# What Should Schools Require Before Approving an AI Tool?

Canonical URL: https://blog.theaieducator.io/posts/approving-ai-tools-for-schools
Publication: Dan Fitzpatrick Insights
Author: Dan Fitzpatrick
Topic: AI Governance and Responsible Leadership
Published: 2026-09-11T13:47:35.000Z
Modified: 2026-09-11T13:48:48.099Z

A new vendor standard can settle what a supplier promises to do with student data. It cannot decide what an AI tool is for in your school, who owns it or what would take it off the list. Approval needs both halves in writing.

## In brief

Before approving an AI tool, a school should require two signatures. The first is the supplier's written promise about data, safety and product changes, which standards such as the September 9, 2026 AFT, UFT and Microsoft agreement and the DfE's generative AI product safety standards now make easier to get. The second is the school's own: what the tool is for, who owns it and what would take it off the list. Dan Fitzpatrick calls this the Two-Signature Rule: a standard can make a product safe to use, but only the school can decide it is worth using.

## Key takeaways

- An AI tool should go on a school's approved list only with two signatures: the supplier's written promise about data and safety, and the school's own statement of purpose, owner and removal condition.
- The AFT, UFT and Microsoft National AI Safety & Privacy Standard, announced September 9, 2026, commits Microsoft not to use student and educator data to train AI models, sell it or repurpose it, and districts can make that enforceable in their contracts.
- England's DfE Generative AI: product safety standards (January 19, 2026) go beyond privacy, asking products to detect cognitive offloading and avoid cultivating personal relationships with users.
- A vendor standard answers whether a product is safe to use; it cannot answer whether a particular use is right for a particular school.
- Contract protections do nothing until a named person in the school knows them, checks them and acts on a breach, so every approved tool needs an owner.
- Every approved tool needs a removal condition and a review date; a list nothing ever comes off is an inventory, not an approved list.
- The bar should rise with the stakes: light for staff-only tools with no personal data, full for staff tools touching student data, and highest for student-facing tools.

On September 9, 2026, the American Federation of Teachers, the United Federation of Teachers and Microsoft announced what they call a [National AI Safety & Privacy Standard for schools](https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/). Before long, some version of the same question will reach your leadership team, from a teacher, a parent or a governor: does this mean we can approve it now?

The short answer is: not on that alone, and not because the standard is weak. A standard like this settles one half of an approval decision: what a supplier promises to do, and not do, with your students' and staff's data. It cannot settle the other half: what this particular use is for in your school, who owns it, and what would take it off the list. Require both halves, in writing, before any AI tool goes on your approved list. Treat a tool with only the first half as not yet approved, however good the paperwork.

## What should a school require before approving an AI tool?

A school should require two signatures before approving an AI tool: the supplier's and its own.

I call this the Two-Signature Rule, and I offer it as a way of thinking rather than a tested method:

> The Two-Signature Rule is the test I ask leadership teams to apply before any AI tool goes on an approved list: it needs two signatures, not one. The first is the supplier's, a written promise about what the product will and will not do with your people's data and attention. The second is the school's own, a written statement of what the tool is for, who owns it, and what would take it off the list. A vendor standard can supply the first signature. Only the school can supply the second.

Most vetting checklists online concentrate on the first signature: privacy law, data retention, security. Those questions matter. But a tool can pass every one of them and still be the wrong thing for your students to use, or a tool nobody owns, or a tool that stays on the list for years after anyone last opened it. A standard can make a product safe to use. It cannot make it worth using.

## What does the new AFT, UFT and Microsoft standard actually settle?

The new standard settles the supplier's side of the decision, for one supplier, in a form a district can enforce.

According to the [AFT's announcement](https://www.aft.org/press-release/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-schools-protect), the agreement rests on three priorities: protecting privacy, enhancing safety, and providing transparency and control. Its central privacy line is plain: "Student and educator data will not be used to train AI models, sold or repurposed." Schools, it says, will "maintain control over how data is used, retained and deleted." The feature that makes it more than a statement of intent is that districts can write these protections into their Microsoft customer agreements, which makes them contractually enforceable. [GovTech's report](https://www.govtech.com/education/k-12/microsoft-aft-uft-set-precedent-for-district-ai-governance) on the same day describes ten principles in the underlying standard, including bans on behavioral tracking and keystroke logging, human review before AI influences discipline or academic placement, a 180-day data removal timeline and breach notification within 72 hours. Those details come from GovTech's reporting; the union's own release summarizes them at a higher level.

