California Law Stops EdTech Companies From Training AI on Student Data

California’s new AB 1159 law bans edtech companies from using student data to train AI models. Learn what this landmark privacy law means for your family.

Monday, September 14, 2026

Key Takeaways

  • California's Assembly Bill 1159 (CALPIPA) bans educational technology companies from using student data from pre-K through higher education to train generative artificial intelligence models.
  • The law closes a loophole by applying privacy restrictions to any company that knows schools use its products. This extends regulations to general-use platforms like Google and YouTube.
  • While federal COPPA rules protect children aged 12 and under, teenagers aged 13 to 17 lack federal online privacy protections. Updated legislation, including COPPA 2.0 and KOSA, remains stalled in Congress.
  • This gap in protection comes as classroom technology use grows. A 2026 survey found that 78% of teachers use AI tools, but only 24% have received formal training on student data privacy.

California has enacted a strict new law to stop educational technology companies from using student data to train artificial intelligence systems. Known as the California Learner Personal Information Protection Act (CALPIPA), the law changes how schools and tech vendors handle student information. Under the new rules, tech companies cannot commercialize students' personal profiles or feed them into AI models.

What Happened

Governor Gavin Newsom signed Assembly Bill 1159 into law to close loopholes in California's student data privacy framework. Introduced by Assemblymember Dawn Addis, the legislation addresses gaps in the state’s 2014 student privacy law. As reported by CalMatters, the older law only applied to platforms "primarily" designed and marketed for students. This allowed consumer tech companies, like Google and YouTube, to bypass regulations even though schools widely use their products.

The new law changes that standard. Now, any company that knows its products are used in schools and markets to students cannot sell student data or use it for purposes outside of classroom instruction. According to the official announcement by Assemblymember Dawn Addis, these protections extend from preschool to higher education, and protect sensitive data such as reproductive health, immigration status, and LGBTQ+ identity.

The Bigger Picture

The rise of artificial intelligence in schools has increased classroom data collection. As we previously reported, the rapid integration of these tools has left student profiles vulnerable to being used by large language models. Assembly Bill 1159 bans tech companies from using covered student information to train generative AI systems. The law does not block personalized learning. Companies can still use data to support an individual student's immediate educational needs, but they cannot use it to train broader, commercial models.

This state-level action comes because federal protections remain limited. While the Federal Trade Commission enforces the Children's Online Privacy Protection Act (COPPA) to require parental consent for children aged 12 and under, older teenagers fall into a regulatory gap. According to a legal analysis of federal age-verification legislation, federal bills like COPPA 2.0 and the Kids Online Safety Act (KOSA) remain stalled in Congress. As a result, teenagers using technology outside of school classrooms have few federal online privacy protections.

What This Means for Families

For parents and educators, the law brings oversight to the digital classroom. Still, technology is deeply embedded in daily school routines. Many popular learning and communication apps, such as Canvas, Duolingo, ClassDojo, and Seesaw, gather large amounts of information, including names, photos, behavior notes, and location data.

While reputable platforms pledge not to sell data, a school app privacy analysis warns that a commitment not to sell data does not mean they will not share it with third-party service providers. In addition, educators often lack the support to use these tools safely. According to a survey published by K12 eLearning, 78% of teachers use AI tools in their classrooms, but only 24% have received formal training on student data privacy. This gap means teachers may unintentionally expose student data to commercial AI tools without realizing the privacy risks.

What You Can Do

Parents can protect their children's data by reviewing the privacy settings on platforms like Google Classroom, ClassDojo, and Seesaw. Reputable services have privacy controls, but teachers can sometimes override defaults, such as posting student work to public class blogs. Parents should ask teachers to restrict sharing settings.

When using self-directed educational apps like Duolingo or classroom AI tutors, families should practice data minimization by avoiding real names, birthdays, or specific personal anecdotes.

Finally, educators and parents should ask district administrators if their school's tech vendors have signed data privacy agreements that explicitly prohibit using student work for generative AI training.

Share: