A lesson plan can take minutes to generate with AI. But the rules can change when you work for a school instead of a family.
Before you paste student needs, upload an assignment, or send materials home, know who hired you. Also know which agreements apply.
Yes, AI-generated lesson plans can be legal and safe for K–12 tutors. Review every output and keep identifiable student data out of unapproved tools.
Your role matters. Independent tutors, school employees, and district contractors face different privacy, approval, and data-contract rules.
Use the checks below to protect privacy, copyright, and lesson quality.
Who can safely use AI lesson plans?
Your work arrangement sets the first rule.
An independent tutor hired directly by a parent often has more room to use AI for planning. This differs from the situation of a teacher employed by a public school.
More freedom does not mean no limits. You need parent trust, clear privacy limits, accurate materials, and suitable tool terms.
Tutors hired directly by families
A family can usually approve AI as a planning assistant. This works best when you use anonymous information.
Think of AI like a cookbook for a general dinner idea. Do not hand it your family’s medical chart.
Ask for “a fourth-grade student who needs practice with multi-step word problems.” Do not name Maya Rodriguez or share her district test score.
Put the boundary in writing. A short client agreement can explain how you use AI drafts.
State that you enter no identifiable student data into unapproved systems. State that you review each final lesson before sharing it.
A parent’s permission does not allow school-owned files to be uploaded. District assessments and special education records may still belong to the school.
School employees and contractors
A school employee must follow district AI policy, technology rules, and approved vendor lists. These rules apply even when planning happens at home.
A district contractor may face the same limits through the service contract. This can apply even when using a personal laptop.
This is the point many tutors miss.
The most common mistake is treating family tutoring and district-funded tutoring as the same legal setting. They are not.
For example, a tutor serving a Brooklyn family may draft a reading game with a generic prompt. No student records are involved.
That tutor may later join a New York City school program. If they receive student records, district policy and New York Education Law § 2-d can change the rules.
Legal access is not permission
A chatbot being online does not mean it is approved for student work. Owning a car does not let you drive in a school bus lane.
The Family Educational Rights and Privacy Act, or FERPA, generally covers funded schools and educational agencies. It applies to schools receiving U.S. Department of Education funding.
A solo tutor is not automatically a FERPA-covered school official. Still, a school contract, confidentiality clause, state law, or parent agreement may bind that tutor.
Use this role test before opening an AI tool: Who hired you? Who owns the account? Are you using school records or district devices? Has the school or family approved this tool? If one answer is unclear, keep the prompt generic until you get a written answer.
Knowing your role is the first filter. The next filter covers details that should never enter a prompt.
Keep student data out of AI prompts
Do not paste student records into public AI tools.
Personally identifiable information, often called PII, can identify a student alone or in combination with other details. A name is an obvious example.
A grade portal screenshot can also identify a student. So can a distinct essay, home address, or recording of a child’s voice.
Data that stays outside the chatbot
Do not paste, upload, or describe these items in a consumer AI account. This rule changes only when your organization approves the tool and data path.
- A student’s full name, email, phone number, address, or student ID.
- Grades, test reports, attendance history, discipline notes, or school portal screenshots.
- An individualized education program (IEP), 504 plan, diagnosis, therapy note, or disability-related accommodation.
- Audio or video recordings, parent emails, and photos containing the student or school documents.
- A rare personal story that makes the child easy to identify in a small school community.
Removing a name is not always enough. A detailed story can still reveal a student’s identity.
For example, “a 12-year-old at Lincoln Middle School whose father was deported last month” may identify one child. People in that community may know who it is.
Tutors often underestimate screenshots and copied parent messages because they can feel like working notes.
But these items can include grades, names, account numbers, and confidential details.
FERPA and COPPA are different
FERPA focuses on education records held by covered schools and agencies. COPPA covers some online collection of children’s personal information.
COPPA means the Children’s Online Privacy Protection Act. It covers certain data collection from children under 13.
COPPA can matter when a child creates an account or enters information. It can also matter when a service collects personal data.
