AI models on student or educator data | Prohibited, aside from narrow safety and security exceptions |
| Advertising or student profiling | Prohibited |
| Tracking identifiable students | Restricted |
| De-identified telemetry for debugging or security | Permitted |
| De-identified telemetry for product improvement | Permitted under the reported terms |
| Higher-risk uses such as biometrics, profiling, memory, or tracking | Subject to additional review |
“Not used for AI training” does not mean the data is off-limits for every other purpose. Schools still need to know what telemetry is collected, how it is de-identified, how long it is retained, and which operational uses Microsoft still permits.d.
Education Week also noted that de-identified information can sometimes be traced back to individuals when AI systems combine background facts, writing style, and other identifying clues.
The agreement also stops short of creating a nationwide privacy law. Its protections become enforceable when school districts incorporate the standard into Microsoft customer agreements, meaning adoption will determine how widely the rules actually apply.
AFT wants the deal to become an industry standard
Politico highlighted that the AFT is already negotiating with OpenAI and Anthropic about adopting similar provisions.
According to Engadget, the union has said it wants the Microsoft agreement to serve as an industry standard rather than remain a one-company arrangement.
If other major AI vendors adopt comparable terms, school districts could gain a more consistent baseline for negotiating privacy, security, and human-oversight requirements across providers.
For now, Microsoft’s deal gives districts a clearer framework for deciding what AI tools can do with school data and what protections belong in the contract before those tools reach classrooms.
Microsoft is also reshaping the AI behind its products, replacing some OpenAI models with its own technology in PowerPoint, Bing, and OneDrive.


