Federal Findings Tracker Issue 02 · July 2026 Topic-organized · Status-tracked · Source-verified The Language Firm K-12 Compliance Intelligence Federal Findings Tracker Issue 02 · July 2026 Topic-organized · Status-tracked · Source-verified The Language Firm K-12 Compliance Intelligence
The Language Firm Intelligence Layer Issue 02 · July 2026

Federal Findings Tracker

A topic-organized record of verified federal government action on K-12 student data and artificial intelligence. Every claim traces to a primary source we retrieved and read. Status reflects the current state of the action as of the refresh date below.

Last refresh July 10, 2026
Next refresh August 1, 2026
Cadence Monthly
Entries tracked 10
Primary sources Retrieved and read
2
Implemented
3
Active
4
Pending
1
Stalled

What this is

A monthly-refreshed tracker of federal government action (executive orders, agency rulemaking, congressional bills, and court decisions) that affects how K-12 districts govern student data and artificial intelligence. Each entry is one federal action, current as of the refresh date.

How we verify

Every claim traces to a primary source we retrieved and read in full: a Federal Register citation, the Code of Federal Regulations, an agency publication, a White House or Justice Department posting, or a legislative record. Where the conventional source could not be retrieved, we cite a retrievable source stating the same fact, or the claim is not made. Gaps are disclosed in the entry body.

How to read status

Implemented: the action is in force. Active: the action is published, in effect, and the issuing body is taking follow-on steps (e.g., implementing rules, building task forces). Pending: proposed but not yet final. Stalled: expected but not delivered, or delivered then paused. Gaps are disclosed in the entry body.

Filter:
Topic 01

Student data privacy

FERPA, COPPA, and federal guidance and enforcement on how student data is handled by AI tools and vendors operating under the school-official and school-authorization mechanisms.

2 Entries
FERPA guidance on AI tools handling student records
Stalled

FERPA (20 U.S.C. § 1232g) governs the disclosure of student education records and applies to every district receiving federal funds. Districts disclose to third-party vendors under the school-official exception (34 CFR § 99.31(a)(1)). PTAC's vendor guidance states that PII from education records disclosed under that exception "may only be used for the purposes authorized by the respective school or district," and that a school or district may require "evidence that the school or district retains direct control with respect to the use and maintenance of PII at all times."

The Department's guidance for vendors under this exception is Protecting Student Privacy While Using Online Educational Services: Requirements and Best Practices (February 2014) and its companion FAQ for third-party service providers, which PTAC describes as presenting the same material in a format geared toward providers. Both predate generative AI and neither addresses it.

No Dear Colleague letter, rulemaking, or guidance addressing generative AI vendors under the school-official exception has issued. PTAC has published AI-adjacent material: the AI Grading System Compromise, AI Tutoring Platform Data Leak, and AI-Generated Phishing & Deepfake Calls scenarios. These are tabletop exercises in PTAC's Data Breach Scenario Trainings series, each packaged as a facilitator's guide, a presentation, and handouts. They are useful. They are not guidance, and they are not a federal action as this tracker defines one.

The Department's July 22, 2025 Dear Colleague letter on AI, signed by Secretary McMahon, addresses allowable uses of formula and discretionary grant funds. FERPA appears in it once, as a single principle: "Data-protective: Systems must comply with federal privacy laws including the Family Educational Rights and Privacy Act." The letter never mentions vendors, contracts, § 99.31, or the school-official exception.

The Department says the rulemaking exists because of ed tech. The Fall 2024 entry for RIN 1875-AA15 records that in February 2022 the Department held three student privacy listening sessions, and that what emerged were "concerns about educational agencies and institutions using online third-party applications in the classroom and the personal information being collected and shared by education technology providers without the consent or knowledge of parents, and the potential use of student information for advertising, marketing, and other non-educational purposes." The Department states that "[t]hese proposed regulations include provisions that would address these concerns." The abstract names vendors outright: the Department intends to amend the provisions governing non-consensual disclosure of personally identifiable information in education records to third parties "(including commercial vendors)."

The Department has set three dates and missed all three. The Fall 2024 edition set the proposed rule for March 2025. The Spring 2025 edition moved it to January 2026 and set final action for May 2026. All three passed. None of them happened. Nothing has landed: the Department's own FERPA page lists the Federal Register notices amending Part 99, the most recent dated December 2, 2011.

A federal agency has deferred to this rulemaking on the record. In the Statement of Basis and Purpose for its 2025 COPPA Rule amendments, the FTC declined to finalize its own ed tech and school-authorization provisions "[t]o avoid making amendments to the COPPA Rule that may conflict with potential amendments to DOE's FERPA regulations," citing the Fall 2024 Unified Agenda entry for RIN 1875-AA15 directly. The Commission added that it "will monitor and weigh future developments with respect to DOE's potential FERPA regulation amendments in deciding whether to pursue COPPA Rule amendments related to ed tech." The deferral held. The rulemaking did not move. Three named dates came and went. That is the basis for the Stalled designation.

The implication for districts: existing FERPA contract obligations apply to AI vendors today, and no AI-specific federal guidance exists to interpret them. A district making a school-official determination for a generative AI vendor is making it without a federal reference point, on the strength of its own reading of the vendor's language. Two agencies are waiting on a rulemaking that names vendors in its own abstract and has missed three of its own dates. Plan on the current contract standard holding through the next school year rather than on federal clarification arriving.

Disclosed verification note RIN 1875-AA15 was read directly at reginfo.gov at the Fall 2024 and Spring 2025 editions (pubId 202410 and 202504), both at Proposed Rule Stage. All three timetable dates and the quoted abstract language are taken from those editions' own fields. The abstract's vendor language is edition-dependent: the Fall 2024 edition reads "including third-party vendors"; the Spring 2025 edition reads "(including commercial vendors)." The current edition could not be retrieved; requests for it returned other editions instead, repeatedly. The rulemaking's status is therefore stated as of the Spring 2025 edition and re-checked at each refresh.
Primary source studentprivacy.ed.gov: FERPA regulations and amendment notices; the vendor guidance is Requirements and Best Practices and the Third-Party Service Providers FAQ; the training material is at Data Breach Scenario Trainings; the July 22, 2025 letter is ed.gov: Dear Colleague Letter on Federal Grant Funds and AI; the rulemaking is reginfo.gov: RIN 1875-AA15 (Fall 2024) and (Spring 2025); the FTC's deferral is at 90 FR 16918
COPPA: AI training, retention, and the school-authorization mechanism
Active

The FTC's amendments to the Children's Online Privacy Protection Rule were approved January 16, 2025, published April 22, 2025 (90 FR 16918), and became effective June 23, 2025. The compliance date: "Except with respect to § 312.11(d)(1), (d)(4), and (g), regulated entities have until April 22, 2026 to comply." The codified Rule sits at 16 CFR Part 312, §§ 312.1 through 312.13; the amendatory text begins at 90 FR 16977.

The Rule text does not name AI model training. Read in full, §§ 312.1 through 312.13 contain no reference to artificial intelligence, machine learning, or model training. The operative mechanism is § 312.5(a)(2): an operator "must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service," and must obtain separate verifiable parental consent for any such disclosure. Section 312.4(c)(1)(iv) carries the same carve-out into the direct-notice obligation.

The rulemaking commentary reaches AI. In the Statement of Basis and Purpose accompanying the final rule, the Commission stated that disclosures of a child's personal information to third parties for monetary or other consideration, for advertising purposes, or to train or otherwise develop artificial intelligence technologies "are not integral to the website or online service and would require consent pursuant to the proposed amendments to § 312.5(a)(2)." That reading reaches disclosure to third parties. It does not reach an operator's own use of children's data to train its own models.

