Microsoft AI privacy rules for American classrooms stopped being a promise and became a signed contract on 7 September 2026, when Brad Smith and Randi Weingarten put their names on a 31-page Memorandum of Agreement. Two days later the American Federation of Teachers, the United Federation of Teachers and Microsoft announced it as the National AI Safety & Privacy Standard, and the coverage was uniformly positive. It is, on any fair reading, the first contractually enforceable privacy floor for artificial intelligence in United States schools.

We read all three published documents end to end: the 820-word press release, the 715-word fact sheet Microsoft published alongside it, and the 9,807-word agreement itself. Together they run to 11,342 words. Across every one of them, the word “Copilot” — the brand under which Microsoft sells almost all of its AI tools — appears zero times.

That is not a gotcha about branding. It is the fastest route into what these Microsoft AI privacy rules actually cover, because the agreement spends one long sentence defining its own perimeter — and general-purpose productivity, collaboration, communication, search and cloud products are explicitly on the outside of it. The press release never quotes that sentence. Neither does the fact sheet. The phrase “primarily designed” appears twice in the agreement and zero times in either public-facing document.

The two Microsoft AI features that are named anywhere in those 11,342 words are Speaker Coach and Speaker Progress. Both are named once each, in an addendum, for the sole purpose of exempting them from one of the ten principles.

None of this makes the standard hollow. The Microsoft AI privacy rules contain a training ban that is genuinely broad, genuinely permanent, and closes the de-identification loophole most student-data contracts leave wide open. Student prompts cannot become training data, and that is a real change. But a district signing on the strength of the press release will have a different picture of the perimeter than a district that read to page 2 — and the gap between those two pictures is measurable, so we measured it.

What the Microsoft AI Privacy Rules Actually Commit Microsoft To

microsoft ai privacy rules schools copilot b closed briefcase standing upright with a top handle v2

The agreement is a real contract, not a memorandum of understanding. Weingarten’s framing in the release — “anything less than legally enforceable provisions is simply a wish list” — is the point of the exercise, and the document is built to survive that test.

The ten principles

Part I sets out ten binding principles, and states plainly that partial compliance is not compliance. Microsoft’s fact sheet summarises the same ten for a lay audience. The two lists match; what differs is that the Microsoft AI privacy rules attach numbers and deadlines to each principle, and the public summary does not.

#PrincipleThe binding number the agreement attaches
1No training on student or educator dataPermanent; survives termination
2Data minimisation by designParental consent under COPPA for under-13s
3Customer owns its dataBackups purged within 180 days; EU or North America only
4Human oversight and explainabilityAgentic features off by default; companions prohibited
5Real accountabilityBreach notice within 72 hours
6Security that matches the stakesIndependent pen testing every year; logs kept 180 days
7Consent and transparency for familiesPlain-language guides within 90 days
8Equity, accessibility and inclusionProvider-funded independent study within 12 months
9No feature creep, no vendor lock-inExport at no cost
10Long-term data responsibilityDeletion and breach duties continue after the contract ends

What is genuinely new here

Three things in that list are not standard in United States education contracts. The training ban explicitly covers de-identified, aggregated and derivative datasets, and says so in terms: “De-identification is not a loophole.” Covered Data may not be used as source material for synthetic data generation either.

The 72-hour breach notification is faster than federal education law requires, because FERPA requires no breach notification at all. The data-residency clause — Covered Data held solely in the European Union or North America — is a commitment most districts have never had in writing. And the cybersecurity obligations underneath the Microsoft AI privacy rules are specific rather than aspirational, down to multi-factor authentication for every member of staff who can reach a system holding Covered Data.

The Microsoft AI Privacy Rules Never Name a Single Copilot

microsoft ai privacy rules schools copilot c strongbox safe with a blank round dial

Microsoft’s education AI is sold under one brand, and that brand is not mentioned. This is worth stating precisely, because it is an unusual absence rather than a rhetorical one.

Zero mentions across 11,342 words

We counted case-insensitively across all three documents that make up the Microsoft AI privacy rules, then re-extracted both PDFs page by page to rule out a text-layer miss.

