A Procurement Checklist for ChatGPT for Teachers
It's free, so districts skip procurement. That's the mistake. Here's the checklist an IT director should run before ChatGPT for Teachers reaches a single classroom.
There's a specific failure mode that free products create in a district, and it's worth naming before anything else: when there's no invoice, there's no procurement, and when there's no procurement, nobody with authority ever reads the data agreement. ChatGPT for Teachers is free for verified U.S. K-12 educators through June 2027, which is a genuinely good deal. It's also exactly the kind of deal that walks past the checkpoint every paid tool has to clear, because the checkpoint is usually the purchase order and there isn't one.
This piece opens the administrative stretch of the series, and it's aimed squarely at the person who owns the rollout — the IT director, the data privacy officer, the assistant superintendent whose name goes on the risk register. The argument is simple: run the same due diligence you'd run for a paid vendor, precisely because the price tag isn't there to force you to. Below is the checklist. It's five sections, and none of them cost money — only attention.
1. Read the data agreement before a teacher signs up
This is first because it's the one that gets skipped, and it's the one that matters most. Somewhere in your organization, someone needs to actually read what OpenAI commits to and what it doesn't. The good news is that the headline terms are favorable and public: OpenAI designates itself a "School Official" with a "legitimate educational interest" under FERPA, student data "ultimately belongs to and remains under the control of the School," and workspace content is not used to train OpenAI's models by default, per analysis from Sonomos and Skoobuzz.
Those are strong commitments. They are not the whole agreement. Reading it is a job, not a headline, and it deserves its own treatment — the full walkthrough of what the School Official designation does and doesn't obligate lives in reading the student data privacy agreement later in this cluster. For the checklist, the action item is binary: has a named person with the authority to accept risk read the terms and signed off? If the answer is "not yet," you are not ready to roll out, free or not.
2. Confirm whether you're claiming the domain or letting teachers self-serve
There are two fundamentally different deployments hiding under the same product name, and you have to pick one deliberately. In the self-serve path, individual teachers verify through SheerID and get personal workspaces you don't administer. In the managed path, a district or school leader claims the domain, which brings educators into one shared, administered workspace with role-based access controls, SAML SSO, MFA, and encryption available to the admin, as described in the guidance on what schools gain from ChatGPT for Teachers.
The difference between claimed and unclaimed isn't a feature toggle. It's the difference between a district that can see and govern its AI usage and one that has thirty ungoverned accounts it will discover during an incident.
If teachers are already signing up individually before IT has claimed the domain, you have a shadow-IT problem forming in real time. Decide the deployment model first. The mechanics of actually claiming the domain and wiring up identity are the subject of the district IT rollout plan — but the decision to go managed belongs at the procurement stage, before the first teacher account exists.
3. Assess your own IT capacity honestly
Free software still costs staff time, and this is where districts under-plan. Ask the uncomfortable questions before you commit: Do you run SAML SSO already through Google Workspace, Entra ID, or another IdP — and does your team have the capacity to configure another integration this quarter? Who owns MFA enforcement policy, and will this fall under it? Who fields the help-desk tickets when a teacher's SheerID verification fails or their SSO login loops? Who deprovisions accounts when a teacher leaves mid-year?
None of these are hard problems, but they are somebody's problems, and if that somebody isn't named before launch, the answer defaults to "the one IT person everyone already overloads." A managed deployment is a small but real ongoing operational commitment. Budget the hours, not the dollars.
There's also a hard technical constraint worth flagging now so it doesn't surprise you later: each workspace is restricted to a single district — you cannot mix educators across districts in one workspace. For a standalone district that's a non-issue. For a shared-services cooperative, a charter network spanning legal entities, or a regional education agency serving multiple districts, that boundary changes your whole deployment topology. Confirm which legal entity owns the domain claim before you start.
4. Write the staff training and acceptable-use plan
A tool that lands in classrooms without guidance doesn't produce zero usage — it produces uneven usage, where a few enthusiasts push the boundaries and everyone else ignores it or misuses it. Procurement is the right time to decide what "appropriate use" means at your district, because the answer shapes everything downstream.
The plan doesn't need to be long. It needs to answer a few concrete questions in writing: What student information, if any, may go into the workspace? (Many districts will say none that's personally identifiable as the safe starting posture, regardless of what the FERPA terms permit.) What's the guidance on reviewing AI output before it reaches students or parents? Who do teachers ask when they're unsure? A one-page acceptable-use guide written before launch prevents a dozen awkward conversations after it. This pairs directly with the privacy work in section 1 — the training plan is how the data agreement's commitments actually reach the person typing into the box.
5. Plan the opt-out and the exit
Two things every serious procurement plans for, and free tools tempt you to skip both. First, opt-out: some teachers won't want to use it, and some parents may have views about AI use in their child's classroom even when no student data is involved. Decide your posture in advance. Is participation voluntary for teachers? Is there a communication going home to families? A district that can answer "yes, and here's how" looks a lot more credible than one improvising after the first complaint.
Second, the exit. The offer is free through June 2027 — a fixed sunset date, not an open-ended promotion. What's your plan when the clock runs out? Will workspaces convert to a paid tier, and is that budgeted? What happens to the content teachers created inside the workspace? You don't need to solve June 2027 today, but you need to have noticed it today, because the district that builds a year of workflows on a free tool and gets surprised by the sunset has done this to itself.
The checklist, condensed
If you take one thing from this, take the list:
| # | Item | Owner |
|---|---|---|
| 1 | A named person has read and signed off on the data agreement | Data privacy officer |
| 2 | Deployment model chosen: claimed domain vs. self-serve | IT director |
| 3 | IT capacity, MFA/SSO ownership, and single-district constraint confirmed | IT director |
| 4 | One-page acceptable-use and training plan written | Curriculum + IT |
| 5 | Opt-out posture and June 2027 exit noted | Superintendent's office |
None of this is exotic, and none of it is expensive. It's the ordinary discipline of adopting a tool that touches teachers and, potentially, student information — applied to a product that happens to skip the invoice that usually forces the discipline. Run the checklist. Then, and only then, move to the mechanics of claiming the domain and standing up SSO and MFA.
Part 87 of 100 in the ChatGPT for Teachers series. Previously: When Voice Mode Beats Typing in the Classroom. Next: SSO, MFA, and the District IT Rollout Plan. Browse more builder insights or explore AI skills for education at aiskill.market.