Can Microsoft Train AI On Student Data Under Its New Deal?

September 15, 2026

Microsoft's new school AI deal bans training on covered student data, but its product scope, district contracts, safety exception, and deletion rules matter.

Microsoft generally cannot train AI on student or educator data covered by its new school agreement. The signed standard bans using covered prompts, responses, files, behavior signals, metadata, and derivatives to train or improve AI models. But the promise is not a blanket rule for every Microsoft product or every school: it applies to defined education products and to districts that incorporate the protections into their contracts. A narrow safety-and-security exception also remains.

The agreement is unusually specific about deletion, memory, AI companions, human review, breach notification, audits, and enforcement. Its most important contribution may be contractual: it turns broad privacy language into terms a participating school district can enforce. Its most important limitation is scope. “Microsoft signed” does not mean every Copilot, search, cloud, productivity, or workplace product is automatically covered.

Research cutoff: September 15, 2026. This article analyzes the signed agreement, Microsoft's announcement, its two-page fact sheet, and current Associated Press reporting. It does not treat a press-release summary as a substitute for a district's actual contract or product configuration.

What Is Microsoft's National AI Safety And Privacy Standard?

The National AI Safety & Privacy Standard for Schools is a 31-page memorandum between Microsoft and the National Academy for AI Instruction, an initiative of the American Federation of Teachers. Microsoft President Brad Smith and AFT President Randi Weingarten signed it on September 7, 2026; Microsoft and the unions announced it publicly two days later.

The document contains ten binding principles. They address model training, data minimization, customer ownership, human oversight, contractual remedies, security, family transparency, equity, feature changes, and long-term data responsibility.

Microsoft's official announcement says U.S. school districts can incorporate the protections into their Microsoft customer agreements. The agreement itself says a participating provider must make equivalent substantive protections available upon request within 90 days of the effective date. Those terms can appear in an existing data privacy agreement, license, or addendum rather than in an identical copy of the 31-page standard.

The timing has attracted attention. Associated Press reporting published September 15 says Microsoft expects the standards to apply to schools it contracts with starting November 1. AP also reports that OpenAI and Anthropic are discussing their own agreements with the AFT, while Google has not said whether it will join.

What Is Confirmed

Covered Student And Educator Data Cannot Be Used For General AI Training

Principle 1 states that a provider may not use covered data to train, fine-tune, update, benchmark, or otherwise improve an AI model. Its list is deliberately broad: prompts, responses, uploaded files, behavioral signals, metadata, and derivatives all count.

The restriction also applies to audio, images, video, biometrics, interaction logs, de-identified data, aggregated data, and transformed data when they derive from covered data. It applies retroactively to covered data collected before the agreement, survives termination indefinitely, and extends to relevant subsidiaries, subprocessors, and partners. The document does allow wholly synthetic data that was not created from covered data and cannot reasonably be linked or reversed to a student, educator, or customer record.

This is stronger than saying data is not used to train a foundation model “by default.” It is a contractual prohibition for covered uses, subject to one defined exception.

The Safety Exception Is Narrow But Real

The agreement permits the minimum covered data reasonably necessary to detect, prevent, investigate, mitigate, or remediate harms and security threats. Examples include self-harm, child sexual abuse material, grooming, violence, bullying, malicious activity, vulnerabilities, incidents, and unauthorized access.

The same section says that data cannot spill into general model improvement, personalization, advertising, behavioral inference, market research, or unrelated product development. It may be used to evaluate or improve a specific safety classifier, safeguard, or security function. Retention must be limited to the safety purpose or a legal requirement, and records of the processing must be available for review and audit subject to reasonable confidentiality, security, and privilege limits.

Upon request, a senior officer must provide an annual plain-language statement confirming that no covered data crossed from the safety systems into another model or product. That is a meaningful accountability mechanism, but it is not the same as continuous public access to every safety-processing event.

Schools Control Retention, Deletion, And Memory

The agreement requires administrative tools or documented processes that let an education customer control retention and initiate deletion. Once a customer starts a valid deletion request, Microsoft must delete covered data from active systems within a contractually agreed period that cannot exceed 180 days, subject to configured retention, legal holds, legal requirements, and permitted safety or incident-response needs. Backups must be deleted or rendered commercially unrecoverable on documented cycles no longer than 180 days under the same exceptions.

Persistent memory receives its own controls. Where an education product stores facts, preferences, profiles, or conversation summaries between sessions, the customer must be able to disable memory. When individual student data is remembered, the person—or a parent or guardian working through the school where applicable—must be able to see it, erase it, and turn it off without losing access to the service.

Deletion still needs verification. A maximum 180-day contract window is not instant deletion, and legal holds or an authorized safety investigation can preserve a copy. That is why turning off AI training is not the same as deleting retained chats.

Covered Data Cannot Be Sold Or Used For Advertising

Principle 3 says the education customer and its students own the prompts, responses, files, outputs, and other covered data. The provider cannot sell or license that data, use it for advertising, or repurpose it for product development or research outside delivery of the contracted service.

