Independent essays and ideasAboutContactDeutsch

Brad Smith unveils Microsoft's enforceable AI privacy pact for US schools

Microsoft has introduced a contract-based AI safety and privacy standard that gives American school districts legal control over how student data is used, a step hailed by teachers' unions but still awaiting broader industry adoption.

Brad Smith speaking at a press conference in New York City about AI safety standards for schools

Brad Smith, Microsoft's vice chair and president, announced on 9 September that the tech giant will offer every US school district the option to embed a "National AI Safety & Privacy Standard" into its contracts. The proposal was made alongside Randi Weingarten, president of the American Federation of Teachers, and Michael Mulgrew, head of the United Federation of Teachers, in New York City, just days after the city and state announced a one-year moratorium on AI in public schools.

What the new standard entails

The 30-page standard sets out ten enforceable protections. Companies that sign the agreement must not use student data to train AI models, must not track pupils, and must ensure that any AI-driven decision is reviewed by a human. The rules also ban the sale of student data for advertising, require a 72-hour breach reporting window and prohibit AI companion chatbots for learners.

"I want to have safeguards in law to ensure that AI is used for its promise and that we guard against its dangers," said Randi Weingarten.

Districts that adopt the standard can terminate contracts and claim damages if a provider breaches the terms. Microsoft will be subject to annual certification, audit rights and mandatory remediation deadlines.

Why the move matters

More than 250 child-safety experts have called for a pause on AI in schools, arguing that existing US laws such as HIPAA, FERPA and COPPA were drafted before generative AI existed and do not address data-training concerns. By embedding privacy safeguards directly into commercial agreements, Microsoft aims to fill a regulatory gap that federal and state authorities have yet to close.

Union leaders argue the standard levels the playing field for schools that previously had little leverage over powerful tech vendors. Michael Mulgrew noted that the agreement gives districts a concrete tool to reassure parents about how their children's data are handled.

What comes next

The standard will become legally binding for any district that incorporates it into a Microsoft contract from 1 November, regardless of whether the district takes additional action. The unions hope that OpenAI and Anthropic, current partners in the National Academy for AI Instruction, will sign similar agreements soon, although neither company has responded to requests for comment.

In the broader US context, the Kids Online Safety Act, which would impose a duty of care on platforms used by minors, stalled after passing the Senate in 2024. Until comprehensive federal legislation is enacted, contract-based approaches like Microsoft's may become the primary mechanism for protecting student data.

For European observers, the development highlights the growing pressure on tech firms to adopt privacy-by-design practices worldwide, a trend that could influence future EU policy discussions on AI governance in education.