Is It FERPA Compliant? A comprehensive overview of FERPA and AI in Student Accounts

Alexandra Lindsay
August 28, 2026

This is Lesson 3 of The Student Accounts AI Field Guide Series, a companion learning series alongside our 2026 State of AI in Student Accounts report.

Ask a student accounts professional what worries them about using AI, and one answer comes up more than any other: FERPA, which stands for Family Educational Rights and Privacy Act.

In Meadow’s 2026 research, 78% of student accounts professionals named privacy and FERPA as a top concern about AI, ahead of security and data leakage at 70% and hallucinations or incorrect guidance at 59%.

Concern about remaining FERPA compliant is very reasonable: student accounts offices work with some of the most sensitive information a college or university holds. The U.S. Department of Education explicitly includes student financial information at the postsecondary level within its examples of education records protected by FERPA.

But our research surfaced a second problem: people are being asked to manage that risk without clear rules or role-specific guidance.

Among student accounts departments using very little or no AI, 57% said it was unclear what they were permitted to do with student data, and 46% said they had no approved tools or institutional guidance. Across the broader sample, 53% described their institution’s AI guidance for tuition billing as unclear or very unclear; only 17% called it clear or very clear. Just one respondent reported having a department-specific AI policy for student accounts.

At some institutions, FERPA compliance is becoming shorthand for “we can’t use AI,” which puts access to meaningful innovation to change outcomes for students at risk.

A better question than “can we use AI?” is: What would have to be true for us to use this particular AI tool, for this particular purpose, with this particular data? That’s exactly what this post aims to dig into.

Before we start, an important disclaimer:

This is for general educational purposes only, not legal advice or a determination that any tool, vendor, configuration, or use case complies with FERPA or other law. FERPA compliance is fact specific, depending on the data involved, how the technology is configured, the institution's annual FERPA notice and policies, the vendor contract, the purpose of disclosure, and other federal, state, and institutional requirements.

Do not enter student specific information into an AI tool based on the examples here. Before using AI with student education records or personally identifiable information, consult your institution's legal counsel or FERPA/privacy officer and IT/security team, and follow your institution's approved tool, procurement, data governance, and security requirements. Institutions may impose stricter requirements than FERPA itself.

First: what does FERPA actually protect?

FERPA, or Family Educational Rights and Privacy Act is a federal law governing education records at educational agencies and institutions that receive funding under programs administered by the U.S. Department of Education (ED). 

The basic rule is relatively straightforward: schools generally cannot disclose personally identifiable information, known as PII, from a student’s education records without the student’s consent unless a FERPA exception allows the disclosure.

Two terms matter enormously when you're thinking about AI.

Education record: A record that is directly related to a student and maintained by the institution or by a party acting for the institution. For colleges and universities, the ED specifically identifies student financial information as an example.

Personally identifiable information (PII): This is broader than a name or student ID. It includes direct identifiers as well as indirect information that, alone or in combination, could allow a reasonable person in the school community to identify the student with reasonable certainty.

That second definition is especially important for AI.

Removing a student's name from a prompt does not automatically make the prompt de-identified.

If you enter:

"A junior biology major who is the only international student in her cohort has an $8,742 past-due balance, a specific institutional scholarship, and missed her second payment-plan installment…"

you may have removed the name while still providing enough information to identify the person.

ED says information is de-identified only when enough direct and indirect identifiers have been removed or obscured that there is no reasonable basis to believe an individual can be identified.

The biggest misconception: an AI tool isn't simply “FERPA compliant” or “not FERPA compliant”

This is where conversations about FERPA and AI often go wrong.

Someone asks:

“Is [AI tool] FERPA compliant?”

And everyone wants a one-word answer.

But FERPA is not primarily a certification system for software products. It governs what educational institutions do with education records and under what circumstances those records can be disclosed.

So the same technology might be usable in one context and prohibited in another.

Imagine two institutions using the exact same underlying AI model.

At Institution A, an employee opens a personal account in an AI tool and pastes a student email containing their name, balance, payment-plan status, and financial-aid information into it.

At Institution B, the institution has formally approved the same AI tool. The provider is operating under institutionally established controls, its access is limited to the records necessary to perform that function, its use of the information is restricted to the authorized purpose, and the institution has addressed its FERPA obligations for third-party access.

Those are not the same FERPA analysis simply because the AI underneath is the same.

The question is not only which model are you using?

It is also:

What data does it receive? Why does it receive it? Who controls what happens to that data? And what has your institution authorized?

