Skip to content
redactsure
Book a review

Explore.

Data Report · RedactSure Research

Does FERPA's School-Official Exception Cover an AI Tool That Reads Student Records? Reading the Four Conditions Against the New Reader

It can, but only when the district can satisfy the exception’s conditions, and the analysis turns almost entirely on one question: what does the AI tool actually receive? The school-official exception at 34 CFR 99.31(a)(1) lets a district share education records with an outside service provider without parental consent, under conditions that include the district’s direct control over the provider’s use and maintenance of the records. For a consumer AI tool that ingests whatever staff paste into it, districts have found the conditions impossible to document, which is why their AI policies prohibit the practice. An architecture in which the model reads tokens rather than records changes what the analysis has to cover. This page walks the regulation’s text and the questions a district’s counsel will ask; districts should run the analysis with their own counsel. The environment that enforces this is built by RedactSure, an AI agent controls, governance and data protection company.

Key findings

What does the regulation actually say?

The consent requirement is FERPA’s default: personally identifiable information from education records is not disclosed without written parental consent. The exceptions follow, and 34 CFR 99.31(a)(1)(i)(B) is the one the entire ed-tech industry operates under. A district may disclose records to a contractor, consultant, volunteer or other party to whom it has outsourced institutional services or functions, provided that the outside party performs an institutional service or function for which the agency or institution would otherwise use employees; is under the direct control of the agency or institution with respect to the use and maintenance of education records; and is subject to the requirements governing use and re-disclosure of personally identifiable information.

Three phrases carry the analysis, and each generates a question a district must be able to answer in writing.

Would otherwise use employees: is the AI tool doing work that is the district’s own work? Drafting attendance letters, assembling intervention plans and preparing state reports are employee functions; the condition fits naturally. A tool doing something no employee does, mining records for product improvement for example, sits outside it.

Direct control with respect to use and maintenance: can the district dictate, and verify, what happens to the records in the provider’s hands? This is the condition with teeth, and the next section is about it.

Use and re-disclosure limits: can the district show the records are used only for the authorized purpose and never passed on, including into model training corpora, vendor analytics or subprocessor systems?

Why does direct control fail for generic AI tools?

Read the direct-control condition against the ordinary scene it now has to govern: a staff member pastes a student’s attendance record into a consumer AI chat window to draft a parent letter.

Where did the record go? To the AI vendor’s servers, under the terms of whatever account tier the staff member happens to have. What will be done with it? The district does not know; on free and consumer tiers, the record may be retained, reviewed or used to improve the service, and the district has no contract saying otherwise. Can the district verify its handling, order its deletion or demonstrate its destruction? No mechanism exists. Was it re-disclosed? The district cannot say.

Every answer is a failure of the direct-control condition, and no policy language can repair it, because the failure is architectural: the record left the district’s control the moment it entered a system the district has no agreement with. District AI policies that prohibit putting student PII into unsanctioned tools are drawing the correct legal conclusion. The PTAC guidance on online educational services anticipated the shape of this problem years before AI: its diligence questions all reduce to knowing where the data goes and holding a contract that governs it.

The prohibition, standing alone, has a cost the numbers now measure. Microsoft’s Work Trend Index records 78% of AI users bringing their own tools to work, and IBM’s 2025 report records one in five breaches involving shadow AI. A district with a prohibition and no sanctioned alternative has invisible use, not no use.

How does a token architecture change the analysis?

Now run the same four conditions against an architecture in which the district’s applications render inside a governed environment and every student identifier is replaced with a consistent token before any model reads a screen, with real values resolving only in district-approved outputs when a named staff member approves them. The full mechanism is described in render-layer tokenization; the FERPA-relevant consequence fits in one sentence: the model never receives an education record.

Condition in 34 CFR 99.31(a)(1) What it requires The question for any AI vendor How the token architecture answers
Institutional service or function The tool does the district’s own work What employee function does this replace? Attendance, intervention, business office and reporting workflows the district staffs today
Direct control over use and maintenance The district dictates and can verify what happens to records Where do the records go, and what governs them there? Records stay in the district’s systems; the model reads tokens; the vendor stores ciphertext it cannot decrypt, with the district holding the keys
Use for authorized purpose only No secondary use, including model training Can records enter training, analytics or logs? Records do not reach the model or the logs; the audit trail is tokens end to end
No re-disclosure Records never passed to other parties Which subprocessors receive what? The set of parties receiving identifiable records shrinks to the district-approved destinations of each workflow

The table is the shape of the memo counsel has to write, and the point of the architecture is that every row’s answer is short and verifiable. The direct-control condition, impossible to document for a pasted record, becomes a statement about where records physically are: in the district’s student information system, where they always were, under the district’s existing control.

One honest boundary: the resolution events, the moments a real name appears in an approved parent letter or state report, are still disclosures in the ordinary course of district business, and they land at destinations the district already sends records to. Counsel evaluates those events exactly as it evaluates today’s letters and reports, because they are today’s letters and reports, prepared differently.

One staff task, before and after

The analysis lands hardest as a single scene, run both ways.

An attendance officer needs to send follow-up letters for eleven students who crossed the district’s absence threshold. Before: she opens the student information system, and for each student copies the name, the attendance history and the family contact into a consumer AI chat window to draft the letter, because drafting eleven individualized letters by hand is her afternoon. Eleven education records have now left the district’s control, into an account with no contract, no direct-control mechanism and no deletion path. Each paste is a disclosure the district cannot document under any exception, performed by a conscientious employee trying to serve families faster. Multiply by every school, every threshold cycle, and the district’s real FERPA posture diverges from its written one by exactly that volume.