Do not assume broad parent approval covers every platform. Check age rules, account ownership, and consent requirements.
The Federal Trade Commission enforces COPPA. The U.S. Department of Education gives student privacy guidance.
Their public materials offer useful starting points. See the U.S. Department of Education Student Privacy Center.
Neither agency gives blanket approval to a tutoring app.
An IEP is a required learning plan for an eligible student. It falls under the Individuals with Disabilities Education Act.
A 504 plan can give accommodations under Section 504 of the Rehabilitation Act. Both documents can include highly sensitive details.
You can request a general teaching format without sharing the plan. This keeps sensitive records outside the tool.
For example, ask for “a short reading-comprehension activity with one instruction at a time.” You can also request large-print-friendly formatting and optional oral responses.
That prompt tells the tool what materials should do. It does not reveal why one child needs them.
There is an exception worth taking seriously. If your task requires an actual IEP, 504 plan, or school record, do not summarize it into a consumer chatbot.
Ask the school or family which approved process applies.
Price is a poor safety signal.
A free generator, paid ChatGPT plan, Canva AI, MagicSchool, Gemini, and district platform can follow different rules. Those rules can cover retention, access, and model training.
Paying $20 to $30 each month may remove ads or add features. It does not automatically create a FERPA-compliant data agreement.
Compare the account, not the logo
| Tool setup | Typical cost | Student-data risk | Best use | Approval needed |
|---|
| Free public chatbot | $0 | High with PII or uploads | Generic activity ideas | Family approval, plus school approval for school work |
| Paid individual AI account | About $20 to $30 monthly | Still needs privacy review | Drafts with no student records | Same approval test as above |
| Education-focused AI product | Often free tier to school pricing | Depends on contract and settings | Teacher-facing lesson drafts | Check vendor agreement and district policy |
| District-procured platform | Set by district contract | Lower only within approved use | Authorized school-system work | District authorization required |
Ask five questions first
Before choosing a provider, ask five questions. These questions matter more than the logo.
Who owns the account? Can the provider retain prompts?
Can prompts or files help train models? What is the minimum user age?
Does a written school or vendor agreement cover this use?
A free account can work for prompts with no student data. School-approved paid tools may be needed when work involves protected records.
The right answer changes with the data. It does not depend only on the brand.
California tutors should check whether a service triggers concerns under SOPIPA. New York tutors should check district processes under Education Law § 2-d.
State rules can add layers above federal law. Local speed limits can be lower than highway limits.
A 60-second AI lesson-plan safety path
1. Identify role
Family tutor, school employee, or contractor?
2. Remove data
No names, records, uploads, or unique stories.
3. Check approval
Read policy, contract, and account terms.
4. Review output
Check facts, age fit, sources, and rights.
Tool choice is only half the decision. A safe account can still become unsafe through a careless prompt.
Use a simple decision matrix before choosing a lesson plan generator. For children under 13, avoid student-created accounts until you check terms and parent consent.
For independent tutoring without student PII, a personal account may suit generic drafts. Review the AI privacy policy first.
If you need school records or district-owned files, use only school-approved AI tools. Check ownership, retention, training settings, controls, age rules, and workflow approval.
Create safe prompts and review records
Treat AI output as a rough draft.
Generative AI predicts likely text from patterns. It does not know your student personally.
It can invent sources, standards, or facts. This is an AI hallucination, a confident but false answer.
Use anonymous prompt templates
Use details about the learning task, not the learner’s identity. These templates work for most private tutoring preparation.
Create a 35-minute sixth-grade lesson on comparing fractions. Use plain language, two worked examples, a five-question exit check, and no references to real students.
Draft three reading activities for a fourth-grade learner who benefits from short directions, frequent checks for understanding, and a choice between writing or speaking an answer.
The second prompt requests a teaching format. It does not request a diagnosis.
That distinction matters because it keeps sensitive records outside the tool.
Keep a human review log
A review log shows that a person checked the AI draft before use. It is not a legal shield.
It helps you work consistently. It also helps explain your process to families.