Is FERPA universal, or is it up to each institution?

The federal requirements of FERPA do not change from campus to campus. An institution cannot simply “interpret” FERPA in a way that overrides federal law.

But FERPA itself leaves institutions responsible for making a number of important determinations.

For example, institutions establish criteria in their annual FERPA notifications for who qualifies as a school official and what constitutes a legitimate educational interest. FERPA also allows institutions to designate certain information as directory information, subject to specific notice and opt-out requirements.

Then another layer sits on top of FERPA: institutional privacy rules, information-security standards, procurement requirements, vendor agreements and applicable state laws. The Department of Education specifically notes that state or local rules may impose additional requirements beyond FERPA.

It is entirely possible for FERPA to permit a disclosure under an exception while your institution still says, “you cannot use that tool.”

Think of FERPA as functioning as the federal baseline. Your institution then has to translate that baseline into operational rules for its own people, systems, and vendors.

The “school official exception”: why it matters for AI 

One of the most relevant FERPA concepts for third-party technology is the school official exception.

FERPA can permit an institution to disclose education records without student consent to a contractor, consultant, or other outside party performing an outsourced institutional service or function, but only if specific conditions are satisfied.

Among other requirements, the outside party must perform a function for which the institution would otherwise use employees; be under the institution’s direct control with respect to the use and maintenance of the education records; be subject to FERPA’s restrictions on use and redisclosure; and satisfy the institution’s criteria for a school official with a legitimate educational interest.

In terms of practical implications for AI platforms: if a vendor receives identifiable student account information, your institution should understand exactly what the vendor is allowed to do with it:

  • Can it use the data only to provide your institution's service?
  • Can it use identifiable student information to improve a general-purpose model for its own benefit?
  • Can the data be disclosed to other parties or subprocessors?
  • What happens when your relationship with the vendor ends?
  • What control does the institution retain?

FERPA does not universally require a written contract for every disclosure made under the school official exception. But ED calls written agreements a best practice and specifically notes that contractual provisions can help establish the “direct control” FERPA requires. State law or institutional procurement policy may also require an agreement.

This is an important nuance: a data processing agreement is not a magic FERPA certificate. But the controls it establishes can be an important part of the FERPA analysis.

What this looks like in practice

The examples below are simplified illustrations of how to think about a use case, not legal conclusions for your institution.

  1. You ask an AI tool to rewrite a generic late-payment reminder. You include no student information at all.

    How to think about it
    : FERPA may not be implicated because you have not disclosed PII from an education record. Your institution may still restrict which AI tools employees can use.
  2. You paste a student's full email into an unapproved consumer AI account. The email includes their name, ID, balance, and aid information.

    How to think about it
    : High-risk and potentially impermissible. You are disclosing identifiable information from an education record to a third party. Unless your institution has established a valid FERPA basis and approved the service for that use, don't assume you can do it.
  3. You delete the student's name and ID first, but leave a combination of unusual facts that makes the student recognizable.

    How to think about it:
    Not necessarily de-identified. FERPA's definition includes indirect identifiers and combinations of information that can identify a student. Simply removing a name is not enough.
  4. Your institution approves an AI vendor to assist with billing inquiries. The provider meets the institution's school-official criteria, is under institutional control regarding the records, has access only for the authorized function, and may not use or redisclose PII for unrelated purposes.

    How to think about it
    : This can be a permissible FERPA structure, assuming all applicable requirements are met. This is the kind of analysis legal, privacy, procurement, and IT teams should conduct before student data enters a system.
  5. You give an AI tool aggregate or properly de-identified account information to identify patterns in payment-plan utilization.

    How to think about it:
    FERPA permits disclosure of properly de-identified information because individual students cannot reasonably be identified. The hard part is making sure the data truly is de-identified.
  6. A student-facing AI assistant retrieves a student's balance after the institution has authenticated the student, limits access to the information needed for that interaction, and operates within an approved institutional/vendor framework.

    How to think about it:
    This is very different from putting student records into a public chatbot. FERPA can accommodate technology that handles education records when the disclosure and access are appropriately authorized and controlled. The exact authentication, access and vendor requirements should be set by the institution.
  7. An AI system has permission to see student data, so the office allows it to automatically make any decision involving those students.

    How to think about it:
    FERPA does not answer every AI-governance question. A permitted disclosure does not establish that an automated decision is accurate, fair, appropriate, secure or lawful under every other requirement. FERPA compliance is one part of the analysis, not the entire analysis.