The provider can transfer data when necessary to provide the requested service, comply with law, or protect minors. That means “no sale” should not be misread as “no subprocessors” or “no provider processing.” The standard separately requires a current public list of subprocessors with access to covered data and a mechanism for advance notice of new ones.

AI Companions And Default Agent Actions Are Restricted

The agreement bars companion-style or relationship-oriented features designed to foster emotional attachment or dependency, prolong engagement beyond the learning task, simulate friendship, or encourage sensitive disclosures.

It also requires externally consequential agent actions to be disabled by default for student deployments unless an authorized school administrator enables them. Examples include sending messages, submitting work, changing settings, accessing third-party systems, or making purchases. Any enabled action-taking feature needs scoped permission, school approval, human oversight, and complete audit logging.

The distinction is important. The document does not prohibit every conversational interface or every automated step. It targets manipulative relationship design and unapproved actions with consequences outside the provider's system.

The Agreement Adds Enforcement And Security Duties

The provider must notify an affected education customer without unreasonable delay and no later than 72 hours after becoming aware of a confirmed or reasonably suspected breach involving covered data. It must provide material updates and cooperate with investigations.

The standard also calls for SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001 or an equivalent, and FedRAMP Moderate or an equivalent federal authorization where the specific customer, deployment, or use requires it. If a listed certification is not current at signing, the provider must be pursuing it and identify a target date in the agreement's addendum.

After the substantive protections are incorporated into a district's agreement, the district can use the contractual remedies available there, including termination for an uncured material breach and damages or other remedies provided by the agreement or law. The Academy and AFT can revoke participation in the standard after the notice and cure process. This is more concrete than a voluntary set of principles, although the exact remedy for a school still depends on its signed terms.

What Is Still Unclear

The public record reviewed for this article does not yet establish:

AP reports that the standard will apply to Microsoft's school contracts starting November 1. The signed agreement, however, says districts may opt to include the principles and that participating providers must make equivalent protections available upon request within 90 days. Those statements may describe an implementation plan not fully spelled out in the public contract. Until Microsoft publishes the district process and covered-product list, a school should ask for the actual addendum rather than relying on the date alone.

The Biggest Scope Limit: Not Every Microsoft AI Product Is Covered

The agreement defines an “AI Provider Educational Product” as a generative-AI service or feature primarily designed and marketed for students, educators, or administrators and used through an authenticated education agreement.

It expressly excludes general-purpose productivity, collaboration, communication, search, cloud, development, and workplace-assistance products that are not primarily designed for educational purposes—even when an educational entity licenses or uses them.

That carveout prevents a careless headline such as “Microsoft can never train on school data.” The accurate statement is narrower: Microsoft cannot use covered data from opted-in, covered education products for general AI training under the agreement.

A district inventory should therefore name the exact SKU, feature, tenant, sign-in path, and contract. “Copilot” is a product family, not a sufficient scope answer. A feature embedded in an education application may be covered while a similarly branded general-purpose feature is not. A teacher's personal account may also sit outside the school's agreement.

This product-boundary problem is common across AI services. Our guide to whether files uploaded to AI are used for training explains why plan, account, feature, feedback, and provider terms must be checked separately.

The SCHOOL Check For Any Education AI Contract

The Microsoft agreement offers a useful template, but buyers still need a repeatable review. Use the SCHOOL Check before treating any “student-safe AI” claim as complete.

S — Scope The Exact Product

Record the product name, plan, feature, tenant, age group, account type, and model provider. Ask whether the contract covers general-purpose tools used by teachers, browser extensions, connected apps, and features released after signing.

C — Contract The Promise

Find the signed data protection terms. A blog post, trust page, or sales statement may help explain a policy, but it does not necessarily give a district an enforceable remedy. Confirm which document controls if terms conflict and whether the district must opt in.

H — Hold Training And Secondary Use Apart

Ask separately about foundation-model training, safety-classifier improvement, product analytics, telemetry, personalization, research, advertising, and feedback. “Not used for training” does not answer every secondary-use question.

O — Observe Storage And Deletion

Map prompts, outputs, files, memory, logs, safety records, feedback, exports, and backups. Record each retention setting, maximum deletion period, legal-hold exception, and confirmation mechanism. If a product supports persistent memory, test whether a user can view, delete, and disable it.

O — Oversee People And Actions

Identify who can enable features, see student data, review automated outputs, and authorize agent actions. Verify that grading, discipline, placement, psychological assessment, and behavioral surveillance cannot happen without the required human control—or at all where policy prohibits them.

L — Log Proof And Lifecycle Changes

Collect the subprocessor list, audit reports, certification scope, incident-notice clock, model or system card, privacy-impact assessment process, and feature-change notices. Recheck after renewals and major releases. A safe configuration today does not prove a future feature inherited the same boundaries.

What Parents And Educators Should Ask Now

Parents do not need to become contract lawyers, but the questions should be concrete:

  1. Which exact AI products and student age groups are enabled?
  2. Is the school's agreement amended to include the ten principles?
  3. Can students use the feature through personal accounts outside school controls?
  4. Are prompts, files, outputs, memory, and metadata all covered?
  5. What is stored, where is it stored, and when is it deleted?
  6. What can be retained for safety, security, legal holds, or feedback?
  7. Which subprocessors and underlying model providers receive content?
  8. Can administrators disable memory, companions, and action-taking features?
  9. How are parents notified after a suspected breach?
  10. Where can families see audit, model, and risk documentation?

The standard shifts more of the burden to providers and districts, which is useful. It does not eliminate the need to decide whether a tool belongs in a classroom. AP quotes Fairplay executive director Josh Golin warning that strong privacy terms could be mistaken for a reason to adopt AI. A privacy agreement answers “under what safeguards?” It does not answer “is this educationally appropriate?”

Does This Make Microsoft School AI Private?

It makes covered deployments more privacy-protective and contractually accountable. It does not make them local, anonymous, or free of processing.

The provider and necessary subprocessors still have to process a student's request to deliver a hosted service. De-identified telemetry can support security, debugging, capacity planning, service health, aggregate performance, and product improvements, although the standard prohibits using telemetry for generative-model training, individual profiling, personalized output, advertising, marketing, or behavioral inference.

The agreement also recognizes that some services may use zero data retention, where prompts and outputs are not stored beyond the immediate session. It names OpenAI's ZDR API as an example, but does not say all Microsoft school AI uses ZDR. If a district selects such a service, the agreement says the Academy must explicitly acknowledge that it is responsible for keeping its own records when records are needed.

Privacy, security, safety, educational value, and local operation are separate properties. For the broader distinction, see secure AI chatbot versus private AI chatbot.

Where OpenVeil Fits—and Where It Does Not

OpenVeil is a hosted AI workspace for adults 18 and older. Normal chat history is stored in the user's browser, with no normal server-side chat-history record, and OpenVeil does not use documented prompts, uploads, media, selected history, or outputs to train foundation models. Active requests are still processed by OpenVeil and necessary providers.

OpenVeil is not intended for minors, marketed as a school AI product, or documented as a student-record system. It does not replace a district data agreement, administrator controls, parental-consent workflow, age assurance, FERPA or COPPA analysis, classroom audit, or procurement review. Do not enter student records or other regulated school data unless your organization has independently authorized the exact use and data route.

For adult educators, administrators, researchers, or parents exploring their own non-student brainstorming, OpenVeil offers a different privacy model from a typical account-synced chatbot. The browser-local history design can reduce the normal server-side conversation archive while preserving hosted convenience. Learn exactly what that means in What Browser-Local Chat History Means In An AI App.

Frequently Asked Questions

Can Microsoft Use Student Prompts To Train AI?

Not when the prompts are covered data under an opted-in agreement for a covered Microsoft education product. The signed standard prohibits using prompts and derivatives for general model training or improvement. A narrow safety-and-security exception allows minimum necessary processing and limited improvement of a specific safeguard.

Does The Agreement Cover Every Microsoft Copilot Product?

No. It covers authenticated generative-AI products primarily designed and marketed for educational use. It expressly excludes general-purpose productivity, collaboration, communication, search, cloud, development, and workplace-assistance products not primarily designed for education.

Does Every School Get The Protection Automatically?

Microsoft says it will extend the standard nationwide, and AP reports a November 1 start for contracted schools. The agreement says districts can request the protections and that they become enforceable after equivalent terms are incorporated into the district's agreement. Schools should verify their own signed addendum and covered products.

Can Microsoft Keep Student Data After Deletion?

Deletion from active systems and backups must occur on agreed timelines no longer than 180 days, but configured retention, legal holds, law, and permitted safety, abuse-prevention, investigation, or incident-response needs can delay or limit deletion. The customer can request written confirmation when deletion is complete.

Does The Standard Ban AI Companions In Schools?

It prohibits companion-style or relationship-oriented features designed to foster attachment or dependency, prolong engagement, simulate friendship, or encourage sensitive disclosure in covered products. It does not ban every conversational educational assistant.

Is OpenVeil A School AI Alternative?

No. OpenVeil is for adults 18 and older and is not a school product, student-record system, or education-compliance solution. Adults can use it for their own authorized work, subject to OpenVeil's documented hosted-processing and product boundaries.

Bottom Line

Microsoft's new agreement does ban general AI training on covered student and educator data, and it backs that promise with unusually detailed controls and contractual remedies. The headline is real. It is also conditional.

Before a school treats the promise as active, it should verify three things: the exact product is within the agreement's education-product definition, the district has incorporated the substantive protections into its contract, and the configured retention, memory, safety, subprocessor, and deletion paths match the intended policy.

The durable lesson reaches beyond Microsoft: do not ask only whether an AI company says it protects student data. Ask which data, which product, which account, which exception, which contract, and which proof.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.