Here’s a question that should make you a little uncomfortable: right now, do you know who on your staff is running student records through AI, and what those tools saw? At most schools, the answer is no. That’s shadow AI, and in education it runs straight into FERPA compliance issues.

Shadow AI in K-12 and Higher Ed

Picture a teacher turning a class roster into a seating chart. She pastes thirty names and thirty sets of grades into a ChatGPT account. Helpful. Also: thirty students’ education records just went to a company your district never vetted, in a way you can’t take back or even see. Now multiply her by every counselor summarizing IEPs, every admissions reviewer running essays through an AI assistant, and every IT contractor pointing an AI coding tool at a database to fix a bug.

FERPA Compliance Checklist

The good news is that FERPA isn’t vague about what it wants. It comes down to a short compliance checklist. Here’s each requirement in plain English, how your everyday AI tools handle it, and what a governed platform like Revecast Orchestrate does instead.

What FERPA RequiresConsumer AI ToolsOrchestrate:
A Governed Platform
Stay in direct control of the record. A vendor handling student records has to be under your control over how they’re used and kept (the “school official” rule, 34 CFR 99.31).The data leaves for a company you don’t control, and copies scatter onto laptops, browser histories, and personal cloud backups.The work runs under accounts and a governance framework you own. Nothing runs outside the guardrails you set.
Limit access to who actually needs it. Use “reasonable methods” so people only reach the records they have a legitimate reason to see.Anyone can paste anything into any prompt. There’s no gate and no one checking.A policy layer decides what data is allowed in and who can run it, enforced by the tool itself.
Use records only for the job. No repurposing the data, and no handing it off to be reused elsewhere.What you type can be logged and used to train the next version of the model.Work stays inside your framework. Nothing gets repurposed or sent off to train an outside model.
Prove who touched what, and when. During an audit or complaint you have to account for who accessed which records, when, and why.The most you get is a usage bill: message counts and an account name. That’s not an audit trail.Every session is logged, audited, and attributed, created the moment the work happens.
Trace exactly what was exposed if something goes wrong. You need to know which students were actually affected.You reconstruct it from memory and old emails, months later, hoping you didn’t miss a student.Sessions are tied to the records they touched, so you can trace it directly instead of guessing.

Why Paid AI Tiers Still Don’t Meet FERPA Requirements

One honest caveat: OpenAI, Google, and Anthropic now sell school tiers that fix the training and admin pieces, and you should absolutely use those over free accounts. But they still don’t hand you that audit trail, and they don’t stop a teacher or staff member from drifting back to the free app that’s already open in her browser. Closing that gap, control you can actually prove, is the whole job of a governed platform.

Play it back as an audit. Same question, two endings. On shadow AI, you’re digging through inboxes hoping you didn’t miss anyone. On a governed platform, you export the log and go to lunch. Same regulation, same auditor, completely different afternoon.

Where This Leaves K-12 and Higher Ed Compliance Officers

So hold any AI tool you use to a single bar: can it meet FERPA compliance requirements, tell you who did what, to which records, and when? If it can’t, it isn’t governed, no matter what the sales page says. And one more thing worth knowing before you decide this can wait: FERPA doesn’t fine you. It pulls federal funding. If you can’t answer that question today, that’s not a reason to panic. It’s a reason to move the work somewhere you can see it.

Learn more about Revecast Orchestrate.