Yes, schools can use AI, but FERPA still applies, and institutions must control data sharing, vendor use, and re-disclosure risk before any tool touches student records. The U.S. Department of Education confirmed in July 2025 that AI use is allowable in federally funded programs when it complies with privacy law. Act now: stop feeding personally identifiable information into unvetted models, audit your vendor contracts, and flag your highest-risk AI use cases this week.
TL;DR:
- Schools must ensure AI tools comply with FERPA by controlling data sharing, vetting vendors, and limiting re-disclosure risks before using student records.
- AI use is permitted when designed with data minimization, staff training, and ethical evaluations, but high-risk decisions require human review and strict oversight.
- Technical risks include AI models absorbing student data into training and potential unintended disclosures through metadata or small sample sizes.
- Implementation requires mapping data use, conducting risk assessments, securing stakeholder approval, and maintaining ongoing vendor oversight and staff training.
- Future regulations are expected to tighten, emphasizing vendor accountability and broader legal considerations beyond FERPA, making proactive governance essential.
Table of Contents
- FERPA basics that matter for AI: education records, PII, and exceptions
- What the Department of Education requires and allows for AI use in schools
- Key risks when AI systems process student data
- A practical compliance checklist for evaluating and governing AI tools
- EmpowerED perspective: expertise behind FERPA-aligned AI governance
- Impact of emerging AI technologies on FERPA compliance and future regulatory outlook
- Balancing AI innovation with FERPA limitations
- Case studies of FERPA violations involving AI and lessons learned
- Why the “AI is either banned or fine” framing misses the point
- Get your team trained before your next AI pilot
- Primary sources worth bookmarking
- Sources
FERPA basics that matter for AI: education records, PII, and exceptions
FERPA protects “education records,” a broad category covering anything a school maintains that’s directly tied to an identifiable student, from grades and disciplinary files to counselor notes and, increasingly, AI-generated summaries of a student’s performance. Personally identifiable information (PII) under FERPA includes obvious identifiers like names and student ID numbers, but also indirect identifiers, biometric data, and information that could allow someone to identify a student “with reasonable certainty.”
Directory information, such as a student’s name, grade level, or dates of attendance, can typically be disclosed without consent unless a family has opted out. Everything else generally requires written consent before disclosure, with a few critical exceptions schools lean on daily:
- School official exception: a vendor acting as a “school official” with a legitimate educational interest can access records without separate consent, provided a contract defines that role.
- Audit or evaluation exception: allows data sharing for program evaluation under specific conditions.
- Health or safety emergency exception: permits disclosure when there’s an articulable threat.
AI vendors almost always operate under the school official exception, which means the contract language, not the technology, determines whether the use is compliant.
What the Department of Education requires and allows for AI use in schools
The Department’s July 22, 2025 Dear Colleague letter didn’t ban AI. It set conditions. The core message: AI uses funded through federal grants are permissible when they align with federal privacy laws, including FERPA, and when districts apply sound judgment in deployment rather than treating AI adoption as automatically safe or automatically risky.
The guidance builds around a few practical principles rather than a rigid checklist:
- Data-protective design: tools should minimize what student data they collect and retain.
- Educator support: staff need training before AI enters daily workflows, not after problems surface.
- Ethical guardrails: systems should be evaluated for bias and appropriateness before wide rollout.
Allowable examples cited in federal materials include adaptive instructional materials, AI-assisted tutoring, and advising tools that help counselors flag students who need support. The limits show up when a tool retains student PII longer than necessary, shares it with third parties without disclosure, or makes high-stakes decisions (placement, discipline, eligibility) without human review.
Pro Tip: Before piloting any classroom AI tool, ask the vendor directly whether your students’ inputs are used to train their underlying model. If the answer is vague, treat that as a no-go until legal counsel reviews the contract.
Key risks when AI systems process student data
The technical mechanics of AI create FERPA exposure that traditional software rarely did. Generative models don’t just store data. They can absorb it into training processes, and outputs can inadvertently reveal information that should have stayed confidential, a scenario that falls squarely under the re-disclosure restrictions in 34 CFR 99.33.
De-identification is often weaker than schools assume. Stripping a name from a record doesn’t eliminate risk when metadata, writing style, or small sample sizes make re-identification possible, particularly in smaller schools or specialized programs where a student’s profile is distinctive. Legal scholars have flagged the complexity of large language models trained on student data as an unresolved compliance question, not a solved one.
Operational failures compound the technical risk:
- Staff copying student data into consumer-grade chatbots that log every conversation.