After, inside the governed environment: she delegates the batch. The agent reads the same student information system screens with identities tokenized, USER_001 through USER_011, attendance patterns and dates in clear because the letters are built from them. It drafts eleven letters, each keyed to its token, and queues them. She reviews the drafts, adjusts two, and approves the batch; the real names and addresses resolve into the letters at the approved send, the district’s ordinary correspondence, disclosed to the families entitled to receive it. The model never held a record. The log holds the whole run as tokens.

The work product is identical, down to the tone she fixed in two drafts. What changed is everything the school-official analysis cares about: where the records went (nowhere), what the provider could do with them (nothing it can read), and what the district can show afterward (all of it). The scene also shows the honest limit of prohibition alone: before the sanctioned path existed, the officer’s choice was the shadow paste or the lost afternoon, and the district’s policy had picked the afternoon on her behalf. The ban analysis prices how that choice actually resolves across a workforce.

What will counsel and the board still ask?

Four questions recur in district reviews of this analysis, and they deserve direct answers.

Is a tokenized attendance pattern still an education record? The pattern reaching the model is keyed to USER_001, with the identifying values absent from model context; FERPA’s definitions turn on whether information is personally identifiable, including through linkage. Counsel will want to examine the tokenization policy’s field list against the regulation’s definition of personally identifiable information, including indirect identifiers, and the field-by-field policy exists exactly so that examination has a document to read. This is a question to settle with counsel, not with a vendor’s assurance, this vendor included.

What contract terms should back the architecture? The same ones PTAC has always pointed to: authorized purpose, direct control language, re-disclosure prohibition, deletion at termination, breach notification, and now the AI-era addition, a written statement of what reaches model context and a commitment to notify if that changes.

What about state student-privacy laws? Many states restrict vendor use of student data beyond FERPA’s floor. The analysis runs the same way against each statute: the data flow to trace is small, and the vendor’s inability to read what it stores does most of the work.

What does the district tell parents? That the AI drafting assistance used by staff never receives their child’s name or records, that a named staff member approves anything that leaves the district, and that the district can produce the full history of what any AI run read and did. Each sentence is an architectural fact rather than a policy promise.

What the record shows

FERPA’s school-official exception can cover an AI tool, and the coverage is earned condition by condition, in writing, with the direct-control requirement doing most of the deciding. Consumer AI tools fail that condition architecturally, which is why district prohibitions are correct and why they are incomplete without a sanctioned alternative. An architecture in which the model reads tokens moves the analysis onto ground a district can actually hold: the records stay in district systems, the vendor cannot read what it stores, and identifiable values appear only in district-approved outputs a named staff member releases. The exception’s text has not changed since before AI existed. What changes is whether an architecture lets a district answer the text’s questions, and that is a choice districts make at procurement. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.

Frequently asked questions

Does using the school-official exception require notifying parents?

Districts must include in their annual FERPA notification the criteria for who constitutes a school official with legitimate educational interests. Districts using outside providers under the exception typically cover them in that notice; counsel confirms the district’s notice language reaches the AI tooling.

Can a district rely on a vendor’s own FERPA-compliance claim?

The obligations are the district’s, and the exception’s conditions are about the district’s control, so a vendor claim cannot substitute for the district’s own analysis. The useful vendor artifact is not a compliance claim; it is the written data-flow statement the analysis needs.

Does the exception cover instructional AI use by teachers?

This page covers administrative workflows. Instructional tools raise the same conditions plus pedagogy and age-appropriateness questions a district’s acceptable-use policy governs separately.

What happens at contract termination?

Under the token architecture the vendor holds ciphertext it cannot read, with keys held by the district, so termination is the district ceasing to use the service rather than a negotiation over data return. The contract should still say so plainly.

Is parental consent an alternative path?

In principle yes; in practice consent at district scale is unworkable for operational workflows, which is why the school-official exception exists and why the ed-tech industry runs on it.

Who inside the district owns this analysis?

Counsel owns the legal conclusion, the technology director owns the vendor diligence and the data-flow verification, and the superintendent owns the board and community narrative. The division of labor is laid out in How Can a School District Let Staff Use AI on Student Records Without Exposing the Data?

How Can a School District Let Staff Use AI on Student Records Without Exposing the Data? · What Is Render-Layer Tokenization? · What Is Supervised Delegation? · On the RedactSure blog: AI Is Already in Your Schools. Make It Safe and Useful.

Sources

Regulation and guidance

  1. FERPA regulations, 34 CFR 99.31(a)(1), disclosure to school officials, including outside service providers. https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
  2. U.S. Department of Education, Privacy Technical Assistance Center, guidance on online educational services. https://studentprivacy.ed.gov/

Incidents and industry data

  1. Security.org, “PowerSchool Data Breach: What Happened and What Families Should Do.” https://www.security.org/identity-theft/breach/powerschool/
  2. Microsoft and LinkedIn, Work Trend Index. https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
  3. IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach

RedactSure documents

  1. RedactSure, “Secure AI for Schools and Campuses” (2026). https://redactsure.com/blog/secure-ai-for-schools-and-campuses/
  2. Product behavior described on this page reflects RedactSure’s current design. This page is information, not legal advice; districts should evaluate FERPA questions with their own counsel.

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.