Microsoft Limits Classroom AI Training, Showing Global Privacy Gaps

Learn how Microsoft’s landmark agreement with the AFT limits student AI data training, exposing a massive gap in legal protections for classrooms globally.

Thursday, September 17, 2026

Key Takeaways

  • Microsoft and the American Federation of Teachers signed an agreement to stop student data from being used to train AI models. However, individual school districts must add these clauses to their own contracts for the ban to take effect.
  • Google's Gemini for Education prevents the company from training AI models on school-managed accounts. Students who use personal Gmail accounts remain covered by consumer terms that allow Google to harvest their data.
  • India will launch its new Computational Thinking and AI curriculum for Class 3 students in the 2026-27 school year. The country's main children's data privacy law will not take effect until May 2027.

The American Federation of Teachers (AFT) has secured a legally binding agreement with Microsoft to protect student and educator data from being used to train artificial intelligence models. As we previously reported, this "National AI Safety & Privacy Standard" aims to fill major gaps in national privacy legislation. However, the deal exposes a growing global divide, as students in countries like India face new AI curriculums without similar legal guardrails.

What Happened

Under the new agreement announced by the American Federation of Teachers, Microsoft has committed to a "National AI Safety & Privacy Standard" that blocks the company from using student or teacher data to train its AI models. The agreement also bans tracking students, selling their data, or using it for targeted advertising. This contract is a win for unions, which negotiated protections that federal law does not currently mandate.

The standard is not automatic. School districts must negotiate these terms into individual contracts with Microsoft to make them legally binding, though Microsoft President Brad Smith noted in the official announcement that the company intends to expand these protections nationwide.

The Bigger Picture

Classroom AI adoption is outpacing government regulations worldwide. In the United States, other major tech giants are handling student data differently. For instance, Google's Gemini for Education recently earned a privacy seal for promising not to use school-managed account data for AI training. However, as security researchers warn, students who use personal Gmail accounts to access these same Google AI tools are subject to standard consumer terms, which allow their data to be used for model training.

In India, the government is rolling out its new Computational Thinking & AI Curriculum for the 2026-2027 school year, which introduces technology concepts starting in Class 3. However, India's primary legal safeguard for children's data, Section 9 of the Digital Personal Data Protection (DPDP) Act, will not take effect until May 2027. This delay means Indian schools are deploying classroom AI tools while the statutory protections against tracking and behavioral monitoring remain inactive. Legal experts point out that upcoming rules may exempt educational platforms from these strict bans entirely, leaving students with fewer default protections.

What This Means for Families

For parents and educators, these developments show that classroom data privacy is highly dependent on local contracts rather than national laws. While some tools offer robust protections, others exploit loopholes. If your child uses school-issued devices or managed accounts, their data may be safe from AI training models. However, if they log into educational tools using personal accounts, their data could be used to train commercial AI systems.

The situation in India shows that even structured, national curriculums can outpace safety laws. As we noted when major districts halted classroom AI, without strict local procurement standards, school districts risk exposing students to unregulated tracking and behavioral monitoring before legal frameworks are fully active.

What You Can Do

Parents and educators can take several steps to protect student privacy. First, ensure children only use official, school-managed accounts, such as Google Workspace for Education, rather than personal accounts for homework.

Second, push school administrators to adopt new privacy standards and frameworks and write the Microsoft-AFT privacy standards directly into their local vendor contracts.

Finally, ask teachers how they teach digital literacy to younger students. In India, for example, the curriculum for Classes 3 to 5 is designed to be low-tech and activity-driven, requiring no active internet devices. Encourage schools to stick to these offline methods until robust data protections are legally active.

Share: