
FERPA-Aligned AI in the Classroom: What Universities Should Ask Vendors
An AI writing-feedback pilot can look low-risk: upload an essay, receive comments, let the instructor edit them. The risk appears when nobody can prove whether the essay trained a model, reached a subprocessor, was deleted, or matched the feedback the instructor approved.
Here, "FERPA-aligned" has a narrow operational meaning: the institution can identify, control, audit, and end every use of education records in the proposed workflow. The buying question is: can the institution reconstruct every student-data handoff and reverse it without vendor improvisation?
We use "reversibility test" as shorthand. It gives academic technology, procurement, security, and faculty reviewers one shared way to examine a tool before a pilot. Counsel still owns the FERPA call; this test helps the team bring better evidence. FERPA alignment is an institutional determination, not a vendor certification. It does not establish SOC 2 compliance or replace reviews under HIPAA, state privacy laws, or institutional security policy.
Quick answer: map, limit, delete, and prove
Before sharing real student data, require the vendor to map one course activity from the LMS or instructor upload through every subprocessor, review screen, and student-facing output.
For each handoff, run four steps:
- Map: record the exact fields and files transferred, including identifiers and metadata.
- Limit: state why the vendor receives the data and which contractual limits govern its use.
- Delete: trace how retention, deletion, course removal, and contract termination propagate.
- Prove: identify the logs that reconstruct the action and the human decision that followed.
FERPA's school official exception can apply to an outside party only under specific conditions, including performing an institutional function, being under the institution's direct control for education records, and using personally identifiable information only for the disclosed purpose. The U.S. Department of Education summarizes those conditions in its school official guidance.

The map should match the pilot you will actually run. A quiz generator using instructor-owned lecture notes has a different record path from a grading assistant that receives named submissions and writes scores back to an LMS.
Request four evidence packets
Ask for a data map, contract clause, log export, and deletion receipt before the security questionnaire disappears into email threads.
| Review area | Evidence worth accepting | Weak answer |
|---|---|---|
| Data inventory | A field-level data map tied to the proposed workflow | "We only collect necessary data" |
| Model use | Contract language naming what is excluded from training and cross-customer improvement | "Enterprise data is private" |
| Retention and deletion | A schedule for prompts, files, outputs, logs, backups, and subprocessors | "Deleted within a reasonable period" |
| Access and audit | Sample logs showing actor, course, action, review state, export, and grade sync | Login history alone |
"We anonymize data" does not explain whether raw submissions remain, when identifiers disappear, or whether a downstream model provider receives the content. Ask for the sequence, systems, and contractual commitment.
Use exact language for deletion: "For every system and subprocessor that stores submitted content, provide the retention period, deletion trigger, backup-expiration period, and evidence available after deletion completes."
A no-training clause can start just as plainly: "Vendor will not use customer content or derived representations to train or improve any model shared across customers and will impose the same restriction on subprocessors." Counsel should adapt the final language.
The Department of Education also provides model terms of service guidance for collection, use, transmission, warning signs, and institutional safeguards.
Treat instructor review as a recorded control
Assessment records should show what the AI proposed, which rubric informed it, what the instructor changed, and what the student received. A "human in the loop" checkbox does not provide that history.

Run one deliberately awkward sample through the pilot: an essay with a quoted source, a defensible outlier interpretation, and a criterion requiring instructor judgment. Verify that faculty can edit feedback, override a score, withhold release, and inspect the audit entry. A smooth happy path proves little.
A sample audit row: actor=faculty-1842, assignmentId=eng101-week3, modelRequestId=req-7814, suggestionState=edited, releaseState=approved, deletionEvent=del-2041. The exact field names can vary; the chain of responsibility should not.
Our product test for a TutorFlow pilot is blunt: can one export show the actor, course resource, suggestion state, release state, and deletion event? If reviewers must reconstruct those facts from email, the workflow is not governed yet.
A hypothetical pilot that passes security and still fails
Imagine a writing center pilots an AI feedback tool in three first-year courses. Each request includes a student ID, assignment ID, rubric score, submission file, and model-provider request ID. SSO and encryption are documented, and the vendor signs the data agreement. The pilot still stalls at renewal.
The privacy officer refuses renewal because the vendor cannot prove deletion. A course administrator can remove a submission from the dashboard, but the vendor cannot show when the raw file leaves backup storage or whether the model subprocessor deletes its copy. Renewal can proceed once the vendor supplies a backup-expiration certificate, a subprocessor deletion receipt, and the complete review log.
Run a 30-minute evidence review before sharing pilot data
Bring procurement, privacy, academic technology, and one faculty representative together. Share the workflow map and make the vendor point to evidence for each answer.

- Confirm the exact courses, roles, integrations, and data types allowed in the pilot.
- Match every data field to an instructional purpose and a contractual use limit.
- Verify the no-training commitment across the vendor and named subprocessors.
- Trigger a test deletion and ask for the documented propagation timeline.
- Inspect an assessment log that includes instructor edits, overrides, and release.
- Test deprovisioning for a dropped student, departing instructor, and vendor support user.
- Record who can pause the pilot if evidence and product behavior diverge.
If your team is evaluating governed content and assessment workflows for a pilot, talk with TutorFlow.
FAQ
Can a university use an AI vendor under FERPA?
Yes, if the institution can document the disclosure basis, purpose, direct-control terms, data path, and workflow. A vendor's general claim does not replace that review.
Should a university allow student work to train AI models?
The cautious default is to prohibit training and cross-customer model improvement unless the institution explicitly approves it. Require precise contract language covering subprocessors.
What should procurement ask an AI vendor first?
Ask the vendor to show the complete data path for one real course activity: what enters each system, why it is used, how it is deleted everywhere, and which log proves the instructor's final decision.


