Technology’s Effect on Advocacy
Government institutions have likewise recognized that these risks are no longer hypothetical. California provides a clear example. In J.M. v. Illuminate Education, Inc., the California Court of Appeal considered claims arising from an educational technology platform used by K–12 schools to collect and process extensive student information, including academic, behavioral, and medical data, to monitor student progress and develop intervention plans. Although the litigation concerned privacy and data- management practices rather than generative AI itself, it reflected judicial recognition of the growing legal challenges posed by data-intensive educational technologies. The California Supreme Court later narrowed the Court of Appeal's approach, holding that the plaintiff's claims failed not because the alleged privacy harms were insignificant, but because the applicable statutes did not extend to the defendant or to the plaintiff's relationship with the defendant. At the same time, the Court confirmed that exposing medical information to a significant risk of unauthorized access may itself constitute a breach of confidentiality, even absent proof that the information was actually viewed. Together, these decisions acknowledge the very real risks created by data-intensive educational technologies while underscoring a broader challenge: existing statutory frameworks do not always provide an effective remedy for the novel harms arising from AI and EdTech system. The evolving legal landscape is also reflected in California's legislative and educational policy initiatives with the legislature establishing a statewide AI in Education Workgroup pursuant to Senate Bill 1288, directing the development of statewide guidance addressing AI governance, student privacy, transparency, academic integrity, and the responsible
use of AI in public schools. (Cal. Dep't of Educ., Artificial Intelligence in California Education (2026); Cal. Dep't of Educ., State Superintendent Tony Thurmond Launches California AI in Education Workgroup (Apr. 16, 2025)). Federal regulators have likewise recognized the need for stronger safeguards. In 2025, the Federal Trade Commission strengthened the Children's Online Privacy Protection Rule (COPPA) by expanding protections for children's personal information, restricting certain third-party disclosures and monetization practices, and imposing stricter data-retention requirements. (Children's Online Privacy Protection Rule, 90 Fed. Reg. 16,840 (Apr. 22, 2025); FTC, FTC Finalizes Changes to Children's Privacy Rule Limiting Companies' Ability to Monetize Kids' Data (Jan. 16, 2025)). Yet one fundamental question remains. Does California law already provide meaningful tools to protect children before AI-related harms become irreversible?
California is not Unregulated
Through a series of legislative initiatives, California has sought to ensure that AI is implemented in a manner that protects students while promoting equitable access to technology. A central component of that framework is California Education Code section 33328.5, which establishes a statewide working group responsible for developing model policies governing the safe and responsible use of artificial intelligence in K–12 education. Those policies are specifically directed at issues such as academic integrity, acceptable and unacceptable uses of AI by students and educators, student data privacy and security, parental access to student information,
59
Consumer Attorneys of California
FORUM September/October 2026
Made with FlippingBook - Online catalogs