Sep 30, 2026

Florida's AI Rule for Schools: What District Tech Teams Need in Place by July 1, 2027

Florida's amended Rule 6A-1.0957, item by item, for district and charter technology teams: parent opt-in, what "direct supervision" should mean, 30-day records, state reporting, vendor terms, and how other states compare.

Flint title card on a cream brushstroke background: Blog 2026, Florida's AI rule for schools: what tech teams need by July 2027.

On September 16, Florida's State Board of Education voted to amend Rule 6A-1.0957, the state's internet safety policy rule, so that it covers the AI tools students use. Every district school board and charter school governing board now has until July 1, 2027 to "adopt and implement" an amendment to its internet safety policy on AI. The amended rule lists 18 things those policies must do at a minimum, plus three kinds of AI no district or charter school may deploy.

Most of the 18 land on the technology office. Someone has to turn each parent's opt-in into access rules for that student, publish the list of approved tools, confirm that every tool keeps at least 30 days of student interactions, and pull usage numbers for the state.

Before Flint, I spent nearly four years in Tallahassee writing and teaching internet-safety lessons for K-5 students. This guide goes through the rule for the district technology teams who now have to put it into practice: what the text says, what it leaves open, what we think "direct supervision" should mean, what to ask vendors, and how other states compare.

I work at Flint, which makes an AI learning platform for schools. Flint appears in one short section near the end, which says where we meet the rule and where we don't. This isn't legal advice, so read the rule with your district's counsel.

How we put this together

  • The rule text comes from the proposed rule published in the Florida Administrative Register on August 26 and the Notice of Change published September 18, which records the amendments the board made on September 16. As of September 30, flrules.org hadn't posted an effective date. Item numbers below follow the amended text.
  • News coverage and vendor posts are named where we use them. Several widely shared summaries differ from the rule text, and we point out where.
  • Flint's section was checked against the product and our help center on September 30.

What does Florida's AI rule cover?

The rule applies to any "artificial intelligence instructional tool," which it defines as "a software application or service that uses generative or autonomous/agentic artificial intelligence, including machine learning, which is made available to a student by an educational entity for educational purposes, including instruction, tutoring, practice, feedback, or completing educator-directed assignments."

It excludes "AI systems that do not interact with students or are used for the purpose of analyzing, classifying, predicting, detecting, or optimizing decision making based on existing data." An AI tutor, an AI writing-feedback tool or a chatbot inside a practice app is covered. An early-warning model that flags students from attendance data isn't. Item 6 makes the policy apply "regardless of whether or not the AI instructional tool was adopted as an instructional material," so tools teachers bring in count as much as tools the district bought.

Two readings follow from that definition. Tools only teachers use, such as a lesson planner, aren't "made available to a student," so they need no parent opt-in. Three parts of the rule reach further than instructional tools, though: item 10 says AI is never used as a decision maker without human review "for any use case," item 18 covers any "district-approved AI tool," and the companion ban in (3)(f) covers "any form of artificial intelligence." An early-warning model that suggests counseling referrals is outside the opt-in, but it still needs a person to review its output.

The rule binds district school boards and charter school governing boards. For a charter, that means the governing board adopts the policy, even when a management company runs the school's technology. Florida College System institutions get a separate rule, 6A-14.0719, and the Miami Herald reported that private schools aren't affected. There's no new statute behind it: the Legislature's 2026 "Artificial Intelligence Bill of Rights," SB 482, died in March, and the board wrote the rule under existing education statutes. The rule has no penalty clause of its own.

Do AI features in Google, Microsoft and other tools count?

Yes, once students use them directly. The definition covers any software application or service that uses generative AI and is "made available to a student," and item 6 applies the policy whether or not the tool was adopted as instructional material. That pulls in AI features inside tools you approved years ago. Since August 10, Gemini in Google Classroom has been on for students of all ages wherever the district had already allowed Gemini. Our CEO Sohan Choudhury covered the Admin console settings that control it. Microsoft Copilot, Canva's AI tools, Grammarly and Quizlet all have student-facing AI features to check the same way.

For each one, the inventory needs the same answers as for a standalone AI tool: is the AI feature on for students, in which grades, and can you turn it on only for students whose parents opted in? In Google Workspace that usually means a separate organizational unit or group for opted-in students. New enrollees and transfers should start without access, and when a parent withdraws consent mid-year, the child's access should come off within a set time.

