A week after New York City announced a one-year moratorium on AI in public schools, Microsoft announced it’ll be giving every school district in the country the option to dictate its own AI privacy and safety rules within its contracts—and the unions behind the deal say they want OpenAI and Anthropic to sign on next.
On Wednesday, Microsoft Vice Chair and President Brad Smith announced the plan alongside American Federation of Teachers President Randi Weingarten and United Federation of Teachers President Michael Mulgrew, mere miles from where New York City Mayor Zohran Mamdani and New York Governor Kathy Hochul first announced the AI moratorium for the nation’s largest school system.
The “National AI Safety & Privacy Standard” will be legally enforceable once written into a district’s Microsoft agreement. It does not ban AI use in classrooms: it gives each school district enforceable controls over how AI products handle student data.
The agreement lets school districts write the protections directly into their Microsoft contracts. Under the standard, companies cannot use student data to train AI models, cannot track students, and cannot let AI make decisions without a human reviewing them. Districts that sign on can also cancel contracts and seek damages if a company breaks the rules. These were some of the major reasons why more than 250 child-safety experts and groups called for an AI moratorium in schools back in April.
“I want to have safeguards in law to ensure that AI is used for its promise and that we guard against its dangers. This is a very important first step,” said Weingarten, who added OpenAI and Anthropic, both partners alongside Microsoft in the unions’ National Academy for AI Instruction, may join Microsoft’s pledge. “They both have expressed willingness to do this kind of agreement, and I am hopeful that they will sign soon.” Neither OpenAI nor Anthropic responded to Fortune’s requests for comment.
Weingarten said the standard fills a gap left by federal and state governments. “We have forged a hard-fought, iron-clad privacy agreement with real teeth that protects students and families, because no one else, including the federal government, has stepped up to do the real work,” she said.
‘Sunshine transparency’ #
The Microsoft president said the protections take effect for every school district Microsoft works with on November 1, whether or not a district takes any action to adopt them. “It is 30 pages, but in some ways it comes down to three words: privacy, safety, and transparency,” Smith said. Microsoft faces annual certification requirements and audit rights under the standard, and must fix security issues within a set deadline. “I actually think the best dose of medicine, if you will, for anybody is sunshine transparency.”
The standard lists 10 enforceable protections in total, including bans on selling student data or using it for advertising, a 72-hour breach reporting requirement, and a prohibition on AI companion chatbots for students.
Mulgrew, who represents roughly 200,000 members in New York City, said the agreement gives districts leverage they lacked before. “It starts to level the playing field in a competitive, ever-changing arena that lacks the guardrails our children and school communities need,” he said.
“We have been clear that we do not believe [AI use in] K through 8 is appropriate at this point in time,” Mulgrew said of the city’s AI moratorium. “Teachers need to start looking into these platforms themselves and start deciding what is appropriate at each grade level.”
“A parent comes up to me who’s working two jobs in New York City, trying to make ends meet,” Mulgrew said, “And they say, ‘I see you using an AI. What’s happening with my student’s data?’ What happens if a teacher can’t say that and can’t give that assurance to a parent?”
Weingarten first called for a K-2 screen ban, a ban on student-facing AI in elementary school, and a ban on companion chatbots for students under 16 in a May speech. She pointed to the limits of existing law in explaining why the union pursued a contract-based approach instead. “HIPAA and FERPA never envisioned the advent of AI,” she said.
There is a broader gap in federal law. The Children’s Online Privacy Protection Act, or COPPA, requires parental consent before companies collect data from children under 13, but it predates generative AI by more than two decades and doesn’t address how AI models are trained. The Kids Online Safety Act, which would impose a broader duty of care on platforms used by minors, passed the Senate in 2024 but has stalled since being reintroduced last year. Americans are overwhelmingly distrusting of existing platforms or the government to protect kids online, even as age-verification laws spread state by state.
breaks the traditional barrier between audience and newsroom. The show transforms
Fortune Daily Fortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders.
Watch here.