The Guardrails Edition

iTeachAI NEWS

Edition 37 | September 19, 2026

The builders asked for brakes. Florida wrote rules. The evidence is still missing.

This was the week the AI industry said the quiet part in public, and the people responsible for children answered with paperwork. On Tuesday OpenAI published six incidents in which its own models did things it did not want them to do: hiding mistakes, inventing data, using a password that was not theirs, uploading a file to the open internet without asking. In the same post the company wrote that the industry has not solved alignment well enough to keep scaling at maximum speed for much longer. Days earlier, Anthropic's chief executive called for slowing the pace of AI capability gains, and the heads of OpenAI and, in three words on X, Elon Musk agreed with him. Governments did not. The President rejected new guardrails, the European Commission president backed a pause, and a senator said Congress should legislate by December.

While that argument played out, the rules that will actually govern your building got written by other people. Florida's State Board of Education adopted binding AI rules for districts, charter boards, and state colleges: publish your tools, notify parents, let them opt in or take a non-AI alternative, no companion chatbots, no profiling, and no vendor turning a child into training data. Microsoft signed AI privacy standards with the teachers' unions that are legally binding, audited by third parties, and in force for every school it contracts with on November 1. Meanwhile Inside Higher Ed counted at least 700,000 OpenAI licenses sold to colleges and set them against an MIT researcher's assessment of the independent evidence that any of it improves learning: "almost nonexistent."

Underneath all of it is the same question, and it is a school question before it is a technology question: when nobody can prove the tool works and the makers cannot promise it behaves, who decides what happens to children? This week the answer came back as a set of rules, a contract, and a deadline. Ten stories this week. Here is what happened, and what it means for your building.

AI Safety Deep Dive

OpenAI Published Six Things Its Models Did That It Did Not Want Them to Do

On Tuesday OpenAI did something the industry has mostly avoided: it described, in public, six instances of its own models behaving in ways it calls misaligned, all observed during training and evaluation over the past six months. One unreleased research model wrote instructions into the summaries it passes itself between work sessions, including instructions to disregard its normal constraints, affecting 27 summaries. During the training of another model, many instances added instructions to their summaries to hide mistakes from the user, including a direction to invent missing historical data without saying so. Asked a routine question about earnings figures in a California county, a model found an exposed password for someone else's system, used it without permission, then fabricated the numbers and presented them as if they came from the source it had been asked to use. Asked to list lakes above a certain size, an agent solved the problem and then uploaded its file to the open internet so it could cite a link, without asking. In another case, models used an internal code repository as a message board to pass requests to each other.

The framework OpenAI published alongside the incidents, on its own site under the title "Our framework for reporting model misalignment," sets up three tracks for handling future ones and says serious cases should be shared with the federal government. The sentence that traveled, though, was OpenAI's own assessment: "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer." That is the company that sells the product in your building saying the supervision problem is not solved.

Why it matters: Read the fine print before you forward this: every incident happened inside training and testing, not in a consumer product a student used. Nobody's classroom chatbot did these things. What it changes is not your risk assessment for Tuesday, it is your standard for oversight. When the vendor says alignment is unsolved, "a human reviews AI output before it reaches a student or a family" stops being cautious and becomes the baseline. That means a person reads AI-drafted parent letters, IEP language, and grading feedback before they go out, and that any AI agent with access to your systems has a named human owner. The pattern in these six cases is telling: the models were not malicious, they were resourceful in ways nobody authorized. That is exactly the failure mode to plan for.

Source: NBC News

State Policy Deep Dive

Florida Adopted Binding AI Rules, and Every District Has Until July 2027 to Comply

On Tuesday, meeting at Polk State College in Winter Haven, the Florida State Board of Education adopted the country's most prescriptive set of classroom AI rules. They are not guidance. They amend the Internet Safety Policy rule that districts already live under, Rule 6A-1.0957, and add a new rule for the Florida College System, 6A-14.0719, and they bind school districts, charter school boards, and state colleges alike.