What does the rule require by July 1, 2027?

The requirements sit in section (3)(e) of the rule, numbered 1 to 18, and the ban on companion-style AI is section (3)(f). These are the items that create work for a technology team. The rest (items 4, 5, 6, 9 and 11) cover teachers' professional judgment, nondiscrimination, the instructional-materials point above, academic integrity, and staff training.

What district policy must doItemWhat it means for the tech office
Notify parents of each approved tool, and let them opt their child in before the student uses it directly, with a comparable non-AI alternative1Track consent per student and per tool, and keep students without consent off that tool
Give tools for VPK through grade 5 an extra review2A separate approval step for elementary tools
Allow agentic AI tools only under the direct supervision of an adult, with a complete activity log and a staff-controlled shutoff3Decide which tools count as agentic, and test the shutoff yourself
Make sure tools are accurate, transparent, viewpoint neutral and accessible to students and staff with disabilities7Accessibility documentation from each vendor, alongside the ADA Title II web accessibility deadlines
Make sure tools don't subject students to undisclosed behavior monitoring, social scoring or psychological profiling8Name any safety alerts, flagging or student profiles in the parent notice
Never let AI make decisions without human review for any use case, including grading, evaluations, promotions, discipline, threat assessment, counseling and ESE referrals, and communications10Check what each tool, instructional or not, decides on its own
Review tools' effectiveness, and require vendors to disclose known limitations and any independent studies12Add both to your vendor questionnaire and your renewal review
Publish a list of approved AI tools, along with the district's AI policies, that parents can find easily13A public page, kept current
Require tools to keep records of student interactions for at least 30 days14Confirm retention and parent access with every vendor
Report every AI tool to the Department of Education, with grades, subjects, frequency of use and duration of student interaction15Usage data by tool, grade and subject
Follow Florida's student online privacy law and the state's student records rule in reviews, notices and contracts16Run AI tools through your existing online-services approval process under s. 1006.1494 and Rule 6A-1.0955
Bar tools from selling, monetizing, profiling or commercially exploiting student data "to train commercial AI models," and prioritize vendors that keep student data in the U.S.17Contract language and data location questions
Tell the Department if an approved tool behaves autonomously in unexpected ways or causes a security incident, including unauthorized data access18An incident reporting path to the state
Never deploy AI designed to meet students' social or emotional needs, simulate friendship, or use relationship-building or anthropomorphic design to keep students engaged(f)Product review before approval

How do you run parent opt-in for every AI tool?

This is the biggest lift. The rule requires a notice in "plain, non-technical language" naming the tool, the grades and subjects where it will be used, the nature of the student interaction, "including whether the tool provides automated feedback or instructional responses," and how to object to content. Then, "if the student will be directly using the tool," parents get "the option for parents to opt their child into using the tool along with information on an alternative, non-artificial intelligence instructional tool that is substantively comparable in instructional quality and access."

Commissioner Henry Mack settled any doubt about the default. "The provision is opt-in, it's not opt-out," he told WINK News. That flips how many districts work today. An Orange County Public Schools spokesperson told WFTV that parents who don't want their child in a particular lesson can ask the teacher, which is an opt-out model.

The Software and Information Industry Association, which represents edtech companies, warned in its July comments on the draft that teachers would need to "track, on a per-tool and per-student basis, which students may use which tools." The opt-in survived into the final text, so that tracking needs a home. What we'd plan for:

  • One system of record for consent, per tool, such as a field in your SIS. Paper forms in a teacher's desk won't hold up once a parent asks.
  • Access driven by your roster, so a student without consent never gets an account. Watch for tools that let any student with a school Google or Microsoft account sign in, or that let anyone with your email domain join a school. Those are the gaps where a student without consent ends up in the tool.
  • A notice template that covers all five required elements for each tool, the last being the opt-in and the non-AI alternative. Our post on how schools are talking to parents about AI has examples of the wording districts use.
  • The non-AI alternative planned before the tool goes live, with a named owner. That part belongs to curriculum as much as IT.

One record per tool can feed the parent notice, the public list and the state report, so the three never drift apart:

FieldFeeds
Tool name, and the AI features students use directlyNotice (1a), public list (13), state report (15)
Grades and subjectsNotice (1b), public list, state report
What students do with it, including automated feedback and any safety alerts or flaggingNotice (1c), item 8 disclosure
Opt-in required (yes if students use it directly), and where consent is recordedNotice (1e), access rules
Non-AI alternative and its ownerNotice (1e)
Agentic or not, and whyItem 3
Data agreement, retention period and approval dateItems 14, 16 and 17
Frequency of use and duration of student interactionState report (15)

What does "direct supervision" mean in Florida's rule?

