I signed the form. It took about four seconds, and I did not read past the second paragraph.
You know the form. It comes home in the folder with the immunization sheet and the field trip slip, and somewhere in it is a clause saying the district may monitor activity on school accounts and school-issued devices. I skimmed it, I signed it, and — this is the part I am less comfortable admitting — I felt relieved. A machine keeping an eye on a browser seemed like the smaller evil next to a twelve-year-old alone with the open internet at eleven at night.
I still think that instinct is defensible. What I never did was ask the second question, the one that turns out to matter more than the first: when the software gets a child wrong, who does that child complain to?
In July, the answer got a lot shorter.
First, what the thing on your child's school laptop actually does
Start with the part nobody disputes, because it is stranger than most parents realize.
In July 2025, researchers at UC San Diego published a count of the American school-surveillance industry. The study, led by Cinnamon Bloss, whose research focuses on the societal impacts of emerging technology, ran a systematic search and then a content analysis of what the companies say about themselves. It found fourteen companies operating in this market in the United States: Ativion, Bark, Blocksi, Deledao, Gaggle, GoGuardian, Lightspeed Systems, Linewize by Qoria, ManagedMethods, Navigate360, Netsweeper, Safer Schools Together, Securly and Sergeant Laboratories.
Keep the method in mind while you read the numbers, because it is doing work. This is a study of what the industry advertises, not an audit of what it does. On that basis:
86 percent (12 of 14) say they also conduct monitoring 24/7 outside of school — not just during school hours, not just on school property.
71 percent (10 of 14) report using artificial intelligence to conduct automated flagging of student activity.
Less than half — 43 percent, or 6 of 14 — report having a secondary human review team. Note the phrase. Not "a human looks at everything." A secondary review team.
29 percent (4 of 14) say they generate individual student "wellness" or "risk" scores, with data visualization tools so administrators can view those scores at the individual, classroom, grade and school levels.
Read those four bullets together: a system that watches at midnight, decides by algorithm, and in more than half the cases has no second pair of human eyes behind the decision. In almost a third, it does not merely flag an event — it scores the child.
This is not a pilot program in three districts. How normal this has become is the part that gets missed: New America reports that nearly 82 percent of K-12 students say they are subject to some form of monitoring, and 38 percent of teachers say it continues outside school hours. A Senate investigation in 2022 — Constant Surveillance, by Senators Elizabeth Warren and Ed Markey — put it at 81 percent of teachers reporting their schools use at least one type of monitoring software. One vendor alone, Gaggle, tracks the online activity of roughly six million students across about 1,500 districts, as The Associated Press and The Seattle Times reported in March 2025.
So far so good, in the sense that none of this is secret. The question was never whether the software exists — it was what happens when the flags do not fall evenly.
The one line that stopped existing on July 24
For more than sixty years there was an answer to that question, and on July 24, 2026, it was removed from the Code of Federal Regulations.
The rule the Department of Education published in July — Federal Register Document 2026-15019, 91 FR 46733, "Rescinding Portions of the Department of Education Title VI Regulations To Align With the Statutory Text and Conform to Executive Order 14281" — took effect the day it appeared. Not thirty days later. The same day.
What it deleted is one sentence long. The Department describes it in its own words: section 100.3(b)(2) was "the current regulation's general disparate-impact prohibition," the clause saying a recipient of federal funds "may not . . . utilize criteria or methods of administration which have the effect of subjecting individuals to discrimination because of their race, color, or national origin."
Have the effect of. Three words. That is the whole fight.
"Disparate impact," unpacked for anyone who has sensibly never needed the term: a rule that does not mention race, is not meant to harm anyone, and still lands measurably harder on one protected group than another. No villain required. It is the doctrine built for policies that produce outcomes nobody consciously chose — which, if you have been paying attention to the last decade of software, should sound familiar.
Three more things about how it was done, all of them in the rule itself.
First, there was no comment period, and no waiting period either. The Department invoked the Administrative Procedure Act's exemption for rules "relating to agency management or personnel or to public property, loans, grants, benefits, or contracts," and because that exemption applies to the section as a whole, it also skipped the delayed effective date normally required before a rule bites.
Second, Education followed the Justice Department, and we need not take a reporter's word for the sequence — the Education rule cites the Justice rule by its own Federal Register citation. The Justice Department went first, in December, rescinding the full text of the equivalent clause in its own regulations, stripping the phrase "or effect" from another, and rescinding two further provisions besides. Effective December 10, 2025 — also the day it published.
