Is an AI Teacher Safe for Kids? A Parent’s Guide to Data Privacy Under FERPA and COPPA

Yes, an AI teacher can be safe for children — but “safe” depends entirely on how the tool handles your child’s data, and two U.S. federal laws set that bar: FERPA and COPPA. A well-built AI teacher is designed to meet both standards from the start, not bolt them on afterward.

A teacher safeguarding a child's notebook and tablet with a padlock and shield, showing that an AI teacher is safe only when the child's data is protected
An AI teacher is only as safe as the way it protects your child’s data — not the technology itself.

The question is not whether AI is inherently dangerous, but whether a specific tool collects only what it needs, keeps it secure, and never trains its models on your child’s information. This guide explains exactly what to check, using FERPA at studentprivacy.ed.gov as the baseline for what schools must already guarantee.

The Short Answer: Safety Depends on Data Handling, Not the AI Itself

What “safe” actually means for a kid’s data

Safety for an AI tutor comes down to three concrete behaviors:

  • It collects only the minimum personally identifiable information (PII) needed to function.
  • It encrypts that data and never shares it with third parties without consent.
  • It does not use a child’s schoolwork to train its underlying model.

The real risk with an educational AI learning tool is rarely “the AI turning malicious” — it is data being logged, retained, or repurposed somewhere the parent never agreed to. A useful analogy is the 2023 incident where Samsung employees pasted internal source code into ChatGPT and that code became part of the record the vendor could retain; the same mechanic applies when a child’s essay or a struggling reader’s practice answers are typed into a system with no data-handling guarantees.

Consumer chatbots vs. purpose-built school tools

General-purpose chatbots like ChatGPT set a minimum age of 13 in their terms of service (18 without parental consent), and by design they are not built to meet COPPA compliance for children under 13. Tools built specifically for classrooms are a different category: a purpose-built AI tutor typically signs a Data Processing Agreement (DPA) with the school and states its FERPA and COPPA compliance in writing. The distinction that matters for a parent is simple — a general-purpose chatbot is not the same product as an AI education tool designed around student-privacy law.

FERPA: What It Is and What It Protects

What FERPA covers

FERPA — the Family Educational Rights and Privacy Act — was enacted in 1974 and is codified at 34 CFR Part 99 (20 U.S.C. § 1232g). It is administered by the U.S. Department of Education and protects the privacy of education records: records directly tied to a student and maintained by a school. FERPA applies to any school or agency that receives federal funding, which covers nearly all U.S. public schools and most colleges. The personally identifiable information it protects includes a student’s name, address, and identifiers such as a student ID or biometric record, as well as indirect identifiers like date or place of birth and any other detail that could reasonably identify the student.

Infographic of the personal information FERPA protects: name, address, student ID, biometric record, date of birth, and education records
FERPA protects far more than grades — a student’s name, address, ID, and biometric data all count as protected records.

Parent and student rights under FERPA

RightWhat it means
Inspect and review recordsSchools must provide access within 45 days of a request
Request amendmentParents can ask the school to correct inaccurate or misleading records
Consent to disclosureA signed consent is required before records are shared, except for specific statutory exceptions
File a complaintParents can file directly with the U.S. Department of Education

These rights belong to the parent until the student turns 18 or enrolls in a postsecondary institution, at which point they transfer to the student, who becomes an “eligible student” under the law.

How FERPA applies to an AI teacher

When a school gives a vendor access to student data, that vendor typically operates under the “school official” exception at 34 CFR 99.31(a)(1) — meaning separate parental consent under FERPA is not required, provided the vendor uses the data only under the school’s direct control and only for the purpose the school authorized. This exception is narrow: a parent who signs their child up for an AI teacher for kids independently, outside of any school arrangement, does not fall under it, and different consent rules apply.

COPPA: The Law That Protects Children Under 13

What COPPA requires

COPPA — the Children’s Online Privacy Protection Act — was enacted in 1998 and updated in 2013. Unlike FERPA, it is enforced by the Federal Trade Commission (FTC), not the Department of Education. It applies to commercial operators of websites, services, or apps that knowingly collect personal information from children under 13. COPPA requires a clear privacy policy, verifiable parental consent before data collection begins, data minimization, reasonable security, and limited retention. Violations carry penalties of up to $53,088 per infraction, an amount the FTC adjusts annually for inflation; in 2022 the FTC secured a $275 million penalty against Epic Games over COPPA violations tied to Fortnite, the largest civil penalty ever obtained for violating an FTC rule at the time. Any AI teacher for kids marketed to households with children under 13 sits squarely inside this rule.

Five COPPA requirements shown as a step-by-step flow: privacy policy, parental consent, data minimization, security, and limited retention
A COPPA-compliant AI tutor has to clear all five steps — from a clear privacy policy to limited data retention.

The 2025 COPPA amendments — what changed

The 2025 COPPA amendments, finalized by the FTC, shifted the default from opt-out to opt-in: operators must now obtain separate, affirmative parental consent before sharing a child’s data with third parties, document each consent decision, and maintain a written data-security program. For an AI tutor, this closes a loophole that previously let some services share data with advertising or analytics partners by default unless a parent actively objected.

Yes, but narrowly. Under FTC guidance, a school can provide COPPA consent on behalf of parents — but only for strictly educational purposes and only when data collection is limited to what is necessary for that use. School consent does not extend to commercial use or advertising. If a child uses an AI tutoring app at home rather than through a school-issued account, the parent — not the school — must give consent.

