Why this question matters
Student data is uniquely valuable, and uniquely at risk.
Once student data has been used to train an AI model, it cannot be extracted. The model retains patterns from that data indefinitely. Districts that don't ask this question now may find their students' data embedded in commercial AI models they never consented to.
What to verify with your SIS vendor:
- No training on district data: Explicit contract language prohibiting use of your data to train AI models
- Third-party model access: If the vendor uses external LLMs (OpenAI, Anthropic, Google), what happens to the data sent to those models?
- Retention policies: How long are AI queries and outputs retained?
- De‑identification standards: If data is de‑identified for training, what standard is used?
- Opt‑in versus opt‑out: Are AI features opt‑in for districts?
- Generative AI features: Special attention to any features that generate text, feedback, or recommendations
- Prompt retention: Do teacher or administrator prompts get stored, and if so where?