I've been working on an edtech project that uses LLMs, curious how others are approaching compliance w/ FERPA, COPPA, etc. I've been using Lakera but as I get closer to some sales meetings I wanted to know if anyone has run into challenges with audit logs, consent tracking, or explaining AI behaviour to school districts/legal teams.

Did you need to build anything custom? Any compliance docs? Curious whats overkill and whats needed.