The first-party route runs through retention. Section 312.10 provides that "[p]ersonal information collected online from a child may not be retained indefinitely," and that "[a]t a minimum, the operator must establish, implement, and maintain a written data retention policy that sets forth the purposes for which children's personal information is collected, the business need for retaining such information, and a timeframe for deletion of such information." That policy must appear in the § 312.4(d) online notice. Chair Khan's statement on the amendments ties § 312.10 to AI directly: the limits "may prove especially salient given the expansion of AI and machine learning tools that feed on data to develop and refine the models and algorithms," and "FTC's enforcement experience has already shown firms citing machine learning as justification for indefinite retention." The Commission alleged that Amazon kept children's Alexa voice recordings indefinitely to further refine its voice recognition algorithm, and has obtained relief requiring not only deletion of children's information collected in violation of COPPA but deletion of the models trained on it. Separately, the Commission proposed in the 2024 NPRM to bar operators relying on the support-for-internal-operations exception from using or disclosing personal information "in connection with processes, including machine learning processes, that encourage or prompt use of a website or online service" (89 FR 2045). That language was not carried into the codified Rule.

The Commission has addressed conversational AI directly. In the 2024 NPRM's discussion of § 312.5(a)(1), the Commission stated that the verifiable parental consent requirement "applies to any feature on a website or online service through which an operator collects personal information from a child," and gave this example: if an operator "institutes a feature that prompts or enables a child to communicate with a chatbot or other similar computer program that simulates conversation, the operator must obtain verifiable parental consent before collecting any personal information from a child through that feature" (89 FR 2051). The Commission proposed no change to § 312.5(a)(1) and framed the statement as a clarification of what the existing requirement already covers.

The Commission has litigated the school-authorization mechanism. In May 2023 the FTC, through DOJ, obtained an order against ed tech provider Edmodo. The COPPA counts were failure to provide information about its data collection practices to schools and teachers, failure to obtain verifiable parental consent, and retaining children's personal information indefinitely. Separately, under Section 5 of the FTC Act, the Commission alleged it was an unfair practice for Edmodo to rely on schools and teachers to obtain consent on its behalf while giving them confusing and inaccurate information about how to do it. The FTC described that as the first time it had alleged an unfair trade practice in the context of an operator's interaction with schools. The order carried a $6 million penalty, suspended for inability to pay; banned the company from using schools as intermediaries in the parental consent process; prohibited requiring students to hand over more personal data than necessary; and required Edmodo to delete models or algorithms developed using personal information collected from children without verifiable parental consent or school authorization. Edmodo's terms of service had told schools and teachers they were "solely" responsible for COPPA compliance, which the FTC called nonsensical and misleading, because "[s]chools or teachers could never be solely responsible for complying with the COPPA Rule given the Rule's other requirements."

The school-authorization rule, in the FTC's own words: ed tech providers may rely on schools to authorize data collection in lieu of parental consent "if — and only if — the information collected from kids is used solely for educational purposes." Edmodo lost that shield because it advertised.

The operator owns its subprocessors. Section 312.8(c) requires that before allowing service providers or third parties to collect or maintain children's personal information, or releasing children's information to them, the operator "must take reasonable steps to determine that such entities are capable of maintaining the confidentiality, security, and integrity of the information and must obtain written assurances that such entities will employ reasonable measures" to do so. In September 2025 the FTC settled with Apitor Technology over a third-party SDK that sent children's geolocation to servers in China. The Bureau of Consumer Protection's director: "COPPA is clear: Companies that provide online services to kids must notify parents if they are collecting personal information from their kids and get parents' consent — even if the data is collected by a third party." The order requires Apitor to ensure that any third-party software it uses complies with the Rule. The $500,000 penalty was suspended for inability to pay.

The most recent action narrows rather than extends enforcement. On February 25, 2026 the FTC issued an enforcement policy statement declining to bring COPPA actions against general-audience and mixed-audience operators ("Relevant Operators") that collect, use, or disclose personal information to determine a user's age, subject to six conditions: no use or disclosure beyond age verification; third-party disclosure only with written assurances and prompt deletion; no retention beyond the verification period; clear notice to parents and children in the privacy policy; reasonable security safeguards; and reasonable steps to determine the method is likely to produce reasonably accurate results. It "does not modify the Commission's position that operators of child-directed sites and services that are primarily directed to children must treat all users as children." A primarily child-directed ed tech tool cannot rely on it. The Commission "intends to initiate a review of the COPPA Rule to address age-verification mechanisms," and the statement remains effective until final rule amendments publish or it is withdrawn. An FTC workshop on age-verification technologies was held January 28, 2026, and the Disney order approved in December 2025 carried a forward-looking age-assurance provision.

