School AI contracts: Microsoft's shift
Practical perspective from an IT leader working across operations, security, automation, and change.
6 minute read with practical, decision-oriented guidance.
Leaders and operators looking for concise, actionable takeaways.
Topics covered
Retrospective covering 9 September 2026, written on 9 September 2026.
School AI contracts should connect supplier promises to the particular product, data and classroom use being approved. My assessment of Microsoft's announcement with US teaching unions is that the useful lesson for UK buyers is enforceable, reviewable scope. A broad statement about responsible AI cannot answer every procurement question.
On 9 September, Microsoft, the American Federation of Teachers and the United Federation of Teachers announced a National AI Safety & Privacy Standard. Microsoft said US school districts could incorporate the protections into their customer agreements. The announcement described commitments on data use, human oversight and transparency. Microsoft's announcement.
What UK buyers should take from the story
The announcement went beyond a statement of aspiration. Microsoft described restrictions on using student and educator data for model training, selling or repurposing it, alongside school control over retention and deletion. It also described human oversight and clearer information about product changes. Those distinct promises explain why the exact contractual scope matters. Microsoft's description of the protections.
This was an announcement about US school agreements. It is not evidence that a UK school has the same terms, that every Microsoft product is covered or that a separate supplier offers equivalent protections. Check the actual contract and proposed use before drawing any of those conclusions.
The procurement lesson is nevertheless useful. Ask a supplier to identify the exact document and product setting supporting each important promise. This gives the school something it can review, test and retain as part of its decision.
Keep legal interpretation with the appropriate adviser. The IT team's role is to make the system and its configuration understandable: what information enters it, where that information goes, who controls it and how the approved activity can stop.
The ICT supplier risk guide provides a structure for that work. The school-specific part is connecting the evidence to the people and learning activities affected.
Review the proposed use before the platform
Separate a staff member drafting generic lesson material from a tool that processes information about a named pupil. These are different proposed activities, even if the supplier uses the same brand for both. Give each one a clear owner and approval route.
Write a short description of the task, the intended users, the information involved and the benefit expected. Include what the tool will not need to receive to complete that task. This helps the review focus on a realistic workflow instead of every feature in the product catalogue.
Ask teaching staff to demonstrate the task using fictional information. The demonstration should include the ordinary mistakes a new user might make, such as selecting the wrong source document or sharing an output with the wrong group. Review the resulting controls without using real pupil material in the initial test.
Build an evidence table for the decision
A useful approval record connects a question to a supplier answer, a practical check and an owner. Avoid collecting documents without recording which decision they support.
| Question | Evidence to request | Practical check |
|---|---|---|
| What may the supplier do with submitted information? | Terms applicable to the exact product and account | Confirm the account used in the pilot |
| How long does information remain? | Retention and deletion explanation | Complete a staged deletion exercise |
| Who can enable features? | Administrator role and control documentation | Demonstrate the intended settings |
| How are changes communicated? | Product-change notification process | Assign a recipient and review owner |
Record unanswered questions explicitly. If a feature depends on terms still under review, keep the pilot within a scope that does not depend on that feature. This is more useful than treating the whole platform as either universally approved or universally rejected.
Make human oversight a real activity
Decide what the responsible person will check before an output is used. For a lesson resource, that could include factual accuracy, suitability for the class and whether the material supports the intended learning objective. The exact checks belong to the staff leading the activity.
Give reviewers enough information to do the job. A button labelled approve is not a complete process if the person cannot see the source material, recognise uncertainty or correct the result. Ask a colleague unfamiliar with the pilot to follow the proposed instructions.
Include a route for raising concerns and stopping the activity. Staff should know who owns the deployment and what to do if a tool behaves unexpectedly. Keep the ordinary non-AI route available while the pilot is being assessed.
The AI governance framework template can help assign responsibilities. Adapt it to the school rather than assuming an organisation-wide policy resolves each classroom decision.
Explain the use in language families can understand
Prepare a plain explanation of the approved activity, the information involved and the safeguards the school has actually verified. Avoid copying a supplier's marketing language or promising capabilities that the school has not tested.
Name the contact for questions and explain how the school will review the pilot. Test the wording with someone outside the project so unfamiliar terms and missing context become apparent before the communication is used.
Keep the explanation consistent with the real configuration. If the service changes, review both the approval record and the information given to affected people. A careful launch message can become misleading if nobody owns it after the pilot expands.
Set a review point before expanding
Agree what evidence would justify continuing: a useful educational or administrative benefit, a workable review process and satisfactory answers to the material procurement questions. Record the time staff spend checking and correcting outputs as part of that assessment.
At the review, approve the defined use, revise it or stop it. Expansion to new users, different information or additional features should be a new decision with proportionate evidence.
The strongest response to the announcement is a clear procurement record: this product, these terms, this activity and these owners. That gives a UK school a basis for a defensible decision without assuming an overseas agreement automatically settles its own responsibilities.
Frequently Asked Questions
Does the Microsoft agreement automatically apply to UK schools?
- The announcement concerns protections that US school districts can incorporate into their Microsoft customer agreements. It does not establish automatic coverage for a UK school or another product. UK buyers should ask their supplier to identify the terms that apply to their own contract, service and proposed use.
What should a school request before approving an AI tool?
- Request the applicable product terms, a clear data-flow explanation, retention and deletion arrangements, administrator controls and a process for handling concerns. Match each answer to the proposed classroom or staff task. Involve the school's privacy and safeguarding leads so a technical demonstration does not become the entire approval process.
Is a supplier promise about responsible AI enough?
- A general principle is a starting point, not complete evidence for a deployment. Ask how the promise appears in the applicable terms and product settings, who verifies it and what happens if the service changes. Keep the approved use and the supporting evidence together so the decision can be revisited.
Share this post
About the author
Daniel J Glover
IT Leader with experience spanning IT management, compliance, development, automation, AI, and project management. I write about technology, leadership, and building better systems.
Continue exploring
Keep building context around this topic
Jump to closely related posts and topic hubs to deepen understanding and discover connected ideas faster.
Explore topic hubs
Related article
Nvidia Hugging Face deal: buyer checks
Nvidia's proposed Hugging Face acquisition raises practical questions about model portability, platform dependence and the evidence AI buyers need.
Related article
Astra cyber safeguards: buying checks
OpenAI's Astra safety update changes the questions buyers should ask about cyber access, interrupted tasks and evidence before approving deployment.
Related article
Smartglasses policy: a workplace guide
Build a practical workplace smartglasses policy. Define recording boundaries, accessibility routes, data ownership and approval evidence before a pilot.
Related article
Spirit data sale: an AI privacy lesson
Google's proposed purchase of Spirit's business data raises practical questions about AI training, employee records and what de-identification really means.
Ready to Improve Your IT Operations?
Book a free 30-minute consultation to discuss your IT challenges. No commitment required, just a focused conversation about where you want to be.
Book a consultationGet Occasional IT Leadership Insights
IT leadership insights, occasionally. No fluff. Unsubscribe any time.
No spam. Unsubscribe any time.