Third, both trace to an executive order signed in April 2025, whose stated policy is "to eliminate the use of disparate-impact liability in all contexts to the maximum degree possible." In all contexts. The schools rule was never about schools; schools were one context on a list.
The Department's own announcement, issued July 23, 2026, with Assistant Secretary for Civil Rights Kimberly Richey as the named official, framed it as housekeeping: disparate-impact provisions, it said, "allow demographic data alone to establish that a school violated federal civil rights laws, even if there is no facially discriminatory policy, practice, or discriminatory intent involved." Education Week put the age of the deleted rules at more than sixty years, and described exactly the situation they had covered: statistics demonstrating a discriminatory effect on discipline rates, "even without intentional bias."
To be very clear, because this is the sentence most likely to be garbled in a repost: nothing about discrimination became legal on July 24. Title VI still prohibits intentional discrimination, and the rule says so. What changed is narrower and, I would argue, worse. A district or its vendor can no longer be found in violation of the Department's Title VI rules because a neutral-looking system produced worse outcomes for a protected group. Only because somebody meant it.
Why deleting a regulation is not like losing a case
Here is where it gets structural, and where most coverage stopped a paragraph too early.
You might reasonably assume that if the Department stops enforcing something, families can still go to court. For most of federal civil rights law that assumption is fine. For this provision it has been wrong for a quarter of a century.
A 2001 Supreme Court decision had already taken the courtroom away. In Alexander v. Sandoval, decided April 24, 2001, the Court held flatly that "there is no private right of action to enforce disparate-impact regulations promulgated under Title VI," and that it is "beyond dispute" that the statute itself "prohibits only intentional discrimination." The regulations went further than the statute; only the agency could enforce them.
Put the two together and the shape of July becomes clear. Since 2001, no student could sue under those regulations — the Department was the only body that could act on them. In July, the Department stopped. That is not one door among several closing. That is the last one.
And the Department's rule leans on Sandoval to justify the deletion, quoting it for the proposition that Title VI "prohibits only intentional discrimination." The decision that made agency enforcement the sole route is now the authority cited for removing it.
Who the software finds
Now the two halves meet — and this is the easiest place in the story to overclaim, so I will hold to exactly what the sources say.
The San Diego researchers do not assert that these products discriminate. They warn. Their finding is that students who only have school-provided devices are more heavily surveilled, and that "historically marginalized students may be at a higher risk of being flagged due to algorithmic bias." Elsewhere they list the shape those risks take: "potential adverse effects of automated surveillance via AI include higher false positive rates for Black students, outing of LGBTQ+ students, or excessive discipline of students with disabilities." May. Potential. Those words stay. And one more that ties back to the 43 percent: companies without human review teams "may be at a higher risk of generating false positive alerts that lead to unwarranted disciplinary procedures for students."
The Senate reached the same posture in 2022, hedged in its own finding heading: monitoring software "may be misused for disciplinary purposes and may result in increased contact with law enforcement, including outside of school hours." Forty-three percent of teachers reported their schools use these tools to identify violations of discipline policies. The safety tool doing discipline work is not a distortion of the product; it is a documented use of it.
But the Senate's sharpest finding was not about bias. It was about ignorance. The companies, it reported, "have not taken any steps to determine whether student activity monitoring software disproportionately threatens students from marginalized groups, leaving schools in the dark" — they "do not track the impact of their products by race and ethnicity, meaning that they have no way of identifying or rectifying adverse impacts." The report set that against Gaggle's chief executive: "We're doing everything we can to make sure that we don't have any bias in our algorithms and our decision-making." The company's own response to the Senate indicated it was unable to track disparate impacts. Both statements can be sincere. That is precisely the problem.
Where numbers do exist, they come from polling by the Center for Democracy & Technology. Students who were outed by the software are not a hypothetical: in the August 2022 wave, 29 percent of LGBTQ+ students reported knowing someone who had been outed because of student activity monitoring, and 56 percent of LGBTQ+ students said they had gotten into trouble for visiting a website or saying something inappropriate online, against 44 percent of non-LGBTQ+ students. The organization's president, Alexandra Reeve Givens, framed the pattern in one line: "these efforts to make students safer more often result in disciplining students instead."
Students with disabilities land in the same funnel. Writing for the Federation of American Scientists in June 2024, Nicole Fuller and Lindsay Kubatzky summarized the same research: students with disabilities are disproportionately impacted by these technologies, special education teachers are more likely to report knowing students who got in trouble or were contacted by law enforcement because of monitoring, and 61 percent of students with learning disabilities report that they do not share their true thoughts or ideas online because of it. Sit with that last number. The intervention worked — the child went quiet.