In England, the Department for Education (DfE) has been building the supplier's side from a different direction. Its [Generative AI: product safety standards](https://www.gov.uk/government/publications/generative-ai-product-safety-standards/generative-ai-product-safety-standards), published January 19, 2026, set out thirteen areas that edtech developers are expected to meet, from filtering and security to cognitive development, emotional and social development, mental health and manipulation. Two of them go further than a typical privacy checklist. A product should be able to "detect cognitive offloading actions that indicate the learner is asking the system to do the work for them." It should "avoid attempting to cultivate personal relationships with users." The document is written for suppliers, and says only that schools "may also find these standards helpful in assessing which AI products are safe for use in education."

That matters more this term because of safeguarding. [SWGfL's summary](https://swgfl.org.uk/magazine/keeping-children-safe-in-education-2026-what-do-schools-need-to-know/) of Keeping children safe in education 2026, in force since September 1, 2026, notes that it points schools to the DfE's generative AI product safety guidance when applying filtering and monitoring duties, and names chatbots and companion-style systems among contact risks. For a school in England, the supplier's signature is no longer only good practice. It is part of showing that you took your safeguarding duties seriously.

## Why is a vendor standard not enough on its own?

A vendor standard is not enough because it answers the question "Is this product safe to use?" while the approval decision asks "Is this use right for us?"

The sharpest version of this objection came within hours of the announcement. In a [statement on the deal](https://fairplayforkids.org/statement-on-aft-uft-deal-with-microsoft/), Josh Golin, executive director of the children's advocacy group Fairplay, argued that the agreement "elides the most important question of all: Should student-facing AI products be used in schools at all?" He made two further points any school leader should weigh. The agreement "only applies to Microsoft, not to the many other companies selling AI products to schools." And it "places the burden on schools to execute and enforce the contract, which they are not in a position to do, and which should be the job of regulators."

You do not have to share Fairplay's view of AI in classrooms to see the force of the enforcement point. A contract clause protects you only if someone in your school knows it exists, checks it and acts when it is breached. That is a job, and jobs need owners.

There is also the question of scale. Instructure's [2026 EdTech Top 40 report](https://www.instructure.com/press-release/new-instructure-data-shows-k-12-districts-are-demanding-evidence-not-just-access), covering September 2025 to April 2026, found that US districts accessed an average of 3,001 digital tools each. No leadership team can meaningfully approve three thousand of anything. An approved list that long is not a decision. It is an inventory. A list nothing ever comes off is not an approved list at all.

## The first signature: what to require from the supplier

The first signature is a set of written answers from the supplier, in the contract or terms rather than on a marketing page.

Between the AFT standard and the DfE's thirteen areas, the ground is well mapped. Before approval, I would ask every supplier of an AI tool to answer these in writing:

1. **Training and reuse.** Will any student or staff data be used to train or fine-tune a model, sold or repurposed? The answer you want is no, without conditions buried in a later clause.
2. **Retention and deletion.** Who decides how long data is kept, and how quickly is it deleted when you ask?
3. **Breach and change.** How quickly will you be told about a breach, and how will you be told when the product changes in a way that affects students?
4. **Filtering and monitoring.** For any student-facing tool, what does it block, what does it log, and who in the school can see those logs?
5. **Learning and well-being.** Does the product notice when a learner is asking it to do the work for them, and does it avoid presenting itself as a friend? Both come straight from the DfE's standards, and neither appears on a typical privacy checklist.
6. **Consequential decisions.** Can the product influence a decision about a student, such as placement, discipline or a grade, without a named person reviewing it first?

If a supplier cannot answer these clearly, that is your answer. If they point to a standard they have signed, read what it commits them to; one supplier's commitment says nothing about the next.

## The second signature: what the school has to write itself

The second signature is three sentences the school writes about each tool: what it is for, who owns it, and what would take it off the list.

**What it is for.** Name the job, not the category. "Supporting teachers" is a category. "Drafting first-pass feedback on Year 10 English essays, which the teacher then edits" is a job. If you cannot name the job, you are approving curiosity, and curiosity belongs in a time-limited trial, not on a permanent list.

