Skip to content
eleved.ai
The Field Guide

Field Guide · Compliance & legal

FERPA Was Written for a Different Machine

FERPA, accessibility, accreditation, copyright, procurement, and employment obligations all apply to AI in ways many institutions have not fully mapped.

5 min read

The rules that govern student records, accessibility, and intellectual property did not anticipate AI. They still apply to it. That combination is where institutions get surprised.

FERPA became law in 1974. The student record it was written to protect lived in a filing cabinet, and the dangerous scenario its authors imagined was a person opening a drawer they should not have opened. Fifty years later, an advisor can paste a student’s academic history into a chatbot to draft a better outreach email, and the question of what just happened to that record does not have a filing-cabinet answer.

To be clear about the stakes: nothing about AI suspended the law. FERPA still applies, accessibility requirements still apply, copyright law still applies. What changed is that the routine motions of using AI now touch all of them at once, usually without anyone in the transaction noticing. The law did not get weaker. The number of ways to trip over it got larger.

The institutional question

What are your actual regulatory obligations when AI touches student records, student-facing services, and institutional work product?

Not the vibes version, the actual version. Most campuses are operating on a mix of instinct and hope here: an instinct that pasting student data into a free tool is probably bad, and a hope that somebody, somewhere, probably legal, is on top of the rest. Instinct and hope are not a compliance posture. And this is one domain where the answers cannot be improvised after the fact, because by the time the question is urgent, the record has already gone somewhere.

What this looks like in practice

Start with FERPA, because it touches the most daily behavior. The law restricts who can access student education records and for what purpose. When an AI vendor’s system processes those records, the vendor generally needs to qualify as a school official with a legitimate educational interest, under a real agreement, with real limits on what it can do with the data. That is a solvable problem with an enterprise contract. It is not solved at all when the tool is a free consumer chatbot on a personal account, which is exactly the shadow-AI pattern from earlier in this series. The advisor drafting that email was trying to help a student. The question nobody asked is whether a student record just left the institution’s custody.

There is a second FERPA wrinkle that almost nobody has metabolized: what AI produces about a student may itself be an education record. A model’s risk score, an AI-generated advising summary, a chatbot’s log of a conversation about a student’s finances. If it identifies a student and the institution maintains it, it is likely covered, which means retention, access, and disclosure rules apply to artifacts nobody thought of as records when they turned the feature on.

Accessibility is the obligation with a clock attached. Federal rules now set explicit deadlines for public institutions to meet WCAG standards for digital services, and AI tools are digital services. A shiny new chatbot that a screen reader cannot navigate is not a minor polish issue. It is a compliance failure sitting on the front door of the institution, and it tends to get built in exactly the fast-moving, pilot-driven way that skips the accessibility review. If the tool serves students, it has to serve all of them, and that requirement does not care how innovative the pilot is.

Copyright and intellectual property are murkier, and the honest answer is that some of it is unsettled law. But institutions still need positions, because the questions arrive weekly. Who owns a course module a faculty member built with heavy AI assistance? Can AI-generated material go into marketing, or accreditation documents, and does anyone need to know it was AI-generated? What happens when a tool trained on copyrighted material produces something uncomfortably close to its source? You do not need to resolve global copyright doctrine. You need house rules, so that people are not each inventing their own.

Accreditors, meanwhile, are starting to ask the readiness question in their own language. Institutions increasingly get asked to show how they govern AI, and here is the useful reframe: everything this series has covered so far, decision rights, policy, data governance, risk assessment, equity audits, is also accreditation evidence. The work you do to be genuinely ready and the work you would show an accreditor are the same work. An institution that governs AI well does not need to prepare a special story for the site visit.

And then there is the layer that will not sit still: state law. AI-specific legislation is moving through statehouses at very different speeds, with different definitions and different obligations. For institutions that operate or enroll across state lines, especially online programs, “which rules apply to us” is a live question that someone needs to own and track, because the answer this year may not be the answer next year.

The pattern across all of it: none of this requires panic, and none of it is optional. It requires the unglamorous move of putting AI on the same compliance calendar the institution already runs for everything else.

The Atlas connection

In Atlas, our AI operating map, this is the compliance and legal domain, in the Defense group — Protect. It leans hard on its neighbors: the vendor and procurement agreements next door are where FERPA compliance actually gets written down, the policy and acceptable use work over in Foundation is where employees learn the rules that keep them out of trouble, and governance — Decide — decides who owns the compliance calendar in the first place. This domain is also where the map meets the outside world, because regulators, accreditors, and courts do not grade on effort. It is the least skippable domain in Defense, and the one where being surprised costs the most.

Questions worth putting on the agenda

A good exercise is to run these against one specific AI tool you already use, and see how many produce a confident answer.

  • Do our AI vendors qualify as school officials under FERPA, with agreements that limit what they can do with student data, including whether they train on it?
  • Are we treating AI-generated outputs about students, scores, summaries, chat logs, as education records with retention and access rules?
  • Have our student-facing AI tools been checked against WCAG accessibility standards, and who signed off?
  • Do we have house rules on ownership and disclosure of AI-assisted work, even where the law is unsettled?
  • Who tracks state AI legislation in every state where we operate or enroll, and when did they last brief leadership?

The bottom line

The regulations were written for a slower machine, but they bind the fast one just the same. Institutions will not get in trouble because the law failed to anticipate AI. They will get in trouble because they assumed that what the law did not anticipate, it did not cover.

The law is old. The obligations are current. The gap between those two sentences is where the risk lives.

Also published on LinkedIn: read this guide on the newsletter .

New guides on LinkedIn

Get the next Field Guide

Each guide lands here first as the canonical archive. Subscribe on LinkedIn to get the next one in your feed — one topic of institutional AI readiness at a time, no hype.

Subscribe on LinkedIn