- Retention settings left at default, keeping records far longer than necessary.
- No human reviewing AI-generated outputs before they’re shared with parents or other staff.
- Cross-system copying that spreads PII beyond its original, approved location.
Each of these is a policy failure, not a technology failure, and each is preventable.
A practical compliance checklist for evaluating and governing AI tools
Governance beats good intentions. Here’s the sequence that actually protects a district or institution, based on the pattern federal and institutional guidance both point toward:
- Map the data before you map the tool. Identify exactly what student data a proposed AI use case would touch, then determine whether it’s education record data, directory information, or something else entirely.
- Run a risk assessment. Treat every new AI tool like a mini privacy impact assessment: what could go wrong, who’s exposed, and what’s the blast radius if it does.
- Apply minimum necessary data. Never feed a tool more student information than the task requires. If a tutoring bot only needs a reading level, don’t give it a full transcript.
- Get stakeholder sign-off. Legal counsel, IT, and instructional leadership should all review a tool before it reaches a classroom.
- Lock down contract language. Contracts need explicit permitted-use clauses, a prohibition on re-disclosure, defined security standards, and a data deletion or return clause when the relationship ends.
- Build in audit and breach reporting. Vendors should be contractually required to report incidents within a defined window, not “when convenient.”
- Control access. Only staff with a legitimate educational interest should be able to query or export AI outputs tied to student records.
- Require human review. Following the approach UW–Madison’s registrar office recommends, no AI-generated record should go out the door without a human checking it first.
- Train staff and audit regularly. One training session isn’t enough. Schedule recurring reviews as tools and vendor terms change.
Pro Tip: Keep a living inventory of every AI tool in use across your school, along with its FERPA classification and contract expiration date. Most compliance failures happen because nobody remembers a tool is even active.
For younger students or special education programs, layer in additional checks tied to COPPA, PPRA, CIPA, and IDEA, since FERPA alone won’t cover every legal obligation those populations trigger.
EmpowerED perspective: expertise behind FERPA-aligned AI governance
This guidance draws on the practical realities administrators face when policy meets classroom practice. Compliance frameworks only work when staff know how to apply them day to day, which is why Empowered Professional Learning built courses that translate federal guidance into usable training. The AI for education guide walks through how districts can turn Dear Colleague letter principles into concrete classroom policy.
Policy documents tell you what’s required. Professional development is what turns those requirements into habits, staff who instinctively flag a risky tool, and administrators who know what an audit-ready contract looks like before a vendor pitch ever lands on their desk.
Impact of emerging AI technologies on FERPA compliance and future regulatory outlook
FERPA was written in 1974, decades before anyone anticipated a model that could generate a plausible-sounding student evaluation from a handful of data points. AACRAO’s guidance on student privacy makes the point directly: the statute wasn’t built for black-box systems, and institutions remain legally responsible even when a vendor hosts or processes the data behind the scenes.
That gap is only going to widen as AI tools grow more capable. Multimodal systems that process video, voice, and text simultaneously raise new questions about what counts as an education record when a classroom recording feeds an analytics tool. Predictive models that flag “at-risk” students based on behavioral patterns raise fairness questions FERPA was never designed to answer, since the statute governs disclosure, not algorithmic bias.
Expect regulatory attention to intensify rather than relax. The Department of Education’s July 2025 guidance is a floor, not a ceiling, and future updates will likely address AI-specific scenarios more directly, particularly around vendor accountability and model training practices. States are also moving independently, several have proposed or passed their own student data privacy laws that layer additional requirements on top of FERPA.
The practical takeaway for administrators: build governance structures flexible enough to absorb new rules rather than locking into a static policy. A contract clause requiring vendors to maintain compliance with “applicable state and federal privacy law, as amended” ages far better than one that names a specific statute and stops there.

Balancing AI innovation with FERPA limitations
The tension between innovation and compliance is usually framed as a tradeoff. It shouldn’t be. Districts that treat FERPA as a wall to work around end up with shadow IT, where teachers quietly use unapproved tools because the approved options move too slowly. Districts that treat FERPA as a design constraint, something to build around from day one, tend to end up with faster, safer adoption.
Vendors have a role here too. The strongest edtech partnerships happen when a vendor is transparent about data flows before a contract is signed, not after a compliance officer starts asking questions. Look for vendors willing to answer specifics: where data is stored, whether it trains their models, how long it’s retained, and what happens to it if the contract ends. A vendor that answers those questions clearly, the way a partnership-model AI study tool provider might structure its institutional agreements, is signaling a level of maturity many newer AI companies haven’t reached yet.

