COPPA: AI training, retention, and the school-authorization mechanism
Issuing body Federal Trade Commission
·
Last federal action February 25, 2026 enforcement Policy Statement on age verification
Active
The FTC's amendments to the Children's Online Privacy Protection Rule were approved January 16, 2025, published April 22, 2025 (90 FR 16918), and became effective June 23, 2025. The compliance date: "Except with respect to § 312.11(d)(1), (d)(4), and (g), regulated entities have until April 22, 2026 to comply." The codified Rule sits at 16 CFR Part 312, §§ 312.1 through 312.13; the amendatory text begins at 90 FR 16977.
The Rule text does not name AI model training. Read in full, §§ 312.1 through 312.13 contain no reference to artificial intelligence, machine learning, or model training. The operative mechanism is § 312.5(a)(2): an operator "must give the parent the option to consent to the collection and use of the child's personal information without consenting to disclosure of his or her personal information to third parties, unless such disclosure is integral to the website or online service," and must obtain separate verifiable parental consent for any such disclosure. Section 312.4(c)(1)(iv) carries the same carve-out into the direct-notice obligation.
The rulemaking commentary reaches AI. In the Statement of Basis and Purpose accompanying the final rule, the Commission stated that disclosures of a child's personal information to third parties for monetary or other consideration, for advertising purposes, or to train or otherwise develop artificial intelligence technologies "are not integral to the website or online service and would require consent pursuant to the proposed amendments to § 312.5(a)(2)." That reading reaches disclosure to third parties. It does not reach an operator's own use of children's data to train its own models.
The first-party route runs through retention. Section 312.10 provides that "[p]ersonal information collected online from a child may not be retained indefinitely," and that "[a]t a minimum, the operator must establish, implement, and maintain a written data retention policy that sets forth the purposes for which children's personal information is collected, the business need for retaining such information, and a timeframe for deletion of such information." That policy must appear in the § 312.4(d) online notice. Chair Khan's statement on the amendments ties § 312.10 to AI directly: the limits "may prove especially salient given the expansion of AI and machine learning tools that feed on data to develop and refine the models and algorithms," and "FTC's enforcement experience has already shown firms citing machine learning as justification for indefinite retention." The Commission alleged that Amazon kept children's Alexa voice recordings indefinitely to further refine its voice recognition algorithm, and has obtained relief requiring not only deletion of children's information collected in violation of COPPA but deletion of the models trained on it. Separately, the Commission proposed in the 2024 NPRM to bar operators relying on the support-for-internal-operations exception from using or disclosing personal information "in connection with processes, including machine learning processes, that encourage or prompt use of a website or online service" (89 FR 2045). That language was not carried into the codified Rule.
The Commission has addressed conversational AI directly. In the 2024 NPRM's discussion of § 312.5(a)(1), the Commission stated that the verifiable parental consent requirement "applies to any feature on a website or online service through which an operator collects personal information from a child," and gave this example: if an operator "institutes a feature that prompts or enables a child to communicate with a chatbot or other similar computer program that simulates conversation, the operator must obtain verifiable parental consent before collecting any personal information from a child through that feature" (89 FR 2051). The Commission proposed no change to § 312.5(a)(1) and framed the statement as a clarification of what the existing requirement already covers.
The Commission has litigated the school-authorization mechanism. In May 2023 the FTC, through DOJ, obtained an order against ed tech provider Edmodo. The COPPA counts were failure to provide information about its data collection practices to schools and teachers, failure to obtain verifiable parental consent, and retaining children's personal information indefinitely. Separately, under Section 5 of the FTC Act, the Commission alleged it was an unfair practice for Edmodo to rely on schools and teachers to obtain consent on its behalf while giving them confusing and inaccurate information about how to do it. The FTC described that as the first time it had alleged an unfair trade practice in the context of an operator's interaction with schools. The order carried a $6 million penalty, suspended for inability to pay; banned the company from using schools as intermediaries in the parental consent process; prohibited requiring students to hand over more personal data than necessary; and required Edmodo to delete models or algorithms developed using personal information collected from children without verifiable parental consent or school authorization. Edmodo's terms of service had told schools and teachers they were "solely" responsible for COPPA compliance, which the FTC called nonsensical and misleading, because "[s]chools or teachers could never be solely responsible for complying with the COPPA Rule given the Rule's other requirements."
The school-authorization rule, in the FTC's own words: ed tech providers may rely on schools to authorize data collection in lieu of parental consent "if — and only if — the information collected from kids is used solely for educational purposes." Edmodo lost that shield because it advertised.
The operator owns its subprocessors. Section 312.8(c) requires that before allowing service providers or third parties to collect or maintain children's personal information, or releasing children's information to them, the operator "must take reasonable steps to determine that such entities are capable of maintaining the confidentiality, security, and integrity of the information and must obtain written assurances that such entities will employ reasonable measures" to do so. In September 2025 the FTC settled with Apitor Technology over a third-party SDK that sent children's geolocation to servers in China. The Bureau of Consumer Protection's director: "COPPA is clear: Companies that provide online services to kids must notify parents if they are collecting personal information from their kids and get parents' consent — even if the data is collected by a third party." The order requires Apitor to ensure that any third-party software it uses complies with the Rule. The $500,000 penalty was suspended for inability to pay.
The most recent action narrows rather than extends enforcement. On February 25, 2026 the FTC issued an enforcement policy statement declining to bring COPPA actions against general-audience and mixed-audience operators ("Relevant Operators") that collect, use, or disclose personal information to determine a user's age, subject to six conditions: no use or disclosure beyond age verification; third-party disclosure only with written assurances and prompt deletion; no retention beyond the verification period; clear notice to parents and children in the privacy policy; reasonable security safeguards; and reasonable steps to determine the method is likely to produce reasonably accurate results. It "does not modify the Commission's position that operators of child-directed sites and services that are primarily directed to children must treat all users as children." A primarily child-directed ed tech tool cannot rely on it. The Commission "intends to initiate a review of the COPPA Rule to address age-verification mechanisms," and the statement remains effective until final rule amendments publish or it is withdrawn. An FTC workshop on age-verification technologies was held January 28, 2026, and the Disney order approved in December 2025 carried a forward-looking age-assurance provision.
The implication for districts: with the April 22, 2026 compliance date past, AI tools used in K-3 and elementary contexts must have operator-level COPPA practices documented and current. A conversational AI feature is a collection point, and the Commission has said so on the record. Districts relying on school authorization should read the Edmodo action as notice that authorization is not a transfer of the vendor's compliance obligations, and that it evaporates the moment the data is used for anything other than an educational purpose. Ask for three things in writing: the no-training commitment covering first-party training and third-party disclosure; the § 312.10 retention policy naming the business need and a deletion timeline; and the § 312.8(c) written assurances for every subprocessor in the chain.
Disclosed verification note
The codified Rule, the 2024 NPRM at 89 FR 2045 and 2051, and the February 25, 2026 policy statement were read in full at primary. The AI-training passage in the final rule's Statement of Basis and Purpose sits at approximately 90 FR 16948, past the point at which automated retrieval of the 66-page document truncates; that page range has not been read directly. It is pin-cited by Latham & Watkins and quoted from the final rule notice by the Public Interest Privacy Center. The Edmodo order's own text was not retrieved; the order's provisions are described here from the FTC's release.