Field Notes / 03  ·  Data Privacy

What FERPA actually requires before your district touches an AI tool.

There is no AI exception to FERPA. Before any tool sees student data, three things have to be true — and one contract clause matters more than all the others.

Matthew Kelso, Ed.D  ·  July 2026  ·  6 min read

A teacher pastes a student's essay into a free chatbot to get feedback faster. The essay has the student's name on it. In that moment, an education record left the district's control and landed on a commercial server under terms nobody read. That's the whole FERPA-and-AI problem in one sentence, and it's happening in most buildings right now, mostly out of good intentions.

FERPA was written in 1974 and it applies to AI tools the same way it applies to a gradebook or a filing cabinet: if a technology accesses, stores, processes, or generates content from education records, the law is in play. No AI exception, no free-tier exception, no "the teacher was just experimenting" exception.

The school official exception, in plain terms

Districts don't get parental consent for every vendor — they rely on FERPA's "school official" exception. It lets a district share education records with a third party when three things are true. The vendor performs a function the district would otherwise do itself. The district keeps direct control over how the records are used and maintained. And the vendor uses the records only for that authorized purpose — nothing else.

Each condition does real work. "Direct control" means a signed agreement, not a terms-of-service checkbox a teacher clicked. "Only for the authorized purpose" is where AI vendors get into trouble, because their business model often wants the data for something more.

The clause that matters most: model training

When students type into an AI tool, many vendors reserve the right to use those inputs to improve or train their models. Read that against the exception above: training a commercial model is not the educational purpose the district authorized. A vendor that trains on student inputs has left the school-official lane, and the district — not the vendor — holds the FERPA problem.

So the single most important line in any AI contract review is the one about training. You're looking for an explicit commitment: student data will not be used to train or improve the vendor's models, ever, including the "de-identified" carve-out — because de-identification claims deserve their own scrutiny. Education-tier products from the major AI companies generally make this commitment. Free consumer tiers generally don't. That difference is the whole reason education tiers exist.

The minimum bar before a tool goes live

A signed data-processing agreement. Purpose limitation, the no-training clause, retention and deletion timelines, breach notification, and a list of subprocessors. If the vendor won't sign one, the evaluation is over.

A COPPA check for under-13 use. FERPA isn't the only law in the room. If students under 13 will use the tool directly, COPPA's consent requirements apply to the operator — and "the school consented for the parents" only stretches so far. Several state frameworks sidestep this entirely by keeping open chatbots out of elementary grades. That's not timidity; it's clean compliance.

Your state law, which is probably stricter. California's SOPIPA, New York's Ed Law 2-d, Illinois' SOPPA — most states now layer requirements on top of FERPA, and some (New York especially) require specific contract language and public posting of agreements. The federal floor is not the ceiling.

An inventory of what's already in use. The audit that matters isn't the tools you approved — it's the ones teachers adopted on their own. Districts are expected to show proactive protection now, not incident response after the fact. A one-page approved-tools list, updated each semester and actually communicated, prevents most shadow adoption by giving teachers a sanctioned path.

What to tell teachers, this week

Keep it to two rules while the formal review catches up. Nothing with a student's name, face, voice, or identifiable details goes into any tool the district hasn't approved. And approved tools get used through district accounts, not personal ones — the protections live in the district's agreement, and a personal login walks right past them.

One caveat that belongs in writing: we're practitioners, not your attorneys, and this note isn't legal advice. What it is: the checklist that makes the eventual conversation with your board attorney short. If you want help building the vendor review process or the staff guidance to go with it, that's a conversation we're glad to have.

Auditing your current tools?

Start with the readiness checklist