As Schools Rush to Adopt AI, Student Data Privacy Lags Behind

As school AI usage climbs past 50%, policy and data privacy protections lag. Learn about the federal legislative gaps and how to safeguard student data.

Friday, July 24, 2026

Key Takeaways

  • A 2025 RAND Corporation survey found that 54% of students and 53% of teachers use AI for schoolwork, but only 45% of school principals report having district-wide AI policies.
  • Ohio became the first state to legally mandate that all public school districts adopt a formal AI policy by July 1, 2026.
  • California's proposed Assembly Bill 1159 aims to block edtech platforms from using student data to train artificial intelligence models, and it gives families a limited right to sue for violations.
  • Recent major edtech security breaches include a PowerSchool exploit that exposed over 62 million student records and a Canvas vulnerability that leaked private messages across thousands of institutions.

More than half of all students and teachers now use artificial intelligence for schoolwork, yet a massive gap remains in school policies safeguarding student data. As schools scramble to adopt guidelines, parents and educators are left wondering how these tools protect children's personal records. While states are beginning to regulate classroom tech, the current framework leaves many families exposed.

What Happened

In response to the rapid integration of AI, Ohio became the first state to mandate that every public school district adopt a formal AI policy by July 1, 2026. This mandate, enacted under House Bill 96, is explained in detail by the law firm Kohrman Jackson Krantz. While the Ohio Department of Education and Workforce released a model AI policy, individual districts must choose how to implement these rules. Some, such as Pickerington Local Schools, are restricting students to closed AI environments to protect their data, according to reporting by NBC4 WCMH-TV.

Meanwhile, California is considering Assembly Bill 1159, which aims to prohibit educational technology companies from using student data to train generative AI systems, as documented by Digital Democracy. The bill faces opposition from the Software & Information Industry Association, which argues that banning data usage could harm personalized learning innovation.

The Bigger Picture

Classroom technology usage has surged far ahead of administrative oversight. According to a RAND Corporation report, 54% of students and 53% of teachers used AI in 2025, yet only 45% of school principals reported having an active school or district AI policy. Other research, such as polling by the Center for Democracy and Technology reported by EdSurge, suggests that student and teacher usage could be as high as 85%.

This "permission-without-policy" gap creates significant risks because federal guidelines have not kept pace with modern technology. The Family Educational Rights and Privacy Act (FERPA), the primary federal law governing student privacy, was written in 1974. It has no explicit cybersecurity requirements and does not address how modern AI models train on user data. Students are also finding ways around existing guardrails. As we previously reported on students outsmarting school web filters, children often bypass administrative restrictions to use unapproved, open AI tools that harvest personal information.

What This Means for Families

When schools lack clear policies, student data is frequently left vulnerable to security threats. The consequences of these gaps are already visible. A massive security breach disclosed by DeepStrike exposed over 62 million student records held by PowerSchool. More recently, a breach at Canvas exposed student identification numbers and private messages across thousands of institutions, according to a U.S. Department of Education alert.

Some edtech vendors have faced allegations of improper collection practices. In one instance, a whistleblower alleged that the school chatbot AllHere collected student data in violation of school district rules, as reported by The Washington Times. Without state-level laws or strict local policies, families have very little recourse if a vendor uses their child's essays and other personal details to train corporate AI models.

What You Can Do

First, request a copy of your school district's AI policy. Verify whether it specifically addresses how vendors store and delete student data.

Next, ask school administrators if agreements with platforms like Canvas or PowerSchool prohibit those companies from using student work to train AI models.

Finally, talk to your children about using only school-approved AI portals. Explain why they should never enter personal details or essays into public chatbots.

Share: