Data Report · By Chris Sowa · Published
Last updated
Can a School District Enable OpenAI Dots on Student Records?
A district needs an applicable FERPA basis and documented control over the records before enabling Dots. Launch materials alone do not establish the school official exception or a suitable data-use agreement.

A district needs an applicable FERPA basis and documented control over the records before enabling Dots. Launch materials alone do not establish the school official exception or a suitable data-use agreement. A student-services task can bring names, grades, guardian contacts and financial details into the same session. FERPA's school official exception can cover a contractor, including a cloud provider, when its conditions are met. The district needs evidence of the service performed, direct control over use and maintenance, and redisclosure limits. Owning the server is not the legal test. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.
Key findings
- Edu workspaces can enable beta versions of Dots through administrator controls; each dot has its own cloud computer and browser and connects to more than 4,000 apps, per The Next Web.
- The model can receive content from permitted applications, per OpenAI's safety document. Education workspaces do not train on content by default. The key holder is not disclosed and no certification is named.
- 34 CFR 99.31(a)(1)(i)(B) makes a contractor a school official only on three conditions: an institutional service, direct control by the district over the use and maintenance of education records, and the redisclosure requirements of 99.33(a).
- Personally identifiable information under 34 CFR 99.3 includes names, address, student number and indirect identifiers such as date of birth. It also covers anything that would let a reasonable person in the school community identify the student.
- The Department of Education's guidance reads direct control as the district deciding how the provider uses and maintains the records. A district that cannot say what the provider's model received cannot show it.
What does an Edu workspace dot do?
The same thing any dot does. It is an always-on agent with its own cloud computer and browser, running on GPT-6 Astra; Edu workspaces can enable beta versions through administrator controls (The Next Web). Custom Rules set what the dot may do on its own, what requires approval and what is forbidden. Auto-review checks planned actions before they run. Secure sign-in keeps the password out of the model's context. Education workspaces do not use content to train models by default. The model receives webpage text and document content within connected apps (OpenAI). The parent page, Do OpenAI Dots' Custom Rules Control What the Agent Sees?, walks each control. Permissions constrain access, but do not establish a field-level minimization policy for a particular task. Nothing in the documentation describes an Edu workspace dot receiving less of a student record than any dot receives of any page.
What does the school official exception actually require?
FERPA's general rule is that a district may not disclose personally identifiable information from education records without written consent. 34 CFR 99.31(a)(1) permits disclosure to school officials with legitimate educational interests. Paragraph (a)(1)(i)(B) extends "school official" to a contractor or other party to whom the district has outsourced institutional services, on three conditions. The party performs a service for which the district would otherwise use employees. It is under the direct control of the district with respect to the use and maintenance of education records. It is subject to the use and redisclosure requirements of 99.33(a). Paragraph (a)(1)(ii) adds that the district must use reasonable methods to ensure school officials obtain access only to records in which they have legitimate educational interests.
Personally identifiable information at 34 CFR 99.3 is wider than a name. It covers the student's and parents' names, the address, a student number and indirect identifiers such as date and place of birth. It also covers other information that, alone or in combination, would allow a reasonable person in the school community to identify the student. A record with the name removed but the date of birth, address and schedule kept is still PII.
The Department of Education's guidance treats direct control as something the district establishes and can show: the district decides how the provider uses and maintains the records, typically through the agreement, and the provider uses them only for the authorized purpose. Legitimate educational interest is task-shaped: a school official gets the records its function needs and not the rest.
Does "direct control" survive a vendor-owned cloud computer?
It can. FERPA does not require the district to own the server. The district must establish direct control over how its contractor uses and maintains education records, together with the other conditions of the school official exception. The Department of Education's cloud computing guidance discusses that arrangement.
For Dots, review the applicable agreement, administrator controls, retention and deletion terms, authorized purposes and access evidence. Custom Rules and a no-training default can be parts of that review; neither establishes every FERPA condition on its own. A representative model request is useful evidence of exposure, but it is not the sole legal test for direct control. See Does FERPA's School-Official Exception Cover AI?.
What does a dot see in PowerSchool?
The following is an illustrative workflow, not a captured Dots session. The actual fields received depend on the application view, permissions and integration.
The screen. PowerSchool's roles decide which pages the signed-in registrar, counselor or principal may open; the dot works under that sign-in and opens what that person may open. Demographics, schedule, grades, attendance, the discipline log and the IEP flag reach the model as text, because the page is what a dot's model receives. Permissions are unchanged; exposure is the visible screen content. Can an AI Agent Use PowerSchool Without Student PII? sets out the alternative: the same session and permissions, with the model handed the task's fields and the student as STUDENT_001.
What does the district keep when the agent sees tokens?
Three things the school official exception asks for. The record: every screen the agent saw as tokens, every action and every approval with a name lands in the AI Control Record and exports to the district's own monitoring. The FERPA officer can show what the model received for each task and that the identifiers were STUDENT_001. The approval: the agent prepares the schedule change, transcript request or budget transfer, and the registrar or principal, under existing permissions, approves it on the record. And the legitimate educational interest test, per task: the Planner's policy states which values are tokenized and which fields the agent receives, and a named person confirms it before the run. That is the task-shaped access 99.31(a)(1)(ii) describes, written in advance and checkable afterward. Whether that satisfies the exception is counsel's call, made from the district's own record.
How do Dots and a governed environment answer the FERPA officer?
| Control | Dots in an Edu workspace | RedactSure governed environment | What the FERPA officer asks |
|---|---|---|---|
| What the model receives | Student content made available by the configured service | The task's fields; STUDENT_001 as token | Show me one PowerSchool screen as the model received it |
| Direct control | Custom Rules over actions; environment, keys and reading set by OpenAI | Environment owned by the district; per-task policy confirmed by a named person | Can we decide how the records are used and maintained? |
| Redisclosure | OpenAI's terms and the plugin connections | Real values resolve only at approved destinations, at the moment of action | Where can the records go? |
| Record of access | Activity View, OpenAI's app | AI Control Record, in the district's monitoring | What was read, by whom, and where is the log? |
| Who approves a record change | User, per Custom Rules | The registrar or principal, under existing permissions, on the record | Is the approver a school official? |
| Keys | Not disclosed | The district; RedactSure holds ciphertext it cannot decrypt | Who can read the records at rest? |
| Model | GPT-6 Astra | Any, swappable without moving the controls | Does changing the model change the controls? |
Where does RedactSure sit?
RedactSure builds the governed environment in the middle column. AI co-workers work inside the student information system, the finance system and the email around them from a secure virtual machine in the cloud the district's posture requires. It runs on hardware-encrypted enclaves with keys the district holds, with no per-application integration and no change to user permissions. Names, student numbers, dates of birth, addresses and the other identifiers chosen by policy are replaced at the render layer by consistent tokens before any model reads the screen. The model is handed the task's fields rather than a picture of the page, and no student enters the model's memory. Grades, attendance counts, dates and amounts stay in clear where the policy says so.
That is what the district avoids: a vendor-owned computer reading the student record in full with no record of it in the district's hands, the position a state auditor or a parent complaint tests. A named person confirms the policy and approves every record change and transfer, under Supervised Delegation. At Scituate School Department, a paid pilot has the AI combing the budgets and the principal approving each transfer; Can AI Prepare Munis Transfers Without Private Data? describes the workflow. Deployments are in pilot.
Methodology and limitations
The page rests on OpenAI's "How we build safety, security and privacy into dots" (September 29, 2026), cited with their dates. The Next Web's launch coverage of the same date is cited as reporting. The regulatory text is 34 CFR 99.3 and 99.31, cited from the eCFR, with the Department of Education's 2014 guidance on online educational services. Regulation is cited from its text; Department findings and case law are not surveyed. Where OpenAI's documentation is silent, the page says so rather than inferring. All sources were read as of September 30, 2026.
No hands-on testing of Dots was performed; what a dot receives in an Edu workspace is OpenAI's own description. The statement that Edu workspaces can enable beta versions comes from press coverage, not from OpenAI's document. OpenAI refers to a system card and to enterprise terms that were not available for this reading. Those documents could disclose direct control terms, key management, certifications, the training default for Edu workspaces or an activity export that the launch material does not. State student privacy laws are not surveyed. Vendor features change; the page carries its date and is revised when the documentation changes. The PowerSchool and Munis examples describe record types, not any district; no customer or prospect is described.
Whether a vendor qualifies as a school official under FERPA's exception, and whether direct control is established, belongs to the district's counsel, not to this page.
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026)
- 34 CFR 99.31, Under what conditions is prior consent not required to disclose information?
- 34 CFR 99.3, What definitions apply to these regulations?
We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.
What the record shows
A district needs an applicable FERPA basis and documented control over the records before enabling Dots. Launch materials alone do not establish the school official exception or a suitable data-use agreement. Document the district's basis for access, then inspect a representative student workflow and its data-use terms before enabling it.
Frequently asked questions
Is an Edu workspace a school official?
Only if it meets all three conditions of 34 CFR 99.31(a)(1)(i)(B): an institutional service, direct control by the district over the use and maintenance of education records, and the redisclosure limits of 99.33(a). A workspace setting does not establish those. The agreement and the facts of what the vendor's system receives and keeps do, and counsel decides.
What does a dot see in PowerSchool?
The screen the signed-in user may open, as text: demographics, schedule, grades, attendance, discipline and flags. OpenAI's documentation says the model receives webpage text and document content within connected apps. PowerSchool's roles are unchanged. Custom Rules limit what the dot may do on the page, not what it reads from it. RedactSure hands the model the task's fields with the student as STUDENT_001, under the same roles.
Who approves the transfer the dot prepares?
In OpenAI's design, the user, per Custom Rules and the mandatory confirmations they cannot override, inside OpenAI's app. In a governed environment, a named district employee, the principal or business manager, under existing permissions in the finance system, with the approval recorded in the AI Control Record. In either design the AI prepares; a person approves.
Does FERPA cover directory information the same way?
No. 34 CFR 99.3 defines directory information as information that would not generally be harmful or an invasion of privacy if disclosed, such as name, address and dates of attendance. Part 99 permits its disclosure under conditions set by public notice. Grades, discipline and special education status are not directory information, and a dot reading the full record reads those.
What about state student privacy laws on top of FERPA?
Many states add their own student data privacy statutes with vendor contract terms, data use limits and deletion requirements beyond FERPA. A district's agreement with an AI vendor has to satisfy those as well. Which apply, and what they require of a vendor whose model receives the record in full, is a question for the district's counsel.
Does a no-training default satisfy direct control?
Not by itself. A no-training default addresses one use of the data. Direct control also concerns how the contractor uses and maintains records for the district. Review the agreement and operational controls against 34 CFR 99.31 and applicable state law. A vendor-owned cloud service is not automatically excluded.
Sources
Vendor documentation
- OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
Regulation and standards
- 34 CFR 99.31, Under what conditions is prior consent not required to disclose information? https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
- 34 CFR 99.3, What definitions apply to these regulations? https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-A/section-99.3
- US Department of Education, Student Privacy Policy Office, "Protecting Student Privacy While Using Online Educational Services: Requirements and Best Practices" (2014). https://studentprivacy.ed.gov/resources/protecting-student-privacy-while-using-online-educational-services-requirements-and-best
Independent analysis and press
- The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers" (September 29, 2026). https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
RedactSure documents
- RedactSure, "Secure AI for Schools and Campuses" (2026). https://redactsure.com/blog/secure-ai-for-schools-and-campuses/
- RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
- RedactSure Research, "How Can a School District Let Staff Use AI on Student Records Without Exposing the Data?" (2026). https://redactsure.com/research/school-district-ai-student-records
- RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
- RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
- RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
- RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
- RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
- Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; PowerSchool is a trademark of PowerSchool Holdings, Inc.; Munis is a trademark of Tyler Technologies, Inc.; named to identify the products. Compliance determinations belong to the organization's counsel.
Editorial verification
- U.S. Department of Education, Frequently Asked Questions: Cloud Computing, official FERPA guidance. https://studentprivacy.ed.gov/sites/default/files/resource_document/file/FAQ_Cloud_Computing_0.pdf
See it on your workflow.
Bring one billing, collections, claims or patient-account workflow and your questions.
Book a demo