The implication for districts: with the April 22, 2026 compliance date past, AI tools used in K-3 and elementary contexts must have operator-level COPPA practices documented and current. A conversational AI feature is a collection point, and the Commission has said so on the record. Districts relying on school authorization should read the Edmodo action as notice that authorization is not a transfer of the vendor's compliance obligations, and that it evaporates the moment the data is used for anything other than an educational purpose. Ask for three things in writing: the no-training commitment covering first-party training and third-party disclosure; the § 312.10 retention policy naming the business need and a deletion timeline; and the § 312.8(c) written assurances for every subprocessor in the chain.

Disclosed verification note The codified Rule, the 2024 NPRM at 89 FR 2045 and 2051, and the February 25, 2026 policy statement were read in full at primary. The AI-training passage in the final rule's Statement of Basis and Purpose sits at approximately 90 FR 16948, past the point at which automated retrieval of the 66-page document truncates; that page range has not been read directly. It is pin-cited by Latham & Watkins and quoted from the final rule notice by the Public Interest Privacy Center. The Edmodo order's own text was not retrieved; the order's provisions are described here from the FTC's release.
Primary source eCFR: 16 CFR Part 312; 90 FR 16918 (final rule) and 89 FR 2034 (2024 NPRM); Statement of Chair Khan on the amendments; Edmodo and its business-guidance explainer; Apitor; Disney; the February 25, 2026 Policy Statement
Topic 02

AI procurement and preemption

Federal guidance and rules shaping how districts evaluate, buy, and deploy AI tools, including the voluntary risk frameworks districts cite in procurement language and the federal-state legal conflict over state AI law.

4 Entries
Executive Order 14365: national AI framework and the state-law challenge
Active

EO 14365, "Ensuring a National Policy Framework for Artificial Intelligence," makes it "the policy of the United States to sustain and enhance the United States' global AI dominance through a minimally burdensome national policy framework for AI" (§ 2). Section 1 names Colorado directly: "a new Colorado law banning 'algorithmic discrimination' may even force AI models to produce false results in order to avoid a 'differential treatment or impact' on protected groups."

The Order directs the Attorney General to establish an AI Litigation Task Force "whose sole responsibility shall be to challenge State AI laws inconsistent with the policy set forth in section 2," on grounds that they "unconstitutionally regulate interstate commerce, are preempted by existing Federal regulations, or are otherwise unlawful" (§ 3). It directs Commerce to publish an evaluation identifying onerous State AI laws (§ 4); directs every agency to "assess their discretionary grant programs" and "determine whether agencies may condition such grants" on states not enacting or enforcing conflicting AI laws (§ 5(b)); directs the FCC to consider adopting a federal reporting and disclosure standard (§ 6); and directs the FTC to issue a policy statement on the FTC Act's application to AI (§ 7).

The BEAD mechanism runs through three layers, not one. Section 5(a) directs that Commerce "shall issue a Policy Notice specifying the conditions under which States may be eligible for remaining funding under the Broadband Equity Access and Deployment (BEAD) Program," and that "[t]hat Policy Notice must provide that States with onerous AI laws identified pursuant to section 4 of this order are ineligible for non-deployment funds, to the maximum extent allowed by Federal law." The ineligibility requires a Policy Notice, which requires a § 4 identification, and is hedged by federal law. None of the three has occurred.

The Task Force was established January 9, 2026 by Attorney General memorandum: "I am hereby 'establish[ing] an AI Litigation Task Force.'" The Attorney General or designee chairs it, the Associate Attorney General is vice chair, and it draws representatives from the Office of the Deputy Attorney General, the Office of the Associate Attorney General, the Office of the Solicitor General, and the Civil Division. The memorandum names no state and no case.

Colorado. SB 24-205 was signed May 17, 2024 and originally took effect February 1, 2026. SB 25B-004, approved August 28, 2025, "extends the effective date of the requirements of Senate Bill 24-205 to June 30, 2026." That is the only extension enacted. On April 9, 2026 xAI sued the Colorado Attorney General (X.AI LLC v. Weiser, No. 1:26-cv-01515, D. Colo.). DOJ moved to intervene April 24. On April 27 the court granted a joint motion staying enforcement. On May 14, 2026 Governor Polis signed SB 26-189, which "repeals and reenacts" SB 24-205's provisions; Session Law ch. 131; effective January 1, 2027.

