A Reference Document · The Language Firm

The Research Glossary

A working vocabulary for K-12 AI governance and the Forensic Read™.

Version 2.6

How to Read This Glossary

Terms are grouped by where they live in the firm's operating system, not alphabetized. The groupings are: (I) the firm and its mission, (II) the Human Being and the terms of exposure, (III) the Forensic Read™ methodology, (IV) the Drift Audit and Tool Spotlight Card classification system, (V) governance vocabulary: operational language for K-12 AI tool oversight, (VI) forensic linguistic instruments the Read applies, (VII) regulatory, contractual, and vendor terms the firm uses against vendor documentation, (VIII) a note on terms used together, and (IX) the Pre-Service Lookup vocabulary: the specific terms used in the firm's open, free-to-use verification tool.

The voice is the same voice the audits use: declarative, dated where applicable, document-naming where relevant. Italics mark terms-of-art as they would appear in body prose of a published audit. Terms specific to the Pre-Service Lookup carry a small Pre-Service Lookup tag inline with the term name.

Three registers of term appear here and are marked as such in the definitions. Some terms are set by law or by a published standard, and the glossary reports them: School Official, Student Data, Subprocessor. Some are established terms of art the firm uses in their settled sense: bound non-party, order-of-precedence clause. Some are the firm's own coinages, and the glossary says so: non-party subject, named reader, seam. A glossary that blurs these three is doing the thing it exists to detect.

I
The firm and its mission

The Language Firm

A compliance, language access, and edtech review practice serving K-12 schools and districts. The firm conducts forensic language analysis on vendor agreements, privacy policies, terms of service, DPA exhibits, and federal compliance language, and produces governance infrastructure from those findings. The firm holds no commercial relationship with any vendor it assesses.

Linguists in the loop

The firm's staffing principle. Every finding the firm publishes carries a named human investigator's signature and date. A person reads, aligns, signs, and stands behind the governance.

The language determines the liability

The operating conviction behind every Forensic Read™. Vendor marketing copy, contract terms, compliance attestations, and incident disclosures are read the way an investigator reads a deposition: for what is said, what is omitted, where responsibility is distributed across documents, and where language shifts between documents to obscure accountability.

Governance that centers the Human Being

The firm's second operating conviction, carried alongside the language determines the liability. Governance is evaluated by what it secures for the Human Being whose data is in the system, not by what it documents for the institution holding it. A governance apparatus can be complete at every institutional layer, carrying a named trigger, an assigned owner, a defined cadence, and a dated filed record, and still secure nothing for the Human Being, because none of those instruments is owed to them.

The claim is one of personhood and liability, not of warmth. A computer cannot be held accountable and an institution can be; the party to whom that accountability is owed is a person, and a governance record that cannot name what it secured for that person has documented a process rather than discharged an obligation. The terms in §II are what make the conviction operational: each states a condition or a quantity a reader can test against a document.

Intelligence Layer

The firm's overarching publication framework. The First Watch (drift audits), the Weekly Incident Bulletin, the Vendor Language Briefing, and the Federal Findings Digest are all Intelligence Layer products.

II
The Human Being and the terms of exposure

Every other section of this glossary supplies an instrument. This one supplies the object the instruments are pointed at. The terms below name the person whose data is in the system, the conditions under which that person is exposed, and the quantities the firm claims about them. Most are decidable from the governing documents alone. Two, compulsory exposure and the distributional half of differential exposure, rest on a premise that sits outside the document set: state compulsory attendance statutes in the first case, and the composition of the population named in the document in the second. Where a term carries such a premise, the definition names it, because a finding that quietly imports an unstated premise is the failure this section exists to prevent.

The Human Being

The person whose data is in the system. Capitalized and carried as a defined term the firm sets and holds constant across every document it reads. The capitalization is a liability convention, not a rhetorical one, and it marks the same function that Exhibit C performs inside a National Data Privacy Agreement: a term whose meaning is fixed in one place and controls wherever it appears. The firm sets this term because no governing instrument in K-12 does. Student Data, School Official, and Subprocessor are defined by the standard and by the regulation; the firm reports those definitions rather than authoring them. The Human Being is the firm's own, entered because the document set names data, roles, and parties, and does not name the person.

Where a governing document refers to data, records, accounts, or users, the firm reads for two things: whether a person is recoverable from the reference, and whether any obligation in the document attaches to that person directly. In K-12 the Human Being is ordinarily a student. The term is not restricted to students, because the same reading applies to staff, families, and any person whose data enters a tool the institution authorized.

Non-party subject

The firm's term for the condition of a person whose data an agreement governs and who holds no right of formation, amendment, exit, or enforcement under it. The person did not negotiate the agreement, cannot amend it, cannot terminate it, and is not a signatory to it. The condition is one of absent privity, not of assumed obligation: the non-party subject carries no duties under the instrument and cannot breach it. Distinguished from bound non-party, which names a different and settled contract-law condition and should not be used for this one.

Two mechanisms produce the condition in K-12, and they operate differently. Under the FERPA contractor exception, consent is not transferred to the district; it is dispensed with, because 34 CFR § 99.31(a) permits disclosure without the consent otherwise required at § 99.30. Under the COPPA school-as-agent doctrine, the school does consent, on the parents' behalf. The first removes the consent requirement; the second relocates it. A read that treats them as one mechanism will mischaracterize which party holds what.

The condition is structural rather than incidental, produced by the school official arrangement operating as designed. Every other term in this section describes a consequence of it.

Compulsory exposure

The condition that distinguishes K-12 data governance from consumer privacy. Within the school a student attends, the Human Being cannot decline the tool the district authorized and cannot exit the relationship the authorization creates. Consumer privacy regimes assume a person who can walk away, and notice, disclosure, and consent are remedies that presuppose that exit. Where exit is unavailable, disclosure is not a remedy and consent is not a control.

Stated premise. The condition rests on state compulsory attendance law, which is external to the document set and varies by jurisdiction. Those statutes compel education rather than enrollment at a particular school, and alternatives to a given district exist in most states. The firm's claim is therefore the narrower one: for the student enrolled where the tool is deployed, no in-system route of refusal exists in the governing documents. That narrower claim is recoverable from the documents and survives challenge; the broader claim that a student cannot decline the district does not.

The firm reads vendor documents drafted for consumer contexts against this condition, because the drafting assumption and the deployment reality do not match. A term that is adequate for a user who can close the account is not thereby adequate for a student who cannot.

Exposure

What became permissible with respect to a named Human Being under the governing documents as they stand on a date. Exposure is the sum of what the documents authorize, decline to constrain, or leave undefined, and it is recoverable from text.

Harm is not recoverable from text. The firm measures exposure and does not claim harm, and holding that line is what makes an exposure finding defensible under challenge. The narrower claim is the stronger one.

Exposure delta

The difference in what is permissible with respect to a Human Being already in the system, measured across a documented change to the governing terms. The measurable form of authorization durability, and the quantity a drift signal is read for once it has been detected.

Reading a delta requires captures of the governing documents at both endpoints of the change, each carrying a retrieval date. Without both endpoints there is a changed document and no measurable delta. Capture custody is therefore a precondition of the finding, not an administrative detail attached to it.

Authorization durability

The condition of an authorization granted at a fixed moment against a document that does not stay fixed. Authorization is an event; the terms it was granted against are a moving object. The gap between them is opened by the unilateral-amendment clause, under which a vendor reserves the right to change terms and continued use is deemed acceptance.

Named for authorization rather than consent because, under the mechanism that governs most K-12 deployments, no consent was given. The FERPA contractor exception dispenses with the consent requirement; what the district grants is authorization. The term consent is reserved for the COPPA school-as-agent pathway, where a school does consent on parents' behalf and where 16 CFR § 312.5(a)(1) requires fresh verifiable parental consent for any material change to the practices already consented to.

Named as a condition rather than as an event so that it can be read on any tool at any time, against the clause itself rather than against an incident. A district cannot edit that clause out of a vendor's contract from inside its own policy; what a Material Update definition secures is a guaranteed re-read and a recorded exposure in place of a silent redefinition.

Differential exposure

A finding that a document's exposure reaches categories of data that identify populations receiving protected services. The finding is recoverable from documents the firm already reads: the NDPA's Exhibit B enumerates a Special Indicator category covering English language learner information, low-income status, medical alerts and health data, student disability information, specialized education services under an IEP or 504, and living situations including homeless and foster care. A provider that marks that category has declared that data in those categories is in scope for the product.

Stated premise. The step from this data is in scope to exposure concentrates among those least able to contest it is a claim about the population, not about the document, and the document does not supply it. The firm states the document-recoverable finding first and marks the distributional claim as an inference drawn from the service categories the statute defines. Differential exposure is a finding about distribution, not about intent. It states where the weight of a document's silences falls.

Contestability

Whether a working route exists by which the Human Being or their family can object, correct, withdraw, or be heard. Distinct from parental rights, which names what the statute grants: contestability asks whether the governing documents supply a mechanism to exercise the grant. A right with no named recipient, no stated route, and no timeline is a right the documents mention rather than a right the documents operate.

The test is the same four-element test the firm applies to any policy. Working routes exist and are readable. FERPA supplies inspection within 45 days at 34 CFR § 99.10(b), amendment at § 99.20, and a hearing at § 99.21. COPPA supplies a parent's right to review, to refuse further use, and to direct deletion at 16 CFR § 312.6(a). The NDPA v2.2 at § 2.2 requires the provider to respond to an LEA request within thirty days and to refer any parent who contacts the provider directly back to the LEA. That referral is the structural point: the route runs through the district, so a district with no internal procedure leaves the statutory right with no terminus. A commitment to honor requests "as appropriate" is not a route.

Silence reads against the person

The human-centered statement of normalization by omission. Where a document declines to address an obligation, nothing constrains conduct in that area, and the consequence of the unconstrained conduct falls on the Human Being.

