Annex III, point 3 covers AI that determines access to education, assesses learning outcomes, or monitors students.
AI that evaluates applications, ranks candidates, or determines admission eligibility for educational institutions.
Automated grading tools, essay scoring engines, or AI that evaluates student performance and assigns marks.
AI that monitors students during examinations, flags suspicious behaviour, or decides exam validity.
AI that determines proficiency levels, recommends educational pathways, or decides access to programmes.
The deciding factor is whether the AI determines access to education or evaluates outcomes in ways that materially affect a student's path.
Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.
Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.
Most institutions using third-party AI tools are deployers, not providers. Deployers have lighter obligations, but you still need to use the system as the provider instructs, run a fundamental rights impact assessment (FRIA), and keep human oversight. If you built your own AI in-house, you're the provider and face the full set of obligations.
Read: Deployer vs Provider, which are you?Handling student data under GDPR means you already have data-protection processes and impact assessments. Those partially cover Articles 9 and 10. But the AI Act adds what GDPR doesn't: model accuracy documentation, bias testing across protected groups, conformity assessment, and continuous post-market monitoring.
See the full GDPR overlap mappingAdmissions, grading, and assessment AI will be under heavy scrutiny. The classifier is free; classify your system and start generating the documentation you need.
Classify your AI system