Colorado is unenforceable, and the order reaches forward to say so. Under the court's order the Colorado Attorney General "shall not initiate enforcement, including but not limited to the initiation of an investigation, for alleged violations of [SB 24-205] (or any legislation replacing or amending [SB 24-205] enacted during this legislative session)" until 14 days after the court rules on xAI's forthcoming preliminary injunction motion. That motion will not be filed until 28 days after the Attorney General completes rulemaking. SB 26-189 requires the Attorney General to adopt rules by January 1, 2027. Enforcement cannot realistically begin before late 2027.

What the rewrite dropped, and what it kept. SB 26-189 removed the duty of care to avoid algorithmic discrimination, the deployer risk management program, the impact assessment requirement, and Attorney General reporting. It replaced them with point-of-interaction notice, a plain-language description of the technology's role within 30 days after an adverse outcome, the right to request and correct personal data, and the right to meaningful human review. It reaches schools: "covered ADMT" means automated decision-making technology used to materially influence a consequential decision in one of seven domains, and education is one of them. It also repealed SB 24-205's affirmative defense for NIST AI RMF alignment.

Note the limit of the Order's own carve-out. Section 8(a) directs a legislative recommendation; § 8(b) provides that "[t]he legislative recommendation called for in subsection (a) of this section shall not propose preempting otherwise lawful State AI laws relating to: (i) child safety protections; (ii) AI compute and data center infrastructure, other than generally applicable permitting reforms; (iii) State government procurement and use of AI; and (iv) other topics as shall be determined." That carve-out binds the legislative recommendation only. It does not restrain the Task Force, the § 4 evaluation, or the § 5(b) grant conditions. The recommendation was published March 20, 2026 as the National Policy Framework for Artificial Intelligence.

The implication for districts: districts in states with their own AI transparency or automated-decision laws are operating inside a federal-state conflict the Order has activated and not resolved. Colorado's example is the one to study, because it is the one the Order names and the one the government sued: the statute was rewritten, narrowed, and stayed, and it still reaches education decisions. Districts should not assume a state rewrite preserves the obligations they built toward, or that a narrower statute stops reaching them.

Disclosed verification note Status is Active rather than Implemented: the Order is in force and its issuing bodies are still building its machinery, which this tracker's taxonomy classifies as Active. Two deliverables due March 11, 2026 remain outstanding as of this refresh: the § 4 Commerce evaluation and the § 5(a) BEAD Policy Notice. The § 7 FTC policy statement issued July 1, 2026 and is tracked as a separate entry. Section 6's clock runs from publication of the § 4 identification, so it has not started. The court order language is quoted from a law firm's analysis of the filing rather than read at the docket; clearinghouse.net, which hosts the case record, blocks automated retrieval.
Primary source whitehouse.gov: EO 14365 full text; the Task Force memorandum is justice.gov: Memorandum of January 9, 2026; the Colorado statutes are SB25B-004 and SB26-189
FTC proposed policy statement on AI accuracy (EO 14365 § 7)
Pending

On July 1, 2026 the FTC issued a proposed enforcement policy statement, Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems, published July 7 at 91 FR 41638 (FR Doc. 2026-13628, File No. P264200). It is the § 7 deliverable of EO 14365, which, in the Commission's words, "directs the Commission to issue this enforcement policy statement clarifying the application of section 5 of the Federal Trade Commission Act ('FTC Act') to AI models, and in particular, address how State laws requiring alterations to the accurate outputs of AI models can conflict with the requirements of the FTC Act." Comments close July 31, 2026. The Commission vote was 2-0.

It opens on education. "Artificial Intelligence (AI) is reshaping how Americans consume information, educate our children, and perform our jobs." The statement cites that more than half of U.S. teens ages 13 to 17 have turned to chatbots for school tasks.