The omission is not neutral, and it does not fall on all parties equally. The drafting party retains the discretion the silence preserves, and in a vendor privacy policy, terms of service, or unilaterally amended DPA, the drafting party is the vendor. The institution inherits the exposure the silence creates without gaining the discretion; the person carries what that discretion permits. This is why the firm reads absence as worst-state rather than as an open question, and why the first question on any silence is which party drafted the document the silence appears in.

III
The Forensic Read™ methodology

The Forensic Read™

The proprietary investigative methodology of The Language Firm. Reads policy language and public posture as two separate evidentiary streams, then classifies the relationship between them. Draws on three established academic disciplines: discourse analysis, pragmatic and intertextual analysis, and forensic language analysis. The methodology moves through four stages in order: Reading, Trace, Surface, Build, each with a specific discipline and a specific output.

Stage 1 · READING

Discipline: discourse analysis. Output: document ecosystem inventory. Maps every document that governs a technology decision: the federal regulation, the district policy, the master service agreement, the data privacy agreement, the privacy policy, the sub-processor list, the incident disclosure, the marketing copy. Establishes how language distributes responsibility across that ecosystem.

Stage 2 · TRACE

Discipline: pragmatic and intertextual analysis. Output: accountability map. Tracks where meaning shifts between documents. Each shift is a transfer of obligation; the TRACE stage makes the transfers visible.

Stage 3 · SURFACE

Discipline: forensic language analysis and the principle of normalization by omission. Output: evidence-grade findings. Identifies what the documents assume, obscure, or fail to address. The No Drift / Watch / Flag labels are the SURFACE-stage output.

Stage 4 · BUILD

Discipline: register and genre construction. Output: governance infrastructure. Produces the documentation a district can stand behind, in the form of signed, dated, filed governance protocols that hold up under audit or program review. The First Watch audits are themselves BUILD outputs, applied recurrently.

Normalization by omission

A principle of forensic language analysis. The proposition that what a governing document fails to say is often more consequential than what it says. Load-bearing omissions create accountability the district carries without realizing it. Read at the level of the person, the same principle is stated as silence reads against the person.

Document ecosystem

The full set of texts that govern a single tool's institutional deployment: vendor privacy policy, terms of service, DPA or SDPC-registry agreement, help-center articles, subprocessor list, product announcements that bear on data handling, and any district-side acceptable use policy.

Accountability map

The TRACE-stage artifact that documents where obligations move between texts in a document ecosystem. Each shift in definition or scope between documents is a transfer of obligation; the accountability map records the transfers.

Evidence-grade finding

A SURFACE-stage finding documented against named primary sources so that the evidence behind the label is reproducible. The standard the firm holds itself to: a finding that would hold up under a federal program review.

Register and genre construction

The BUILD-stage discipline. Produces governance infrastructure in the register and genre appropriate to the audience and the regulatory context.

IV
The Drift Audit and Tool Spotlight Card system

Drift

The phenomenon the firm's audit work exists to detect: the movement of a vendor's governing documents, enforcement behavior, or product surface away from the state a district authorized. Drift is read against a governance baseline; without a dated baseline there is nothing to read change against. A single dated change to a vendor's policy, terms, or product language is a drift signal; the recurring practice of checking each governance signal against current primary sources as of a defined audit date is the Drift Audit. The firm distinguishes three vectors by where the movement occurs: policy-layer drift, enforcement-layer drift, and product-surface drift.

Tool Spotlight Card

The firm's internal per-tool governance assessment. Cards are not published; they are the firm's working instrument, used to produce the public-facing audits, briefings, and findings that derive from them. Each card scores a tool across six governance policy signals, four operational fit categories, and 20 scored questions. Cards carry a decision label (Teacher-OK, Conditional, or Do Not Deploy) and a numerical score out of 20 corresponding to one of three recommendation bands. Cards are versioned and named in published audits by their version and date.

Drift Audit

A recurring practice in which each governance signal documented in a Tool Spotlight Card is checked against current primary sources as of a defined audit date. The audit does not re-score the tool; it compares current signal status against the most recent card version and produces a drift category for each tool.

Filing rotation

The defined period a drift audit covers. The rotation set at audit 002 (May 2026) was a four-week monthly cadence. The current rotation is stated on the face of the most recent audit; this entry defines the term and does not carry the current value.

Decision label

The Tool Spotlight Card's top-line recommendation. One of three: Teacher-OK (approved for teacher-facing use); Conditional (approved subject to specific conditions met by the district); Do Not Deploy (not approved for K-12 institutional use).

The three drift categories (SURFACE-stage output)

No Drift

All governance signals reviewed against current primary sources are confirmed accurate. The card requires no update.

Watch

New context exists that practitioners should be aware of, but it does not change the card's decision label, policy signal badges, or core governance assessment.

Flag

A material change has occurred that affects the accuracy of information documented in the card. The card requires an update before continued practitioner use. The decision label may or may not change as a result.

Pre-Service Lookup usage. The same label is used in the Pre-Service Lookup's three-state verdict system, with a related but narrower technical definition: a verdict of Flag is produced when any of the rubric's three dealbreakers is triggered, or when any axis accumulates two or more worst-state answers. In both uses, the label carries the same operational meaning, a problem the reader needs to act on, and signals that continued use of the tool requires resolution. Two instruments of the methodology, one consistent vocabulary.

The three forensic patterns (TRACE-stage output)

Policy-posture convergence

The vendor's governing policy documents and its public posture describe the same product to the same standard.

Policy-posture divergence

The vendor's governing policy documents and its public identity are telling different stories. The product's surface-level presentation has not changed, but the data practices underneath have shifted materially.

Asymmetric movement

Policy language and public posture did not move in the same direction or at the same layer.

Repeated divergence (longitudinal subtype)

A vendor's second consecutive divergence finding, in the same direction, constitutes a vendor trajectory rather than a one-time event.

The three vectors of drift (Policy Brief §01)

Policy-layer drift

Changes in the governing privacy policy, terms of service, data processing addendum, or subprocessor disclosure. These are the artifacts that legal counsel reviews during initial procurement; once authorized, they are rarely re-read.

Enforcement-layer drift

Changes in how an existing policy is operationalized. The policy itself does not change; the vendor begins to enforce, verify, or detect against the policy in ways that produce new institutional consequences.

Product-surface drift

Expansion of the product's capability scope under existing contractual coverage. The DPA still applies, the no-training commitment still applies, the certifications still apply, but the product a district authorized now includes capabilities that did not exist at the time of authorization.

V
Governance vocabulary · Operational language for K-12 in a shifting accountability climate

The terms below appear throughout the firm's audits, briefs, and engagements. They name the conditions edtech vendors, SIS platforms, and AI tool providers are already using in their DPAs, terms of service, and product documentation. The functional purpose is simple: when the people in the building can name the term, the conversation moves from "should we use this tool?" to "does this vendor's documentation meet our obligations?"

AI Tool

A software product that applies machine-learning or generative models to institutional inputs, which an institution authorizes and deploys in an instructional or operational setting. Read by the firm at the level of the specific product and tier the institution authorized, not at the level of the vendor that supplies it. The definition turns on what the product does rather than on how the vendor markets it: a tool that runs inference on student work is within scope whether or not the marketing copy says artificial intelligence, and a tool that says so in its marketing is not within scope on that basis alone. Marketing is posture, and posture is a separate evidentiary stream from function.

AI Governance

The continuing institutional practice of confirming that the conditions under which an AI tool was authorized still hold, with responsibility for that confirmation assigned to a named reader on a stated cadence.

Non-contracted vendor

A vendor other than the one a district has contracted with directly, but whose involvement is consequential to the district's deployment of the contracted product. Entered under this name because third-party vendor is unusable in the firm's register: under FERPA and COPPA, the contracted vendor is the third party (see third party, regulatory usage), so applying the phrase to a vendor further out inverts the statutory referent inside the firm's own documents.

The category is broader than subprocessor (the contracting vendor's designation, under the DPA, of a party it engages to process data on its own behalf) and broader than upstream vendor (which describes a dependency direction, toward foundation models and infrastructure).

Upstream vendor risk

The institutional exposure that arises from dependencies the contracting vendor itself depends on: model providers, infrastructure providers, sub-processors. A district's DPA may name the vendor signing the agreement; the upstream stack carries risk the DPA may or may not reach.

Foundation model dependency

The condition of an edtech or AI product whose core function relies on a foundation model the vendor does not itself train. The dependency runs to the model rather than to the consumer product built on it: a model is trained weights reached through an API, while a product is the interface, memory, workspaces, file handling, connectors, sign-on, and audit logging assembled around it. Consumer applications are products; the models beneath them are the dependency. The word third-party is avoided here because it carries three incompatible referents (see third party, regulatory usage); the model provider is a party the district has no agreement with, which is the fact that matters and which the phrase does not convey.

Naming the model alone does not complete the finding. The same model is commonly served by several counterparties under different terms, and the serving arrangement, not the model, is what governance attaches to. Anthropic's Claude models, for example, are reachable through Anthropic's own API and through Amazon Bedrock, Google Cloud, and Microsoft Foundry, and the operator differs by route: Google Cloud's platform is Google-operated, Microsoft Foundry is Anthropic-operated, and data handling on the Google Cloud offering is governed by Google Cloud rather than by Anthropic. One model, four contractual paths, four subprocessor chains, four data-residency postures. A governance baseline that records only the model name has recorded nothing a named reader can act on. It must record provider, serving platform, operator, the terms that govern that route, and the pinned model version, each with a retrieval date.

The dependency is also interruptible by parties the district and the vendor are both outside of. Claude Fable 5 became generally available across all four platforms on June 9, 2026; access was suspended on June 12, 2026 to comply with a U.S. Department of Commerce export-control directive; Anthropic began restoring access on July 1, 2026 after the controls were lifted. Nothing in a district's DPA reached that sequence. Model retirement carries the same structure on an ordinary schedule: deprecation dates on partner-operated platforms are set by the partner, so a pinned version can be withdrawn on a timetable set by a party the district never contracted with. This is why the dependency is recorded as a governed party rather than a technical footnote.