The board added the supervision requirement on the day of the vote. Item 3 says: "Ensure an AI instructional tool deploying autonomous/agentic AI shall only be permitted to be used in grades Voluntary Prekindergarten through grade 12 if under the direct supervision of an adult, maintains a complete log of activities, and include a mechanism that allows school personnel to immediately suspend or disable the tool's autonomous functionality without vendor assistance."

It covers only tools "deploying autonomous/agentic AI." The rule defines that as "a machine-based system that operates through a continuous cognitive loop, such as would allow it to be proactive, set goals, make multi-step decisions, execute actions and gather, log or generate data sets with minimal or no human oversight." That isn't how it was widely reported. The News Service of Florida story that WFSU and CBS Miami ran said "students will also not be able to use AI unsupervised," with no mention of the agentic limit. The Palm Coast Observer then wrote that Flagler Schools' Khanmigo tutoring "could be banned under the rule disallowing unsupervised AI use." In the same article, Flagler's instructional technology coordinator, Teresa Phillips, called Khanmigo "a fantastic program."

The rule also never defines "supervision" or "direct supervision," and as of September 30 the Department of Education hadn't published guidance. Mack said the department will set up work groups with superintendents, WINK reported.

Which tools count as agentic is also open. A chatbot that answers when a student types sits at one end. An agent that browses, fills in forms or submits work on its own sits at the other. Many AI tutors fall in between, running a web search or a calculation inside a single reply. Until the department says more, ask each vendor in writing whether its product chains several steps or tool calls without a person approving each one, or acts when the student isn't in the session. That tracks the rule's "continuous cognitive loop" more closely than asking whether a tool uses AI.

Our view: "direct supervision" can be read two ways, and districts should decide which they mean before the Department does. One is presence: an adult is in the room while the student uses the tool. The other is visibility: an adult can see what the tool and the student are doing. For agentic tools we'd require both. Presence alone can mean an adult in the room who can't see the screen, and a log only IT can pull after the fact doesn't let anyone step in.

Visibility, in our view, means four things:

  1. A named adult is responsible for each student's use: the teacher who assigned it, or a designated staff member for open-ended use.
  2. That adult can read the full conversation while it happens and afterward. A usage count isn't enough.
  3. That adult can stop it immediately, for one student or a whole class, without calling the vendor or IT.
  4. When the adult isn't watching the screen, a concerning message reaches a person quickly, for example through an email alert. Under item 8, that kind of monitoring has to be disclosed in the parent notice.

Whether to hold non-agentic tools to the same standard is a policy choice, and it has a cost. Several widely used tools, including general-purpose assistants students use for homework, can't meet all four points, and Flint doesn't fully meet point 3 today (details below). Parents and board members will expect something close to it anyway. Governor DeSantis set that expectation in a news release after the vote, quoted by the Florida Phoenix: "We will not accept tools that hide from parents, harvest student data, grade kids in secret, or pretend to be a friend."

What records and reports does the rule require?

Item 14 requires AI tools "to maintain records of student interactions for a minimum of thirty (30) days to allow parental access to education records," citing FERPA and Florida's education records statute. Thirty days is a floor. How long records are kept beyond that is set by your district's records retention schedule, not the vendor's default. The same item lets districts review those interactions "to monitor for instructional accuracy, alignment to state standards," and developmental appropriateness. Before you approve a tool, find out how long it keeps conversations by default, who in your district can read them, and how quickly you can hand one student's full history to a parent.

Item 15 requires a report to the Department of every AI tool in use, including "the name of each AI instructional tool, applicable grade levels and subject areas, frequency of use, and duration of student interaction." Districts "are not required to report per-student or per-teacher information." The rule doesn't set a deadline, a frequency or a format, and we found no reporting template from the Department yet. Some summaries go further than the text: Lightspeed Systems' September 25 post says districts must be ready to "report on which tools are used, by whom, how often, and for how long."

Frequency and duration by grade and subject is data many AI tools don't break out today. Ask each vendor for a sample export now, while there's time to fill the gaps.