DocumentFormatWords“Copilot”
Press release, news.microsoft.comWeb page8200
Microsoft fact sheetPDF, 2 pages7150
Signed Memorandum of AgreementPDF, 31 pages9,8070
Total—11,3420

The contrast is sharpest on the announcement page itself. The raw HTML of that page contains the string “Copilot” 19 times — every one of them in Microsoft’s global site navigation and footer, linking to Copilot for organisations, Copilot for personal use and Microsoft 365 Copilot. The announcement text sitting between that navigation and that footer contains it zero times.

Microsoft product names inside the 31-page agreement
Microsoft 365 11
Dynamics 365 4
Azure 3
Bing 2
Speaker Coach / Speaker Progress 1 each
Copilot 0

The only two AI features named are named to exempt them

Addendum C carries Microsoft’s own notes. It names Speaker Coach and Speaker Progress — the presentation-coaching features in PowerPoint and Teams — and records that “Principle 2’s Prohibited practices do not apply” to them. The stated reason is reasonable on its face: during a user-initiated speaking activity these features process only the data needed to give coaching feedback.

But the arithmetic stands on its own. In the whole corpus of Microsoft AI privacy rules, exactly two Microsoft AI features are identified by name, and the sentence identifying them is a carve-out.

How the Microsoft AI Privacy Rules Define Their Own Perimeter

microsoft ai privacy rules schools copilot d door panel in a plain frame with a round handle

Everything in the agreement applies to something called an “AI Provider Educational Product”. That term is defined on page 2, and the definition does two jobs: it draws a boundary, and then it names what falls outside.

The sentence that draws the line

The first half scopes the standard to generative AI services “primarily designed and marketed for use by students, educators and administrators, with authenticated usage under an agreement between the educational entity and the AI Provider”. The second half is the one that matters:

“For the avoidance of doubt, general-purpose productivity, collaboration, communication, search, cloud, development, or workplace-assistance products, including products that may be licensed or used by educational entities but are not primarily designed for educational purposes do not constitute an AI Provider Educational Product.”

That is seven excluded categories in a single sentence. Read against Microsoft’s actual catalogue, “productivity” and “collaboration” and “communication” describe Microsoft 365, Teams and Outlook; “search” describes Bing; “cloud” describes Azure. The agreement names Microsoft 365 eleven times in its compliance tables and Azure three times — as the estate whose certifications are being listed, not as covered educational products.

Which side does Microsoft 365 Copilot sit on?

We cannot answer that from the documents, and that is precisely the finding. Microsoft 365 Copilot is a workplace-assistance product licensed to schools; it is not primarily designed and marketed for students. On the plain words of the definition it reads as excluded from the Microsoft AI privacy rules. Microsoft has not said so, and no published document resolves it.

A district reading the press release would have no reason to ask the question. The release says flatly that “tech companies cannot use student data to train AI” and “students can never be tracked” — unconditional sentences, with no scope qualifier anywhere in its 820 words.

PhrasePress releaseFact sheetAgreement
“primarily designed”002
“general-purpose”002
“do not constitute”001
“upon request”0011
“two years”002
“60 days”001

The Microsoft AI Privacy Rules Are Opt-In by Design

microsoft ai privacy rules schools copilot e shield standing upright with a plain flat face

The fact sheet says that from 1 November 2026 Microsoft will make the protections available to every school district in the United States, addable to new or existing agreements with no renegotiation or renewal required. That is a real commitment and a low-friction one. It is not the same as automatic.

“Upon request” appears eleven times

The machinery inside the Microsoft AI privacy rules is request-driven. Providers must make the protections available to education customers “upon request within 90 days of the Effective Date”, through a process that “should be easy to find and easy to use”. Part I then states that the ten principles bind the provider across every product it supplies “to an EDU Customer who has opted in to the principles”.

So the protections are available to every district and applied to the districts that ask. The Verge, reporting the same day, described it accurately — districts “can opt to add the terms” — but the announcement’s own language contains no verb of that kind at all.

What a district actually has to do

Three things follow for anyone running school IT. First, someone has to make the request; nothing lands automatically on 1 November. Second, the protections may be folded into an existing data privacy agreement or addendum and “need not be adopted in the identical form”, so the resulting terms need reading line by line.

Third, and most importantly, the district’s own contract is where the remedy lives. The Microsoft AI privacy rules say this explicitly: where protections are incorporated, a district’s remedies are “the contractual remedies available under its agreement with the AI Provider”, and making those protections available “reflects commitments undertaken by the AI Provider only”.