Two boundary cases. Where a vendor self-hosts open-weight models, there is no model provider in the data path at all, and the dependency runs to a weights license and to whoever operates the inference, which is a materially different and often better posture that the register should distinguish rather than flatten. Where a district or teacher supplies its own API key, the model provider becomes the district's direct counterparty under generic commercial terms: see model-key passthrough. Specific model versions are deliberately not named in this entry, because releases and platform names both turn over faster than any reference document revises and a named version dates the definition rather than illustrating it. Where the vendor does not disclose the dependency, it is established from the subprocessor list, the Trust Center, and the DPA's subprocessor exhibit, and its absence from all three is itself a supply chain visibility finding. The dependency is a governance fact whether or not the vendor discloses it.

Definition drift

The phenomenon in which a term defined one way in federal regulation is redefined more narrowly in a vendor's DPA, redefined again in the privacy policy, and dropped entirely from the incident disclosure or marketing copy.

Gap

A problem inside the documents: something missing, contradictory, or vague in the language itself, such as a term left undefined, a definition that narrows between documents, or a "reasonable" standard with no anchor. Gaps live in language.

Seam

A place where no specific role at the district owns the work of checking access and agreement documentation. When a vendor updates a privacy policy, nobody at the district is positioned to notice, because the job was never assigned. Seams live in org charts.

Tool sprawl

The accumulation of edtech and AI products in active use across a district faster than any single role can authorize, inventory, or govern them. Tools enter through uncoordinated pathways: a district contract, a school-level purchase, a teacher signup, a free tier adopted in a hurry, a pilot that quietly became permanent. The proliferation itself is not the failure; the failure is that most of the accumulated tools carry no authorization record anyone can now produce. Tool sprawl is the product-side counterpart to identity sprawl, which is the account-side: the two compound together, because each tool admitted outside the Authorizing Officer process stands up new identity stores outside the agreements the district negotiated, and each is itself the scaled product of an open seam. The Tool Intake Register exists to convert sprawl back into an inventory a named reader can govern. A tool no one can justify is a tool no one is governing.

Identity sprawl

The accumulation of disconnected student and staff accounts across many vendor products, each holding identity data the district never inventoried and no single role governs. In identity-management practice the term stops at the IT layer: too many credentials, no central directory. In governance it reaches the authorization question, because each account is an authorization granted on a student's behalf. Sprawl is what an open seam produces at scale: where no Authorizing Officer is named, every individual signup stands up a new identity store outside the agreements the district negotiated, and the count compounds with each tool, each teacher, each roster sync. The harm is not only exposure but unanswerability: when a sub-processor is breached, a district cannot say whether its data is involved in accounts it never knew existed. The Subprocessor and Dependency Register exists to convert sprawl back into an inventory a named reader can act on. Sprawl lives between adoption and authorization.

Named reader

The specific person assigned to read and comprehend a tool's governing documents, the user policy, terms, and data processing agreement, before the institution signs off on the tool, and who is accountable for what that signature authorizes. A signature is meant to certify that a thorough reading took place; the named reader is the person that reading is assigned to. The named reader is the person accountable; the Human Being is the person the accountability is owed to.

Authorizing Officer

The role a district designates, in writing, to evaluate, approve, procure, or activate a tool that will collect, receive, or process Student Data. The term exists to close a seam: where no one is named, every employee is an authorizing officer by default, and a tool can enter the building through an individual signup the district never sees. A functioning definition states that no other employee may create an account, accept terms of service, or enable a tool for student use, regardless of cost, including free and individually registered accounts.

Named Authorizing Officer rather than Authorized User because Authorized User is already a defined term in most enterprise terms of service, where it means an end user permitted to access the service under the customer's account. A district that capitalizes Authorized User in its own policy and then reads a vendor's terms is holding two incompatible meanings of one defined term across its document ecosystem, which is definition drift of the district's own making. Use by someone who is not the Authorizing Officer is the parallel contractor relationship at its origin: it places Student Data outside the agreements the district negotiated, where its protections do not attach.

Supply chain visibility

The institutional capacity to see what an AI product is actually built on: which model dependency under which serving arrangement, which sub-processors, which upstream services. The capacity question, of which foundation model dependency is the specific per-tool finding. Absence of an answer on any of the three is itself the finding: a dependency the district cannot establish is one it cannot enter on a governance baseline and cannot re-read when it changes.

Software Bill of Materials (SBOM)

An inventory of the software components a product is composed of. In the K-12 AI context, the absence of an SBOM, or its functional equivalent for model dependencies, is a documented governance gap.

Capability scope at time of authorization

The set of product features a district approved when it first authorized a tool, captured in dated form. A capability-scope record is the institutional artifact against which product-surface drift can be measured.

Governance baseline

A dated, single-page record per authorized tool, capturing the specific tier authorized; the data practices in effect at authorization (no-training commitment, FERPA/COPPA alignment, subprocessor list); the model dependency where one exists; the capability scope authorized; the contractual basis (DPA version and exhibits, SDPC listing); and the date of last verification.

The model dependency is recorded as five fields rather than one: provider, serving platform, operator of that platform, the terms governing that route, and the pinned model version. The five-field form is what makes the record re-readable. The same model served under a different platform, operator, or set of terms is a different exposure, so a baseline that names only the model gives a later reader nothing to measure a change against, which is the one thing a baseline exists to do.

Verification cadence

The frequency at which a governance baseline is re-checked against current primary sources.

Material Update

A change a vendor makes to its terms of service, privacy policy, data processing agreement, or product behavior that alters how Student Data is collected, used, disclosed, retained, secured, or defined. The term names the trigger a district policy uses to require a fresh read: a material update returns the tool to the named reader for review against the district's own definitions before its use continues. It is the district-policy counterpart to a drift signal: the drift signal is what the firm's audit work observes; the material update is what a district's own policy obligates someone to act on.

The concept is not the firm's invention, and two governing instruments already carry versions of it. COPPA requires direct notice to the parent of any material change in collection, use, or disclosure practices to which the parent previously consented, at 16 CFR § 312.4(b), and requires fresh verifiable parental consent for that change at § 312.5(a)(1). The NDPA v2.2 requires the provider to add data elements to Exhibit B when a material change has occurred, by Addendum, with thirty days for the LEA to object before the change is incorporated. A district definition that is narrower than either is narrower than the floor its own agreements already set.

The exposure the term addresses is the unilateral-update clause, under which a vendor reserves the right to change terms with or without notice and continued use is deemed acceptance, the condition named at authorization durability. A district cannot edit that clause out of a vendor's contract from inside its own policy; what the definition secures is a guaranteed re-read and a recorded exposure in place of a silent redefinition.

Trigger

A change from the previously agreed-upon state that obligates a defined action under district policy. The agreed-upon state is the dated record a district writes per tool: the function delegated to the vendor, the terms accepted, the data permitted, the control required, captured as a governance baseline. A trigger is any departure from that record: a vendor that widens what it collects has changed the data, a vendor that reserves the right to train on district inputs has changed the terms, a vendor that adds a downstream processor has changed the control. Each is read against the baseline; without a dated baseline there is nothing to measure the change against, and the change passes unregistered. Trigger events are characteristically quiet, vendor-initiated, and leading rather than lagging: they arrive in a revised policy, a new exhibit, or a settings default that flipped between releases, detectable upstream of any confirmed incident. An operative trigger carries a named owner, a cadence, and dated documentation; a trigger no one is assigned to watch is a line in a policy, not a control. The Material Update is the firm's most precisely defined trigger; the drift signal is what the firm's audit work produces when it observes one from the outside.

Procurement-event vs. standing-obligation

The distinction between treating AI tool authorization as a one-time procurement step and treating it as a continuing institutional obligation.

VI
Forensic linguistic instruments · The reading techniques the Read applies

These are the concrete linguistic analyses the Forensic Read™ uses at the TRACE and SURFACE stages to convert vendor documents into evidence. Each instrument names a specific construction or omission a district can be trained to recognize on its own. Sharp's Reading Record demonstrated each of these against the OpenAI Teacher Access Terms, Service Terms, and Student DPA in An Unread Deputy & A Signed Contract (May 14, 2026); the definitions below carry that worked example as their reference case.

Agentless passive construction

A sentence built so that an action is described but the actor performing it is removed. Information is removed. Identifiers are stripped. Provisions may be waived. In ordinary prose this is a stylistic choice; in a regulated document, the deleted actor is almost always where accountability would normally live.

Modal verb analysis

The practice of tagging every modal verb in a contract (shall, must, will, may, can, should) and sorting them on two axes rather than one. The first axis is type: obligation modals (shall, must, will) impose a duty on a named party; permission modals (may, can) reserve a discretion to a named party. These are different operations, not two points on one scale, and reading may as a weak obligation misses what it actually does, which is to license conduct the reader may have assumed was prohibited. The second axis is direction: which party each modal binds, and which party it frees.

A third question sits on top of both. Shall is the most litigated modal in Anglo-American contract drafting, used inconsistently to mean must, will, and is entitled to within a single instrument, which is why plain-language drafting guidance prefers must for obligation. A document that uses shall throughout is not thereby a strong document; the ambiguity is itself a finding, and the instrument reports it as one.

Indefinite phrasing

The practice of identifying words that function as standards but are left undefined within the document: reasonable, proper, appropriate, as applicable. The finding is not that these words are empty. Reasonable carries a substantial body of interpretive authority, and federal regulation uses it deliberately, as at 34 CFR § 99.31(a)(1)(ii), which requires reasonable methods to limit school-official access.

The finding is that the standard is not set in the instrument the parties signed. Where a term is undefined, its content is supplied later, by an external standard the district did not choose, cannot predict, and would have to litigate to establish. That is a transfer of interpretive control from the signature to a future forum, and it is a stronger and more defensible claim than saying the word has no anchor. The remedy is the same in either case: define it in the instrument, or name what supplies the meaning.

