See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    AI Proctoring and Student Surveillance: Governance and Privacy

    A technical guide to governing AI proctoring systems under FERPA, COPPA, and state privacy law, with least-privilege access controls and auditable logging for every agent action on student records.

    Technical Architecture for Least-Privilege Proctoring Access

    1. Scoped Runtime Access

      Limit AI proctoring engine access to the minimum LMS and SIS data fields required for a given exam session, rather than broad standing API access.

    2. Immutable Audit Logging

      Capture AI agent actions, including data reads, flags raised, and inferences generated, with timestamps that support FERPA recordkeeping obligations.

    3. Biometric Isolation

      Store facial embeddings and gaze vectors separately from identity-linked records, using tokenization to reduce re-identification risk.

    4. Sub-Processor Visibility

      Document data residency and sub-processor relationships where third-party foundation models perform behavior analysis, since this affects the school official exception.

    5. Automated Retention Pipelines

      Enforce deletion schedules for proctoring video and keystroke data through automated pipelines given the volume generated per session.

    Governance Controls to Implement Before Deployment

    • Execute a data processing agreement that explicitly designates the vendor as a FERPA school official, defining legitimate educational interest and institutional control.
    • Map each data type collected, including video, audio, keystroke, and biometric signals, to a documented educational purpose before deployment.
    • Confirm whether biometric processing occurs on-device or in the cloud, since this determines sub-processor and jurisdictional obligations.
    • Determine whether COPPA's school-consent exception applies for students under 13 and document the consent mechanism used.
    • Require a full, exportable audit log of AI agent access and inference actions on student records as a contractual condition.
    • Build incident response procedures specific to proctoring outputs, such as false-positive flags, distinct from general data breach response.

    AI Proctoring as an AI Agent Governance Problem

    Regulatory Mapping: FERPA, COPPA, and State Privacy Law

    Vendor Accountability and the Limits of Contractual Delegation

    Evaluation Criteria for AI Proctoring Vendors

    • School Official Status: Does the vendor operate as a FERPA school official, and what contractual language defines legitimate educational interest and institutional control?
    • Data Category Transparency: What specific data categories are collected, where are they stored, and what is the retention and deletion schedule?
    • Exportable Audit Logs: Can the institution obtain a full, exportable audit log of AI agent access and inference actions on student records?
    • COPPA Consent Mechanism: How does the vendor address COPPA requirements for students under 13, and what consent mechanism is documented?
    • Runtime Access Scope: What runtime controls limit the AI system to only the data fields required for a given proctoring session?

    Governance Gaps in AI Proctoring Systems

    Common structural weaknesses observed across AI proctoring deployments in education settings, and the controls above that address each one.

    Governance gaps and their descriptions
    Governance GapDescription
    Biometric and Behavioral DataFacial recognition, gaze tracking, and keystroke biometrics collected without clear regulatory classification.
    Regulatory AmbiguityFERPA, COPPA, and state laws apply unevenly, with no education-specific statute governing AI monitoring directly.
    Unmanaged Agent AccessProctoring engines often hold broad API access to LMS and SIS records beyond session requirements.
    Audit Trail GapsFew systems produce immutable logs of AI agent reads, flags, and inferences on student data.

    Govern AI Proctoring Systems With Auditable, Least-Privilege Controls

    Trussed AI provides runtime governance for AI agents, including access scoping, audit logging, and policy enforcement applicable to AI systems handling sensitive student data.

    See Runtime Governance in Action