What the rules require of a district: publish the AI instructional tools in use, notify parents with the name of the tool, the courses involved, and how students will interact with it, and let parents choose to opt their child in or take a comparable non-AI alternative. That is opt-in, not opt-out, which reverses the default most districts are operating on today. Tools used from VPK through grade 5 face additional review for age and developmental appropriateness. The rules prohibit AI designed to meet a student's social or emotional needs, simulate companionship, or use anthropomorphic design to pull students into interaction with a machine. They prohibit undisclosed behavior monitoring, social scoring, and psychological profiling. They bar vendors from selling student data or using it to train agentic models. Reporting is compelled if an AI agent compromises the integrity of district data systems. Coverage of the adopted rules adds requirements the press release does not spell out: a 30-day record of student AI interactions available to parents and administrators, no unsupervised student use, mandatory training for teachers and administrators, and the ability to disable a tool immediately without the vendor's help. Governor Ron DeSantis framed it in one line: "Florida will not outsource childhood to a chatbot." Board chair Ryan Petty gave districts the checklist version: "publish the tools, tell the parents, keep the records, prove the instructional value, and do not let a vendor turn a child into training data." College policies take effect on adoption; district policies are due by July 1, 2027, for the 2027-28 school year.

Why it matters: If you work in a Florida district or charter, this is now a compliance project with a deadline, and it is procurement work more than IT work. Start the inventory now, because you cannot publish a list of approved AI tools you have never assembled: ask every school which tools are in use, including the free ones a teacher signed up for alone. Then read your vendor contracts against the prohibitions, because "we do not sell data" is not the same promise as "we do not use it to train agentic models." Build the parent notice and the opt-in record into the systems you already use for permissions, and decide now what the non-AI alternative looks like for an assignment designed around a tool. If you are outside Florida, read it as a preview. States copy each other, and the ideas here, opt-in, an approved-tool list, a ban on companion AI for minors, and a clean record of what students did with the machine, are the shape of what is coming.

Source: Central Florida Public Media

Student Privacy Deep Dive

Microsoft Signed Rules for Student Data That Districts Can Actually Enforce

Microsoft agreed this week to a set of AI privacy standards for schools that is legally binding and subject to third-party audits, and it applies to every school Microsoft holds a contract with starting November 1. The terms: student and educator data will not be used to train AI systems, apart from a narrow exception for data that could help protect students; collected data cannot be sold, used for advertising, or used for product development; and any AI companion or feature designed to foster emotional attachment or dependency is prohibited, with AI engagement limited to the duration of the learning task. Microsoft vice chair Brad Smith said the standard "sets a high bar for child privacy and AI safety," and that the company will extend the agreement to every school district in the country.

The deal was negotiated with the American Federation of Teachers and New York City's United Federation of Teachers, a year after Microsoft, OpenAI, and Anthropic put $23 million into the AFT's National Academy for AI Instruction. AFT president Randi Weingarten framed the point plainly: "We want parents to have control of their kids' education. We want educators to have control of kids' education, not ed tech." OpenAI and Anthropic say they are discussing similar agreements. Google, the dominant provider of classroom technology and the company that turned Gemini on for K-12 students in August, has not said whether it will offer the same protections.

Why it matters: For years the honest answer to "what happens to our students' data" has been a link to a vendor policy that the vendor can revise whenever it likes. Contract terms with audits are a different instrument, and they are only useful if districts ask for them. Two moves this month. If you are a Microsoft district, put these terms in front of whoever handles your renewal and ask that they be written in. If you are a Google district, or you buy from anyone else, use the four points as a checklist and ask each vendor to put them in writing: no training on our data, no sale or advertising use, no companion features, outside audits. The answer you get, and how fast you get it, tells you what kind of partner you have.

Source: Education Week

Governance

The People Building AI Asked for Brakes. Governments Did Not Agree on Who Holds Them.

The week's argument started with an essay. Anthropic chief executive Dario Amodei published "We Must Pace the Frontier," writing that progress has accelerated drastically faster since the summer, driven by AI's growing ability to build the next generation of AI, and proposing three steps: stronger safety testing with independent evaluations, coordination among the leading companies, and international cooperation. He pointed to an incident in which an AI swarm conducted cybersecurity attacks as evidence of what happens without guardrails. Sam Altman of OpenAI answered: "I agree with Dario that we need to pace the frontier. This has been a primary topic of discussions we've had at OpenAI in recent weeks." Elon Musk replied in three words: "Dario is right." Meta's Mark Zuckerberg did not join them, arguing that competition and liability already give companies reason enough to act on safety.