Cross-document precedence reading

The technique of reading a vendor's multi-document contract package against itself to determine which document controls when documents conflict.

Normalization by omission (applied)

The SURFACE-stage principle of normalization by omission, applied at the level of specific contract architecture: an omission across documents, such as a missing order-of-precedence clause, can be more consequential than any omission within a single document.

VII
Regulatory, contractual, and vendor terms

These terms appear throughout the firm's published work in their conventional usage; the firm reads vendor documents against the federal language listed here. Government terms carry working citation links to authoritative public sources. Regulatory and standard-set definitions in this section are reported, not authored: where the firm's own construction of a regulatory term is offered, the entry says so.

FERPA

Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g (1974, as amended); implementing regulations at 34 CFR Part 99. The federal statute governing the privacy of student education records, administered by the U.S. Department of Education's Student Privacy Policy Office.

Contractor exception (34 CFR § 99.31(a)(1)(i)(B))

The provision under FERPA that lets a school share education records with a contractor without the parental consent otherwise required at § 99.30. The regulation sets three conditions on the outside party: it performs an institutional service or function for which the agency would otherwise use employees; it is under the direct control of the agency with respect to the use and maintenance of education records; and it is subject to the redisclosure limits of § 99.33(a).

Two further conditions sit outside subparagraph (B) and are routinely omitted from vendor-side readings. Under § 99.7(a)(3)(iii), a district with a policy of disclosing under § 99.31(a)(1) must specify, in its annual notification of rights, the criteria for who constitutes a school official and what constitutes a legitimate educational interest. Under § 99.31(a)(1)(ii), the district must use reasonable methods to ensure school officials reach only records in which they have a legitimate educational interest. A district that has designated a vendor but never amended its annual notice has not completed the exception, whatever the DPA says. The NDPA v2.2 makes the point on its own face at § 3.2, which assigns that annual-notification duty to the LEA.

Signing a Student DPA designates the vendor as a School Official and is the act of deputizing; the contractor exception is sustained only when the deputizing is paired with the working conditions above. It is also the provision that produces the non-party subject condition, since it removes the consent requirement rather than transferring the consent.

Direct control

The condition stated at 34 CFR § 99.31(a)(1)(i)(B)(2): the outside party must be under the direct control of the agency or institution with respect to the use and maintenance of education records. The regulation states the condition and does not decompose it.

The firm's construction. The firm reads the condition as three components that must hold together: knowledge of what the contractor is doing, authority to direct what the contractor does, and enforcement when the contractor does not follow direction. Take any one of the three away and direct control fails as a working matter. This decomposition is the firm's operationalization of the regulatory phrase, offered so the condition can be tested against a document rather than asserted, and it is identified as the firm's rather than the regulation's wherever it appears in published work.

Deputizing

The shorthand the firm uses for the act of designating a vendor as a School Official under the FERPA contractor exception. The firm distinguishes between deputizing (the contract event) and direct control (the ongoing working condition); a deputizing without direct control is a documented governance failure regardless of what the DPA's text appears to cover.

School Official

A FERPA-defined role a contractor may occupy under the contractor exception. The role is conferred by district designation, not claimed by the vendor: NDPA v2.2 § 1.1 states that in performing the Services the Provider shall be considered a School Official with a legitimate educational interest, and Exhibit C defines the term by reference to the three conditions at 34 CFR § 99.31(a)(1)(i)(B). A vendor's terms of service can signal willingness to accept the conditions; they cannot confer the role. The role is sustained only while direct control is maintained.

Parental rights

The rights FERPA grants to parents: to inspect and review the student's education records, to seek amendment of records believed inaccurate, misleading, or in violation of privacy rights, and to consent to disclosures except where § 99.31 authorizes disclosure without consent. Each carries a route in the regulation: inspection within a reasonable period and no more than 45 days at 34 CFR § 99.10(b), amendment at § 99.20, and a hearing at § 99.21 if amendment is refused.

The rights transfer to the student when the student becomes an eligible student, which § 99.3 defines as a student who has reached 18 years of age or is attending an institution of postsecondary education. The second branch reaches dual-enrolled high school students and is routinely dropped from vendor and district summaries that state the age alone.

Under COPPA, a parallel and separately sourced set of rights runs to the parent of a child under 13 at 16 CFR § 312.6(a): to review the categories of personal information collected, to refuse further collection or use, and to direct deletion. What the statutes grant is the right; whether the governing documents supply a working route to exercise it is contestability.

Third party (regulatory usage)

A term whose referent shifts by instrument, which is why the firm does not use it unqualified. Under FERPA, a disclosure of education records to any party other than the educational agency or institution is a disclosure to a third party, so the contracted vendor is the third party, admitted only through an exception at § 99.31. Under COPPA, third party is defined at 16 CFR § 312.2 as any person who is neither an operator with respect to the site or service nor a support-for-internal-operations provider, which places the operator outside the category and the operator's downstream recipients inside it. In commercial contract usage, third party ordinarily means a non-signatory to the agreement in hand.

Three referents, one phrase. The firm names the instrument whenever the term is used, and uses non-contracted vendor and subprocessor for the specific relationships it needs to describe.

Bound non-party

A non-signatory made subject to the obligations of an agreement it did not execute. The condition is established in contract and arbitration doctrine and arises through recognized theories: incorporation by reference, assumption, agency, alter ego, estoppel, and third-party beneficiary status. The firm uses the term in that settled sense and not for the person whose data is at issue, who is a non-party subject and holds no obligations at all.

Two bound non-parties appear routinely in K-12 document sets. A Subprocessor is bound by flow-down: NDPA v2.2 § 2.3 requires the Provider to execute a Subprocessor Agreement with every Subprocessor, obligating it to protect Student Data no less stringently than the DPA and barring it from selling that data, though the Subprocessor never signs the district's agreement. A Subscribing LEA is bound by adoption: Exhibit C defines it as an educational entity that was not party to the original Service Agreement and that accepts the Provider's General Offer of Privacy Terms by executing Exhibit E, taking the terms as written without negotiating them.

The forensic value of the term is what it exposes at the edges. A district's remedy against a Subprocessor runs through the Provider, because the district has no privity with the Subprocessor; a Subscribing LEA inherits an agreement negotiated by an Originating LEA whose posture and state supplement may differ from its own. Both are places where an obligation is presumed to travel and may not.

Order-of-precedence clause

A contract-drafting mechanism that establishes, before any dispute arises, which provision or document controls when the terms of a single agreement conflict. Widely used in commercial contract practice, and set out in federal procurement regulation at FAR 52.215-8 and FAR 52.212-4(s), both current as of August 2026.

The ranked items are provisions as well as documents, which is the feature that matters forensically. FAR 52.215-8 ranks the Schedule, representations and instructions, contract clauses, other documents and attachments, and the specifications. FAR 52.212-4(s) runs to nine ranks and places named paragraphs of the ranking clause itself both above and below outside instruments. A clause that ranks its own paragraphs against attachments is the same structure the NDPA's Priority of Agreements uses when it places Exhibit H above the Standard Clauses.

Two features carry across to K-12 reads. FAR 52.212-4(s)(4) places addenda, expressly including software license agreements, at rank four, below the schedule and below core clause paragraphs: vendor license terms are ordered rather than left to float. And FAR 52.212-4(u) provides that where a EULA or terms of service would require the Government to indemnify, the clause is unenforceable and deemed stricken, and that acceptance through an "I agree" click box, click-wrap, or browse-wrap does not bind the Government or an authorized end user. That is federal regulation refusing to treat click-through acceptance as institutional assent, drafted by the government for its own contracts. Both clauses also rank the specification last: the most detailed document controls least, and length is not precedence.

Parallel contractor relationship

The condition that arises when a vendor accepts content from district-affiliated individuals through a pathway the district has no mechanism to see. Direct control over a relationship the district does not know exists is unavailable as a matter of fact, regardless of contract text.

COPPA

Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 (enacted 1998); implementing regulations at 16 CFR Part 312 (the COPPA Rule), administered by the Federal Trade Commission. The federal statute governing online services directed to children under 13.

Amendment of record as of August 2026. The Rule was amended at 90 FR 16977, published April 22, 2025, effective June 23, 2025, with a compliance date of April 22, 2026. Five changes bear directly on K-12 reads. Biometric identifiers are now expressly personal information at § 312.2, including voiceprints, facial templates, faceprints, gait patterns, and genetic data. Separate verifiable parental consent is required for disclosure to third parties unless the disclosure is integral to the service, at § 312.5(a)(2). Indefinite retention of children's personal information is prohibited outright at § 312.10, which also requires a written data retention policy stating purposes, business need, and a deletion timeframe, published in the online notice. A written information security program is required at § 312.8(b), with a designated coordinator, annual risk assessments, testing, and annual evaluation. Written assurances must be obtained from service providers and third parties before they collect or receive children's personal information, at § 312.8(c).

One proposed change was not adopted. The 2024 notice of proposed rulemaking would have codified the school authorization exception and added definitions of School and school-authorized education purpose. Those provisions were removed from the final rule. The pathway most K-12 deployments rely on therefore still rests on FTC guidance rather than on rule text, and a load-bearing non-event of that kind is exactly what a governance record should name.

PPRA

Protection of Pupil Rights Amendment, 20 U.S.C. § 1232h; implementing regulations at 34 CFR Part 98. Enforced alongside FERPA by the U.S. Department of Education; governs parental rights over surveys, the collection of personal information for marketing, and certain physical examinations in federally funded programs.

DPA · Data Processing Addendum / Data Privacy Agreement

The contractual instrument that governs how a vendor handles data on behalf of a district. The DPA governs how the vendor handles submitted data, not what staff submit; the district's AUP is the primary governance mechanism for the latter.

SDPC

Student Data Privacy Consortium. Maintains a resource registry of vendor DPAs (sdpc.a4l.org). The absence of an SDPC listing is a documented condition on certain Conditional decision labels.