Where the Microsoft AI Privacy Rules Have Real Teeth

microsoft ai privacy rules schools copilot f access card standing upright with a round hole

It would be wrong to leave the impression that this is a public-relations document. Principle 5 is titled “Real Accountability — Enforceable, Not Just Promised”, and it contains the line “A privacy agreement without teeth is not a privacy agreement.” The agreement then does the work.

The training ban is the strongest clause in the document

Principle 1 prohibits using any Covered Data — prompts, responses, uploaded files, behavioural signals, metadata, or any derivative — to train, fine-tune, update, benchmark or otherwise improve AI models, at any time, for any purpose. It applies to text, audio, images, video, biometrics and interaction logs. It applies to de-identified and aggregated datasets. It survives termination permanently.

It also requires a written annual statement, signed by a senior officer, confirming that no Covered Data was used for training outside the narrow safety exception in the preceding twelve months. That is an unusually specific attestation to find in a vendor contract, and it is the part of the Microsoft AI privacy rules a district’s counsel will value most.

The numbers that bind

ObligationDeadline in the agreementStated publicly?
Breach notification to the district72 hoursFact sheet only
Critical / high pen-test findings fixed30 daysNo
Medium-severity findings fixed90 daysNo
Backup copies purged after deletion180 daysNo
Audit logs retained180 days minimumNo
Plain-language family guides published90 daysFact sheet, undated
Independent equity study funded12 monthsFact sheet, undated

The obligation language is dense in a way the public documents are not. “Must” and “shall” appear 105 times in the signed Microsoft AI privacy rules against four times across the press release and fact sheet combined.

Binding language: “must” + “shall” per 1,000 words
Signed agreement 10.7
Microsoft fact sheet 2.8
Press release 2.4

What the Microsoft AI Privacy Rules Say That the Announcement Does Not

Four facts sit in the agreement and in neither public document. None is hidden — all four are in the PDF the press release links to — but a reader who stops at the release will not have them.

A two-year term

Part I states that the principles are effective from the date signed and “remain in force for a term of two years”, and that continuing past that term requires written renewal by both parties every two years. The press release describes no term for the Microsoft AI privacy rules. Neither does the fact sheet.

Sixty days’ notice

Part II, clause 3: “AI Provider may terminate its participation in this agreement with 60 days’ written notice.” Weingarten’s “iron-clad” and Mulgrew’s “real teeth” are fair descriptions of the obligations while participation lasts. They are not descriptions of its duration.

The practical reading is less alarming than it sounds, because protections already incorporated into a district’s own contract live in that contract and are governed by it. But the standard itself — the thing being extended to every district in the country — is a two-year, 60-day-exit arrangement, and no public document says so.

Seven of the eight provider slots are empty

The signature section lists the Academy and then eight numbered “AI PROVIDER — Legal name” slots. One carries “Microsoft Corporation”. Seven are blank. Of four “FOR THE AI PROVIDER” signature blocks, one is signed: Brad Smith, timestamped 7 September 2026 at 07:41:17 PDT, with Weingarten countersigning at 15:58:36 EDT the same day.

The document is plainly built as a multi-vendor standard — a seal other providers can earn. On 9 September 2026 the Microsoft AI privacy rules had exactly one signatory, and the announcement’s phrase “tech companies” is, for now, one company.

The Carve-Outs Written Into the Microsoft AI Privacy Rules

Addendum C is a page most readers will never reach. It is also where the two live exceptions sit.

ISO 42001 is pending until December 2027

Principle 5 requires SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001 — the AI management systems standard — or equivalent. Where a provider does not hold one at signing, it must be actively pursuing it with a target date in Addendum C.

Microsoft’s entry states that it “has not completed an independent assessment under ISO 42001” for its educational products and is targeting completion by 31 December 2027. That is 15 months after the Microsoft AI privacy rules take effect. The AI-specific certification among the four required is the one not yet held, and neither public document mentions it.

The Speaker Coach exemption

The second entry exempts Speaker Coach and Speaker Progress from Principle 2’s prohibited practices, which is the principle covering behavioural tracking, keystroke logging, profiling and biometrics. The scope is narrowed sensibly — only during user-initiated speaking activities, only for coaching feedback — but “students can never be tracked”, as the press release puts it, has one written exception, and it is to a feature that ships inside Teams.

The Strongest Case for the Microsoft AI Privacy Rules

The criticism above is about the gap between a release and a contract. It is not an argument that the contract is bad, and the honest case for it is strong.

It fills a gap nothing else fills

Weingarten’s line — “HIPAA and FERPA never envisioned the advent of AI” — is simply true. FERPA governs education records, was written in 1974, has no breach-notification duty and says nothing about model training. COPPA covers under-13s and advertising, not fine-tuning. No federal rule stops a vendor training on classroom prompts. The Microsoft AI privacy rules do, for the products they cover, in language a district’s counsel can enforce.

The scope limit is defensible on its own terms

A standard aimed at AI built for children is a coherent thing to write, and stretching it across every general-purpose cloud product would have made it unsignable. The agreement also protects the floor it sits on: clause 1A says nothing in the standard “reduces, limits, or supersedes any greater protection” in law or in a district’s existing agreement, and that participation “may not be used to reduce, waive, or otherwise diminish any protection or right that would otherwise apply”.

That is a genuinely well-drafted safeguard. It means the narrow perimeter of the Microsoft AI privacy rules costs districts nothing they already had — it simply delivers less than the announcement implies.

The context explains the timing

This landed a week after New York City and Los Angeles imposed one-year bans on student-facing AI, and after Weingarten’s May speech calling for screen bans from kindergarten to second grade and a ban on companion chatbots for under-16s. A vendor watching two of the largest school systems in the country close their doors has a strong commercial reason to offer terms. That does not make the terms worse; it makes them explicable.

What the Microsoft AI Privacy Rules Mean for School IT Teams

For anyone who has to operationalise this, the documents support a short and concrete checklist. The same discipline applies to any AI models and tools procurement, and to the data management and analytics contracts that sit underneath it.

Five questions to ask before signing

Which of our licensed products does this actually cover? Ask Microsoft, in writing, to list the products it treats as AI Provider Educational Products, and to say explicitly whether Microsoft 365 Copilot is among them. This is the single question the Microsoft AI privacy rules do not answer for you.

What form will the terms take in our contract? They “need not be adopted in the identical form”, so compare the offered addendum against the ten principles, clause by clause.

What happens at renewal? The standard runs two years. Confirm what governs your terms if it is not renewed in writing by both parties.

Which certification is live today? ISO 42001 is targeted for December 2027, not held now. SOC 2 Type II, ISO 27001 and ISO 27701 are current for Microsoft 365.

Where does our remedy sit? Confirm the termination and damages language sits in your agreement, not only in the standard, because that is where the Microsoft AI privacy rules put it.

Where this fits a wider governance programme

A vendor commitment is a floor, not a programme. It does not classify your data, decide which year groups use which tools, or tell you who reviews an AI-assisted decision before it reaches a pupil. Our own trust and security approach treats vendor terms as one input among several, alongside your own retention rules, access controls and staff training.

FAQ: Microsoft AI Privacy Rules for Schools

Do the Microsoft AI privacy rules apply automatically from 1 November 2026?

No. Microsoft has committed to making them available to every United States district from that date, with no renegotiation or renewal needed. But the mechanism is request-driven: protections are provided “upon request” and bind the provider for customers who have opted in.

Does the standard cover Microsoft 365 Copilot?

No published document says. The definition of a covered product excludes general-purpose productivity, collaboration, communication, search and cloud products not primarily designed for education, which on its plain words appears to exclude it. Ask Microsoft directly and get the answer written into your contract.

Is student data really banned from training?

For covered products, yes, and the clause is strong: all data types, de-identified and aggregated sets included, permanent, surviving termination, with an annual signed attestation. The narrow exception is safety and security, interpreted narrowly with the burden on Microsoft.

Can Microsoft walk away from these AI privacy rules?

It can end its participation in the standard on 60 days’ written notice, and the standard itself runs two years unless renewed. Protections already written into a district’s own agreement are governed by that agreement, not by the standard.

Are other vendors covered by the Microsoft AI privacy rules?

Not yet, and the name is the clue. The agreement is drafted for multiple providers — eight name slots, four signature blocks — but as of 9 September 2026 only Microsoft has signed.

References