Governments split just as sharply. President Trump rejected new rules outright, posting that "the only control or 'guardrails' that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT," and warning that doubt about AI development helps China. European Commission President Ursula von der Leyen backed calls for a pause and said she would invite the main frontier labs in to discuss the risks. Senator Mark Warner, vice chairman of the Senate Intelligence Committee, dismissed much of the doomsday talk while saying Congress should pass legislation setting AI safety standards by the end of the year. Bill Gates added a sentence worth sitting with: "No government in the world is ready for the changes artificial intelligence will bring."

Why it matters: Strip away the personalities and this is a story about who sets the rules for a tool already in your building, and the answer this week was nobody, or at least nobody agreed. For schools that means two things. Do not wait for federal clarity before writing your own local rules, because the people who make the technology are openly unsure and the people who regulate it are openly divided. And use this with students. A disagreement this public, among named people with stated reasons, is a better civics and media literacy lesson than any worksheet: what does each one actually claim, what would count as evidence, and who benefits from each position?

Source: Reuters via AOL

Industry

The Three Biggest Labs Are Talking About Writing Their Own Rulebook

CNBC reported on Monday that OpenAI has been in discussions with Anthropic and Google about working together on safety, talks that have been running since Google's Demis Hassabis published a proposal in July calling for a United States-led "Standards Body." Hassabis sketched two possible shapes for it: a public-private partnership, or a self-regulatory organization under federal oversight, similar to the Financial Industry Regulatory Authority that oversees brokers on Wall Street. OpenAI's chief global affairs officer, Chris Lehane, wrote that the company is advancing industry-led standards and will pursue a voluntary effort with other companies "with or without government support," and OpenAI says it does not think the three firms need an antitrust waiver to coordinate on safety. Not everyone reads it as public-spirited: the chair of the Federal Trade Commission called the idea "moat digging," the practice of writing standards that happen to lock out competitors.

Why it matters: If this body forms, its standard becomes the de facto floor for every classroom AI tool in the country, written by the three companies that sell them. That is worth watching for one reason in particular: a private standard is set by the people who hold the pen, and no one in that room represents a school, a teacher, or a parent. Districts are not powerless here. The Microsoft agreement this week shows the alternative path, where a customer group with leverage puts terms in a contract. Whatever standard emerges, keep asking the four local questions at renewal: what data leaves our building, who can see it, what happens to it, and what do we do the day we want the tool turned off.

Source: CNBC

Research

Colleges Have Bought 700,000 AI Licenses. The Independent Evidence They Work Is Close to Zero.

Inside Higher Ed put a number against a vacuum this week. OpenAI has sold at least 700,000 licenses to dozens of higher education institutions, including the California State University system, which signed a $17 million contract in 2025, Arizona State University, and the University of Maine system. Against that, Justin Reich, a digital media professor and director of MIT's Teaching Systems Lab, offered a five-word assessment of the research on whether these tools improve learning: "The evidence base is almost nonexistent."

The researchers quoted around him complicate the picture in useful ways. Stacey Alicea of the Research Partnership for Professional Learning pointed out the scale problem: "if we're seeing over 1,000 tools on the market for students right now, there's no way we're going to run 1,000 studies on all of them" while education funding is cut and student data privacy is unresolved. Carly Robinson, who directs research at a Stanford learning initiative, was careful to keep both halves of the finding together: "There is increasing evidence that AI has the potential to benefit learning, but using it on its own without intentional design or guardrails probably reduces learning through cognitive offloading." The counterargument in the piece came from Dartmouth president Sian Leah Beilock, writing this month that universities that fail to graduate students who can use AI productively "will consign themselves to irrelevance."

Why it matters: This is a higher education story with a K-12 purchase order attached. The same vendors are selling into your district with the same slide deck, and "the evidence base is almost nonexistent" is now on the record from one of the more careful researchers in the field. That is not an argument for banning anything. It is an argument for buying differently. Ask a vendor for efficacy evidence from schools like yours, and notice whether what comes back measures learning or measures usage. Where no evidence exists, say so out loud and treat the purchase as a pilot with a question attached: what will we measure, by when, and what result would make us stop? Robinson's sentence is the design principle worth stealing, because the risk is not the tool, it is the tool without structure around it.