Access 4 Learning (A4L) Community

Access 4 Learning (A4L) Community. The nonprofit membership organization that maintains the data-interoperability and data-privacy standards used across K-12. The Student Data Privacy Consortium (SDPC) is its special interest group, and the National Data Privacy Agreement is authored within that consortium and published and copyrighted under the A4L Community. The authoritative versions of the NDPA and its state supplements are held by A4L and, by the terms printed on the document itself, may not be altered in any substantive manner; districts and vendors that change the terms do so by amendment, not by editing the standard text.

NDPA · National Data Privacy Agreement

National Data Privacy Agreement. The standardized student-data privacy contract authored by the Student Data Privacy Consortium and published by the Access 4 Learning (A4L) Community. Version 1 was released in 2020; version 2 in April 2024; version 2.1 in 2025; version 2.2 on November 19, 2025, which is the current standard version as of August 2026. The NDPA is the closest thing K-12 has to a common DPA template, adopted voluntarily through state alliances rather than mandated by law.

It is built from a Preamble and five articles of Standard Clauses plus lettered exhibits: Exhibit A (products and services), Exhibit B (the Schedule of Student Data), Exhibit C (definitions), Exhibit D (special instructions for disposition of Student Data, which the parties are directed not to complete at execution), Exhibit E (the General Offer of Privacy Terms, by which a Subscribing LEA adopts the same terms), Exhibit F (adequate cybersecurity frameworks, from which the Provider must mark at least one and may change its selection on notice without amending the DPA), and Exhibit G (supplemental state terms). Exhibit H carries vendor or district modifications and is not present in the Standard version from v2 forward; it appears only in the Vendor-Specific and District-Modified builds, and its presence is therefore a signal in itself.

Its Priority of Agreements clause functions as an order-of-precedence clause, and it runs in two directions. Outward, for the treatment of Student Data only, the DPA controls over the service agreement, terms of service, privacy policies, and any bid, RFP, license agreement, or other writing. Inward, where Exhibit H, the Standard Clauses, and Exhibit G conflict, Exhibit H controls, followed by Exhibit G. A modification exhibit that outranks the standard clauses is where a vendor-specific build does its work, and it is the first place the firm reads in any package that has one.

The firm reads the signed copy on file, never the clean template. The live questions are which version governs, which state supplement applies, whether Exhibit H is present, and whether the vendor signed the standard text or a build that edited the definitions or the carve-outs. The presence of an NDPA is a starting condition, not a finding.

Exhibit C (NDPA)

Exhibit C. The definitions exhibit of the National Data Privacy Agreement. Section 1.4 of the v2.2 Standard Clauses provides that capitalized terms take their meanings from Exhibit C and that, with respect to the treatment of Student Data, definitions used in the DPA prevail over terms used in any other writing. Exhibit C is therefore the document the firm reads first in any NDPA package: it is where the agreement's protective scope is set, and where a vendor-modified build does its quietest damage, by narrowing a single defined term.

The v2.2 exhibit defines seventeen terms: Change of Control, Contextual Advertising, Data Breach, De-Identified Data, Education Records, LEA, Metadata, Originating LEA, Personally Identifiable Information, School Official, Service Agreement, Student Data, Student Generated Content, Subprocessor, Subprocessor Agreement, Subscribing LEA, and Targeted Advertising. The term is Education Records, not Educational Records, and it takes its meaning from 20 U.S.C. § 1232g(a)(4) and 34 CFR § 99.3 rather than from the exhibit itself.

Schedule of Student Data (Exhibit B)

Schedule of Student Data. Exhibit B of the National Data Privacy Agreement: the provider-completed checklist declaring which categories of student data a product collects, each marked Required or Optional per product. The instrument carries two names for itself in v2.2, and the firm cites both: the exhibit is titled Schedule of Student Data, while § 1.3 of the Standard Clauses refers to the Schedule of Data. Either name reaches the same exhibit.

From version 2 forward the Schedule is no longer LEA-specific: the provider lists the superset of data elements collected or created by the application, and an LEA narrows its own scope through the SDPC Resource Registry rather than by editing the exhibit. Changes travel by Addendum, and the LEA has thirty days from receipt to object before the Addendum is incorporated. The exhibit also carries the disclosure of countries where Student Data is stored outside the United States, and a None option for products that collect no Student Data.

The Schedule enumerates the categories the NDPA contemplates: Application Technology Metadata; Application Use Statistics; Assessment (including standardized test scores, observation data, and voice recordings); Attendance; Communication; Conduct; Demographics; Enrollment; Parent/Guardian Contact Information; Parent/Guardian ID; Parent/Guardian Name; Schedule; Special Indicator (English language learner information, low-income status, medical alerts and health data, student disability information, specialized education services under an IEP or 504, and living situations such as homeless or foster care); Student Contact Information; Student Identifiers; Student Name; Student In App Performance; Student Program Membership; Student Survey Responses; Student Work (student generated content); Transcript; Transportation; and an Other field. Because the Schedule is a provider self-report, the forensic risk it carries is under-marking: a product that collects a category but leaves the box unchecked. The Schedule states what the provider declares; the Read tests that declaration against the product's actual behavior and its other documents. Two categories now interact with the amended COPPA Rule and warrant a paired read: Assessment voice recordings and any biometric input, since § 312.2 now treats voiceprints and facial templates as personal information. The Special Indicator category is the entry point for a differential exposure reading.

Student Data (vendor DPA usage)

Student Data, as commonly defined in vendor DPAs. The defined contract term most vendor agreements use in place of FERPA's statutory language. The NDPA v2.2 model is broad: it covers data gathered, created, or inferred by the provider, or provided by the LEA or its users, students, or parents, for a school purpose, that is descriptive of the student; it includes Metadata that has not been stripped of all direct and indirect identifiers; it expressly includes personally identifiable information as defined at 34 CFR § 99.3; and it is deemed to constitute Education Records for the agreement's purposes.

The standard text carries its own carve-out, and the firm reads it as such rather than treating carve-outs as a vendor-modification pattern alone: Student Data shall not include properly De-Identified Data or anonymous usage data regarding a student's or LEA's use of the provider's services. Two exclusions therefore sit in the standard, before any vendor edits anything.

Common vendor-modified and vendor-authored definitions narrow the scope further in recurring ways: by limiting the term to information the student or district provides, which excludes what the vendor derives or infers; by relabeling behavioral and telemetry data as the vendor's own usage data or service data, which walks it into the anonymous-usage carve-out; and by widening the de-identified carve-out into broad rights of use and retention after termination. The result is a defined term that sits below the statutory floor while appearing to expand protection, an instance of definition drift. The firm's standing test is whether the vendor's definition is coextensive with, broader than, or narrower than the § 99.3 definition of personally identifiable information, and what each carve-out removes.

De-Identified Data

The category a vendor claims has been stripped of identifiers so that a student can no longer be identified, and the category vendors most often carve out of Student Data to claim broad rights of use and retention after termination. Two standards apply and they are not identical. FERPA sets the operative federal standard at 34 CFR § 99.31(b)(1): data is de-identified only after all personally identifiable information is removed and the agency or other party has made a reasonable determination that a student's identity is not personally identifiable, whether through single or multiple releases, and taking into account other reasonably available information. Exhibit C of the NDPA defines the term for agreements built on that template, in terms of removal or obscuring of PII such that the remaining information does not reasonably identify a specific student, including information that alone or in combination is linkable to one.

NDPA v2.2 § 4.5 adds three conditions the firm reads for directly: the provider agrees not to attempt re-identification without the LEA's written direction; a provider that creates De-Identified Data must use a process complying with either NIST de-identification standards or U.S. Department of Education guidance; and the provider's use of De-Identified Data expressly survives termination of the DPA and any request to return or dispose of Student Data. The survival clause is in the standard text, not a vendor addition.

The firm reads the carve-out, not the label: data remains Student Data where re-identification is reasonably possible, or where the vendor retains the ability or the contractual right to re-identify it. A vendor's use of de-identified, anonymized, or aggregate does not establish the status on its own. The label is the vendor's. The determination is the named reader's.

Subprocessor

A party engaged by the vendor, on the vendor's own behalf, to process data in order to deliver or improve the service. Exhibit C of the NDPA v2.2 defines the term as a party other than the LEA or the Provider whom the Provider uses for data collection, analytics, storage, or other service to operate or improve its service, and who has access to or storage of Student Data. The chain matters: the subprocessor processes for the provider, and the provider processes for the district. Describing a subprocessor as processing on the district's behalf collapses a link the district's remedies depend on.

The binding runs by flow-down rather than by signature, which makes the subprocessor a bound non-party. NDPA v2.2 § 2.3 requires a Subprocessor Agreement with every subprocessor, obligating protection no less stringent than the DPA and prohibiting sale of Student Data; § 4.4.1.4 exempts disclosure to subprocessors from the provider's general no-disclosure covenant. Under COPPA, 16 CFR § 312.8(c) separately requires the operator to take reasonable steps to determine that such parties can maintain confidentiality, security, and integrity, and to obtain written assurances to that effect. Subprocessor disclosure is one of the six governance policy signals scored on the Tool Spotlight Card.

No-training commitment

A vendor's contractual or policy-level commitment that data submitted through its products will not be used to train its models. A no-training commitment in marketing copy is not the same as a no-training commitment in the DPA.

BYOK · Customer-managed encryption

The enterprise data-security feature in which the customer holds the encryption keys for its data at rest rather than the vendor: the vendor stores the data but cannot decrypt it without the customer-held key. This is a control the district gains, and it governs data at rest, not the path student input travels to inference. It is the meaning BYOK carries in enterprise storage and infrastructure contexts. Distinct from model-key passthrough, which shares the acronym but names a different object in the data path.

BYOK · Model-key passthrough

The arrangement in which a district or teacher supplies its own foundation-model API key to a third-party tool, which then routes student input through that key to the model provider. It is commonly presented as a privacy upgrade, on the claim that the tool never stores the data because the data goes directly to a provider the customer authorized. Read forensically, it is a liability transfer. The foundation model provider stops being the tool's subprocessor named under the DPA and becomes the district's direct counterparty under generic commercial API terms: terms that are not FERPA-aware, carry no school official designation, make no COPPA representations about under-13 users, and place compliance on the customer. The tool's no-storage claim can be accurate while the student-data exposure migrates to a party the district holds no education-specific agreement with. The key the district brings is an API credential governing inference, not the encryption key of customer-managed encryption. Where a tool uses passthrough, the model provider is a governed party: the governance baseline must record it, and the provider's API terms must themselves receive a named reader.

SSO / SCIM

Single Sign-On / System for Cross-domain Identity Management. Standard enterprise authentication and provisioning protocols.

AUP · Acceptable Use Policy

The district-side governance instrument that constrains how authorized tools may be used by staff and students.

LEA

Local Educational Agency. A school district, in federal terms. Statutory definition at 20 U.S.C. § 7801 (Elementary and Secondary Education Act, as amended by ESSA). Note that the NDPA uses a broader contract definition: Exhibit C extends LEA to a state agency, an educational service agency, a charter school, or a private school or school system, in addition to the federal definition.

ESA / BOCES

Educational Service Agency / Board of Cooperative Educational Services. Regional intermediaries authorized by state statute to develop, manage, and provide services to LEAs (statutory definition at 20 U.S.C. § 7801).

E-Rate

Schools and Libraries Universal Service Support Program. The federal program providing discounts to eligible K-12 schools and libraries for broadband and telecommunications service. Established under section 254 of the Communications Act of 1934, 47 U.S.C. § 254; implementing rules at 47 CFR Part 54, Subpart F (§§ 54.500–54.523); administered by the Universal Service Administrative Company (USAC) under FCC oversight. Funding eligibility carries program conditions, including the Children's Internet Protection Act (CIPA) certification at 47 CFR § 54.520.

VIII
A note on terms used together

Several of the most consequential pairings in the firm's vocabulary deserve explicit clarification because they answer different questions and are independent dimensions.

  • Drift category (No Drift / Watch / Flag) answers did this tool change since we last looked? It is the SURFACE-stage output of an individual tool review.
  • Forensic pattern (Convergence / Asymmetric / Divergence) answers what kind of change? It is the TRACE-stage output that describes how policy and posture moved.

A Watch finding can be Convergent (Claude Enterprise, audit 001, stable governance with one announced-but-unconfirmed item) or Asymmetric (Claude Free, positive posture move under static structural policy). A Flag finding is almost always Divergent. The layered structure is what allows the framework to express what a binary compliant / non-compliant judgment cannot.

The same care applies to the three vectors of drift (policy-layer, enforcement-layer, product-surface), which describe where in the vendor's stack a movement is happening, and to the forensic patterns, which describe the shape the movement takes across the policy and posture streams. The Policy Brief argues that most existing AI governance frameworks are calibrated to detect policy-layer change but not enforcement-layer activations or product-surface expansion. Its supporting figures, an asymmetric pattern in 43% of tools at audit 001 (April 2026) rising to 63% at audit 002 (May 2026), are two dated observations rather than a trend, and are cited here with their dates for that reason.

A third pairing belongs alongside these two, because it answers a different question again. Gap and seam name two places a problem can live. A gap is a problem inside the documents, something missing, contradictory, or vague in the language. A seam is a place where no specific role at the district owns the work of checking access and agreement documentation. The two are independent: a district can have either, both, or neither. The dangerous case is both: a real gap in the documents, and nobody at the district positioned to find it. The Forensic Read™ is the instrument for finding gaps; a single named owner running a quarterly verification cadence is the instrument for closing seams. Gap asks what is wrong with the paperwork? Seam asks whose job was it to check?

A fourth pairing exists between the firm's broader vocabulary and the Pre-Service Lookup's narrower vocabulary. The word Flag appears in both: as a SURFACE-stage Drift Audit category and as a Pre-Service Lookup verdict. Both uses share an operational meaning (a problem the reader needs to act on) and signal that continued use of the tool requires resolution; the underlying technical criteria differ because the two instruments operate at different scales. Similarly, posture is used in the firm's audits to describe a vendor's full public stance and in the Pre-Service Lookup to describe an axis-bounded slice of that stance. The vocabulary is consistent across the firm's instruments by design: a reader who learns the language through one application carries it forward to the others.

A fifth pairing sits beneath the other four, because it names the two ends of every obligation this glossary defines. Named reader and the Human Being are the person accountable and the person affected. The named reader is the role a district assigns to read a tool's governing documents and stand behind what the signature authorizes; the Human Being is the person whose data that signature places in the system. Governance frameworks reliably define the first and almost never define the second, which is why a district can hold a complete governance record and still be unable to state what any of it secured for a student. Named reader asks: who signed? The Human Being asks: who is bound by it?

A sixth pairing is new in this edition and exists because the fifth one was stated imprecisely. Bound non-party and non-party subject both describe someone outside the signature, and they are opposite conditions. A bound non-party acquires obligations without signing: the subprocessor under a flow-down clause, the Subscribing LEA under a General Offer. A non-party subject acquires exposure without signing, and acquires no obligations at all, because there is nothing in the instrument the student could breach. Collapsing the two flatters the student's position by implying a party status the documents do not grant. Bound non-party asks: who owes duties they never negotiated? Non-party subject asks: who bears consequences they cannot contest?

IX
The Pre-Service Lookup vocabulary · Terms used in the firm's free verification tool

The Pre-Service Lookup is the firm's free, openly-published verification tool, a structured, rubric-bounded application of the Forensic Read™ scoped to K-12 AI vendor governance triage at the document layer. It is the most basic and topical application of what the methodology can produce, intended to extend a thin slice of the methodology to people who could not otherwise apply it: pre-service teachers, parents, school boards, state agencies. The terms below are specific to that tool. Some are tool-internal language (axis, rubric, dealbreaker, verdict); others are regulatorily-anchored terms the rubric grades against and are defined here in the form they take inside the rubric. Terms that already appear elsewhere in this glossary (FERPA, COPPA, DPA, subprocessor, parental rights) are not duplicated here; the Pre-Service Lookup uses those terms in their conventional sense and the §VII definitions apply.

The rubric's structural vocabulary

Rubric Pre-Service Lookup

The structured set of twelve inputs across three axes, plus three single-input dealbreakers, that the Pre-Service Lookup's Scorer applies to produce a verdict. The rubric is decidable from documents alone, requires no specialized legal training, and produces consistent results between evaluators reading the same documents. Portability of the rubric is the methodology's reproducibility claim, narrowed and made operational. The rubric is not the full Forensic Read™; it is one applied instrument of the methodology, scoped to a single category of analysis.

Axis Pre-Service Lookup

One of the three categories the rubric uses to evaluate a vendor's posture: data posture, FERPA posture, and children's data posture (COPPA). Each axis contains four binary-with-mid inputs. The verdict is calculated by summarizing the results across all three axes together, not by collapsing them into a single score. The three axes are the regulatorily-anchored dimensions of K-12 AI governance, each maps to a body of existing law or widely-accepted privacy practice that produces decidable readings from documents alone.

Posture Pre-Service Lookup

The current state of a vendor's commitments, capabilities, and language as it bears on a specific axis of evaluation. Used three ways in the Scorer: data posture (the vendor's stance on input handling), FERPA posture (the vendor's stance on student record handling), and children's data posture (the vendor's stance on under-13 users). Posture is a snapshot, not a guarantee; the First Watch audits exist because posture drifts. The term is used in this specific axis-bounded sense throughout the Pre-Service Lookup, distinct from public posture as it appears in the Drift Audit's policy-posture pairing.

Mid-state Pre-Service Lookup

The middle answer on any rubric input, indicating partial compliance, ambiguous language, or conditional support. Mid-state answers do not trigger dealbreakers but they count against the 3-of-4 best-state threshold required for a Proceed verdict. The Scorer's amber-bordered middle option corresponds to mid-state. The three-option structure (best-state / mid-state / worst-state) matches the actual phenomenology of reading vendor documents: does the document explicitly commit, partially commit, or fail to address?

Dealbreaker Pre-Service Lookup

An input on the rubric that, if answered with the worst-state option, automatically triggers a Flag verdict regardless of how the remaining inputs are answered. The Scorer has three dealbreakers, one on each axis: training-use of inputs (data), school official designation (FERPA), and under-13 age gate (COPPA). These are the three single-clause findings the methodology treats as non-negotiable: inputs where the failure cannot be aggregated away by strong posture elsewhere.

The verdict vocabulary

Verdict Pre-Service Lookup

The output the Scorer produces when the rubric is applied: Proceed, Caution, or Flag. The verdict is deterministic: two readers who answer the twelve inputs the same way arrive at the same verdict. The verdict is a starting point for governance action, not a substitute for it; it signals which tools warrant first-pass triage attention, not whether a district has discharged its full institutional obligations.

Proceed Pre-Service Lookup

The verdict assigned when a tool earns at least 3-of-4 best-state answers on every one of the three axes, with no dealbreakers triggered. A Proceed verdict signals that the rubric finds no posture concerns on data, FERPA, or COPPA. The tool can be used as intended within the conditions noted during scoring. The 3-of-4 threshold is calibrated to be meaningfully selective without being unattainable; verdict distributions produced under this threshold track real differentiation in the current K-12 AI landscape.

Contract holder Pre-Service Lookup

The party whose name appears on the agreement governing a vendor's tool: a district contract, a school-level contract, a teacher account, or a personal student account. The contract holder determines which terms apply, which DPA (if any) is in force, and which protections the user can rely on. The same vendor can sit in a different governance posture depending on which contract path was used to procure it. Used in the rubric to grade whether the procurement path supports the institutional reliance the deployment requires.

