Your AI Policy Is Not a Data Privacy Plan

More than half of students now use AI for schoolwork. Fewer than half of principals have any AI policy at all, and the policies that do exist rarely govern the one thing that matters most: what the vendor does with the data.

Published August 11, 2026 • Jeff Katzman • 4 min read

Writing an AI policy has become the easy part. Sarah Hernholm reported in Forbes in July that 54 percent of students and 53 percent of teachers used AI for school in 2025, a jump of more than 15 percentage points in a single year. Meanwhile only 45 percent of principals reported having a school or district AI policy, and just 34 percent of teachers said their district had guidance addressing AI and academic integrity.

That gap is real, and it is getting attention. Ohio became the first state to require every public district to adopt a formal AI policy, with a deadline of July 1, 2026. Oklahoma has set a 2027-28 deadline of its own. Maryland has gone further and required districts to name AI coordinators and align procurement with state guidance. Districts are responding. Documents are being written.

But most of those documents answer a narrow question: may a student use AI on an assignment? That is a classroom management question. It is not a data question. And the data question is the one that carries institutional risk.

The Policy Governs the Student. Nothing Governs the Vendor.

When a student types a question into an AI tutor, that text goes somewhere. It lands in a log. It may be retained for months. It may be reviewed by a human for quality assurance. It may be used to improve a model. Very few district AI policies say anything at all about any of that, because the policy was written to regulate behavior inside the building rather than the contract that sits behind the tool.

The consequences are not hypothetical. The PowerSchool breach disclosed in December 2024 exposed roughly 62 million student records and 10 million teacher records. A Canvas LMS incident in the spring of 2026 touched more than 8,800 institutions. Neither of those was an AI failure. Both were reminders that education data concentrates fast and leaks badly, and that adding a new category of highly personal data to that pile deserves more scrutiny than a paragraph in a handbook.

The uncomfortable part: an AI tutoring transcript is more revealing than a gradebook. A grade says a student scored 68 percent. A transcript says which concept the student could not follow, how many times they asked for help, what language they switched to when they got frustrated, and what they typed at 11:40 on a Tuesday night. FERPA was written in 1974. It was not written for that.

Legislators Have Noticed. Procurement Has Not Caught Up.

State lawmakers are moving toward the contract layer. California AB 1159 would prohibit student data from being used to train AI models unless doing so directly benefits the school. Idaho SB 1227 requires specific data privacy protections for AI tools used in schools. Across 31 states, 134 AI-in-education bills were introduced this session, with data privacy among the most common themes.

This is the right direction, but legislation moves slower than adoption, and coverage remains uneven. A district in a state with no such bill still needs an answer today, because teachers are already using these tools whether or not procurement has blessed them. The practical answer is not to wait for a statute. It is to put the requirements in the purchase agreement.

Five Questions Every AI Vendor Should Answer in Writing

  • Is student data used to train models? The answer should be no, stated in the contract rather than in a marketing page.
  • What is the retention period, and who can delete data? The district should be able to trigger deletion without filing a support ticket and hoping.
  • Who are the subprocessors? Most AI tools call a model provider. Name it, and name what it receives.
  • What is the audit right? A privacy promise no one is permitted to verify is a marketing claim.
  • What happens at contract termination? Export format, deletion certification, and timeline should all be specified.

Privacy Is an Architecture Decision, Not a Disclosure

The strongest privacy posture is the one that reduces how much sensitive data leaves the institution in the first place. That is a design choice made long before a contract is signed. Tools that run inside the systems a school already governs inherit the controls the school already built. Tools that require a separate student account, a separate login, and a separate data store create a second copy of the student record in a place the district does not control.

This is why LTI integration matters for reasons that have nothing to do with convenience. When an AI tutor launches inside Canvas, Moodle, D2L, or Blackboard, identity stays with the LMS, the roster stays with the LMS, and the district keeps the governance surface it already audits. Core-LX built the Socrat platform to deploy that way in hours, and to be FERPA compliant and WCAG 2.1 AA accessible from the start, because retrofitting either one after launch is far harder than designing for it.

None of this makes privacy risk disappear. It makes the risk legible, contractual, and reviewable, which is the most any institution can reasonably ask. The districts that will handle the next five years well are not the ones with the longest AI policy. They are the ones who can say precisely where every student keystroke goes, how long it stays there, and who is allowed to look at it.

Adoption is no longer the interesting question. Custody is.

Ask Us the Five Questions

Socrat deploys inside the LMS you already govern, in hours, via LTI. We will answer every data question in writing before you sign anything.

Read the Full Article

Read "Schools Race To Write AI Policies. What About Student Data Privacy?" on Forbes

Share Your Thoughts

#StudentDataPrivacy #AIinEducation #EdTech #FERPA #K12 #AIPolicy #HigherEd

About Core Learning Exchange: We provide turnkey Career and Technical Education (CTE) solutions for grades 6-14, offering 450+ courses from 20+ providers aligned to state standards and industry certifications. Our AI platform uses proven Socratic methodology to develop critical thinking skills through personalized, adaptive learning—deployed in hours via LTI integration.