It names Colorado and asserts implied preemption. The statement observes that "an AI company might be tempted to alter or steer the output of its systems contrary to consumers' reasonable expectations for various reasons, including attempted compliance with a State law, such as Colorado's recently revised Artificial Intelligence Act," and states:

Although the FTC Act does not expressly preempt State law, State law is impliedly preempted to the extent it conflicts with a Federal regulatory scheme. A State law that requires an AI firm to deceive its consumers obviously conflicts with section 5's express purpose of protecting consumers from such conduct.

A footnote adds that "Colorado has since materially revised the law referred to by this Executive Order, but the new version poses many of the same concerns." The statement cites SB 26-189 by section for the proposition that "the revised version of that law explicitly provides AI companies can be held liable for discriminatory outcomes caused by their customers' use of their products."

Read the limits. It is proposed, not final. The Commission "at this time takes no position on whether the practices discussed in this statement may also be unfair under the FTC Act," which reserves half of Section 5. And it is a distinct instrument from the February 25, 2026 age-verification policy statement tracked in the COPPA entry; two FTC policy statements five months apart are easy to conflate.

The implication for districts: a district operating under a state AI law that requires disclosures, explanations, or output constraints now has a federal agency asserting on the record that those requirements may be impliedly preempted where they conflict with the FTC Act. That is not a holding and it binds no one. It is the enforcement posture of the agency that regulates the vendors, and it is open for comment until July 31.

Primary source Federal Register: 91 FR 41638
NIST AI RMF: Trustworthy AI in Critical Infrastructure Profile
Pending

NIST released a concept note on April 7, 2026, launching development of an AI RMF Trustworthy AI in Critical Infrastructure Profile. The profile does not exist yet. NIST's project page lists status Ongoing, started April 2026, and describes the profile in the future tense: it "will guide CI operators towards specific risk management practices to consider when engaging AI-enabled capabilities." NIST is convening a Community of Interest before publishing a draft.

The concept note scopes to AI "across Information Technology (IT), Operational Technology (OT), and Industrial Control Systems (ICS)." Those are technology domains, not sectors. It enumerates no sectors and excludes none. NIST states that it "welcomes participation from across the entire critical infrastructure ecosystem — including all sectors, organizational roles, and supply chain partners," and that it will "develop a profile that provides critical infrastructure sectors with increased confidence to deploy AI agents and tools."

K-12 sits inside the critical infrastructure designation. The Education Facilities Subsector of the Government Facilities Sector covers pre-kindergarten through 12th grade schools. GAO states that "the Department of Education (Education) is the lead agency, or sector risk management agency, for the subsector." The sector's own risk management agencies are DHS and GSA.

The implication for districts: do not assume the CI profile will route around you. Nothing in the concept note carves K-12 out, and the federal sector designation places K-12 schools inside critical infrastructure with the Department of Education as the subsector's lead. Track the Community of Interest and the eventual draft rather than treating the profile as someone else's framework.

Disclosed verification note CISA's Government Services and Facilities Sector page is the conventional citation for the Education Facilities Subsector definition, but it blocks automated retrieval and could not be read. GAO states the sector risk management agency fact directly and is retrievable, so it is cited here in CISA's place.
Primary source nist.gov: April 7, 2026 concept note; the subsector lead agency is confirmed at GAO-23-105480
NIST AI Risk Management Framework 1.0: pending revision
Active

NIST states that AI RMF 1.0 is being revised. The statement appears on NIST's AI Risk Management Framework page. No draft of the revision has been published and NIST has not posted a public timeline for one.

The AI RMF (1.0, January 2023) and the Generative AI Profile (NIST AI 600-1, July 2024) remain the active voluntary frameworks in the meantime.

The one place the AI RMF carried legal weight in the United States is gone. Colorado's SB 24-205 provided an affirmative defense for developers and deployers aligned to the NIST AI RMF. SB 26-189 repealed that framework, and the affirmative defense with it.

The implication for districts: the AI RMF is voluntary guidance and NIST does not enforce it. Districts that have written AI RMF 1.0 into procurement language should locate every version reference in executed multi-year contracts before the revision publishes, because the citation in a signed RFP will point at a superseded version once the new one lands. Citing the framework by name rather than by version number, or adding language that follows the current edition, avoids the problem.

