# US District AI Policy Template: What FERPA and COPPA Settle

Canonical URL: https://blog.theaieducator.io/posts/us-district-ai-policy-template
Publication: Dan Fitzpatrick Insights
Author: Dan Fitzpatrick
Topic: AI Governance and Responsible Leadership
Published: 2026-10-11T07:26:36.000Z
Modified: 2026-10-11T07:29:25.364Z

Only two of the ten sections in a US district AI policy are settled by federal law. Here is which ones, why the best state model policies leave the harder half unwritten, and a ten-section template you can copy.

## In brief

A US school district's AI policy must contain ten sections, and only two are settled by federal law: what a vendor may do with student records under FERPA's school official exception at 34 CFR 99.31, and what a tool directed to children under 13 must do under the amended COPPA Rule, in force since its April 22, 2026 compliance date. One more, human review of AI-supported decisions about students, is settled in some states and not others. The remaining seven, including whether students may use AI and from which grade, are the district's own decisions. The US Department of Education declined in April 2026 to add any federal parental consent, opt-out, bias testing or data governance requirement, leaving those choices to states and localities.

## Key takeaways

- A US district AI policy needs ten sections: scope, purpose, staff use, student data and vendors, children under 13, student use by grade, disclosure in graded work, approved tools, decisions AI may not make, and accountability with a review date.
- Only two of those ten are settled by federal law, and neither is an AI rule: FERPA's school official exception at 34 CFR 99.31, and the Federal Trade Commission's amended COPPA Rule, whose compliance date passed on April 22, 2026.
- FERPA's school official exception requires a vendor to be under the district's direct control with respect to the use and maintenance of education records, which a consumer chatbot that trains on what you type is not.
- The FTC declined to finalize its proposed ed tech amendments to the COPPA Rule, so no codified rule lets a district supply parental consent on a family's behalf, and voiceprints and facial templates are now personal information.
- The US Department of Education's supplemental AI priority of April 13, 2026 creates no obligation for a district that is not applying for a grant; commenters asked for consent, opt-out and data governance mandates and the Department declined.
- State guidance narrows the field without finishing the job: Ballotpedia recorded 27 states with K-12 AI guidance as of August 2025, and Washington DC's September 2026 model policy states that it covers staff use and not student use or procurement.
- The sections districts most often leave blank are student use by grade and what takes a tool off the approved list, and a board handed a policy with those holes in it tends to close them by banning AI outright.

A US school district's AI policy must contain ten sections, and only two of them are settled by federal law. FERPA governs what a vendor may do with student records. The amended COPPA Rule governs tools directed to children under 13. Everything else, including whether students may use AI at all, is the district's own decision, written down or left open.

That split matters this fall, because boards have started deciding by default. On October 9, 2026, [NBC Washington reported](https://www.nbcwashington.com/video/news/local/maryland/frederick-county-bans-ai-use-for-all-students/4165666/) that the Frederick County, Maryland, Board of Education had voted to ban artificial intelligence for all public school students. Five weeks earlier, New York City Public Schools announced a one-year moratorium on student-facing AI tools from 2-K through eighth grade, covering roughly 600,000 students, while teachers kept permission to use AI for instructional planning, [as K-12 Dive reported on September 2, 2026](https://www.k12dive.com/news/new-york-city-pauses-ai-use-for-elementary-middle-school-students/829496/).

A moratorium is a policy. It is the policy a district writes when it cannot tell which questions are its own. So here is the map, and then the template.

## What must a US district AI policy contain?

A district AI policy must contain ten sections: scope, purpose, staff use, student data and vendors, children under 13, student use by grade, disclosure in graded work, approved tools, decisions AI may not make, and accountability with a review date. Two are settled by federal law. One is settled in some states and not others. The remaining seven are yours, and a board that leaves them open has not avoided a decision. It has handed it to whoever opens a browser tab on Monday morning.