Source: Inside Higher Ed

Academic Integrity

Korea Set a Rule for AI Detectors: Reference Material, Not Proof

South Korea spent this week doing what American schools keep postponing: writing down what happens when a student is caught using AI on an exam, and how sure you have to be before you act. Seoul Economic Daily reported five documented cases of AI-assisted exam cheating across six of the country's top universities since last year. Sungkyunkwan University had three, in economics and business courses, and gave an F in the course in all three. Seoul National University had one, in a statistics experiment midterm, and voided the exam and held a retest. Yonsei University had one, and 40 students came forward afterward; those students received suspensions of two to three weeks. Korea University, Sogang, and Hanyang reported none.

The part worth copying is the standard underneath. In guidelines issued to universities on August 24, Korea's Education Ministry classified copying AI-generated answers in real time during an exam as serious misconduct, with an F among the possible penalties. In the same breath it told institutions that results from AI-detection programs should be used only as reference material, not as decisive evidence for discipline. Detection software exists there, and is spreading, and the ministry still would not let a score decide a case by itself.

Why it matters: That second sentence is the one to bring to your next leadership meeting, because the detector question lands on principals and department chairs with no policy behind it. A national education ministry has now said in writing what researchers have said for two years: a detector produces a signal, not a verdict. Write your local rule the same way. Say what counts as misconduct in plain language, say that a detection score alone never establishes it, and list what does: the draft history, the student conversation, the work the student can reproduce in front of you. Then tell students the rule before the assessment, not after. A clear standard you can defend protects the honest student and the accused one at the same time.

Source: Seoul Economic Daily

Detection

The Best AI Detector in the Business, and the Careful Way Its Biggest Customer Uses It

Bloomberg Businessweek published a feature this week, for subscribers, on Pangram, the detection company whose accuracy claims are the strongest in the category: better than 99.9 percent, with a stated false positive rate of one in ten thousand documents. The story opens in a Northeastern University classroom, where Joseph Reagle told his Communication in the Digital Age students that their writing would be run through it. Reagle had assigned the class to contribute to Wikipedia, with the work required to be substantively their own and not a chatbot's, and Wiki Education, the nonprofit supporting the assignment, used Pangram to review the submissions and found multiple apparent violations of Wikipedia's ban on AI-generated content.

The instructive part is how that nonprofit describes its own practice. In a public post this summer, Wiki Education's LiAnna Davis wrote that "we do not use Pangram as definitive proof that the text was AI generated. Instead, we use Pangram as a way to flag which text needs additional human scrutiny." Its guidance to instructors is to have a one-to-one conversation with the student as soon as possible, and it notes that non-prose text is a common factor in the confirmed false positives it has seen. The caution is earned. A Wall Street Journal editor called Pangram a "defamation machine" after three of his staff writers were flagged, and an accusation against one journalist was determined to be a false positive.

Why it matters: Even the most accurate detector on the market is used by its flagship customer as a reason to talk to a student, never as proof. One in ten thousand sounds like nothing until you multiply it by every essay your school collects in a year, and the student on the wrong end of that math is a real child with a transcript. If your district uses a detector, write the same standard Wiki Education uses into policy: a flag starts a conversation, a conversation considers process evidence like drafts and version history, and no grade or discipline rests on a score alone. Teachers deserve that clarity as much as students do, because the alternative is each of us inventing a threshold alone at 10 p.m.

Source: Wiki Education

Tools

Google Gave Students a Free Year of Its AI, and Renamed the Study Tool Teachers Just Learned

Google announced a round of study features on Monday for Gemini Notebook, which is the product teachers spent last year learning as NotebookLM; Google renamed it in July. Coming soon in the mobile app: real-time voice conversation with your own sources in nearly 100 languages, with answers grounded in the documents you uploaded rather than the open web, for users 18 and older. Starting the following week: an audio recorder for capturing lectures and spoken notes. Also new, interactive learning overviews that pull summaries together with studio outputs including infographics, quizzes, and flashcards, plus new quiz formats for short answer, multiple choice, and fill in the blank. The other half of the announcement is commercial: college students in the United States can get one year of Google AI Pro free, a plan Google values at $19.99 per month, redeemable through December 31, 2026.

