Back to news
Sunday report

Sunday Signal Report: September 20, 2026

The two largest districts in the country took generative AI away from students. In the same stretch, four vendors bought or expanded their way deeper into teacher practice. Both are governance moves. Only one of them went through a board.

Rob here

Two governance moves. One board vote.

Chamath spent this week asking what companies are still paying frontier labs for if open-weight models sit only months behind. Satya Nadella's line is the one that stuck: you pay twice, once with money and again with the proprietary knowledge you have to feed the model to make it useful.

Screenshot of Chamath Palihapitiya's X article: Deep Dive: The Open vs. Closed AI Race, with its cover graphic of open-weight model logos facing closed-lab logos

TypeSafe launched Jev on Sept. 15. Diogo Almeida, who helped build ChatGPT, designed it to skip generated text and return typed decisions with calibrated probabilities. TechCrunch covered the developer reaction on Sept. 18. Treat the speed and cost multiples as TypeSafe's. The school-system question is which jobs need a frontier model, which need weights you control, and which need a fast, bounded decision with a human still owning the call.

The loud story this week was restriction. New York City and Los Angeles Unified, the two largest public school districts in the country, are pausing student use of generative AI. Florida's state board approved rules the same week that require parent notification, parent consent, and a comparable non-AI alternative for any student who opts out.

The quiet story was acquisition. McGraw Hill bought Teachally on Sept. 2 and TeachFX on Sept. 17. Microsoft published a five-principle education commitment on Sept. 16. Google added modules to its educator training series. OpenAI kept expanding a teacher product that districts did not procure through a curriculum adoption.

Both of those are governance moves. Restriction is governance aimed at students, executed in public, by people who can be voted out. Consolidation is governance aimed at teachers, executed in a press release, by people who cannot. One of them got a board meeting.

I keep noticing that the restriction debate and the procurement debate are running on separate tracks in most districts. The people arguing about whether eighth graders should touch a chatbot are usually not the same people reviewing what a coaching tool is doing with classroom audio. That gap is where the next three years of trouble lives.

K-12 leadership

The two largest districts in the country pulled student AI. The pause is the easy part.

What changed: New York City banned generative AI for public school students from 2K through eighth grade for one year, a moratorium that reaches roughly 600,000 students, about two-thirds of the district's enrollment, and that comes with disabling or discontinuing the AI components of more than 38 previously approved programs plus a new screen-time policy. Los Angeles Unified, the second largest district, adopted its own moratorium on student generative AI use for the current school year, four years after launching and then losing a custom district AI platform. Both announcements landed in the first days of September and spent this week being argued about nationally. Why it matters now: this is the first time the restriction argument has been carried by districts with enough scale to set a default for everyone else, and it is being made on grounds of critical thinking and student-teacher relationship rather than on cheating. The detail that deserves more attention than the headline is the number 38. Disabling AI features inside programs a district already approved is an admission that the AI surface entered the building through renewals and feature updates rather than through a procurement decision anyone remembers making. Rob's take: I do not read this as anti-technology and I would not pretend it is a national trend on a sample of two. I read it as a district discovering it had no approval architecture and buying itself a year. That is a defensible move if the year gets used. It is institutional cosplay if the moratorium expires and the same features quietly switch back on. The uncomfortable question for every leader watching from a distance is not whether you agree with New York. It is whether you could produce, this week, an accurate list of every AI feature currently live in your approved software. Concrete implication for a district leader: inventory before you legislate. Ask your team for a list of approved products whose AI functionality arrived after the original contract was signed, and who approved that functionality. If the answer is that nobody did, you have found the real governance gap, and no moratorium closes it.

AI governance

While students lost access, the teacher layer got bought

What changed: McGraw Hill acquired TeachFX on Sept. 17, an AI coaching tool that records and analyzes classroom talk and returns private feedback to the teacher plus aggregated instructional insights to school leaders. The company put the professional learning market it is buying into at roughly six billion dollars. That deal came two weeks after McGraw Hill acquired Teachally, an AI platform for customizing its K-12 curriculum. On Sept. 16 Microsoft published a five-principle education commitment covering safety and privacy by design, educators remaining in control, AI supporting rather than replacing student thinking, system strengthening, and student preparation, pointing back to the Privacy and Safety Standard it signed with the AFT the week before. Google added Guided Learning and AI Quests modules to its educator training series. Why it matters now: none of this required a student-access vote, a board agenda item, or a curriculum adoption cycle, and most of it lands on adults rather than students, which is exactly the surface the restriction wave does not touch. A classroom-audio coaching product is a student data question whether or not a student ever opens it, and an aggregated instructional insights dashboard is an evaluation instrument whether or not anyone calls it one. Rob's take: I like coaching tools and I think most teachers are underserved by the feedback they currently get. That is precisely why the terms matter. The sentence I would not want said in my district is that we adopted a coaching product and discovered later it was also a supervision product. Vendor principle documents are not the answer here. A principle you publish about yourself has no remedy in it. The five commitments Microsoft published are good sentences and they are not contract language, and the difference between those two things is the whole job. Concrete implication for a district leader: for any AI tool that captures teacher or classroom audio, text, or behavior, write down three answers before renewal season. Who can see the individual-level output, what is the retention period, and is the aggregate view ever admissible in an evaluation conversation. If your vendor cannot answer in writing, you do not have a coaching tool, you have an unscoped observation system.