This is the American counterpart to [the school AI policy template](https://blog.theaieducator.io/posts/school-ai-policy-template) written for England, where the settled clauses come from the Department for Education, JCQ and statutory safeguarding guidance. The sections look alike; the law underneath them does not.

## Which clauses does federal law actually settle?

Federal law settles two things and declines the rest: what happens to student records when you hand them to a vendor, and what a product must do before a child under 13 uses it. Neither is an AI rule. Both predate generative AI by decades, and both bind the tools your staff already use.

FERPA lets a district give education records to an outside vendor without parental consent only through the school official exception. Under [34 CFR 99.31(a)(1)](https://www.law.cornell.edu/cfr/text/34/99.31), a contractor may be treated as a school official if it "performs an institutional service or function for which the agency or institution would otherwise use employees", "is under the direct control of the agency or institution with respect to the use and maintenance of education records", and is subject to the redisclosure limits in 99.33(a).

Read "direct control" slowly. A consumer chatbot whose terms let the provider improve its models on whatever you type is not under your direct control. That is not a close call, and it is the clause most district policies get wrong by silence. The longer argument is [can staff put student data into ChatGPT](https://blog.theaieducator.io/posts/can-staff-put-student-data-into-chatgpt).

COPPA is the second settled clause, and the surprise is what it does not say. The Federal Trade Commission's amended Children's Online Privacy Protection Rule was published on April 22, 2025, took effect on June 23, 2025, and carried a compliance date of April 22, 2026 for most provisions, so it binds now. In the same rulemaking the FTC said it is ["not finalizing the proposed amendments to the Rule related to ed tech"](https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule) and will keep enforcing COPPA in ed tech consistent with its existing guidance. No codified rule lets a district consent on a parent's behalf. Plenty of policies assume one does. The amended Rule also brings biometric identifiers, voiceprints and facial templates among them, inside personal information, which quietly captures every voice-enabled tool a district might pilot in an elementary classroom.

Then the thing leaders expect to find and do not. On April 13, 2026 the Department of Education published its [final supplemental priority on advancing artificial intelligence in education](https://www.federalregister.gov/documents/2026/04/13/2026-07087/final-priority-and-definitions-secretarys-supplemental-priority-and-definitions-on-advancing), effective May 13, 2026. Commenters asked for parental consent, opt-outs, bias testing and data governance. The Department declined, said it upholds the student privacy protections already in law, and left those choices to states and localities. The priority decides which grant applications win. It requires nothing of a district not applying for one.

| Clause | Who settles it | Your position |
|---|---|---|
| What a vendor may do with student records | Federal law, FERPA 34 CFR 99.31 | Settled. Direct control is a contract term, not a preference. |
| Tools directed to children under 13 | Federal law, amended COPPA Rule | Settled. No school-consent shortcut exists. |
| Human review of decisions affecting students | Your state, in some states only | Check your state guidance before you draft. |
| Whether students may use AI, and from which grade | The district | Yours. A ban is an answer; so is silence, and silence is the worse one. |
| What takes a tool off the approved list | The district | Yours, and almost always missing. |

## Why do state model policies leave the harder half unwritten?

State guidance narrows the field without finishing the job, and the better documents admit it. As of August 2025, [Ballotpedia recorded 27 states](https://ballotpedia.org/AI_guidance_issued_by_state_departments_of_education) that had released AI guidance for K-12 public schools, voluntary almost everywhere. California's says it is "in no way, required to be followed." Oklahoma's says it "is not law or regulation."

Two 2026 examples show the shape of the gap. Maryland's State Board guidance of February 24, 2026 carries real obligations: districts "must minimize data collection by limiting student data shared with AI systems", "must clearly communicate what AI tools are used, what data are collected", must conduct "documented risk assessments" before approval, and must ensure "any AI-supported decision affecting students requires human review." Yet the Board memo carrying it says "no action is required; this information is for information and discussion only", and the local planning guide calls itself "a reflective planning tool. It is not a compliance checklist." Five obligations, no deadline, no required elements.