And the concrete instance, hedged the way its reporters hedged it: in the screenshots of flagged content the Associated Press and Seattle Times obtained from one district's records, "at least six students were potentially outed to school officials after writing about being gay, transgender, or struggling with gender dysphoria." Six students, one district, one set of records. Not a national statistic — but the exact mechanism the researchers listed as a potential adverse effect, doing it, in a real school, to real children.
Now the detail that made me put down my coffee.
In that same 2022 report, the Senate told the Department of Education what to do about it. Its second recommendation: the Department "should require local education agencies to track the potential impacts of these tools on students in protected classes, including data on the use of student activity monitoring tools for disciplinary purposes and other disparate effects." And the footnote supplying the legal authority — footnote 96 — cites 34 CFR § 100.3(b)(2).
That is the provision. The one deleted on July 24, 2026. The hook the Senate reached for to make somebody start measuring whether this software falls harder on some children than others was quietly unscrewed from the wall four years later, before anyone ever hung anything on it.
The strongest case for the other side, in its own voice
I would be doing you a disservice if I pretended this was a one-sided argument. It is not, and the people who wanted the standard gone have written down why.
The executive order makes the case plainly: disparate-impact liability, it argues, creates "a near insurmountable presumption of unlawful discrimination . . . where there are any differences in outcomes," and "all but requires individuals and businesses to consider race and engage in racial balancing to avoid potentially crippling legal liability." If any statistical gap can start an investigation, the safest move for an institution is to manage the statistics — itself a form of race-consciousness the law is supposed to disfavor. That is a real argument, not a pretext.
The case against the standard is also not a fringe one. Writing in the Federalist Society Review in June 2025, Dan Morenoff argued the doctrine was never legislated at all — that "no Congress ever passed, no President ever signed, and as a result Title VII never contained (and does not contain now) any language outlawing employment policies bearing disparate impacts across demographic groups." Whatever you make of the conclusion, the observation underneath it is fair: much of this framework came from agencies rather than Congress, and what an agency wrote, an agency can unwrite. That is the whole lesson of July.
The Justice Department's legal theory goes further — its Office of Legal Counsel has argued that effects-based liability is itself unconstitutional, because it contemplates "liability based on disparate effects alone, without regard to an employer's likely intent." Scope that carefully: the opinion is about Title VII and employment, not Title VI and schools. It tells you the administration's general constitutional theory, not a holding about your child's district.
Then the vendors' case, which deserves better than a sneer. The company says it saves lives, and it is not an unserious claim. In a 2019 report using its own internal figures, Gaggle stated that for every 10,000 students in a six-month period a district can expect it to identify 49 students indicating suicide or self-harm, and that in the 2017-18 academic year the service "saved the lives of 542 students who were planning or actually attempting suicide." The company's numbers, from the company, seven years ago. But if you are a superintendent and the alternative is finding out on Monday, you can see why you sign.
You can even point to the industry correcting itself without being made to. In January 2023, after bias concerns, Gaggle dropped the keywords it once flagged — it stopped flagging students for words like "gay" and "lesbian," citing greater acceptance of queer kids in schools. Reform without regulation. It happens.
So here is the honest reframe. Every one of those points can be true, and none of them is an argument for making the question unaskable. The researchers themselves call not for a ban but for oversight, noting that "the dearth of research on efficacy and the notable lack of transparency about how surveillance services work indicate that increased oversight by policy makers of this industry may be warranted." You can believe the software saves lives and still want to know whether it costs some children more than others. Until July, there was a federal rule under which that question could at least be posed.
Now cross one border
Here is a coincidence I only noticed halfway through the reporting. The district whose flagged records the Associated Press obtained is Vancouver — Vancouver, Washington, which shares its name with the far more famous city a few hundred miles north, on the other side of an international line. The confusion is so easy I nearly made it myself.
But make the drive on purpose, cross into British Columbia, and the legal question changes shape completely.
Start with the standard the United States just deleted. In British Columbia it is not a regulation an agency can rescind on a Friday — it is a holding of the Supreme Court of Canada, which settled the same question in the opposite direction on November 9, 2012. In Moore v. British Columbia (Education), 2012 SCC 61, the Court set out the test: a complainant must show they have a protected characteristic, that they experienced an adverse impact with respect to a service customarily available to the public, and that the protected characteristic was a factor in that adverse impact. Once that is shown, the burden shifts to the respondent to justify the practice.