A special warning about “anonymizing” prompts

A common workaround we heard in our research was: We'll just anonymize the student data first.

That can be useful when it is done correctly.

One respondent told us their institution does not allow student-specific information to be uploaded into its AI tool, so any analysis has to be anonymized first.

But proper de-identification is more demanding than replacing “Jane Smith” with “Student A. Context itself can identify people.

A better practical test is: Could someone familiar with our campus reasonably work out who this is from the combination of facts I've supplied?

If the answer might be yes, do not assume you've solved the FERPA problem.


Data minimization is a best practice when using AI

In our State of AI in Student Accounts report, we described FERPA not as a reason to stop building, but as a design requirement.

That means:

  • Designing systems so privacy doesn't depend solely on an employee remembering what not to paste into a prompt
  • Narrowly scoped access
  • Setting appropriate permissions
  • Giving a system only the information it actually needs
  • Making sure one student's information cannot surface to another student
  • Restricting what the system can modify
  • Handing a question to a human when it falls outside the system's authorized scope

That is a much more useful model for AI adoption than the extremes of: “Never use student data with AI” or “The vendor says they're FERPA compliant, so anything goes.”


FERPA compliant does not mean AI safe

You could design an AI workflow that satisfies your institution's FERPA requirements and still have a bad AI workflow.

FERPA is primarily about students' education records and their disclosure and use. It does not make an AI answer accurate, eliminate hallucinations, automatically solve cybersecurity, accessibility, bias, retention, records-management or institutional-policy questions.

Our survey makes that clear. After FERPA/privacy, the next two concerns student accounts professionals raised were security/data leakage at 70% and hallucinations or incorrect guidance at 59%. Even when you’ve cleared a FERPA hurdle, make sure you’re deploying a tool in a way that is productive and results in accurate insights and action.

Eight questions to bring to your IT and legal teams

Bring your team a concrete workflow and work through these questions as a starting point:

  1. What exact information will enter the AI system? Is any of it an education record or PII from an education record?
  2. Why does the AI need that information? Could the same job be done with less data, de-identified data, or no student-specific data at all?
  3. What permits the disclosure? Are we relying on student consent, the school official exception, properly de-identified information, or another FERPA provision?
  4. What happens to the information after we provide it? Who can access it, how long is it retained, can it be used for other purposes, can it be used to train or improve other models, and can it be redisclosed?
  5. What control does the institution have? Is the tool approved? What contractual, technical, and administrative controls govern its use? Does access reflect legitimate educational interests? Can AI-related features be disabled?
  6. If information will be returned directly to a student, how are we making sure it reaches the right student? What authentication and access controls does the institution require?
  7. What sits beyond FERPA? Ask about institutional privacy and security policies, state laws, records requirements, accessibility, cybersecurity and any other rules relevant to the particular workflow.
  8. Has the vendor completed the current HECVAT (Higher Education Community Vendor Assessment Toolkit)? The latest release, HECVAT 4, added a dedicated section on AI that asks how the vendor's product uses AI, so review that section closely as part of your evaluation. Because earlier HECVAT versions do not include this AI-specific content, treat a completed older version as insufficient for an AI-related procurement and ask the vendor for the current one instead.

Notice how different that conversation is from: “Can we use Claude?” These questions mean more work for you on the front end, but will help unlock access to tools that will improve your work and departmental outcomes.


The goal is to use AI tools confidently

Student accounts professionals are right to be careful with student information and balance that caution with their appetite for new tooling and supportive workflows. One of the most encouraging findings in our research was that staff were far more worried about mishandling student data than they were about AI replacing their jobs. If the scale is tipped too much to the site of caution, your student accounts function cannot benefit from innovation that could drive meaningful outcomes for your institution’s ability to keep students enrolled and drive down student A/R.

Don’t let your institution fall into the “we can’t use AI because of FERPA” trap. Once a student accounts team knows where the lines actually are, it can finally start experimenting confidently inside them.

This is The Student Accounts AI Field Guide Series, a companion learning series alongside our State of AI in Student Accounts report. Each lesson covers a practical topic grounded in real data from the field. Sign up to receive the full series in your inbox.

Meadow's research for this series is drawn from the State of AI in Student Accounts report, based on a survey of 147 student accounts, billing, collections, and One Stop professionals conducted in March 2026. Download the full report here.

Subscribe to our blog

Oops! Something went wrong while submitting the form.

Ready to get started?

Get in touch with our team today.