The District of Columbia drew the boundary more honestly. OSSE released an AI model policy for staff use on September 1, 2026, on a stoplight framework: red for high-stakes decisions needing human judgment, such as discipline, teacher evaluations and IEP or Section 504 eligibility; yellow for limited use with safeguards, such as drafting IEP language; green for permitted use with human review, such as lesson planning. It is a useful document. It also says it "is focused on staff use and does not set guidance for student use or tool procurement."

So a district adopting the best model policy available has settled staff use and left student use, procurement and accountability where it found them. That is the harder half, and the half parents ask about.

## The template: a district AI policy you can copy

Copy the ten sections below and work through them in order. Brackets mark a decision only your district can make, left visibly unfinished on purpose: a template that pretends those decisions are made is worse than none. Sections 4 and 5 are marked Settled; do not soften them. Section 9 is settled for you in some states.

### 1. Scope and status

This policy applies to all employees, contractors, volunteers and students of [district], and to any use of artificial intelligence for district purposes on any device. It takes effect on [date], approved by [the board, on date]. Where it conflicts with the district's data privacy, acceptable use or student records policies, [name the policy that wins].

### 2. Purpose

[District] permits AI use to [state the two or three outcomes you want: cut time spent on administrative drafting, widen access for multilingual learners, strengthen feedback]. It does not permit AI use that [state the two or three you refuse: replacing a professional judgment about a student, generating a record nobody has read, producing work a student submits as their own].

### 3. Staff use: what is permitted without asking

Staff may use approved tools without asking for [list: drafting communications, generating lesson materials, summarizing documents they wrote]. Staff must get approval from [named role] before using AI for [list: anything involving identifiable student information, anything a family receives as a formal determination]. A staff member who uses AI remains the author of the output and answers for its accuracy.

### 4. Student data and vendors (Settled)

No education record, and no personally identifiable information from one, may be entered into an AI tool unless the vendor holds a written agreement placing it under the district's direct control with respect to the use and maintenance of education records, limiting redisclosure in line with 34 CFR 99.33(a), and prohibiting use of district data to train or improve the vendor's models. Consumer accounts and personal logins are covered by no such agreement and may not be used with student information. [Named role] keeps the list of vendors that hold one.

### 5. Children under 13 (Settled)

Any tool directed to children under 13, or known to be used by them, must meet the amended COPPA Rule before it reaches a classroom, including verifiable parental consent where the Rule requires it and the treatment of biometric identifiers such as voiceprints and facial templates as personal information. The district does not assume it can consent on a parent's behalf. [Named role] confirms compliance in writing before approval.

### 6. Student use: which tasks, and from which grade

Students in [grades] may use approved tools for [tasks]. Students in [grades] may not, for [tasks]. Where students use AI, a member of staff [supervises directly / reviews afterward]. Students with disabilities using assistive technology, and multilingual learners using translation support, are [state the exception, because every district that has written a restriction has needed one].

### 7. Disclosure in graded work

Students must declare AI use in graded work by [method], stating [what was used, for which part, and what the student did themselves]. Undeclared use is handled under [the academic integrity policy, by name], and [named role] decides on the balance of evidence, not on the output of a detection tool. Detectors are not reliable enough to carry a finding alone, which is why [whether they work at all](https://blog.theaieducator.io/posts/do-ai-detectors-actually-work) is worth settling before a case arrives rather than during one.

### 8. Approved tools

Only tools on the district's approved list may be used for district purposes. A tool reaches the list when [named role] has confirmed the agreement in section 4, the check in section 5 where it applies, and a written statement of what the tool is for, who owns it, and what would take it off. The list is published at [location] and reviewed [frequency].

