Microsoft Agrees Not to Train AI on Student Data in Pact with Second-Largest US Teachers Union
The legally binding deal with the American Federation of Teachers bans student tracking and mandates human oversight - filling a vacuum left by absent federal regulation.

A Contract Where Regulation Falls Short
Microsoft has entered a legally binding agreement with the American Federation of Teachers that prohibits the company from using student and teacher data to train its artificial intelligence models. The pact, which takes effect for participating school districts on 1 November, represents what AFT - the second-largest teachers union in the United States - characterises as a private sector workaround to the absence of federal AI guardrails in education.
The agreement carves out exceptions only for what Microsoft and AFT term "narrow safety and security" scenarios, though the parties have not publicly defined the boundaries of those carve-outs. At Opentechwire, we've tracked how vaguely worded exemptions in data-use policies often expand over time; the enforceability mechanism here will be the real test.
What the Pact Prohibits
Beyond the training-data ban, the contract forbids Microsoft from tracking students across its education products. It also blocks the company's AI tools from making autonomous decisions in school settings - requiring a human to remain in the loop for any consequential action. Microsoft must additionally disclose to educators and parents how its AI systems function, a transparency mandate that goes further than the company's standard enterprise terms.
Breach of any provision would expose Microsoft to contract liability, a structure that AFT President Randi Weingarten described as having "real teeth." The union is now in active negotiations with OpenAI and Anthropic, seeking parallel agreements.
The Regulatory Vacuum
Weingarten framed the deal as a response to federal inaction. "We have forged a hard-fought, iron-clad privacy agreement with real teeth that protects students and families, because no one else, including the federal government, has stepped up to do the real work," she said in a statement accompanying the announcement.
The comment underscores a broader pattern: as generative AI proliferates in classrooms - through homework helpers, grading assistants, and lesson-planning tools - US regulators have issued guidance but no binding rules. The Federal Trade Commission has warned edtech vendors about deceptive data practices, and the Department of Education has published AI principles, yet neither agency has promulgated enforceable standards specific to schools.
That vacuum has pushed unions and district administrators into direct negotiation with technology vendors, a dynamic more common in enterprise procurement than in public education. The AFT deal suggests that collective bargaining power, rather than statute, may shape the near-term governance of AI in American schools.
Why Narrow Exceptions Matter
The "narrow safety and security" language is the agreement's potential weak point. Safety exceptions in data-use contracts have historically covered everything from content moderation to fraud detection to product improvement under the banner of "security research." If Microsoft's internal security team labels a new model-training pipeline as a safety project, does that fall within the carve-out? The agreement does not appear to establish an independent arbiter, leaving interpretation to the contracting parties.
In practice, enforceability will depend on whether AFT-affiliated districts audit Microsoft's data flows and whether the union is willing to litigate ambiguities. Contracts of this kind are rare in edtech; most school systems accept vendor terms as written, with limited leverage to negotiate bespoke privacy clauses.
District-Level Adoption
The protections become available to school districts beginning in November, but the agreement does not automatically cover every school that licenses Microsoft products. Districts will need to opt in, either by amending existing contracts or by adopting the AFT-negotiated terms in new procurements. That opt-in structure means coverage will be uneven, favouring districts with strong union presence or dedicated legal counsel.
For smaller or under-resourced districts - often those serving higher proportions of low-income students - the administrative lift of contract renegotiation may prove prohibitive. The result could be a two-tier system in which well-organised districts secure binding privacy protections whilst others remain subject to standard vendor terms.
Broader Moves to Limit AI in Schools
The Microsoft-AFT agreement arrives amid a wave of local AI restrictions. New York City announced a one-year moratorium on generative AI tools for students through eighth grade, citing concerns about accuracy and age-appropriateness. Los Angeles extended a similar ban to all public school students, regardless of grade level.
These moratoria reflect unease amongst educators and parents, but they also risk widening equity gaps. Students in private schools and affluent districts often retain access to AI tools, either through institutional licenses or personal subscriptions, whilst students in public systems face outright bans. At Opentechwire, we've noted this pattern in other technology rollouts - early restrictions tend to concentrate access amongst those who can route around them.
What Comes Next
AFT's negotiations with OpenAI and Anthropic will clarify whether the Microsoft model can scale across the AI supply chain. OpenAI's enterprise agreements already include data-separation clauses, but those contracts typically allow the company to use aggregated or anonymised data for model improvement. Whether AFT can secure a blanket training ban - matching the Microsoft deal - remains to be seen.
Anthropic, meanwhile, has positioned itself as a safety-focused AI lab, but its commercial terms are less transparent than OpenAI's. If the union succeeds in extracting similar commitments from both companies, the resulting template could become a de facto standard for AI in education, filling the regulatory void with private contracts.
The risk, however, is that enforceability remains weak. Without regulatory backstop or independent oversight, these agreements rely entirely on the willingness of unions and districts to monitor compliance and, if necessary, to sue. That is a fragile foundation for protecting the data of millions of students.