Read the list again. There is no intent element — precisely the element the deleted American regulation did without, and the American statute still requires. And note who the case was about: Jeffrey Moore, a British Columbia public school student with a severe learning disability. The population the monitoring literature keeps naming as over-disciplined is the population that set the country's discrimination test.
British Columbia's human rights tribunal says the quiet part in one line of its own plain-language guide: there is no requirement to prove discriminatory intent. Section 8 of British Columbia's Human Rights Code is the operative provision, covering denial or discrimination in "any accommodation, service or facility customarily available to the public" — and naming, among its protected grounds, race, physical or mental disability, sexual orientation, and gender identity or expression. All three of the groups the San Diego researchers listed as facing potential adverse effects are in there.
Then the structural difference, the one that matters most against Sandoval. In British Columbia the student can file the complaint themselves — the Code forbids discrimination when seeking access to or using a public service, and enforcement runs through a tribunal a person petitions directly. It does not wait on a federal agency deciding this year that the question is worth asking. In the United States the deleted regulation was enforceable only by the Department; in British Columbia the equivalent claim belongs to the kid.
There is a process duty on top of it. Before a BC public body — school districts included — launches a new initiative, a privacy impact assessment is required first, by statute: section 69(5) of the province's Freedom of Information and Protection of Privacy Act. Not a best practice. A legal requirement, before deployment rather than after the screenshots leak. British Columbia's freedom of information association calls the rights that act creates over student personal information quasi-constitutional — while noting, fairly, that platforms now have enough market power to insist on take-it-or-leave-it terms.
And the direction of travel is the reverse of ours. In October 2025 — weeks before Washington's first deletion — Canada's privacy regulators, federal, provincial and territorial together, with British Columbia's Office of the Information and Privacy Commissioner among the signatories, adopted a joint resolution on educational technology in Banff. Its ask of AI-driven edtech is close to the mirror image of what the Department of Education removed: conduct and publish privacy impact assessments examining the specific risks to children and young people, and "where AI systems are used, conduct and publish Algorithmic Impact Assessments prior to deployment or major updates." The resolution reaches monitoring technology by name, down to proctoring software that watches eye movement and keystroke patterns.
Before this turns into a travel brochure, three corrections.
British Columbia has not banned any of this software. Nothing in the record says otherwise. What it has is a legal standard that survives, a process duty that runs first, and a complaint a student can file without permission from a federal agency. That is not protection. It is a preserved question.
Second, the industry is the same industry. British Columbia's own education ministry points independent schools at it directly: schools needing "social media monitoring/digital threat assessment support," among other services, "are encouraged to connect with Safer Schools Together." That vendor is one of the fourteen companies in the San Diego sample. The border does not stop the software. It changes what a family can do about it.
Third, the civil-liberties objection up there is old, and I will date it honestly. The BC Civil Liberties Association wrote in April 2003 — about video cameras, not algorithms — that "continuous, suspicionless, monitoring of student behavior is inimical to freedom, privacy and the hallmarks of a democratic society." Twenty-three years old, about a different technology, and it reads like last week.
Now run the tape forward
Everything above is on the record. This next part is not — it is extrapolation, and requires no new invention, only the continuation of what already exists.
Four of the fourteen companies already generate individual "wellness" or "risk" scores, with dashboards that let administrators sort them by student, classroom, grade and school. That is the seed. Everything after it is plumbing.
Just imagine a district that likes the dashboard and asks for a trend line — this student's score over the semester, not just today. Just imagine the score joined to attendance and grades, because both already live in the same student information system and joining them is a Tuesday's work. Just imagine a state education agency deciding a rolled-up version of that score is a useful early-warning indicator, and asking districts to report it. Nobody in that chain does anything sinister. Each step is a small efficiency.
Then imagine a fifteen-year-old who searched a phrase at two in the morning during the worst month of their life, who is fine now, and who has a number attached to them that they have never seen, cannot correct, and will not be told about. Imagine the child is on an individualized education program, or is not out at home. Imagine the flag reaches a parent first.
And here is the part that has actually changed. In that whole imagined chain, if the scores land twice as hard on students with disabilities as on everyone else — and nobody intended it, and nobody can even measure it, because the vendors do not track outcomes by group — there is no longer a federal rule under which the pattern alone is a problem. The rule that would have covered it stopped existing on July 24, 2026. What is left is intent, and software does not have any.
What the smart people are saying — and who agrees with whom
The striking thing about this fight is that the two sides are not lined up where you would expect.