- Date and tool: Record the platform and account type used.
- Prompt check: Confirm no PII, school record, upload, or identifying story was included.
- Accuracy check: Verify facts, answer keys, links, citations, and math steps.
- Teaching check: Confirm grade level, reading load, standards, timing, and age fit.
- Rights check: Review text, images, quotations, and worksheets for license concerns.
- Final approval: Save the edited version and note what changed.
The most common error is accepting a polished answer key without solving the problems yourself. A wrong fraction answer can damage parent trust quickly.
Check quality before each session
Check factual claims against a reliable source. Check state standards on the official state education site.
Do not trust an AI-generated citation alone. Test links and read every question aloud.
Make sure examples and images avoid stereotypes and age-inappropriate material.
For accessibility, check font size, contrast, plain-language directions, captions, and non-typing response options. Each can affect whether a student can join the activity.
The ADA, IDEA, and Section 504 do not make every AI suggestion suitable. A specific child may need a different accommodation.
If you paste sensitive data by mistake, stop using that thread. Keep only records needed for incident reporting.
Check the provider’s deletion options. Tell the family, school contact, or district contact when required.
Do not quietly erase the mistake when reporting rules apply.
Check copyright before sharing materials
Generation does not erase copyright.
The Copyright Act of 1976 protects original expression. This includes many worksheets, passages, illustrations, songs, and test-prep materials.
AI can make text that resembles protected work. It can also invent citations or copy a recognizable style too closely.
Fair use is not automatic
Fair use can allow limited use in some cases. It does not make every educational handout safe.
Private tutoring may carry less risk than selling materials online. Still, purpose, amount, work type, and market effect all matter.
Do not ask AI to recreate a current workbook page. Do not request a novel chapter or paid test-prep questions.
Build an original activity around the skill instead.
Check images and citations
Verify each quotation, image source, link, and attribution before sharing materials. AI citations can name a real author but invent an article.
That is like a GPS route that looks right, then sends you into a lake.
Use public-domain sources, licensed materials, or your own examples when possible. Follow Creative Commons terms when you use that content.
Those terms may require attribution. They may also limit commercial use.
The Digital Millennium Copyright Act, or DMCA, can matter when you upload or post claimed content. A private worksheet is not always free from copyright concerns.
Risk rises when you reuse it across dozens of paid clients.
Academic integrity needs a boundary
AI can help make practice questions, explanations, and lesson structures. It should not secretly complete graded student work.
Do not use it to finish a student’s essay, science report, or take-home assessment. That crosses an academic integrity line.
Tell families how AI fits into your service. Clear language avoids false expectations.
You might say, “AI may assist with tutor-created practice materials.” Add that you review all materials and never submit student work.
Copyright concerns what you share. Authorization concerns whether you could create it through that tool.
Get the right approval for your role
Approval should match the data source.
For direct-to-family tutoring, a written agreement can cover your tools and data limits. It can also state who gets materials and how long you keep notes.
It does not need 20 pages. A clear one-page policy often works better because families can read it.
A simple family disclosure
Use plain language, such as: “I may use AI tools to draft general practice activities.” State your privacy boundary in the same notice.
“I do not enter your child’s name, school records, grades, IEP or 504 information, address, recordings, or identifying information into public AI tools.”
“I personally review and adapt each final activity.”
That statement is honest only when you follow it. Do not promise that a provider never retains data without checking settings and contracts.
District work needs written clearance
If a school or district hires you, ask for its AI policy first. Do this before using AI for student-related work.
Ask if a district platform is required. Ask whether uploads are allowed.
Also ask if the contract treats you as a school official.
A paid individual account cannot replace a district data-processing agreement. It is like buying a strong padlock for an unauthorized door.
The International Society for Technology in Education and Common Sense Education support educator judgment. Their guidance stresses privacy, safety, and human review.
Your employer’s policy and contract still control your work.
Tutoring marketplaces may also restrict how you communicate with families and store session notes.
Further reading
If you want to learn more about this topic, these sources may interest you: