California has enacted a strict new law that stops education technology companies from using student data to train artificial intelligence models. Signed by Governor Gavin Newsom, Assembly Bill 1159 aims to close major loopholes in existing laws and protect students from preschool through college. The law shifts the burden of privacy protection from school districts to tech vendors, while giving families a path to legal action.
What Happened
On September 10, 2026, Governor Gavin Newsom signed Assembly Bill 1159 to restrict how educational technology companies collect and use student data. As we previously reported, the bill sailed through the legislature with strong support from unions representing teachers, nurses, and professors. According to the bill's author, Assemblymember Dawn Addis, the law ensures that commercial tech entities cannot take advantage of personal student data for financial gain.
A key provision of AB 1159 prohibits tech operators from using a student's personal information, including unique identifiers and coursework, to train generative AI systems. This stops platforms like Canvas and DuoLingo from turning essays and schoolwork into training data. The new law also establishes the Higher Education Student Information Protection Act, which extends these privacy protections to college students starting July 1, 2027. It broadens previous rules to cover any company whose products are designed or marketed for schools, closing loopholes used by consumer-facing platforms that are widely used in classrooms.
The Bigger Picture
This legislative update comes as school-related software use explodes. During the 2024-2025 school year, school districts accessed an average of nearly 3,000 distinct edtech tools, representing a nine percent increase from the year before. At the federal level, the Children's Online Privacy Protection Act (COPPA) protects children aged 12 and under, but Congress has stalled on COPPA 2.0. This leaves teenagers with almost no digital privacy rights outside school, meaning states must write their own laws.
For example, outside classroom walls, unregulated youth sports leagues are actively collecting and selling kids' biometric data under the guise of mandatory player registration. At the same time, colleges and visitor centers that deploy mobile campus apps face increasing pressure to comply with strict location privacy rules to protect minor visitors. California's new law is part of a broader package of child safety measures, including restrictions on children's access to chatbots, which we covered alongside other safety-focused legislation.
What This Means for Families
For parents and educators, the most significant change is that the law removes the regulatory burden from schools. Under the Privacy Rights Clearinghouse's analysis, tech companies, not teachers or parents, must ensure compliance. AB 1159 restricts the collection of highly sensitive information, such as reproductive health data, sexual orientation, and immigration status. This prevents companies from selling student information to third parties, which has previously led to students being targeted with predatory financial offers. If a tech company violates these rules, the law gives harmed students and families the direct right to bring a civil lawsuit against the offending edtech operator.
What You Can Do
- Check the settings on platforms your children use to ensure data-sharing features are turned off where possible.
- Ask school administrators if local school technology contracts clearly prohibit vendors from using student work to train AI tools.
- Read the privacy policies of sports leagues, clubs, and youth organizations carefully, as these programs often fall outside school district protections.