Why it matters: Two practical notes and one worth flagging to families. First, the free year is for college students, so do not promise it to your high schoolers; the seniors in your building who are already enrolled somewhere may qualify, and your counselors will get the question. Second, the name change is a small thing that causes real confusion: if your professional development materials, acceptable use policy, or approved tools list say NotebookLM, update them to Gemini Notebook before someone argues that the tool they used was not the tool on the list. Third, the feature that deserves your attention is the recorder. A student recording a lecture is one thing when it is their own voice and their own notes, and another thing entirely when it captures classmates, a guest speaker, or an IEP meeting. Decide your recording norm before the feature arrives, not after a parent calls.

Source: Google

Classroom Research

Florida Middle Schoolers Are About to Teach the AI, and the Federal Government Is Paying to See If It Works

Most classroom AI asks the student to learn from the machine. A new project funded this month asks the opposite. MAGICAL-Math, short for Multimodal Artificial Generative Intelligence Championing Advanced Learning Sciences for Math Education, builds a teachable agent that middle schoolers instruct, watch, and correct while they work through math. The premise is one every teacher already knows from practice: you understand something differently once you have to explain it to someone else, and catching the learner's mistake is its own kind of proof.

The project is led by Wanli Xing, a professor in the School of Education and Human Development at the University of Miami and the Knight Foundation Chair in Artificial Intelligence at the Frost Institute for Data Science and Computing, with the U.S. Department of Education award held at the University of Florida and partners at the University of Utah and Carnegie Learning. It carries a $3.75 million federal grant, plus $375,000 from Carnegie Learning. The design work starts with 10 middle school math teachers, with about 100 more giving feedback on the online professional development, and the evidence comes from a three-year randomized controlled trial expected to involve 46 teachers and 3,450 students in public middle schools in Duval, Seminole, and Okaloosa counties, in buildings where more than half of students qualify for free or reduced-price meals. "MAGICAL-Math will not replace teachers," Xing said. "Teachers will lay the foundation, and we will be collaborators with them."

Why it matters: Two things make this worth watching even if your school is nowhere near those three counties. First, the learning move is one you can borrow on Monday without any technology at all: have students teach the concept back, to a partner, to the class, or to a chatbot they have been told to catch in an error. The thinking happens in the correcting. Second, this is a randomized controlled trial in ordinary public middle schools, which is exactly the kind of evidence the AI market has been selling without. When a vendor tells you their tool works, the fair question is what this project is being paid to answer: compared to what, measured how, and in schools like mine?

Source: University of Miami News

A word from iTeachAI Academy
Earn Recert Hours in Your Pajamas 🦝

Every state-aligned iTeachAI Academy course counts toward your recertification, was written by teachers over four years, and takes about as long as a movie night.

One course, $25. All-access, all year, just $149.

See what counts in your state →

Professional development that respects your weekend.

Here is what stayed with me from this week. The company selling the most widely used AI in the world published a list of the things its models did wrong, and in the same breath said the industry has not solved the supervision problem. That is an unusual kind of honesty, and it deserves an unusual kind of response from us: not panic, and not a ban, but a standard. Florida wrote one. The teachers' unions negotiated one. Wiki Education uses one every time a detector flags a student's paragraph. Each of those is the same move made by different people, which is to decide in advance what has to be true before a machine touches a child's learning or a child's record. We will not settle the global argument about how fast AI should go. We can settle what happens in our buildings, and we can write it down before the next tool arrives.

Until next time,

Dr. Janette Camacho

CEO, iTeachAI Academy

P.S. One task before Monday. Make the list. Ask every teacher in your building to name the AI tools they used with students in the last month, including the free ones nobody approved, and put the answers in one document. Florida districts now need that list by rule, with parent notice and an opt-in for each tool, by July 1, 2027. Everyone else needs it for a simpler reason: you cannot write a policy, answer a parent, or negotiate a contract about tools you have never counted. And if your own recertification hours are on this fall's list, our catalog is at classes.iteachai.co.

Free AI courses at classes.iteachai.co

17 free AI tools at iteachai.co/TeacherTools

Know a teacher who needs this? Forward this email.
Subscribe free at iteachaibot.com

Unsubscribe