Any AI that touches student education records or PII.
Vendor as a 'school official' with legitimate interest, data-use limits, no redisclosure, and consent where the exception doesn't reach.
Standards tell you how to be responsible. This page is about being defensible when someone challenges you: which laws actually apply, why AI outputs are records, the evidentiary file to defend a decision, and where IP, consent, and liability sit.
An orientation aid for working with counsel, not legal advice. Obligations vary by state, sector, and institution. Verify everything here with your own general counsel, privacy officer, and compliance team.
Standards alignment is not legal compliance. The obligations that bind a US campus, the trigger that makes each apply, and the part of the framework that answers it.
Any AI that touches student education records or PII.
Vendor as a 'school official' with legitimate interest, data-use limits, no redisclosure, and consent where the exception doesn't reach.
Public and federally funded institutions; any student- or public-facing tool.
Accessible AI interfaces and outputs, WCAG 2.1 AA is the operative bar, with firm DOJ deadlines for public entities.
Programs, students, or research partners in the EU; some education uses are 'high-risk'.
Risk classification, transparency to affected people, human oversight, and documentation for high-risk systems.
Varies by state, e.g., Colorado AI Act, CCPA/CPRA, Illinois BIPA for biometrics/proctoring.
Impact assessments, consumer/data-subject rights, biometric consent, and notice for consequential automated decisions.
AI in admissions, advising, conduct, or anything affecting protected classes.
No disparate impact; documented bias testing and a basis to defend a consequential decision.
AI in hiring, performance, monitoring, or anything affecting faculty and staff as employees.
Bias audits and ADA Title I accommodation in hiring; notice and often a duty to bargain where AI changes working conditions.
Student health, counseling, or any clinical/covered-entity context.
BAAs with vendors, minimum-necessary use, and safeguards for protected health information.
International students and EU-based research subjects or partners.
Lawful basis, data-subject rights, transfer mechanisms, and limits on solely automated decisions.
Pre-college, dual-enrollment, or programs serving under-13 minors.
Verifiable parental consent before collecting a child's data through an AI tool.
The moment a prompt or output is discoverable, it's a record you must retain, produce, or defend. Most campuses have no schedule for any of it.
Treat AI inputs and outputs as potential education records, public records, or business records, classified and retained accordingly, not transient chat.
Decide how long prompts, outputs, and logs are kept, where, and when they're destroyed, and align it with your existing records schedule.
At public institutions, AI interactions can be requestable. Assume discoverability and avoid putting in a prompt what you wouldn't want released.
When litigation is anticipated, automated deletion of relevant prompts, logs, and outputs must stop. Build a hold trigger into the AI systems, not just email.
When OCR opens an investigation or a denied applicant sues, 'the model decided' is not a defense. For each consequential AI use, assemble the evidentiary file before you need it.
AI doesn't only affect students. Using it on faculty and staff, in hiring, monitoring, or evaluation, opens a distinct body of employment and labor law.
Resume screeners and video-interview tools face EEOC scrutiny and a growing set of state and local laws, bias-audit mandates, video-interview consent. Audit for disparate impact and keep a human on the decision.
Hiring and performance AI must accommodate disabled applicants and employees; automated screening can unlawfully exclude. Build accommodation and an opt-out into the process.
AI-driven productivity and surveillance tools raise privacy, consent, and morale questions, and, in some states, legal limits. Be transparent about what's monitored and why.
An AI-informed adverse employment action needs the same evidentiary file as any consequential decision: human review, the basis, and a documented appeal.
Where faculty or staff are unionized, deploying AI that changes job duties or working conditions can trigger notice and bargaining obligations under labor law and your collective-bargaining agreements.
Counsel gets these weekly. Five positions to decide on purpose, before a dispute forces the answer.
Set institutional position on ownership of AI-generated work, and note that purely AI-generated content may not be copyrightable at all.
Generative tools carry latent infringement risk. Push that exposure to the vendor through warranties and IP indemnification.
Clarify who owns student–AI work and how it interacts with academic-integrity and existing student-IP policy.
Address AI use in research and publication, disclosure expectations, and how it meets funder and journal requirements.
Define when AI-generated institutional content must be labeled, for transparency and to avoid misrepresentation.
When you must tell people AI is involved, when notice isn't enough, and the appeal path that is also your strongest defense.
Tell people when AI is used in a consequential way about them, admissions, advising flags, conduct, financial aid. Increasingly a legal requirement, not just good practice.
Plain-language: that AI is used, for what, what data it uses, and how to reach a human. No dark patterns.
Some uses (biometrics, minors, certain state laws) require affirmative consent, not just notice. Know which bucket you're in.
For consequential decisions, offer a meaningful path to a human, required under several frameworks and the strongest defense you can build.
Publish how someone contests an AI-informed decision, to whom, and by when. An unusable appeal is no appeal.
Where liability lands for an AI-driven error, and the contract and coverage terms that move it off your books.
Shift IP-infringement and data-breach liability to the party that built and controls the model.
Vendor caps are often a fraction of your real exposure, negotiate them against the data at stake.
Confirm your policies actually cover AI-driven errors and AI-related breaches; many predate the risk.
Liability needs a human home. Every high-risk AI system should have a named owner, not a committee.
Get commitments on accuracy, availability, and security you can actually enforce, not aspirational marketing.