Item 18 adds an incident duty: districts must tell the Department if an approved tool "exhibits any unexpected autonomous behavior or any IT safety or security incident caused by the approved tool, including unauthorized data access." It gives no timeline, so fold it into your existing incident response plan and your vendors' breach notification terms.

What should Florida AI vendor contracts say?

The data training clause is narrower than the headlines. Item 17 bars tools from selling, monetizing, profiling or commercially exploiting "student data to train commercial AI models." A contract that simply bans any model training on student data, binding the vendor and every company it sends data to, is cleaner than arguing later about what "commercial" means. The same item says districts "must prioritize vendors that maintain student data storage and processing within the United States," so a vendor that processes data abroad can still be approved, with that weighed against it. Item 16 ties everything to Florida's student online privacy law, s. 1006.1494, which already bars targeted advertising and building student profiles outside school purposes.

Under item 12, approval processes "must require vendors to disclose known instructional limitations and any available independent evaluations or studies regarding the effectiveness of the tool," though "the absence of such evaluations or studies may not, by itself, preclude approval." Districts also have to review each tool's effectiveness "to determine whether continued use supports student learning and achievement."

The companion ban in (3)(f) covers "any form of artificial intelligence" designed, marketed or configured to "meet a student's social or emotional needs, including Social Emotional Learning," to "simulate friendship, companionship, or an emotional relationship with a student," or to use "relationship-building or anthropomorphic design features for the purpose of encouraging a student to continue interacting." Ask vendors what the AI calls itself, what it's instructed to say when a student treats it as a friend, and who finds out. Our comparison of the safest AI platforms for K-12 schools lays out how the major tools handle moderation and alerts.

Which other states have similar AI rules for schools?

Florida is the only state we found that requires parents to opt in. Several others passed laws this year that overlap with parts of its rule:

StateLawClosest to Florida's rule
OklahomaSB 1734, signed May 12, 2026Parents can opt students out of student-facing AI "at any time" without academic penalty. Districts disclose their AI tools, vendors and data at least once a year, and educators review AI outputs before use. Policies are due before the 2027-28 school year.
UtahHB 273, signed March 18, 2026The state's model AI policy, which districts base theirs on, limits educators to student-facing AI tools the district approves, requires written notice to parents when AI is used for instruction, and bars using AI to grade student work on its own.
VirginiaHB 1186 and SB 394, signed April 13, 2026State guidance, which school boards must follow, requires data agreements that bar training external AI models on student data, and gives teachers transcripts, dashboards, alerts and audit logs.
North Carolina2026 budget act, section 7.39 (staff summary)The state publishes lists of reviewed AI tools and tools in use, and every district adopts an AI policy by June 30, 2027.
CaliforniaAB 1159, signed September 10, 2026Operators of K-12 sites and apps can't use student information to train generative AI systems, with some exceptions.
Ohio and TennesseeOhio Revised Code 3301.24; Tennessee Public Chapter 550 (2024)Every district adopts an AI policy. Tennessee boards also report compliance to the state each year.

Our AI policy library keeps a running table of which states require districts to adopt an AI policy, with example policies from schools.

Questions for every AI vendor under Rule 6A-1.0957

Copy these into your vendor questionnaire. Each maps to an item in the amended rule.

Florida AI rule: vendor questions

Consent and access (items 1 and 2)

  • Can we keep specific students off your tool, per student, using our roster? Can a student get in any other way, such as signing in with a school Google account or joining by email domain?
  • For our parent notice, can you describe in plain language whether your tool gives automated feedback or instructional responses?
  • What additional safeguards apply in VPK through grade 5?

Supervision and shutoff (item 3)

  • Does your product ever take actions a student didn't ask for, such as browsing, submitting work or messaging others? If so, show us the complete activity log.
  • Can a teacher read each student's conversation live and afterward?
  • Can our staff turn the tool off, for one student, a class, a grade or everyone, without contacting you? How fast does it take effect?

Decisions and evidence (items 10 and 12)

  • What does your tool decide without a teacher's approval, if anything?
  • What are its known instructional limitations, in writing?
  • What independent evaluations of its effectiveness exist?

Records and reporting (items 14, 15 and 18)

  • How long do you keep student conversations by default? Can we keep them at least 30 days?
  • How fast can you give us one student's complete conversation history for a parent request?
  • Can you export usage by grade, subject, frequency and duration of student interaction?
  • How and how fast will you tell us about a security incident or unexpected autonomous behavior?

