Media Center

Important guidance on the use of generative AI tools for school district business

July 6, 2026
Publications

The following guidance addresses a matter of increasing importance to school entities across Pennsylvania. Artificial intelligence tools such as ChatGPT, Microsoft Copilot, Google Gemini, and similar generative AI platforms have become increasingly common in both legal and business settings, and we understand the appeal of using them to quickly research issues, draft documents, or think through problems. However, we have become aware that a growing number of school district administrators are using unprotected, consumer-grade versions of these tools to address sensitive litigation matters, student issues, employment concerns, and other confidential district business. We strongly advise that school districts and their administrators exercise significant caution when using any generative AI products for matters involving confidential legal, employment, or student-related issues. The risks are real, and in many cases, they are not yet fully understood. This advisory explains the key concerns and the types of policies school districts should consider adopting.

Confidentiality and attorney-client privilege risks

When you communicate with your attorney about a legal matter, those communications are generally protected by attorney-client privilege, and documents prepared in anticipation of litigation may be protected under the work product doctrine. AI platforms do not offer these same protections. When you enter a prompt into an AI tool, whether you are summarizing facts, exploring legal theories, or drafting a response to a demand letter, that information is typically processed, logged, and stored by a third-party technology provider. In most cases, sharing confidential information with a third party outside the attorney-client relationship waives the privilege that would otherwise apply, and the same concern extends to work product. Several courts have already found that documents created by a party to litigation using an AI tool are not privileged and not protected by the work product doctrine. Significantly, at least one court has found that a client sharing AI outputs with counsel after the fact did not render them privileged retroactively. In other words, you cannot shield AI outputs you obtain simply by sending them to your lawyer.

Even if newer enterprise versions of tools like ChatGPT offer enhanced data protections, the legal landscape on whether AI-generated data remains privileged is unsettled, and the risk of an inadvertent waiver is real. When school district employees or administrators enter sensitive information into a generative AI platform, they risk the district’s legal position in ways that may be difficult or impossible to undo.

Discoverability in litigation

Opposing counsel in litigation has broad authority to request documents and information through the discovery process. If you have used an AI tool to analyze the facts of a case, draft correspondence, develop a litigation strategy, or prepare for a deposition or hearing, those prompts and outputs will likely be discoverable, even if the AI-generated documents are later shared with counsel. This means your adversary could demand that you produce any AI-generated content related to the dispute and could attempt to subpoena records from the AI provider.

In the school district context, this concern is particularly acute. In employment disputes, student discipline hearings, special education due process proceedings, and civil rights litigation, AI-generated content and the underlying prompts could reveal the reasoning process behind adverse employment actions, IEP determinations, or disciplinary measures in ways that are unfavorable or easily taken out of context. Discovery of your AI interactions could reveal your assessment of the strengths and weaknesses of the district’s position, factual admissions you may not have intended to make, or strategic considerations you would never want disclosed.

Pennsylvania Right-to-Know Law

Pennsylvania school districts are subject to the Right-to-Know Law (RTKL), 65 P.S. §§ 67.101–67.3104. Records created or maintained by a local agency are presumptively public. If an administrator uses an AI tool to draft correspondence, analyze a personnel matter, or research a student disciplinary or special education issue, the prompts entered and the outputs generated could arguably constitute “records” under the RTKL. This means they could be subject to disclosure upon request, potentially exposing sensitive deliberations, legal strategy, or protected student information. Districts should be aware that the use of AI tools may inadvertently create public records that would not otherwise exist.

Student privacy and FERPA

School districts have obligations under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, and Pennsylvania’s student records regulations. Inputting personally identifiable student information into a generative AI platform could constitute an unauthorized disclosure of education records, potentially exposing the district to federal funding risks and state-law liability. Even seemingly innocuous queries about a student’s situation, when combined with identifying details, may trigger FERPA obligations that consumer-grade AI platforms are not designed to satisfy.

Employee privacy concerns

Personnel matters, including investigations into misconduct, performance evaluations, and accommodation requests, involve sensitive employee data. Using AI tools to research or draft documents related to these matters creates risks under both federal and state privacy frameworks, as well as potential liability under collective bargaining agreements that may address the confidentiality of personnel records. Administrators should never input employee-specific information into any generative AI platform without express guidance from the district solicitor.

Recommended actions and policies

To safeguard the district’s interests, we recommend the following immediate steps. First, do not use any AI tool to analyze facts, draft documents, or develop a strategy concerning any matter that is currently in litigation or that you reasonably believe may lead to litigation. This includes using AI to summarize disputes, analyze potential claims, or prepare for a lawsuit or hearing. Second, do not input personally identifiable student information, protected health information, personnel records, or attorney-client privileged communications into any generative AI platform. Third, if you are uncertain whether a particular use of AI is appropriate, consult with your attorney before proceeding. Direct all substantive legal questions to your legal team rather than to an AI platform. AI tools cannot replace the judgment of counsel, and consulting them does not carry the same privilege risks.

In addition to these immediate steps, we strongly recommend that each school district adopt a comprehensive AI acceptable use policy applicable to all employees, administrators, board members, and contractors. Such a policy should clearly define which AI tools, if any, are approved for district use, specifying that only enterprise-grade versions with appropriate data protection agreements may be used for district business. The policy should also require that any use of AI tools for district business be documented and reported to a designated administrator or the district solicitor. We strongly suggest that districts implement a data classification framework that categorizes information by sensitivity level, such as public, internal, confidential, and legally privileged, so that confidential and privileged information is never entered into generative AI tools.

Because AI-generated content may be subject to the RTKL and litigation discovery obligations, districts should update their records retention schedules and legal hold procedures to account for AI-generated materials, including both prompts and outputs related to district decision-making.

Finally, districts should provide regular training to administrators, teachers, HR personnel, and board members on the risks of using AI tools for sensitive matters, with concrete examples of how AI use could compromise privilege, violate FERPA, or create discoverable records that undermine the district’s position in litigation.

Vendor agreements

If a district does choose to use AI tools, it should ensure that any vendor agreement includes robust data protection provisions, including prohibitions on the vendor’s use of district data for model training, clear data retention and deletion commitments, compliance with FERPA and applicable Pennsylvania privacy laws, and breach notification obligations.

Board oversight

The school board should formally adopt AI governance policies by board resolution, designate a responsible official (such as the superintendent or a chief technology officer) to oversee compliance, and require periodic reporting on AI usage across the district. The district solicitor should be involved in reviewing and updating these policies on at least an annual basis.

Conclusion

We recognize that AI tools offer genuine benefits in many contexts, and we do not discourage their use for routine business tasks unrelated to litigation or sensitive matters. However, the intersection of public records laws, student privacy obligations, employment law confidentiality, and the evolving law of attorney-client privilege in the AI context creates a landscape where even well-intentioned use of tools like ChatGPT can expose a district to significant legal risk. A proactive, policy-driven approach is the most prudent course of action.

If you have any questions about this guidance or would like to discuss how it applies to your particular circumstances, please do not hesitate to reach out. We are committed to helping you navigate these evolving issues and to protecting your interests at every stage. We are also available to assist your district in developing and implementing the policies and training programs described above.

This communication is intended as general guidance for school district administrators and does not constitute individualized legal advice. The applicability of the principles discussed herein may vary depending on your district’s specific circumstances. Please consult directly with your district solicitor or legal counsel before taking action based on this advisory.

RELATED PROFESSIONALS

Jeffrey T. Sultanik

Abigail Guenther

Related Practices

Education Law

Privacy & Data Security