**Who owns it.** One named person who knows what the supplier promised, checks that it is still true, and is the first call when something goes wrong. This is the answer to Fairplay's enforcement point. The contract does nothing until a person picks it up. If the owner leaves, the tool is unowned until someone else signs.

**What would take it off the list.** A condition and a date. "We will review this in February and remove it if teachers are not editing the feedback before students see it" is a removal condition. "We will keep it under review" is not. It is the same logic as the Exit Question I put to AI pilots, set out in [why AI pilots so often go nowhere](https://blog.theaieducator.io/posts/why-ai-pilots-go-nowhere): anything without a decision date stays forever by default.

For student-facing tools, add a fourth line: what students would lose if the tool did this work for them. Sometimes the honest answer is "nothing much," and the tool frees time for better work. Sometimes the answer is "the thinking we are trying to teach," and then approval should come with limits on when and how students may use it.

Here is how the two signatures work together in a hypothetical case. A head of English asks to approve an AI feedback tool for Year 10 essays. The supplier has signed a standard and confirms in writing that essays are not used for training, are deleted within a set period and are never used to grade a student without teacher review. That is the first signature, and it is solid. The school's side reads: for first-pass feedback that teachers edit before students see it; owned by the head of English; removed if an audit in February shows unedited feedback reaching students, or if students begin submitting the tool's suggestions as their own redrafts. Both signatures are there. The tool goes on the list, with a date beside it.

Change one detail. The head of English leaves at Christmas and nobody takes over. The first signature is unchanged, but the second is now blank. Under the Two-Signature Rule, the tool is no longer approved until a new owner signs.

## What Good Looks Like

Good tool approval is visible in a short list, a name beside every entry, and at least one tool that has come off.

When I work with leadership teams on AI governance, the first thing I ask to see is not the approved list. It is the last tool that came off it, and why. Across the schools and organizations I work with, the teams with the healthiest lists can answer that question in a sentence. The teams that cannot usually have a list that only grows.

In practice, the schools with the strongest lists share a handful of habits:

- **The list is short enough to read.** Staff can name what is on it without looking it up.
- **Every entry has both signatures.** The supplier's written answers are filed, and the school's three sentences sit beside them.
- **Student-facing tools face a higher bar than staff tools.** The approval for a tool students use directly includes the fourth line about what they would lose.
- **Removal is normal.** Taking a tool off the list is treated as a decision working, not a failure.
- **Parents can see it.** The list, and what each tool is for, is published in plain language.

I have advised the UK Department for Education, the Knowledge and Human Development Authority (KHDA) in Dubai and the Ministry of Education in Kazakhstan on AI in education, and I have a lot of sympathy for the people who write standards. A national standard has to work for every school, which is precisely why it cannot tell any one school what to choose. That choice was always going to land with you.

## When is a supplier's signature enough on its own?

A supplier's signature can carry most of the weight when a tool is used only by staff, touches no personal data and does no more than the tools staff already use.

The counterargument deserves a fair hearing: requiring a written purpose, owner and removal date for every staff productivity tool can turn governance into paperwork, and paperwork is how approved lists end up ignored. The answer is to scale the second signature to the stakes, not to drop it.

| Use | First signature (supplier) | Second signature (school) |
|---|---|---|
| Staff only, no personal data | Enterprise terms and data protection checked once | One line: what it is for and who to ask |
| Staff use involving student data | Full written answers on training, retention, breach and change | Purpose, named owner, removal condition and date |
| Student-facing | Full written answers, plus filtering, monitoring, learning and well-being | Purpose, owner, removal condition, and what students would lose |

The bottom row is where the Two-Signature Rule matters most and a contract alone is weakest. It is also where the public argument is loudest this month, from the [restriction decisions](https://blog.theaieducator.io/posts/should-schools-ban-ai) some US districts have made to Fairplay's challenge to the question itself.

## What should leaders do this term?

Take your current approved list, or the tools staff are already using if you do not have one, and check every entry for both signatures.

Anything missing the supplier's written answers gets a request this month, using the six questions above. Anything missing the school's three sentences gets a named owner and a review date, or comes off. Anything student-facing gets the fourth line. Then publish the result, in plain language, to staff and parents.

Where a supplier has signed the new standard, or can show how its product meets the DfE's thirteen areas, welcome it: the first signature gets quicker and firmer. Then do the part no standard will do for you. It is the principle behind the [decisions AI should never make in your school](https://blog.theaieducator.io/posts/which-decisions-should-ai-never-make): the tool can be excellent, but the approval still has to belong to a person.

