Microsoft has agreed to introduce new AI guardrails for schools in the United States after signing a National AI Safety & Privacy Standard with the American Federation of Teachers (AFT) and the United Federation of Teachers (UFT). Microsoft’s announcement was issued on September 9 and the agreement was reported by Euronews on September 15. It is scheduled to apply to Microsoft school contracts nationwide from November 1, 2026.
The agreement is a contract-based framework rather than a new federal statute. Its provisions can be incorporated into Microsoft customer agreements used by U.S. school districts and other institutions, making the commitments enforceable under those contracts. Microsoft Vice Chair and President Brad Smith said the company would extend the agreement to every school district in the country, reinforcing its commitment to a more secure future for education.
The standard prohibits AI companions and other features designed to foster emotional attachment or dependency, or to keep students engaged beyond the learning task. It also states that AI systems must not make decisions without human oversight and that students cannot be tracked.
Microsoft says student and educator data will not be used to train AI systems or AI models, except for a narrow safety-related purpose. The agreement also restricts the sale, advertising use and product-development use of data collected through covered education products. Schools retain control over data use, retention and deletion, while families and educators must receive plain-language information about how tools work, what data they collect and which safeguards apply. These requirements support data privacy, student privacy and child privacy.
Third-party audits and transparency measures are central to the arrangement. The AFT agreement says participating providers must make the substantive protections available to education customers within 90 days of the effective date when requested. The agreement also gives districts contractual remedies, including the ability to end agreements and seek damages for violations, according to Microsoft’s announcement.
For school districts and vendors, the development shifts discussion of AI governance and compliance from broad principles toward procurement language, evidence and ongoing controls. Requirements on training-data use, retention, access, human oversight and auditability affect product design, data maps, supplier management and incident-response processes. They may also influence the selection of classroom tools and other AI tools used by staff.
The controls also align with established information-security practice. ISO/IEC 27002 security controls provide implementation guidance for protecting information assets, while ISO/IEC 5259-4 addresses data quality across the machine-learning lifecycle. Nemko Digital’s reporting on building trustworthy AI likewise identifies lifecycle governance, data integrity, human oversight and accountability as relevant controls for AI-enabled products.
The U.S. Department of Education’s 2025 guidance had already highlighted privacy, responsible adoption and engagement with affected stakeholders, including parents. The new agreement supplies a vendor-specific contractual mechanism for several of those concerns, while leaving each district to decide whether and how to deploy AI and implement secure AI adoption.
OpenAI and Anthropic have said they are discussing similar safeguards with the AFT. Google, a major provider of education technology, had not announced an equivalent commitment when Euronews published its report. School districts and suppliers should therefore watch for competing frameworks, requests to add the standard to existing agreements, audit requirements, additional safeguards and changes to student-facing AI features before the November 1 implementation date.
The immediate issue for organizations is not simply whether an AI tool is available, but whether its data practices, human controls, documentation and monitoring can satisfy enforceable education-sector requirements. For schools and technology providers, effective compliance will depend on governance controls, clear guidance and a sustained commitment to protecting student access, student data and safety.