Most of what gets called AI safety for children is content filtering, and content filtering is the least interesting part. It matters, it is table stakes, and it is also the question every vendor is happy to answer because they all have the same answer.
The questions worth asking are duller and harder: what can the thing be talked into, what is kept, who can see it, and what happens when it is confidently wrong. Those have different answers for different products, and the answers are findable.
Four kinds of safety, and only one gets discussed
1. Content: what it will say
The obvious one. Every serious product filters, and the mainstream tools are broadly comparable here, so this is rarely the deciding factor even though it gets asked first.
One thing genuinely worth checking: whether the product was built for children or had a child mode added. Those fail differently. A tool designed for adults with guardrails bolted on tends to be safe in the expected cases and strange in the unexpected ones.
2. Surface: what it can be talked into
This is the one that separates products, and it has almost nothing to do with filtering.
An open text box is a negotiable surface. Children are persistent, inventive and have unlimited time, and the entire internet is full of phrasings that get around rules. A tool with no free-text input is not safer because it is better behaved; it is safer because there is nothing to negotiate with.
That is also a real cost, and worth saying plainly: a bounded tool cannot answer why the sky is blue, cannot look at the worksheet in front of your child, and cannot re-explain an idea five different ways. The chatbot and tutor comparison covers that trade properly. It is a trade, not a free win.
3. Data: what is kept, and who can see it
Findable, rarely read, and the answers differ more than people expect. Three questions, and you want specifics rather than reassurance:
- Is your child’s work used to train models? Wanted answer: no, or a clear opt-out you can actually find.
- How long is it kept, and can you delete it? A number, and a mechanism.
- Who can see it? Which is the question parents most often assume has an obvious answer. For school-issued tools it frequently does not: the controls sit with the district, not with you.
In the US, a product aimed at under-13s is in COPPA territory, and schools handling student records are in FERPA territory. You do not need to know the statutes. You need the vendor to mention them without being pushed, because a children’s product whose site never names either has not thought about it.
4. Accuracy: what happens when it is confidently wrong
The one almost nobody asks, and the one most likely to affect your child on an ordinary Tuesday.
Every one of these tools produces errors, and the fluent register makes them hard to spot. A child cannot evaluate a confident wrong explanation, because evaluating it requires the knowledge they came to get.
What reduces it is narrowness and determinism. A tool grading a multiple-choice answer against a stored key either matched or did not. A tool free-writing an explanation of long division can be wrong in ways nobody notices. Ask which parts of a product are generated and which are checked against something fixed, because the answer tells you where the errors will live.
The age question, answered honestly
There is no evidence-based age at which AI tutoring becomes appropriate, because the evidence does not exist yet. What can be said:
- The younger the child, the more the case rests on the tool being bounded, because an eight-year-old cannot assess a confident claim and will not tell you when something felt odd.
- Reading fluency is the real gate, not age. A tool that teaches by text is useless, and quietly frustrating, for a child who is still spending everything on decoding.
- Solo use is a different decision from use with an adult nearby. The recurring finding across the research is that adult involvement is what makes AI tutoring work, which is a safety argument as much as a learning one.
What to actually do
- Use it in the same room for the first two weeks. Not supervision, proximity. You will learn more in two sessions than from any policy document.
- Ask your child to show you the weirdest thing it has said. Framed as a joke, this gets you the truth. Framed as an inspection, it gets you nothing.
- Check one factual claim a week. Pick something it asserted and look it up together. It teaches the habit you actually want, which is not trusting fluent text.
- Agree what it is not for. Finishing work that gets graded is the line most worth drawing explicitly, and the cold retest tells you whether it is holding.
- Know where the off switch is. For a school-issued tool that is the district. For anything you chose, it should take under a minute.
Where we sit, declared
Sprout Tutor is in development and not for sale, so weigh this as the interest it is. On the four axes above: it has no open text box, so the surface is not negotiable; questions are generated against a curriculum code and marked deterministically against a stored answer rather than by a model judging correctness; a child reaches it through a PIN the adult holds and can regenerate; and the adult view shows the literal questions asked and answered, so the record is not a summary anyone has to trust.
What that buys is narrowness, and narrowness is also the limitation. It will not answer your child’s question about black holes.
The short version
Content filtering is table stakes and every mainstream product does roughly the same thing, so asking about it first tells you least. What separates products is what they can be talked into, what is kept and who can see it, and what happens when they are confidently wrong.
An open text box is a negotiable surface, and a narrower tool is safer for a duller reason than good behavior: there is nothing to argue with. That narrowness costs you real capability, and any honest comparison says so.
There is no evidence-based age threshold, because the evidence does not exist. Use it in the same room for two weeks, check one factual claim a week, agree out loud what it is not for, and know where the off switch is.
Sprout Lessons builds standards-aligned lessons for grades K–12, around whatever your child is actually into. Start free.
Checked 16 September 2026. This page is general guidance rather than legal advice; COPPA and FERPA are named as the US frameworks a children’s or school product should be able to speak to, not as a summary of what they require. The state of the research on whether these tools help is covered, with sources, in does AI tutoring actually work. Vendor data practices change: read the current policy of whatever you are considering rather than relying on this page.
FAQ
What should I actually ask about AI tutor safety?
Four things, and only the first usually gets asked. Content, meaning what it will say, where mainstream products are broadly comparable. Surface, meaning what it can be talked into, which varies enormously and is where products really differ. Data, meaning what is kept and who can see it, which is findable but rarely read. And accuracy, meaning what happens when it is confidently wrong, which almost nobody asks about and is most likely to affect your child on an ordinary Tuesday.
Why does an open text box matter for safety?
Because it is a negotiable surface. Children are persistent, inventive and have unlimited time, and there are endless phrasings that get around rules. A tool with no free-text input is not safer because it is better behaved, it is safer because there is nothing to negotiate with. The honest cost is that a bounded tool cannot answer an off-topic question, cannot look at the actual worksheet, and cannot re-explain one idea five different ways.
What should I ask about my child’s data?
Is their work used to train models, where you want a no or a findable opt-out. How long is it kept and can you delete it, which needs a number and a mechanism rather than a reassurance. And who can see it, which parents often assume has an obvious answer; for school-issued tools it frequently does not, because the retention and deletion controls sit with the district rather than with you. In the US, expect a children’s or school product to name COPPA and FERPA without being pushed.
What if the AI tells my child something wrong?
Assume it will, because they all produce errors and the fluent register makes them hard to spot. A child cannot evaluate a confident wrong explanation, since evaluating it requires the knowledge they came to get. What reduces the exposure is narrowness and determinism, so ask which parts of a product are generated and which are checked against something fixed. Then check one factual claim a week together, which builds the habit of not trusting fluent text.
What age is old enough for an AI tutor?
There is no evidence-based threshold, because the evidence does not exist yet. Three things can be said. The younger the child, the more the case rests on the tool being bounded, since a young child cannot assess a confident claim and will not report that something felt odd. Reading fluency is the real gate rather than age, because a text-based tool is useless and quietly frustrating for a child still spending everything on decoding. And solo use is a different decision from use with an adult nearby.
Do I need to sit with my child while they use it?
For the first two weeks, be in the same room, which is proximity rather than supervision and will teach you more in two sessions than any policy document. After that it depends on the child and the tool, but the recurring finding across the research is that adult involvement is what makes AI tutoring work at all, which is a safety argument as much as a learning one. Tools sold as hands-off are arguing against the evidence.