### 9. Decisions AI may not make

AI may not make, or substantially determine, decisions about [student discipline, eligibility for special education or Section 504 services, grade promotion or retention, personnel evaluation]. In each case a named person reviews the evidence and decides, and the record shows who. [If your state requires human review of any AI-supported decision affecting students, cite it here and treat this section as settled.]

### 10. Accountability and review

[Named role] owns this policy and answers for it. Staff report AI-related incidents to [named role] within [period]. The policy is reviewed on [date], earlier if [a vendor changes its terms, state guidance is issued, an incident occurs, or a tool on the list changes what it does]. The review is recorded in writing, including a decision to change nothing.

## What I See in Practice

The mistake I see most often is a district writing the sections it finds easy and leaving the two that decide everything. Sections 6 and 8 are the ones that go missing. Writing about AI for Forbes, and then sitting with leadership teams who have read the column and want to act, I keep hearing one conversation: everyone agrees staff should use AI thoughtfully, and nobody will say out loud which grade a student may start, or who takes a tool away once it is in classrooms.

Those omissions explain the bans. A board handed a policy with a hole where student use should be will either send it back or close the hole the only way one meeting allows, which is to prohibit everything. New York City's moratorium is the scoped version of that move. A district-wide prohibition with no pilot and no end date is the unplanned version, and it usually arrives after something has gone wrong.

The test is not whether your policy sounds responsible. It is whether its lines survive contact with a Monday. That is what [the Heading Test](https://blog.theaieducator.io/posts/what-should-a-school-ai-policy-contain) is for, and most drafts lose three quarters of their content to it.

## What takes a tool off your approved list?

Nothing, in most districts, which is why approved lists grow and never shrink. My test is deliberately double:

> The Two-Signature Rule is the test I ask leadership teams to apply before any AI tool goes on an approved list: it needs two signatures, not one. The first is the supplier's, a written promise about what the product will and will not do with your people's data and attention. The second is the school's own, a written statement of what the tool is for, who owns it, and what would take it off the list. A vendor standard can supply the first signature. Only the school can supply the second.

In a district the second signature belongs to a named officer, not a committee. Three sentences carry it, plus a fourth for student-facing tools: what students would lose if the tool did this work for them.

A standard can make a product safe to use. It cannot make it worth using. An approved list that long is not a decision. It is an inventory. This is my suggested way of thinking about approval rather than a tested instrument, and [approving AI tools for schools](https://blog.theaieducator.io/posts/approving-ai-tools-for-schools) sets out the process around it.

## What should you do before the next board meeting?

Five steps, in this order.

1. Print the ten sections and mark 4 and 5 as settled. Saying so early stops the meeting spending its energy there.
2. Check whether your state requires human review of AI-supported decisions about students. If it does, section 9 is settled too, and you cite it rather than debate it.
3. Put a name and a date against each of the remaining seven. Not a department. A person.
4. Draft section 6 first, because it is the one the board will ask about and the one a moratorium replaces.
5. Set the review date in section 10 and name the four events that bring it forward. A policy with a date and no triggers gets reviewed late.

Do those five things and you walk in with a decision to approve rather than a document to admire. Section 10 is also why [who is accountable when AI gets it wrong](https://blog.theaieducator.io/posts/who-is-accountable-when-ai-gets-it-wrong) is the question leaders find hardest and boards remember.

## Where this goes next

The template settles the document. It does not settle what your district is trying to achieve with AI, and in what order. A policy written before that conversation records decisions nobody has made. If your leadership team is working through this, it is the kind of work I support through [AI strategy sessions for schools and districts](https://theaieducator.io/ai-strategy-for-schools?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=us-district-ai-policy-template), and the [weekly newsletter](https://theaieducator.io/?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=us-district-ai-policy-template#newsletter) carries the governance changes worth knowing about as they land.