Primary source nist.gov: AI Risk Management Framework; the repealed affirmative defense is in leg.colorado.gov: SB26-189
Topic 03

Funding

Federal grants, discretionary funding priorities, and proposed legislation that direct district AI spending, including ESEA/Title programs, NSF supplements, and bills tying funds to AI literacy.

4 Entries
Secretary's Supplemental Priority: Advancing AI in Education
Implemented

The Department finalized a Supplemental Priority on Advancing AI in Education on April 13, 2026 (91 FR 18774, FR Doc. 2026-07087, Docket ID ED-2025-OS-0118, 34 CFR Part 75), effective May 13, 2026. The priority covers projects that (a) expand the understanding of artificial intelligence, or (b) expand the appropriate and ethical use of AI technology in education. The proposed priority published July 21, 2025 (90 FR 34203); over 300 parties commented. Signed by Secretary McMahon.

The priority does not attach to every competition automatically. "When inviting applications for a competition using one or more priorities, we designate the type of each priority as absolute, competitive preference, or invitational through a notice in the Federal Register" (34 CFR 75.105(c)(1)–(3)). It is a standing option the Department may select.

The Department was asked three times to regulate AI vendors, and declined three times. Commenters recommended "requirements for vendors to provide comprehensive data governance policies that transparently detail how student data will be collected, used, protected, and destroyed, and whether it will be used to train AI models." Changes: None. Commenters, citing COPPA and FERPA, recommended the Department "mandate parental notification requirements and opt-out provisions as a standard when AI tools are implemented in schools." The Department's response:

The Department is committed to upholding all student privacy protections under law and the central role of families in the education of their children. The Department believes that how best to ensure safety and communicate about technology use is optimally decided at the state and local level and declines to enact requirements at the federal level.

Changes: None. Commenters suggested "school districts should be required to vet and disclose the AI technology vendor's privacy policies and data-sharing practices." Changes: None. On documentation requirements, the Department said the July 2025 grant-funds guidance "addresses many of these issues" and that adding requirements "would be duplicative of existing laws and regulations."

What the Department did accept: "age-appropriate" inserted at (a)(ii); a new (a)(xi) on age-appropriate methodologies and developmental readiness in AI tool selection; "and ethical" inserted at (b); a new (b)(x) on universal design for learning; and (b)(xi) on using AI to improve program outcomes.

Check the governing document, which is not always the Federal Register notice. In the Supporting Effective Educator Development (SEED) FY 2026 competition, administered by the Department of Labor's Employment and Training Administration on ED's behalf, the Federal Register notice (91 FR 20989, April 20, 2026) is a one-page announcement carrying no point values, and it states that "[t]he application notice and instructions on Grants.gov is the official document governing the grant competition." That document, issued April 16, 2026 (corrected April 20, updated April 30) under opportunity number DOL-OESE-33914, provides: "An application may receive a maximum of 10 additional points under Competitive Preference Priority 1, a maximum of 5 additional points under Competitive Preference Priority 2, and a maximum of 5 additional points under Competitive Preference Priority 3 for a maximum of 20 additional points." Competitive Preference Priority 1 is Returning Education to the States; Priority 2 is Advancing Artificial Intelligence in Education; Priority 3 is Career Pathways and Workforce Readiness. SEED FY 2026 closed June 1, 2026.

The implication for districts: check each competition's application notice rather than assuming the AI priority applies or that it carries the most weight. Where it was designated, it was worth 5 points; Returning Education to the States was worth 10 in the same competition. And the Department has now said on the record that whether a vendor must disclose its use of student data for model training is a state and local decision. That decision is yours.

Primary source Federal Register: 91 FR 18774; the SEED designations and point values are in the SEED FY 2026 Application Notice and Instructions (opportunity DOL-OESE-33914), not in the Federal Register competition notice; see also the SEED program page
NSF Dear Colleague Letter: K-12 AI Education supplements
Implemented

NSF 25-035, "Expanding K-12 Resources For AI Education," invites supplemental funding requests from existing NSF awardees with K-12 AI or computer science education experience to "refine, scale, evaluate, and/or implement established K-12 activities." Budget requests "may be up to 20% of the original award budget with a maximum of $300,000." The DCL advances the goals of the Executive Order on Advancing Artificial Intelligence Education for American Youth (EO 14277, April 23, 2025).

