Professor Julia Stoyanovich of NYU on AI governance principles
Stoyanovich, NYU professor and founding director of the Center for Responsible AI, makes three asks: prove AI tools work through independent efficacy and equity standards before classroom use, keep student data home rather than flowing to vendor platforms, and open data for independent verification. She warns AI tutors are flooding fastest into low-income schools.
May I start?
You may begin.
All right.
Thank you very much for the opportunity to testify.
My name is Julia Stojanovic.
I'm a professor of computer science and data science at NYU and the founding director of the Center for Responsible AI.
I have worked on AI governance in the city for nearly a decade, and I'm a proud New Yorker.
I have three asks today and they share one principle.
The city should not run AI systems on our children that no one outside the vendor can see, check or hold to account.
First, prove it works.
AI tutors are flooding into classrooms right now, fastest into low-income schools, because they promise to do more with less.
And today, the vendors grade their own homework.
They self-attest that their tools are tested, equitable, and safe.
There is no independent yardstick.
The city's own vetting process, IRMA, checks data privacy, but by its own account, it does not yet review whether a tool is effective or whether it's biased.
One in three New York City third graders cannot read.
A tutor that's quietly worse for multilingual learners scales that gap across thousands of kids at once.
So my first ask, before a tool reaches a classroom, require it to meet an independent efficacy and equity standard.
Does it measurably improve learning?
And does it work as well for English language learners?
And students with disabilities.
Meets the standard should be a precondition for procurement.
Second, keep the data home.
Those same AI tutors record how children think, struggle, and learn.
Some of the most sensitive data we collect on a young person.
Today, that data routinely flows out
through vendor APIs to models running on private platforms, where it can be retained and reused with little transparency and little recourse.
When I testified before the U.S.
Congress on DeepSeek, I called this a loss of data sovereignty.
The moment data leaves your control and falls under someone's control.
Time expired.
Okay.
The third is to keep the data open so that people can check whether these systems work.
So in summary, prove it works, keep the data home, and open the data.
Thank you so much for your testimony, and if there's anything to expand upon, please submit written testimony.
Thank you.
Aisha Ifran.