States ask “is it safe?” Districts mostly don’t.

Two 2025–26 reports, read side by side, describe the same edtech market from opposite ends. The gap between them is where most student data actually lives.

Two reports landed in my inbox this year that, read separately, are unremarkable. Read side by side, they describe a problem nobody in K–12 edtech is being straight about.

The first is SETDA’s 2025 State EdTech Trends Report, which surveys state education agencies. Among states that have issued procurement guidance for AI-enabled edtech, 95% lead with the “Safe” indicator: data privacy, security, student protection. It outranks Interoperable (59%) and Evidence-based (45%). If you only read state guidance, you would conclude that K–12 has decided privacy is the first question you ask about a tool.

The second is CoSN’s U.S. State of EdTech 2026, which surveys the district technology leaders who actually buy the software. There, only 55% of districts require safety information from vendors, and 54% of district CTOs report no familiarity with the quality-indicator framework that state guidance is built on.

So: states advise, districts implement, and the two have not met.

Why the gap exists, and why it isn’t anyone’s fault

The obvious reading is that districts are being careless. I don’t think that’s right, and the same CoSN report explains why: 58% of districts report being understaffed for instructional technology support, and 65% for cybersecurity. Meanwhile the money that paid for a lot of this capacity is gone. The share of districts sustaining ESSER-funded edtech has fallen from 27% to 6%.

You cannot run a rigorous vendor privacy review with a team that is already underwater keeping Chromebooks alive. State guidance assumes a district capability that state funding did not build. The gap isn’t negligence. It’s arithmetic.

What makes this urgent rather than merely unfortunate is that adoption did not wait. 79% of districts now have AI guidelines in place, up from 57% a year earlier, but only 34% have AI data-privacy policies specifically. Districts have written rules about what teachers may do with AI far faster than they have written rules about what vendors may do with student data. Those are very different documents, and the second one is the one that matters when something goes wrong.

The part that should worry vendors

Here is the statistic I keep coming back to, from the same CoSN survey: 86% of districts vet a tool before it reaches a classroom, and 61% maintain approved-app lists.

Read that alongside the 55% figure and you get something genuinely strange. Most districts do gate tools. Fewer than half of those gates check the thing state guidance says to check first. The review is happening. It is just not asking about safety, because the person running it was never handed the framework and does not have time to build one.

If you build software for schools, that has an uncomfortable implication. You are going to be evaluated. The evaluation will probably not be rigorous. And you will be tempted to treat that as good news.

It isn’t. A vetting process that waves you through is not a vetting process that protects you when a breach happens, and the sector has already watched what that looks like. It is also, I’d argue, the single clearest opportunity in K–12 edtech right now. The bar for demonstrating safety is being set by state guidance that districts can’t yet enforce, which means a vendor who meets it voluntarily is meeting a standard the market will eventually demand and currently rewards nobody for.

What we’re doing about it

We drafted our NY Education Law §2-d pack (data inventory, data privacy agreement, Parents’ Bill of Rights supplement, security plan) before Lerad had a single user, and it is with education-privacy counsel now. It is a draft until they say otherwise, and I’ll keep calling it a draft until then.

The reason isn’t virtue. It’s that a school shouldn’t have to run a rigorous privacy review to find out whether we did our homework, because the report above says most of them can’t. The work should be legible from the outside. If you’re evaluating us, ask for the pack. If you’re evaluating anyone else, ask them for theirs, and notice how they react to being asked.


Sources: SETDA, 2025 State EdTech Trends Report; CoSN, U.S. State of EdTech 2026.

WorldTree is building Lerad, a teacher dashboard that unifies student data across platforms, engineered to NY Ed Law §2-d standards from the first line of code.

Join the pilot →