## Sources and further reading

- Federal Trade Commission, [Children's Online Privacy Protection Rule, final amendments](https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule), 90 FR 16918, April 22, 2025; effective June 23, 2025; compliance April 22, 2026.
- US Department of Education, [Secretary's Supplemental Priority on Advancing Artificial Intelligence in Education](https://www.federalregister.gov/documents/2026/04/13/2026-07087/final-priority-and-definitions-secretarys-supplemental-priority-and-definitions-on-advancing), 91 FR 18774, April 13, 2026; effective May 13, 2026.
- Cornell Law School, Legal Information Institute, [34 CFR 99.31](https://www.law.cornell.edu/cfr/text/34/99.31).
- Maryland State Department of Education, [Artificial Intelligence Guidance](https://msde.maryland.gov/media/25025), State Board of Education, February 24, 2026.
- OSSE, District of Columbia, [AI Model Policy for staff use](https://osse.dc.gov/release/osse-releases-ai-model-policy-guide-responsible-staff-use-schools), September 1, 2026.
- Ballotpedia, [AI guidance issued by state departments of education](https://ballotpedia.org/AI_guidance_issued_by_state_departments_of_education), 27 states as of August 2025.
- K-12 Dive, [New York City pauses AI use for elementary, middle school students](https://www.k12dive.com/news/new-york-city-pauses-ai-use-for-elementary-middle-school-students/829496/), September 2, 2026.
- NBC Washington, [Frederick County bans AI use for all students](https://www.nbcwashington.com/video/news/local/maryland/frederick-county-bans-ai-use-for-all-students/4165666/), October 9, 2026.

*Dan Fitzpatrick is The AI Educator. He helps leaders and organizations understand, plan for and lead the changes caused by AI. [More about Dan](https://theaieducator.io/about?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=us-district-ai-policy-template).*


## Frequently asked questions

### What must a US school district AI policy contain?

Ten sections: scope and status, purpose, staff use, student data and vendors, children under 13, student use by grade, disclosure in graded work, approved tools, decisions AI may not make, and accountability with a review date. Two are settled by federal law. The other eight are mostly yours to decide.

### Does federal law require school districts to have an AI policy?

No. The US Department of Education's supplemental priority on advancing AI in education, published April 13, 2026, shapes which grant applications win priority and imposes nothing on a district that is not applying. Commenters asked for consent and data governance mandates, and the Department left those choices to states and localities.

### How does FERPA apply to AI tools in schools?

Through the school official exception. Under 34 CFR 99.31, a vendor may receive education records without parental consent only if it performs a service the district would otherwise staff, sits under the district's direct control over the use and maintenance of those records, and accepts the redisclosure limits in 99.33(a).

### Can a school district give COPPA consent on behalf of parents?

Not under any codified rule. In its April 2025 amendments the Federal Trade Commission said it was not finalizing the proposed ed tech provisions and would keep enforcing COPPA in ed tech under its existing guidance, so a district relying on a school consent shortcut is relying on practice, not regulation.

### Do state AI guidance documents tell districts what to put in a policy?

Rarely in full. Ballotpedia recorded 27 states with K-12 AI guidance as of August 2025, almost all voluntary. Maryland's February 2026 framework sets five obligations with no deadline and no required elements, and its planning guide describes itself as a reflective tool rather than a compliance checklist.

### Why are school districts banning AI instead of writing a policy?

Because a ban is the only decision one board meeting can make when the policy in front of it leaves student use blank. New York City's one-year moratorium through eighth grade is the scoped version of that move. A district-wide prohibition with no pilot is the unplanned version.

### Who should own an AI policy in a school district?

One named person, not a committee and not a department. Section 10 of the template asks for the role that owns the policy, the period within which staff must report incidents, the review date, and the four events that bring that date forward. A policy with no owner has no reviewer.

---
Source: [US District AI Policy Template: What FERPA and COPPA Settle](https://blog.theaieducator.io/posts/us-district-ai-policy-template)
Publisher: [The AI Educator](https://theaieducator.io)