Policy and public systems

States are writing the rules a quarter behind the districts

What changed: the Florida Board of Education approved AI rules on Sept. 16 requiring districts to fold AI into their internet safety policies, notify parents when a student will use an AI product, obtain parental consent, and offer a non-AI instructional alternative of similar instructional quality when a parent declines. Districts have until July 1, 2027 to finalize those policies, for the 2027-28 school year. Florida's state colleges got a parallel rule prohibiting student AI use on graded work unless an instructor explicitly permits it. In Kansas, the state board reviewed a draft instructional-technology policy and pushed action to its October 13-14 meeting, and on Sept. 17 the Kansas Board of Regents made an AI framework its top strategic priority for higher education, seating a committee to draft guardrails covering teaching, research, administrative oversight, data privacy, cybersecurity, and academic integrity. The Regents chair said plainly that the board was behind on this. Why it matters now: the state layer is arriving with consent architecture and deadlines, not with pedagogy, and the deadlines are far enough out that the districts will have made their real decisions first. That is the ordinary shape of education policy and it is worth naming rather than complaining about. A consent-and-alternative requirement is also a bigger operational lift than it reads. Offering a non-AI alternative of similar instructional quality means maintaining two versions of instruction indefinitely, and the burden of that lands on teachers, not on the vendor whose product triggered the consent form. Rob's take: I would rather have a consent rule than nothing, and I would not confuse it with a learning standard. Consent tells a family they have a choice. It does not tell a teacher what good practice looks like, and it quietly assigns the cost of dissent to the classroom. The states that do this well will publish the parallel-track expectation and fund it. The states that do it badly will publish the form. Concrete implication for a district leader: if a consent requirement is coming to your state, model the parallel track now on one course, not on all of them. Find out what a genuinely comparable non-AI version of a single unit costs in teacher hours. That number is your negotiating position when the rule arrives.

Cybersecurity and privacy

Three days, two Cisco zero-days, and a reminder that the identity plane is the attack surface

What changed: CISA added Cisco Secure Email Gateway CVE-2026-76461, a SQL injection flaw reported as allowing command execution as root, to the Known Exploited Vulnerabilities catalog on Sept. 14 with a Sept. 17 remediation date. Two days later it added Cisco Identity Services Engine CVE-2026-76460, an incorrect use of privileged APIs, and Acronis Backup CVE-2026-87886, an incorrect default permissions flaw, both due Sept. 19. That follows ConnectWise ScreenConnect CVE-2026-84869 and GitLab CVE-2026-85706 added Sept. 11. Separately, Proofpoint documented multiple state-aligned threat actors rapidly adopting the BlueMoon exploit kit, which chains recent Chrome and Windows zero-days. Why it matters now: look at what got hit. Email gateway, identity services, remote access, backup. Those are not edge applications, they are the four systems a district depends on to recover from everything else, and three of the four are the systems an attacker needs in order to make recovery impossible. The three-day due dates are also the story. CISA is no longer assuming a patch window measured in weeks for this class of product, and a district patch cadence built around monthly maintenance nights does not meet that clock. Rob's take: the uncomfortable part of a backup permissions vulnerability is that it invalidates the plan most leadership teams point to when asked about ransomware. The answer to how do we recover is usually a backup system nobody has tested an attacker against. I would separate two questions in your next security conversation. Can we patch this fast, and can we still recover if the thing we were going to recover with is the thing that was compromised. Concrete implication for a district leader: ask for the last verified restore date from immutable backup, not the last successful backup job. Those are different facts and only one of them survives a bad week. If nobody can name the date, schedule the test before the next KEV entry makes it urgent.

Agentic AI checkpoint

Agentic AI checkpoint: two stable tags, one product merge, no new authority

Hermes Agent published stable v0.21.3 under the tag v2026.9.14 on Sept. 14. Its canonical notes describe it as a patch release that rolls up roughly 338 pull requests merged since v0.21.2 into a stable tag so that downstream consumers, including hosted and cloud deployments that auto-update to the newest release tag, receive two specific fixes: remote dashboard sessions no longer expiring during refresh bursts, and long-lived processes no longer leaking duplicate state database writer handles. Both are reliability and session-integrity work, not capability work, and the second one continues the cleanup of the session-store rewrite that shipped in v0.21.0. OpenClaw published stable 2026.9.5 on Sept. 19, following stable 2026.9.4 on Sept. 11, maintaining the roughly weekly stable cadence noted in prior checkpoints. A linux-stable artifact published Sept. 19 is flagged as a prerelease and should not be treated as a production tag despite the name. In the commercial agentic lane, Anthropic merged its chat product and its agentic Cowork product into a single assistant and expanded document and slide handling, which is a surface-area consolidation worth noting because it changes what a single authenticated session can reach, not because it is a capability announcement. Nothing in this window grants an agent new operational authority, new data access, or reduced human approval. The two patch releases point the other direction: the maturing work in this space is currently about recovery, session integrity, and not corrupting your own state, which is the correct order of operations before anyone hands an agent a district workflow.