The data axis vocabulary

Training-use of inputs Pre-Service Lookup

A vendor's practice of using user-submitted content to train or improve its AI models. The rubric's most consequential input asks whether the default behavior involves training, whether an opt-out exists but is off by default, or whether training is opt-in only (best-state). A yes-by-default answer is a dealbreaker because it transfers commercial value from student work to vendor model development without affirmative authorization. Related to but more specific than the firm's broader concept of no-training commitment; the rubric grades the default behavior the documents disclose, not the strength or durability of the commitment elsewhere.

Retention specificity Pre-Service Lookup

Whether a vendor's policy specifies a concrete retention period (in days, months, or years) for the content users submit. Specific retention is named in the documents. Vague retention uses qualifiers like "as long as necessary." Indefinite or unstated retention is the absence of any retention claim at all. The rubric grades for the document's specificity, not for the substantive length of any stated period: a stated retention of seven years is more rubric-favorable than an unstated retention of seven days, because reproducible reading requires a stated number.

For services covered by the amended COPPA Rule, the worst-state answer now also indicates a probable rule violation rather than only a documentation weakness. 16 CFR § 312.10 provides that children's personal information may not be retained indefinitely, and requires a written data retention policy stating the purposes of collection, the business need for retention, and a timeframe for deletion, published in the online notice under § 312.4(d). Where a covered operator publishes no retention timeframe, the reader is recording an absence the Rule requires to be present.

Deletion right Pre-Service Lookup

A user's or school administrator's ability to trigger the removal of stored content held by a vendor. A self-serve deletion right means the user can complete the action through the product interface. By-request deletion means the action requires emailing the vendor or filing a ticket. Absence of either is treated as a worst-state answer on the data axis. The rubric input is the narrowest testable form of contestability, and for under-13 users it has a floor: 16 CFR § 312.6(a)(2) gives a parent the right to direct deletion of the child's personal information at any time, by a means that is not unduly burdensome.

Trust Center Pre-Service Lookup

A vendor-published subdomain or page (commonly trust.[vendor].com) that aggregates compliance attestations, certifications, subprocessor lists, DPAs, and security documentation in one location. Trust Centers are the highest-yield single resource for performing a rubric-bounded read on a vendor with mature governance documentation. The presence of an active, dated Trust Center is a best-state indicator for subprocessor disclosure on the rubric's data axis.

The FERPA axis vocabulary

FERPA school official designation Pre-Service Lookup

The designation, made by the district under 34 CFR § 99.31(a)(1)(i), that allows a school to disclose education records to a contractor without prior parental consent, provided the contractor performs a service the school would otherwise perform itself, is under the school's direct control with respect to use and maintenance of those records, and is subject to the redisclosure limits of § 99.33(a).

The rubric input grades what the vendor's standard terms say about that designation, and the direction of the act matters. The district confers the designation; the vendor accepts the conditions attached to it. A vendor that explicitly accepts in its standard terms has agreed to be bound by those conditions for that data. A vendor that disclaims the designation is signaling it will not accept them, a dealbreaker on the rubric's FERPA axis. Acceptance is a necessary condition and not a sufficient one: the designation still requires the district-side steps at § 99.7(a)(3)(iii) and § 99.31(a)(1)(ii), which the rubric does not reach and the full methodology engages under deputizing and direct control.

Directory information Pre-Service Lookup

Under FERPA, a category of student record information that would not generally be considered harmful or an invasion of privacy if disclosed: 34 CFR § 99.3 lists name, address, telephone listing, email address, photograph, date and place of birth, grade level, enrollment status, dates of attendance, participation in activities and sports, and honors received, among others, and excludes social security numbers and most student ID numbers.

The category is not consent-free by default. § 99.37(a) permits disclosure only where the district has given public notice of what it has designated as directory information, of the right to refuse the designation, and of the period within which a parent or eligible student must object in writing. A district may also limit directory disclosures to specified parties or purposes in that notice, and is then held to the limit. The rubric grades whether a vendor's privacy policy distinguishes directory information from the broader category of education records clearly, and whether it treats the distinction as a district-side determination rather than its own.

Disclosure logging Pre-Service Lookup

A vendor's practice of maintaining a record of disclosures of student records to other parties, available to the school for inspection. FERPA places the recordkeeping duty on the school rather than on the vendor, at 34 CFR § 99.32(a), and the record must be kept with the student's education records for as long as those records are maintained.

The input carries a caveat the reader should hold. Section 99.32(d)(2) exempts disclosures to a school official under § 99.31(a)(1) from the recordation requirement, and school-official disclosures are precisely the category most K-12 AI vendors occupy. A vendor that provides accessible disclosure records is therefore supplying visibility the regulation does not compel for that pathway, which is why the rubric treats it as a best-state indicator rather than as evidence of compliance with a duty. Where the vendor makes further disclosures onward, § 99.32(b) and § 99.33(b) do reach the arrangement, and the record must name the additional parties and their legitimate interests.

The COPPA axis vocabulary

Age gate Pre-Service Lookup

The mechanism by which a service determines whether a visitor is under 13 before collecting personal information from them. The COPPA Rule does not require the determination to be verified, and the rubric does not grade it as though it did. What the Rule requires is neutrality: the definition of mixed audience website or online service at 16 CFR § 312.2 provides that any collection of age information, or other means of determining whether a visitor is a child, must be done in a neutral manner that does not default to a set age and does not encourage visitors to falsify age information, and that no personal information may be collected from any visitor before that screen, other than for the limited purposes at § 312.5(c).

The rubric therefore grades three things on this input. Whether a screen exists at all. Whether it operates neutrally, or defaults to an over-13 value, pre-fills a date, or signals which answer avoids friction. And whether the under-13 branch routes to verifiable parental consent or to a school authorization pathway, rather than to the same product with the same collection. A screen that defaults, pre-fills, or steers is the worst-state answer and a dealbreaker; a neutral screen with no downstream branch is worst-state on the same input for the second reason. A screen the user simply fills in, operating neutrally and branching correctly, is not disqualifying, because the Rule contemplates exactly that mechanism.

COPPA Rule §312.5 Pre-Service Lookup

The section of the COPPA Rule (16 CFR § 312.5) that governs parental consent. Paragraph (b)(2) enumerates nine methods: a consent form signed and returned by postal mail, facsimile, or electronic scan; a credit card, debit card, or other online payment transaction that notifies the primary account holder of each discrete transaction; a toll-free telephone call to trained personnel; a video-conference with trained personnel; verification of a government-issued identification against a database, with the identification deleted promptly after verification; knowledge-based authentication using dynamic multiple-choice questions difficult enough that a child aged 12 or younger in the household could not reasonably answer them; submission of a government-issued photographic identification compared by facial recognition against an image of the parent taken by phone camera or webcam and confirmed by trained personnel, with both promptly deleted; and, for operators that do not disclose children's personal information, email plus additional confirming steps, or text message plus additional confirming steps, in each case with notice that the parent may revoke the consent.

Two corrections to common summaries follow from the text. Email-based consent is not categorically excluded: email plus is an enumerated method for non-disclosing operators. And the video-conference method requires trained personnel, not merely a call with the parent. What the Rule does exclude is any mechanism resting on an unconfirmed checkbox or a bare typed address with no further step. Paragraph (b)(3) allows an approved safe harbor program to approve a non-enumerated method for its members, and § 312.12(a) allows any interested party to petition the Commission for approval of a new method, so the enumerated list is a floor rather than a closed set.

School-as-agent doctrine Pre-Service Lookup

An FTC guidance position under COPPA that permits a school to authorize, on behalf of parents, the online collection of personal information from students under 13, provided the collection is for the use and benefit of the school and for no other commercial purpose. The doctrine functions as a substitute for the otherwise required verifiable parental consent.

Status as of August 2026. The doctrine remains guidance and is not codified. The 2024 notice of proposed rulemaking would have written a school authorization exception into the Rule, together with definitions of School and school-authorized education purpose; those provisions were removed from the final amendments published April 22, 2025. The exceptions enumerated at 16 CFR § 312.5(c) contain no school exception. The pathway therefore rests on the FTC's COPPA FAQs and the Statement of Basis and Purpose rather than on rule text, which is a materially weaker footing than the FERPA contractor exception it is often paired with, and worth stating on any governance record that relies on it.

The rubric grades whether a vendor invoking this doctrine has the contractual structure to support the reliance, or whether the invocation is unsupported. Alongside the FERPA contractor exception, this is the second mechanism producing the non-party subject condition, and the one of the two that operates by relocating consent rather than removing it.

Data minimization Pre-Service Lookup

The principle that a service should collect and keep only the personal information reasonably necessary for the activity the user is engaged in. Under COPPA the principle appears in two operative places rather than as a general standard, and the rubric grades against both. 16 CFR § 312.7 prohibits conditioning a child's participation in an activity on disclosing more personal information than is reasonably necessary to participate. Section 312.10 limits retention to what is reasonably necessary to fulfill the purpose of collection and requires deletion thereafter. A vendor's stated commitment to minimization is the input; these two provisions are what the commitment is measured against.

The procurement and operational vocabulary

Procurement path Pre-Service Lookup

The route by which a tool entered a district's use: district contract, school-level contract, teacher account, or personal student account. Different procurement paths trigger different governance obligations and produce different DPA coverage. The rubric's contract holder input is the operational expression of procurement path. The Pre-Service Lookup's narrower framing of a concept the firm engages more broadly under parallel contractor relationship.

Drift signal Pre-Service Lookup

A dated change to a vendor's policy, terms, or product language that warrants a fresh read. Drift signals are documented in the First Watch audit series and surface on the Tool Spotlight Card. The Pre-Service Lookup itself does not grade drift; drift is a separate finding from the firm's audit work that may prompt a re-scoring of an already-graded tool. The term lets the rubric's verdict be honest about its own datedness: a Proceed verdict produced today may not describe the tool's posture six months from now, and the drift signal is what the audit series produces to track that. What a detected drift signal is then read for, with respect to a person already in the system, is the exposure delta.

Verification and Revision

This glossary is compiled from The First Watch Drift Audit No. 001 (April 6, 2026), Drift Audit No. 002 (May 6, 2026), Governance at the Speed of Drift (Policy Brief, May 2026), The Forensic Read™ methodology page (languagefirm.org/the-forensic-read), the Clarifier Workshop reference set, the firm's About Us page, An Unread Deputy & A Signed Contract (Sharp's Reading Record, May 14, 2026), and the methodology documentation of The Pre-Service Lookup (May 2026).

Where a term appears verbatim in a published firm artifact, the definition reflects that artifact's usage. Where a term has been carried across documents, the definition reflects the firm's consolidated usage as of the edition in which it was entered. Government terms in the regulatory and Pre-Service Lookup sections carry working citation links to authoritative public-facing sources: the Cornell Legal Information Institute (law.cornell.edu) for U.S. Code statutory text, the eCFR (ecfr.gov) for current regulations and FAR clauses, acquisition.gov for FAR commercial-contract clauses, and the FCC's program page for E-Rate. Links should be treated as the starting point for verification of statutory or regulatory language, not the endpoint; the audits' own methodological principle applies here too.

The Pre-Service Lookup vocabulary was added in v1.6 (May 2026). v1.7 (June 2026) reduced each term entry in the firm, methodology, drift, governance, instrument, and regulatory sections to its core definition, removed the engagement-terms section, added the AI Tool, AI Governance, and Named reader entries to the governance vocabulary, and renumbered the remaining sections so they ran in sequence. The Pre-Service Lookup vocabulary and the synthesis note were left intact.

v1.8 (June 2026) added five entries to the regulatory section documenting the National Data Privacy Agreement: the Access 4 Learning (A4L) Community, the NDPA itself, Exhibit C, the Schedule of Student Data (Exhibit B), and Student Data as commonly defined in vendor DPAs. The A-Z index was updated to reach each new term.

v1.9 (June 2026) added three terms a district sets as controlling definitions in its own policy and reads vendor documents against: Authorized User and Material Update in the governance vocabulary, and De-Identified Data in the regulatory section. The A-Z index was updated to reach each new term.

v1.10 (June 2026) added Identity sprawl to the governance vocabulary, defining the proliferation of vendor accounts a district never inventoried as the scaled consequence of an open seam, and tying it to the Subprocessor and Dependency Register and the named reader. The A-Z index was updated to reach the new term.

v2.02 (June 2026) split the single BYOK entry in the regulatory section into two terms: customer-managed encryption, a data-at-rest control the district gains, and model-key passthrough, a foundation-model API arrangement that makes the model provider the district's direct counterparty under terms that carry no education-specific protections. An acronym that resolves to two different objects in the data path is a forensic hazard the glossary should not carry under one heading. The A-Z index was updated to reach both terms.

v2.03 (June 2026) added two governance-vocabulary terms: Tool sprawl, the product-side counterpart to identity sprawl, naming the accumulation of unauthorized tools as the scaled consequence of an open seam and tying it to the Tool Intake Register; and Trigger, a change from the previously agreed-upon state that obligates a defined action, read by a named reader against the governance baseline. The A-Z index was updated to reach both terms. This edition also unified the version label on the cover and masthead, which read v2.2 against the changelog's v2.02.

v2.4 (June 2026) corrected the Foundation model dependency entry in the governance vocabulary: the examples now name foundation models rather than the consumer products built on them, and the definition states that the dependency runs to the model, not to the product that wraps it. This edition also set the cover, masthead, and colophon labels to the single-decimal form v2.4, retiring the zero-padded label form for the displayed version.

v2.5 (August 2026) added The Human Being and the terms of exposure as a new second section, placed before the methodology because it names the object the instruments are pointed at. The section carried nine entries: the Human Being, bound non-party, compulsory exposure, exposure, exposure delta, consent durability, differential exposure, contestability, and silence reads against the person. Governance that centers the Human Being was entered in the firm-and-mission section beside the language determines the liability, as the firm's second operating conviction. The terms-used-together note gained a fifth pairing, named reader and the Human Being. The prior sections were renumbered and the section cross-references in the body text were updated accordingly; the section references formerly carried in the changelog entries above have been replaced with section names, since a renumbering that silently rewrites its own history is the practice this glossary exists to detect. The A-Z index was updated to reach each new term, and the letter H was opened.

v2.6 (August 2026) is a correction edition, produced from an audit of the glossary against its own primary sources. Six terms were renamed or split. Bound non-party was returned to its settled contract-law meaning, a non-signatory made subject to obligations, and repointed at the two parties in a K-12 document set who actually occupy that condition: the Subprocessor bound by flow-down under NDPA § 2.3, and the Subscribing LEA bound by adoption under Exhibit E. The condition of the person whose data is at issue was entered as a new term, non-party subject, since that person holds no obligations under the instrument and cannot breach it. Consent durability became authorization durability, because the FERPA contractor exception dispenses with consent rather than transferring it, and the section had already said as much. Authorized User became Authorizing Officer, since Authorized User is a defined term in most enterprise terms of service meaning the opposite thing. Third-party vendor was retired in favor of non-contracted vendor, and a new regulatory entry, third party, documents the three incompatible referents the phrase carries across FERPA, COPPA, and commercial usage. A sixth pairing was added to the terms-used-together note to hold bound non-party and non-party subject apart.

v2.6 also corrected the record against primary sources. The NDPA entry now reports version 2.2, published November 19, 2025, in place of 2.1, and lists all exhibits including Exhibit D and Exhibit F, which were previously omitted, and notes that Exhibit H is absent from the Standard build from version 2 forward and that its Priority of Agreements clause ranks Exhibit H above the Standard Clauses. Exhibit C now names all seventeen defined terms and corrects Educational Records to Education Records. The Schedule of Student Data entry records that the exhibit title and § 1.3 use two different names for the same document, and adds the version 2 superset requirement and the thirty-day Addendum objection window. Student Data records that the standard text itself carves out De-Identified Data and anonymous usage data. De-Identified Data adds the NDPA § 4.5 conditions. Subprocessor was corrected to state that the subprocessor processes on the provider's behalf, not the district's. The contractor exception adds the annual-notification requirement at 34 CFR § 99.7(a)(3)(iii) and the reasonable-methods requirement at § 99.31(a)(1)(ii); direct control now identifies its three-component reading as the firm's construction rather than the regulation's. Parental rights was promoted out of the Pre-Service Lookup section, since the statute is not tool-specific, and now records that FERPA rights transfer at 18 or upon postsecondary enrollment, whichever comes first. Disclosure logging records the recordation exception at § 99.32(d)(2), which exempts the school-official disclosures most K-12 AI vendors operate under. Directory information adds the notice and opt-out conditions at § 99.37(a). The age gate entry was rewritten against the mixed-audience definition at 16 CFR § 312.2, which requires neutrality rather than verification. The verifiable parental consent and § 312.5 entries now list all nine enumerated methods and correct two errors: email plus is an enumerated method for non-disclosing operators, and the video-conference method requires trained personnel. The COPPA entry records the substance of the 2025 amendments and the fact that the school authorization exception was proposed and not adopted; the school-as-agent entry carries that non-event on its face. Retention specificity and data minimization were anchored to § 312.10 and § 312.7. Modal verb analysis was rewritten to separate obligation from permission rather than scaling them together, and to treat the ambiguity of shall as a finding. Indefinite phrasing was rewritten to claim that undefined standards transfer interpretive control to a future forum, rather than that they carry no content. Compulsory exposure and differential exposure now name the premises they rest on that the documents do not supply, and the second section's admission rule was rewritten so that it no longer excludes two of its own entries. Filing rotation and the Policy Brief percentages were dated. The foundation model entry was rewritten after the model, platform, and operator relationships were checked against provider documentation: it no longer names specific model versions or platform names, both of which turn over faster than the glossary revises; it drops third-party as a modifier, since the glossary now documents three incompatible referents for that phrase; and it states that the governable object is the serving arrangement rather than the model, since one model is commonly served by several counterparties under different operators and different data-handling terms. The entry now records what a governance baseline must carry for a model dependency, the June 2026 export-control suspension as a dated instance of a dependency interrupted by a party outside every agreement in the stack, the fact that deprecation timing on partner-operated platforms is set by the partner, the self-hosted open-weight case in which no model provider sits in the data path, and where the dependency is established when the vendor does not disclose it. Two dependent entries were reconciled to it in the same pass: Governance baseline now requires the model dependency as five fields, provider, serving platform, operator, governing terms, and pinned version, replacing the single foundation model and version field entered earlier in this edition, which could not be measured against; and Supply chain visibility now names the serving arrangement rather than the model alone, cross-references the model dependency entry as its per-tool finding, and states that an unanswerable dependency is itself the finding. Pill colors were struck from the drift-category and forensic-pattern entries, which describe classifications rather than the design system of the audits that display them. The order-of-precedence entry was rewritten after both FAR citations were read in full: the citation to FAR 52.212-4 now carries the paragraph (s) pincite, since order of precedence is one paragraph of a long clause; recognized in federal law was corrected to federal procurement regulation; treated consistently in commercial-contract practice was reduced to widely used, since judicial treatment of these clauses is not uniform; and the definition now states that both clauses rank provisions as well as documents, which is what makes them the correct analogue for the NDPA's Priority of Agreements. The entry also now records FAR 52.212-4(s)(4), which ranks software license agreements as addenda, and FAR 52.212-4(u), under which a EULA or terms-of-service indemnification clause is unenforceable against the Government and click-wrap or browse-wrap execution does not bind.

Terms added or revised in future editions of this glossary should be documented with the audit cycle or publication in which the change occurred, in the same dated, document-naming register the firm applies to vendor documentation.

Glossary v2.6 · Compiled May 2026, revised August 2026 · The Language Firm, LLC. The Forensic Read™, The First Watch, the Tool Spotlight Card, the Clarifier Workshop, and the Pre-Service Lookup are proprietary instruments of The Language Firm, LLC.