On the deletion itself, the split is exactly what you would predict. Sixty civil rights organizations issued a joint statement on July 23, 2026, condemning the removal of what they called the disparate impact tool and describing policies "that appear neutral but unfairly and disproportionately harm or disadvantage" students of several backgrounds; moving without an opportunity for public comment, they said, was "indefensible." Facing them: the Federalist Society's constitutional argument, the Justice Department's Office of Legal Counsel, and the executive order's own reasoning. That is a genuine legal disagreement between serious people, and it will be litigated for years.
But on the surveillance — on whether the software watching your child is understood, audited or accountable — the line disappears. Those percentages did not travel only through progressive channels. Fox News covered the same numbers in August 2025, reporting that these companies "monitor kids day and night, not just during school hours and not just on school devices," that nearly a third assign risk scores, and that "71% rely on AI to flag behavior." The Senate report, meanwhile, was written by two of the chamber's most progressive members — and the Federation of American Scientists comes at it from evidence policy, New America from education, the Center for Democracy & Technology from privacy, the San Diego team from public health.
Nobody in that list is calling for the software to be outlawed. What they converge on is smaller and more achievable: measure the thing. Publish what it does. Tell the family. That consensus was four years in the making — and the one federal instrument capable of forcing any of it was removed without asking the public a question.
What does this mean for you?
You cannot restore a federal regulation from your kitchen. You can do the following, and most of it takes an email.
Find out which vendor. Ask your district, in writing, which student activity monitoring product it uses. The fourteen names are listed above; procurement records are usually public. You are entitled to know who is reading your child's documents.
Ask the four questions that map to the four statistics. Does the monitoring run outside school hours and off school devices? Does the product use automated AI flagging? Is there a secondary human review team, and does it see every flag or a sample? Does the district receive individual risk or wellness scores? "We use industry-standard safety software" answers none of those.
Ask what a flag actually triggers. Who sees it — a counselor, an administrator, a school resource officer, a parent? Does anything go to law enforcement? Does a flag enter the student record, and for how long? Can a family see one, and is there any process to correct it?
Ask for the disparity numbers, and expect to be told they do not exist. Ask your board to publish the counts anyway: flags and resulting discipline, broken out by disability status and by race. That is what the Senate asked the Department to require in 2022, and a district or a state can still do it voluntarily.
Talk to your kid before the software does. Tell them the school account is read — by a machine, all the time, including at home. Not to frighten them, but because the alternative is a child who finds out the day they are called into an office. And tell them a flag is not a verdict; it is a false positive until somebody checks.
If you think a policy is landing harder on one group, the route changed but did not vanish. The federal effects-only path at the Office for Civil Rights is closed. Intentional discrimination is still prohibited and still complainable. State civil rights law, state student privacy law, your school board and your legislature all remain open — and states have been the faster movers here anyway.
If you are in British Columbia — or anywhere comparable — ask for the assessment. A privacy impact assessment is legally required before a public body deploys something like this. Ask to see it. If it does not exist, that is itself the finding.
The lesson, as I see it
Disparate impact was never really a doctrine about intentions. It was the law's admission that big systems produce patterns nobody chose, and that a pattern can hurt a child just as thoroughly as a motive can.
That admission was written for institutions built out of people — hiring committees, discipline codes, bus routes. We then spent a decade quietly moving those decisions into software, which has effects in enormous quantity and intentions in none. Which means the effects-based test was not a legacy provision when it was deleted. It was the only one still pointed at how decisions actually get made now.
I keep coming back to that Senate footnote. Four years ago someone staffing a report went looking for the legal hook that would make a company find out whether its algorithm flags disabled kids twice as often, wrote down 34 CFR § 100.3(b)(2), and moved on, assuming the hook would be there when somebody needed it. It was never aimed at this software. It was never tested against a monitoring vendor. It was removed, in a document that took effect the day it was printed, after a comment period that did not happen.
My vote? Do at the district level what the federal government just declined to do nationally. Make the counts public — flags raised, discipline that followed, broken out by group — and let the numbers be boring. A school system that can show you the software falls evenly has nothing to fear from publishing it. A school system that cannot tell you either way has just described the problem.
And go read the form. It is still in the folder, behind the immunization sheet. It takes four seconds to sign and about ten minutes to actually understand, and I have come to think those ten minutes are the most useful thing a parent can do about any of this before the school year starts.
Somewhere tonight a piece of software is reading a thirteen-year-old's search bar and deciding what it means, and nobody is required to check its work. The HAIA Foundation exists to keep asking who checks — and that work lands every week at the Substack. Bring a parent.







