← All posts / Policy

Ten Enforceable Rules: Microsoft and the Teachers Unions Just Rewrote the Deal Between AI and American Classrooms

Microsoft, the AFT and the UFT have signed a first-of-its-kind National AI Safety & Privacy Standard for schools — ten legally enforceable principles that bar student data from AI training, advertising and sale, and require human oversight of AI decisions. Districts can write it into their contracts starting in November.

Ten Enforceable Rules: Microsoft and the Teachers Unions Just Rewrote the Deal Between AI and American Classrooms

For years, the debate over AI in American classrooms has run on two parallel tracks that never quite met. On one track, districts signed AI contracts faster than anyone could read them. On the other, teachers unions warned about student privacy, data harvesting, and algorithms quietly making decisions about children. On September 9, those tracks converged: Microsoft, the American Federation of Teachers (AFT), and the United Federation of Teachers (UFT) announced a National AI Safety & Privacy Standard for Schools — a first-of-its-kind agreement that turns ten principles into legally enforceable contract language that any school district in the country can adopt.

This is not another voluntary framework or a softly-worded pledge. The unions negotiated the terms directly with Microsoft, and the result is a document the AFT publishes as a binding commitment: “The AI Provider must comply with all ten, across every AI” product it supplies to a district. Starting in November, districts will be able to write the standard into new or existing Microsoft agreements, converting principles into contractual obligations with real legal recourse.

What the ten principles actually do

The core protections cluster around three ideas: data, decisions, and transparency.

Data. The standard bars Microsoft from using student or educator data to train AI models, from selling it, and from using it for advertising. The training ban carries only a narrow carve-out for security circumstances — the kind of exception needed to investigate misuse without opening a general-purpose loophole. Tracking students, the profiling practice that has defined the edtech privacy fights of the last decade, is prohibited outright. The standard also includes explicit provisions for what happens when things go wrong, including breach notification requirements.

Decisions. AI systems are prohibited from making consequential decisions in schools without human oversight. That single line matters more than it looks. The most persistent fear educators expressed about classroom AI was not that a chatbot would give a wrong answer — it was that an automated system would silently shape a student’s placement, evaluation, or disciplinary record. Under the standard, a human being must remain in the loop wherever AI touches decisions about children.

Design and disclosure. Microsoft’s own fact sheet frames the requirement in engineering terms: AI systems “must be designed to avoid harmful or manipulative experiences, protect sensitive information, and meet rigorous standards” for security and safeguards. For families, the standard promises visibility into how AI is being used — a meaningful shift from the status quo, where parents often discovered which tools had their children’s data only after an incident.

Why enforcement is the whole story

Plenty of organizations have published AI-in-education principles. What distinguishes this agreement is the mechanism. As Fortune reported, the standard becomes legally enforceable once it is written into a district’s Microsoft contract — transforming what would otherwise be a corporate policy into a warranty that districts can enforce in court. GovTech’s analysis called it a precedent for district AI governance precisely because it gives schools contractual recourse when protections are violated.

The sequencing is also deliberate. The announcement lands amid a season of classroom AI retrenchment — most visibly in New York City, where officials have moved to restrict screens and AI in early grades. Microsoft President Brad Smith, who announced the deal alongside union leaders, framed the standard as building on those NYC restrictions rather than fighting them. “This standard sets a high bar for child privacy and AI safety, and we’ll extend this agreement to every school district across the country,” the company said — a signal that Microsoft would rather bind itself by contract now than face a patchwork of district-level mandates later.

For the AFT, the deal is a rare example of a labor union shaping technology policy rather than reacting to it. Randi Weingarten’s organization represents more than a million members, and the union spent the last two years watching AI vendors court superintendents with free pilots and glossy dashboards. The standard flips the power dynamic: instead of districts negotiating alone against a trillion-dollar vendor, they can inherit terms negotiated by the largest teachers union in the country.

The strategic read

Three implications are worth watching.

First, this raises the floor for every vendor in education. Microsoft was willing to accept a no-training-on-student-data rule and human-oversight requirements in a binding contract. Once one district signs those terms, every competitor — Google, OpenAI, Anthropic, and the long tail of edtech startups — faces an obvious question at the negotiating table: why won’t you? The AFT and UFT have effectively published a template for collective bargaining over AI, and the political pressure to adopt it will not stop at Microsoft’s door.

Second, it marks a turn from deployment speed to deployment governance. The first phase of classroom AI was a land grab; the second is turning out to be a rule-writing exercise. The standard notably does not ban AI in schools — Fortune pointed out that it constrains rather than prohibits. That reflects a pragmatic consensus emerging among educators: the technology is already embedded, so the fight worth having is over data rights, oversight, and accountability, not prohibition.

Third, the November rollout is the real test. A standard only binds districts that adopt it, and adoption requires districts to actually amend their contracts — an administrative lift for resource-strapped school systems. Microsoft has committed to extending the agreement nationwide, and the unions will push local affiliates to demand it. Watch how many of the roughly 13,000 districts across the country move in the first contract cycle.

The limits

Honesty requires noting what the standard does not do. It governs Microsoft’s products only — a Copilot classroom assistant falls under it; a student’s personal use of a consumer chatbot does not. Enforcement depends on districts opting in, and on districts having the legal capacity to pursue remedies if Microsoft breaches. And the narrow security exception to the training ban, while defensible, will deserve scrutiny as it gets applied in practice.

But those caveats shouldn’t obscure the shift. For the first time, the largest AI vendors and the people who run American classrooms have agreed on enforceable rules — written not as regulation from above, but as contract language from below, negotiated between a company that sells AI and unions that represent the adults responsible for the children AI increasingly touches. Ten principles, one signature at a time, are becoming the terms of engagement between AI and the American school.