FERPA vs. COPPA: How the Two Laws Differ

Both laws can apply to the same AI tutor at once, but they answer different questions and hold different parties responsible. The table below lays out the split.

FERPACOPPA
What it regulatesEducation recordsPersonal data collected from children under 13
Who it applies toSchools receiving federal fundingCommercial operators (the AI tool itself)
Administered byU.S. Department of EducationFederal Trade Commission (FTC)
Who is accountableThe schoolThe company that built the tool
Consent mechanismSchool official exception or signed parental consentVerifiable parental consent (or narrow school consent)

The practical difference is who answers for a failure. FERPA holds the school accountable for what happens to a student’s records; COPPA holds the software vendor accountable for what it does with a child’s data. Most AI tutoring tools used in K-12 settings are subject to both laws at the same time, which is why a compliant vendor needs to satisfy each one separately rather than treating them as interchangeable.

No funds shall be made available under any applicable program to any educational agency or institution which has a policy or practice of permitting the release of education records (or personally identifiable information contained therein…) of students without the written consent of their parents.

20 U.S.C. § 1232g(b)(1), the FERPA statute

What the Laws Do NOT Cover: The AI Gaps Parents Should Know

AI-generated data falls through the cracks. FERPA protects traditional education records — grades, attendance, disciplinary notes — but it does not clearly extend to AI-generated data: the predictive insights and behavioral patterns a model infers about a child while it works. Sharing a test score with an ed-tech platform requires consent under FERPA; an AI-derived prediction about that same student’s future performance often does not clearly trigger the same requirement, because it is not a traditional “education record” in the statute’s original sense. Examples of this gray zone include:

  • Predicted future grades or risk-of-failing scores generated by the model.
  • Behavioral or engagement patterns inferred from how a child interacts with the tool.
  • Inferred reading level, attention span, or learning-style profiles never explicitly entered by a teacher.

COPPA does not directly address behavioral analytics or learning-pattern profiling either, leaving a real gap between what the law was written for in 1974 and 1998 and what today’s AI tutoring apps actually generate.

Comparison of data protected by law (grades, attendance, discipline notes) versus the AI gray zone (predicted grades, behavior patterns, learning profiles)
Traditional records are covered by law, but AI-generated predictions about your child fall into a legal gray zone.

The compliance gap in real schools is just as real. The law on paper is not the same as practice on the ground. Independent surveys of U.S. school districts, including research from the Center for Democracy & Technology, have repeatedly found that many districts adopting AI tools have not formalized a written data-governance policy or a signed Data Processing Agreement with the vendor, and that staff awareness of which federal law actually governs student data is inconsistent from one district to the next. The gap means a parent cannot assume a school’s use of an AI teacher for kids is automatically compliant just because the school adopted it — it is worth verifying directly.

How to Vet an AI Teacher for Your Child: A Practical Checklist

Questions to ask before your child uses any AI tutor

  1. Does the tool explicitly state FERPA and COPPA compliance in its privacy policy?
  2. Has it signed a Data Processing Agreement (DPA) with your school or district?
  3. Does it train its model on student data — look for an explicit “we never train on student data” statement?
  4. What encryption does it use — AES-256 encryption at rest and TLS 1.2+/1.3 in transit are the current baseline?
  5. How quickly is data deleted on request — 30 days is the common standard?
  6. Does it hold independent certifications, such as SOC 2 Type 2 or 1EdTech?
  7. How fast does it commit to notifying users of a breach — 72 hours is widely treated as best practice?

Green flags and red flags

A tool worth trusting states its policy plainly. Green flags to look for:

  • A transparent, plain-language privacy policy.
  • An explicit “no selling, no training on student data” commitment.
  • A signed DPA available to the school or district on request.
  • Verifiable parental consent flows for children under 13.
  • Visible data minimization — the tool asks for a name and grade level, not a home address or social media handle.

A tool worth avoiding hides behind vague language. Red flags include a privacy policy that talks about sharing with unnamed “partners” for advertising, no age gate or consent step at signup, and requests for data that has nothing to do with tutoring. If you want to see how a compliant tool actually behaves day to day, it helps to look at how it handles specific tasks — for example, how an AI teacher for homework help processes a submitted assignment, or how its answers hold up when you check AI teacher accuracy against a textbook. The same data-handling standards that make an AI teacher app trustworthy on privacy tend to show up in how carefully it is built overall.

What parents and teachers can do today

A few practical habits close most of the gap:

  • Read the privacy policy before registration, not after.
  • For children under 13, confirm that consent has actually been given — either by a parent at home or by the school under the narrow educational-purpose exception.
  • Avoid pasting a child’s full name, address, or other PII into general-purpose chatbots that were never built for COPPA compliance.
  • Ask the school directly whether a DPA is on file with any AI vendor it uses.

This matters because, as of fall 2024, only about 48% of U.S. school districts reported having trained their teachers on AI use at all — parents who ask these questions are often filling a gap the school itself hasn’t closed yet.

Bar chart showing only about 48% of US school districts trained teachers on AI use as of fall 2024, versus 52% that did not
As of fall 2024, barely half of US districts had trained teachers on AI — so proactive parents fill the gap.

This article is educational and is not legal advice. FERPA, COPPA, and state student-privacy laws are complex and change over time, and how they apply can depend on your child’s specific school, state, and situation. For guidance on a particular tool or district, contact your school’s privacy officer or an attorney who handles education and privacy law.

FAQ

keyboard_arrow_up