Collaboration works best as an ongoing relationship, not a one-time contract review. Quarterly check-ins between IT, instructional leadership, and vendor account teams catch problems before they become incidents. Educators also need a low-friction way to flag concerns, a suspicious data request, an unclear feature update, without waiting for the next scheduled review. The districts getting this right treat their AI vendor list the way they’d treat any other regulated partnership: actively managed, not “set and forget.”
Case studies of FERPA violations involving AI and lessons learned
Most AI-related FERPA problems aren’t the result of malicious intent. They’re the result of speed outpacing process. A common pattern: a teacher or staff member pastes student writing samples, IEP notes, or behavioral incident reports into a consumer chatbot to get a quick summary or rewrite, not realizing the platform logs and potentially retains that input. Because the tool wasn’t vetted or covered by a school official agreement, that action can constitute an unauthorized disclosure of PII, even though no one intended harm.
Another recurring scenario involves AI notetaking or meeting-summary tools used during IEP meetings or parent conferences. Without an approval workflow, a well-meaning staff member might record and transcribe a sensitive conversation using a personal account, creating a record the school has no visibility into and no ability to secure or delete on request.
The lesson from institutions that have navigated this well, including the approach detailed in UW–Madison’s registrar guidance, is consistent: require unit-level approval before any AI tool is used in a context involving student data, and mandate human review of AI-generated records before they circulate further. Approval workflows aren’t bureaucratic friction for its own sake. They’re the mechanism that catches a risky tool before it becomes an incident report. Every documented case shares the same root cause: a gap between what staff assumed was fine to use and what the institution had actually vetted.
Why the “AI is either banned or fine” framing misses the point
Most conversations about FERPA and AI collapse into a false binary: either lock everything down or let teachers experiment freely. Neither extreme survives contact with how schools actually operate. The Department of Education’s own July 2025 guidance rejects that framing directly by tying permission to compliance rather than to the technology itself.
What gets underestimated is how much of this comes down to contract literacy, not technical sophistication. A district doesn’t need a data scientist to catch most AI risks. It needs someone reading vendor terms closely enough to notice a missing deletion clause or a vague data-training provision. That’s a governance skill, not an engineering one, and it’s the piece most compliance conversations skip in favor of debating the technology.
The conventional advice, “just get everything approved by IT,” also falls short because IT departments rarely have visibility into instructional context. A tool that looks fine on a security checklist can still create FERPA exposure if it’s deployed in a special education setting without the added protections IDEA requires. Compliance has to be cross-functional: legal, IT, and instructional leadership need to review AI tools together, not in sequence.
If there’s one priority for 2026, it’s building the habit of proactive vendor vetting before adoption rather than reactive cleanup after a problem surfaces. Reactive compliance always costs more, in trust, in legal exposure, and in the time it takes to rebuild a policy from scratch.
— Brian Koster, Ed.D.
Get your team trained before your next AI pilot
Empowered Professional Learning gives district teams what a policy memo alone can’t: hands-on training that turns FERPA requirements into daily classroom habits. The AI in Education course walks staff through vendor vetting, data minimization, and human-review practices, with a PD certificate at the end so your professional development hours count toward the compliance training your policy already requires.

Every course is self-paced with instructor guidance, so a counselor, a teacher, and a district administrator can all move through the material on their own schedule without pulling staff out for a full-day workshop. Districts weighing a broader rollout can request bulk licensing for entire teams, which pairs well with a pilot group first. If your district is introducing AI tools this semester, start with a pilot for your leadership team through the AI in Education course page and build your policy training around what your staff actually needs to know before the next tool lands on a teacher’s desk.
Primary sources worth bookmarking
Keep these on hand for policy memos, board presentations, or vendor negotiations:
- The Dear Colleague letter on AI and federal grant funds (July 22, 2025), for the Department’s core principles on allowable AI use.
- Studentprivacy, for definitions, exceptions, and vendor contract guidance straight from PTAC.
- UW–Madison’s registrar guidance on AI, as a working example of an institutional approval and human-review policy.
- For schools handling student photos or directory data in specialized products, this yearbook student data privacy guide offers a useful consent and directory-information walkthrough.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Guidance on the Use of Federal Grant Funds to Improve Education Outcomes Using Artificial Intelligence (Dear Colleague, July 22, 2025)
- U.S. Department of Education press release on AI guidance
- Studentprivacy
- FERPA and Artificial Intelligence (AI) — UW–Madison Office of the Registrar