## The next step

If your leadership team is working out what belongs on its approved list and who should own it, this is the kind of work I support through [AI strategy sessions for schools](https://theaieducator.io/ai-strategy-for-schools), alongside the governance questions that sit underneath it. For the wider picture, [what responsible AI adoption looks like in practice](https://blog.theaieducator.io/posts/what-responsible-ai-adoption-looks-like-in-practice) sets out the habits an approved list belongs to.

## Sources and further reading

- American Federation of Teachers, "AFT, UFT and Microsoft Announce 'National AI Safety & Privacy Standard' for Schools to Protect Students, Families and Educators," September 9, 2026. [aft.org](https://www.aft.org/press-release/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-schools-protect)
- Microsoft, "AFT, UFT and Microsoft announce 'National AI Safety & Privacy Standard' for schools," Microsoft Source, September 9, 2026. [news.microsoft.com](https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/)
- GovTech, "Microsoft, AFT, UFT Set Precedent for District AI Governance," Government Technology, September 9, 2026. [govtech.com](https://www.govtech.com/education/k-12/microsoft-aft-uft-set-precedent-for-district-ai-governance)
- Fairplay, "Statement on AFT/UFT Deal with Microsoft," Josh Golin, September 9, 2026. [fairplayforkids.org](https://fairplayforkids.org/statement-on-aft-uft-deal-with-microsoft/)
- Department for Education, "Generative AI: product safety standards," GOV.UK, January 19, 2026. [gov.uk](https://www.gov.uk/government/publications/generative-ai-product-safety-standards/generative-ai-product-safety-standards)
- SWGfL, "Keeping Children Safe in Education 2026: What Do Schools Need to Know?," July 9, 2026. [swgfl.org.uk](https://swgfl.org.uk/magazine/keeping-children-safe-in-education-2026-what-do-schools-need-to-know/)
- Instructure, "New Instructure Data Shows K-12 Districts Are Demanding Evidence, Not Just Access to Edtech Tools," 2026 EdTech Top 40 report, June 29, 2026. [instructure.com](https://www.instructure.com/press-release/new-instructure-data-shows-k-12-districts-are-demanding-evidence-not-just-access)

*Dan Fitzpatrick is the founder of The AI Educator, a Forbes contributor and the author of bestselling books on AI in education. [Read more about Dan](https://www.theaieducator.io/about).*

## Frequently asked questions

### Does the AFT and Microsoft AI standard mean schools can approve Microsoft's AI tools?

Not on its own. The standard settles what Microsoft promises to do with student and educator data, and districts can make it contractually enforceable. It does not decide what a tool is for in your school, who owns it or when you would remove it. The school still has to write that half itself.

### How should schools vet AI tools before approving them?

Get two things in writing. From the supplier: answers on training, retention, breaches, product changes, filtering, learning and consequential decisions. From the school: what the tool is for, who owns it and what would take it off the list. Student-facing tools also need a line on what students would lose.

### What questions should schools ask AI vendors?

Ask whether student or staff data trains models or is sold, who controls retention and deletion, how fast breaches and product changes are reported, what student-facing tools block and log, whether the product detects learners outsourcing their thinking, and whether it can influence decisions about a student without human review.

### Who should approve AI tools in a school?

A named senior leader should approve the list, but every tool on it needs its own named owner. The owner knows what the supplier promised, checks it stays true and is the first call when something goes wrong. If the owner leaves and nobody takes over, the tool should lose its approval.

### Do schools in England have to follow the DfE's generative AI product safety standards?

The standards are written for edtech developers and suppliers, not schools. The DfE says schools may find them helpful when judging which AI products are safe. Keeping children safe in education 2026 points schools to the DfE's product safety guidance for filtering and monitoring, so they are sensible questions to put to suppliers.

### How often should a school review its approved AI tools list?

Give every tool its own review date when it is approved, rather than reviewing the whole list once a year. Tie each date to a removal condition, such as unedited AI feedback reaching students. Removing a tool should be treated as the approval process working, not as a failure.

---
Source: [What Should Schools Require Before Approving an AI Tool?](https://blog.theaieducator.io/posts/approving-ai-tools-for-schools)
Publisher: [The AI Educator](https://theaieducator.io)
