Show summary Hide summary
California lawmakers are moving to close a privacy gap that leaves college students vulnerable to data scraping and AI training from campus technology. AB 1159 would extend protections already applied in K–12 schools to higher education, barring many uses of student data and giving students new legal tools to fight misuse.
What the bill proposes
Authored by Assemblymember Dawn Addis, AB 1159 would create the Higher Education Student Information Protection Act, a framework that places limits on how campus platforms and third-party vendors can collect, share or monetize student information. The measure specifically targets practices that feed student-generated material into machine-learning systems.
Meridian BID could reshape Oklahoma City corridor: plan promises safer streets and more businesses
High school football week zero: standout players and key takeaways
Under the draft legislation, companies supplying educational software would be prohibited from using identifiable or sensitive student data to train or refine artificial intelligence models without clear consent. The bill also adds enforcement mechanisms for individuals who suffer harm when those rules are broken.
- Ban on AI training uses: EdTech providers could not repurpose students’ coursework or personal details as training data.
- Legal recourse: The bill creates a private right of action, allowing affected students to sue vendors for violations.
- Class-action window: The text includes a limited period for coordinating class claims after a breach is discovered.
- Implementation timeline: Sponsors plan to phase the protections into higher education beginning in mid-2027.
For students, the stakes are practical: work submitted for classes could otherwise be harvested to improve commercial AI tools, or sold to third parties, altering both privacy and future opportunities.
Voices on campus
Some undergraduates report feeling blindsided after learning their assignments or written work were used to train software without notice. One freshman said she felt uneasy that her ideas might be repurposed by private companies — not only because of privacy, but because it felt like losing control over her own intellectual work.

Addis frames the bill as protecting both privacy and students’ futures, arguing that learners should not be treated as raw material for Big Tech. She has emphasized the need for clear boundaries between educational tools and commercial exploitation.
Incidents that alarm advocates include reported data-handling failures by major vendors. Investigations and reporting in recent years have shown some third-party education companies transferring records or allowing access to detailed personal information — from contact details to demographic data — raising concerns about unregulated sharing and sale of student profiles.
Where this fits in California policy
AB 1159 builds on existing K–12 protections, notably the Pupil Online Personal Information Protection Act, which limits how student data is collected and used in schools and forbids targeted advertising to minors. The new measure applies those principles upward into colleges and universities.
Separately, lawmakers have introduced complementary legislation. SB 1101 would require companies to notify individuals, and in some cases federal authorities, before transferring student data to outside entities — a move aimed at increasing transparency and oversight.
As of this month, AB 1159 cleared the Assembly earlier this year and is under consideration in the Senate, while SB 1101 is still moving through committee review.
Practical implications
If enacted, the bill would change vendor contracts, procurement processes and campus privacy policies. Universities would need to vet software more carefully and update data-use agreements to prohibit unauthorized training of AI models.
EdTech companies could face higher compliance costs and litigation risk, and students would gain a clearer path to hold vendors accountable. For researchers and product teams that rely on real-world educational data, access could be restricted or require explicit agreements and consent protocols.
Whatever the outcome, the debate signals a growing demand for stronger limits on how personal data collected in learning environments can be used — particularly as AI systems increasingly rely on large, diverse datasets drawn from everyday interactions online and in classrooms.












