Back to news Schools & parenting
24 July 2026 · 2 min read

Schools Adopt AI Faster Than They Protect Children's Data

AI use in classrooms has surged, but most schools lack policies that address what happens to student data. Federal privacy law predates the tools now in use, and recent breaches have exposed tens of millions of student records. Families are urged to ask schools direct questions before children use AI tools.

AI use in schools rose sharply over the past year. A 2025 RAND survey found that 54% of students and 53% of teachers used AI for school, both up more than 15 percentage points from the year before. Policy has not kept pace. Only 45% of principals reported having a school or district AI policy, and just 34% of teachers said their district had a policy specifically addressing AI and academic integrity.

Where policies do exist, they rarely give student data privacy its own attention. Ohio became the first state to require every public school district to adopt a formal AI policy, with a deadline of July 1, 2026, and its model policy names data privacy and FERPA compliance directly. Not every district will use that model, and many schools still have no AI policy at all into which such protections might be written.

The underlying law is old. FERPA, the federal statute governing student education records, was written in 1974. It has no explicit cybersecurity requirements and was not built for AI models that train on the data they touch. California's AB 1159, still moving through the legislature in mid-2026, would prohibit schools and vendors from using student data to train AI models, and Idaho's SB 1227 would require data privacy protections specifically for AI tools. These measures face opposition and do not extend to families in states that have introduced nothing similar.

The risks are concrete. A breach of PowerSchool, disclosed in early 2025, compromised over 62 million student records and nearly 10 million teacher records. In spring 2026, a breach at Canvas exposed names, email addresses, student ID numbers, and private messages from more than 8,800 institutions. A whistleblower has also alleged that a chatbot vendor improperly collected student data in violation of a district's own written policies.

Compliance specialists say the document that matters most is a signed data privacy agreement between the school and each vendor, one that restricts use, prohibits redisclosure, and grants audit rights. The Foundation encourages parents to ask whether such agreements exist, what happens when a vendor relies on another company's model, and how long a child's data is kept once the tool is no longer used. This account is based on reporting by Forbes.

Sources

Newsletter

Occasional news on the Foundation's programs, research, and events.

Unsubscribe at any time. See the privacy policy.