For counsel, privacy & compliance

Defensible, not just responsible

Standards tell you how to be responsible. This page is about being defensible when someone challenges you: which laws actually apply, why AI outputs are records, the evidentiary file to defend a decision, and where IP, consent, and liability sit.

An orientation aid for working with counsel, not legal advice. Obligations vary by state, sector, and institution. Verify everything here with your own general counsel, privacy officer, and compliance team.

Which laws actually apply

Standards alignment is not legal compliance. The obligations that bind a US campus, the trigger that makes each apply, and the part of the framework that answers it.

FERPA
Applies when

Any AI that touches student education records or PII.

Requires

Vendor as a 'school official' with legitimate interest, data-use limits, no redisclosure, and consent where the exception doesn't reach.

Pillar 4 · Governance, Risk & Compliance
ADA Title II / §504 / §508
Applies when

Public and federally funded institutions; any student- or public-facing tool.

Requires

Accessible AI interfaces and outputs, WCAG 2.1 AA is the operative bar, with firm DOJ deadlines for public entities.

Tool review · accessibility gate
EU AI Act
Applies when

Programs, students, or research partners in the EU; some education uses are 'high-risk'.

Requires

Risk classification, transparency to affected people, human oversight, and documentation for high-risk systems.

Standards alignment
State AI & privacy laws
Applies when

Varies by state, e.g., Colorado AI Act, CCPA/CPRA, Illinois BIPA for biometrics/proctoring.

Requires

Impact assessments, consumer/data-subject rights, biometric consent, and notice for consequential automated decisions.

AI Registry & risk register
Title VI / Title IX / EEOC
Applies when

AI in admissions, advising, conduct, or anything affecting protected classes.

Requires

No disparate impact; documented bias testing and a basis to defend a consequential decision.

Pillar 2 · AI Principles
Employment & labor law
Applies when

AI in hiring, performance, monitoring, or anything affecting faculty and staff as employees.

Requires

Bias audits and ADA Title I accommodation in hiring; notice and often a duty to bargain where AI changes working conditions.

Pillar 7 · Roles & Responsibilities
HIPAA
Applies when

Student health, counseling, or any clinical/covered-entity context.

Requires

BAAs with vendors, minimum-necessary use, and safeguards for protected health information.

Pillar 4 · data governance
GDPR
Applies when

International students and EU-based research subjects or partners.

Requires

Lawful basis, data-subject rights, transfer mechanisms, and limits on solely automated decisions.

Standards alignment
COPPA
Applies when

Pre-college, dual-enrollment, or programs serving under-13 minors.

Requires

Verifiable parental consent before collecting a child's data through an AI tool.

Governance Guide

AI outputs are records

The moment a prompt or output is discoverable, it's a record you must retain, produce, or defend. Most campuses have no schedule for any of it.

The decision-defensibility file

When OCR opens an investigation or a denied applicant sues, 'the model decided' is not a defense. For each consequential AI use, assemble the evidentiary file before you need it.

Attach to every high-risk registry entry
  1. What the system did, and the exact role AI played in the decision
  2. The human review: who, with what authority, and the basis for the final call
  3. Bias / disparate-impact testing performed, with results and date
  4. The notice given to the affected person, and when
  5. The appeal or human-review path offered, and its outcome
  6. The model documentation / system card the decision relied on
  7. The audit-log entry for that specific decision, time-stamped
Build it into the AI Registry

Employment & the workforce

AI doesn't only affect students. Using it on faculty and staff, in hiring, monitoring, or evaluation, opens a distinct body of employment and labor law.

IP & copyright positions to set

Counsel gets these weekly. Five positions to decide on purpose, before a dispute forces the answer.

Notice, consent & the right to a human

When you must tell people AI is involved, when notice isn't enough, and the appeal path that is also your strongest defense.

1
When notice is required

Tell people when AI is used in a consequential way about them, admissions, advising flags, conduct, financial aid. Increasingly a legal requirement, not just good practice.

2
What the notice says

Plain-language: that AI is used, for what, what data it uses, and how to reach a human. No dark patterns.

3
Consent vs. notice

Some uses (biometrics, minors, certain state laws) require affirmative consent, not just notice. Know which bucket you're in.

4
Right to human review

For consequential decisions, offer a meaningful path to a human, required under several frameworks and the strongest defense you can build.

5
Appeal path & timeline

Publish how someone contests an AI-informed decision, to whom, and by when. An unusable appeal is no appeal.

Liability & insurance

Where liability lands for an AI-driven error, and the contract and coverage terms that move it off your books.

Indemnification from the vendor

Shift IP-infringement and data-breach liability to the party that built and controls the model.

Limitation-of-liability review

Vendor caps are often a fraction of your real exposure, negotiate them against the data at stake.

Cyber / E&O coverage check

Confirm your policies actually cover AI-driven errors and AI-related breaches; many predate the risk.

Named internal accountable owner

Liability needs a human home. Every high-risk AI system should have a named owner, not a committee.

Warranty & performance terms

Get commitments on accuracy, availability, and security you can actually enforce, not aspirational marketing.