Data and design (items 16 and 17, and (3)(f))

  • Do you or any company you send student data to use it to train AI models, commercial or otherwise?
  • Where is student data stored and processed? Is it all in the U.S.?
  • What does the AI call itself, and what is it instructed to do when a student treats it as a friend or asks for emotional support?

How does Flint handle these requirements?

Flint is an AI learning platform where teachers build activities that students work through with Sparky, Flint's AI tutor, and where students can also chat with Sparky on their own. Here is where it stands against the rule today, including where it falls short. The screenshots come from a demo class on our staging site.

Supervision (item 3)

We don't read Sparky as agentic AI under the rule. It answers when a student sends a message and doesn't act between messages, though within a single reply it can run a web search or a calculation. The Department hasn't said where that line falls, so here is how Flint does against the visibility standard above. Teachers see students' sessions live, get "Needs attention" alerts when Sparky thinks a student needs help, and can pause an activity. School administrators can read every student chat, including chats students start on their own. There's no single switch that turns off all student AI at once yet.

Annotated screenshot of a teacher's activity page in Flint: 1, the "Needs attention" panel where Sparky flags students who need help during the activity; 2, the live list of every student's session, each of which the teacher can open; 3, when each session started and was submitted, how long it lasted, and a Download as CSV button.

Records for parents (item 14)

Student chats are kept until the school asks for them to be removed, and teachers can print a session transcript for a parent. There's no bulk transcript export yet.

Annotated screenshot of a saved student session in Flint: 1, the session header, since sessions stay in Flint until the school asks for removal and a teacher can print one for a parent; 2, the student's own message asking Sparky to write her thesis; 3, Sparky's reply, which declines and asks her to explain her reasoning.

Academic integrity (item 9)

For each student message, a teacher can open its paste history and see whether the student pasted text in or typed it.

Annotated screenshot of a student message in Flint: 1, the student's final thesis, time-stamped; 2, the Paste History panel, which reads "The student has not pasted anything when writing this message."

The other requirements

  • Consent and access (item 1): Flint doesn't track parent consent. Schools decide who is rostered, and school administrators can remove a student's access themselves. For Florida, use roster or invite-only access rather than letting anyone with your email domain join, so students without consent can't add themselves.
  • VPK through grade 5 (item 2): administrators can set how Sparky talks to each grade level. Flint can also turn off open-ended chat for specific grades while teacher-assigned activities keep working, but today Flint's team switches that on for you.
  • Companion design ((3)(f)): Sparky's instructions describe it as "a teaching assistant, NOT a friend, counselor, or therapist" and tell it not to suggest ongoing relationships like "I'm always here for you." Messages that treat Sparky as a friend or confidant are flagged and emailed to the staff your school chooses. Sparky does have a name and a mascot, speaks in the first person, has optional voices, and can save memories of a student's interests and preferences to personalize help. Review those against the anthropomorphic design clause and item 8 yourself.
  • Reporting (item 15): school analytics show usage by day and by person, with a CSV download on every chart, and each activity lists how long every session lasted. Usage isn't broken out by grade or subject yet, so the state report will take some spreadsheet work.
  • Data (item 17): Flint doesn't use student data to train AI models. Student conversations are processed by Anthropic and OpenAI under their business terms, which don't train on that data by default. Some features, such as web search, file conversion and running code, use other providers. Ask us for the full list for U.S. schools.

What should happen when?

The rule says "adopt and implement" by July 1, 2027, so notices, opt-ins, the public list and the non-AI alternatives have to be working by then, not only written. Working backward from a board's notice-and-hearing calendar:

  • Fall 2026: inventory every AI tool and AI feature students touch, by grade and subject, with the contract that governs it.
  • Winter: send vendors the questions above, make the agentic call for each tool, and build the consent field and access rules.
  • Spring 2027: board adoption, the public list live, and consent collection built into registration for 2027-28.
  • July 1, 2027: policies adopted and implemented.
  • By September 1, 2027: the existing rule already requires boards to adopt their internet safety policy each year by September 1, so the AI amendment joins that annual cycle from then on.

Mack also directed the Department to update the Florida Digital Classrooms Plan, which will ask districts to show how evidence of effectiveness drives purchasing and renewal. We'll update this page when the Department defines supervision or publishes a reporting template.