What is this course about?
Everything changes when the user is twelve. This course covers the safety requirements a tutoring agent for minors must meet that an adult-facing one never triggers: layered moderation, tested crisis escalation, boundary design that prevents the agent becoming a confidant, and the mandatory reporting workflow that has to sit behind a disclosure.
Who is this course for?
- Directors of student services and counseling
- District technology leaders deploying student-facing AI
- School counselors and social workers
- Curriculum and instruction leaders
What do I need before starting?
- Familiarity with your district's mandatory reporting procedures
- Recommended: The K-12 AI Compliance Stack (K12-1)
What will I be able to do afterwards?
- Specify the safety requirements that apply because the user is a minor
- Design layered moderation across input, output, and conversation level
- Build and test a crisis escalation path end to end
- Connect agent disclosures to the district's mandatory reporting workflow
- Red-team a student-facing agent against a child-safety test suite
What does each module cover?
What changes when the user is twelve?
40 minThe safety requirements that apply to minors and do not exist for adult users.
Objectives
- Enumerate minor-specific safety requirements
- Distinguish developmental appropriateness from content filtering
- Set the risk posture before design begins
Topics
Activity. List the requirements your district would apply to a human tutor and map each to the agent.
How do you layer moderation?
55 minInput filtering, output filtering, and conversation-level review, and why any single layer fails.
Objectives
- Design moderation at three distinct layers
- Explain why single-layer moderation fails predictably
- Tune thresholds against false positives that block legitimate learning
Topics
Activity. Configure three moderation layers and measure the false-positive rate on real student questions.
What happens when a student discloses self-harm?
55 minCrisis escalation designed, implemented, and actually tested rather than assumed.
Objectives
- Design the crisis escalation path with named human recipients
- Implement immediate response behavior that does not abandon the student
- Test the full path end to end including after hours
Topics
Activity. Run a full end-to-end escalation test including the after-hours path and time it.
How does mandatory reporting work when an agent receives the disclosure?
45 minThe reporting obligation and how the workflow has to be built for an agent-mediated disclosure.
Objectives
- Determine reporting obligations for agent-received disclosures
- Design a workflow that preserves the record and the timeline
- Train staff on their role in the agent-mediated path
Topics
Activity. Map the reporting workflow from agent detection to filed report with timestamps.
How do you stop the agent becoming a confidant?
50 minBoundary design that keeps a tutoring agent tutoring rather than substituting for human relationship.
Objectives
- Design boundaries that redirect toward human support
- Detect relational drift in conversation patterns
- Handle loneliness disclosures without cruelty or overreach
Topics
Activity. Design and test the agent's response to five escalating relational prompts.
How do you log for safety without building surveillance?
45 minRetention and access design that supports safety review without monitoring every child.
Objectives
- Specify minimal logging sufficient for safety review
- Design access controls on safety logs
- Set retention that meets obligation without indefinite storage
Topics
Activity. Write the logging specification and defend each retained field.
What do families get to see and control?
40 minParent transparency, opt-out, and communication that builds trust rather than triggering alarm.
Objectives
- Design family-facing transparency about the agent
- Implement opt-out that works across systems
- Communicate deployment to families proactively
Topics
Activity. Draft the family communication and opt-out process for an agent launch.
Red-teaming your tutor with a child-safety suite
60 minThe hands-on module: adversarial testing against a structured child-safety test suite.
Objectives
- Execute a structured child-safety red-team
- Document and triage every failure found
- Establish a re-test cadence tied to model changes
Topics
Activity. Run the full suite, log every failure, and remediate the highest-severity three.
What is the capstone project?
Child-safety review package for a student-facing agent
Produce the complete safety package for a student-facing agent: moderation architecture, tested escalation path with timings, mandatory reporting workflow, logging specification, family communication, and red-team results with remediation.
Deliverable: A safety package a superintendent could present to a board and a counselor would trust.
How are learners assessed?
- Escalation path must pass a timed end-to-end test including after hours
- Red-team results reviewed for coverage against the standard suite
- Logging specification defended field by field
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for k-12.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Children's Online Privacy Protection Rule
Federal Trade Commission
Governs data handling for the under-13 users this course centers on.
- OWASP Top 10 for LLM Applications
OWASP
Red-team methodology basis for Module 8, adapted to child safety.
- Student Privacy Compass
Future of Privacy Forum
District practice guidance on student-facing tool deployment.
- NIST AI 600-1, Generative AI Profile
NIST
Generative-AI risk taxonomy underpinning the moderation design.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 3 must involve an actual school counselor in design and delivery. An escalation path designed only by technologists routes to people who are not there and cannot act.
- The red-team suite in Module 8 is the course's most valuable artifact. Build it with counselors and ship it as a standalone, versioned asset districts can re-run after every model change.
- Handle the self-harm content carefully in delivery. Warn facilitators in advance, provide participant support resources, and do not use real student disclosures as examples under any circumstance.
- Module 5's relational drift material is genuinely difficult and under-researched. State the uncertainty explicitly rather than presenting a confident framework the evidence does not support.
- Do not let Module 6 slide into a monitoring product pitch. The stated design goal is minimal sufficient logging, and every retained field must be individually justified.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Safe AI Tutoring for Minors: Guardrails and Escalation course cover?
Everything changes when the user is twelve. This course covers the safety requirements a tutoring agent for minors must meet that an adult-facing one never triggers: layered moderation, tested crisis escalation, boundary design that prevents the agent becoming a confidant, and the mandatory reporting workflow that has to sit behind a disclosure. It runs 6 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Child-safety review package for a student-facing agent.
Who should take Safe AI Tutoring for Minors: Guardrails and Escalation?
It is written for Directors of student services and counseling, District technology leaders deploying student-facing AI, School counselors and social workers, Curriculum and instruction leaders. Prerequisites: Familiarity with your district's mandatory reporting procedures; Recommended: The K-12 AI Compliance Stack (K12-1).
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for k-12 teams that cannot send work to a public AI tool.
How do we get access to Safe AI Tutoring for Minors: Guardrails and Escalation?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for k-12 cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.