The window is conditional rather than closed: "Consideration of supplemental support requests submitted after December 1, 2025, is subject to continuation of this funding opportunity." NSF's posting still carries the active funding opportunity flag.

The DCL names four themes: teacher professional development; curricula and instructional materials; technology and tools; and networks. Seven directorates participate, each with its own eligibility rules.

The implication for districts: districts were not applicants, but the DCL specifies what should reach classrooms and when. "Activities with the potential to be implemented in classrooms within 12 months of the supplement award date will be prioritized for funding." Target outcomes "should highlight resources that educators can successfully use 'out of the box,' without need for sustained external personnel, engineers, programmers, or other technical support staff." And each project must show "a plan for implementation with one or more education partners, e.g., school system(s), education nonprofit organization(s), museum(s), other public or private providers of K-12 education services." Track which NSF-funded universities, research centers, and CS education networks in your region received supplements under this DCL, and what they plan to deliver.

Primary source nsf.gov: Dear Colleague Letter NSF 25-035
K-12 AI Literacy and Readiness Act of 2026 (H.R. 8747)
Pending

H.R. 8747, the K-12 AI Literacy and Readiness Act of 2026, was introduced by Representative Randy Fine (R-FL-6) on May 12, 2026 and referred to the House Committee on Education and Workforce. The bill amends the Elementary and Secondary Education Act of 1965 to allow federal funds for student instruction on the safe, effective, and responsible use of artificial intelligence (as defined in the National Artificial Intelligence Initiative Act of 2020), and for professional development for teachers, paraprofessionals, school librarians and media personnel, specialized instructional support personnel, and administrators. Per the sponsor, "[t]he bill has no fiscal impact and creates no new spending programs. It simply clarifies that existing education dollars can be used for AI curricula and training in a responsible way." It has not been reported out of committee.

The implication for districts: if enacted, the bill would create explicit statutory authority for using current ESEA funds toward AI literacy, a question districts currently navigate through Department guidance rather than statute. Districts already spending federal funds on AI literacy under the Department's April 13, 2026 AI priority would gain statutory backing.

Disclosed verification note Congress.gov blocks automated retrieval of its bill pages. The official GPO text is available at govinfo.gov (BILLS-119hr8747ih), linked below, and the bill's contents and status are confirmed against the sponsor's announcement. Status is verified as of the refresh date by direct review rather than continuous monitoring.
Primary source govinfo.gov: official text (BILLS-119hr8747ih); see also the sponsor's announcement
Literacy in Future Technologies AI Act (H.R. 5584)
Pending

H.R. 5584, the Literacy in Future Technologies (LIFT) AI Act, was introduced on September 26, 2025 by Rep. Tom Kean Jr. (R-NJ-7) and Rep. Gabe Amo (D-RI-1) and referred to the Committee on Science, Space, and Technology. Per the committee, the bill "authorizes the National Science Foundation to support programs that promote AI literacy for K-12 students and educators. It funds the development of age-appropriate AI learning materials, teacher training, and hands-on educational tools." On June 25, 2026 the committee ordered the bill reported, as amended, by a vote of 34-1, as part of a bipartisan package of ten AI bills advanced together. It awaits House floor consideration.

A Senate companion exists. S. 4414, also titled the LIFT AI Act, was introduced April 28, 2026 by Sens. Schiff and Rounds, read twice, and referred to the Committee on Commerce, Science, and Transportation.

The implication for districts: if enacted, LIFT AI would create an NSF-administered pipeline of AI literacy curriculum, instructional material, and teacher training reaching districts through NSF-funded institutional partners. Districts are not direct applicants but would receive the downstream resources. A companion bill, H.R. 5351 (NSF AI Education Act of 2025), was ordered reported in the same markup.

Disclosed verification note Congress.gov blocks automated retrieval of its bill pages. The bill's description, the 34-1 committee vote, and the June 25, 2026 markup are confirmed against the House Science, Space, and Technology Committee's own record, which also hosts the GPO bill text. Any floor action after the refresh date will not be reflected here until the next refresh.
Primary source House Science Committee: H.R. 5584 and the June 25, 2026 markup record