Skip to content
For education & edtech

Education AI is high-risk under the EU AI Act.

AI used in admissions, grading, exam proctoring, and learning assessment falls under Annex III, point 3 (education and vocational training). If your AI influences who gets admitted, how students are graded, or whether they pass, you have until December 2, 2027 to comply.
01 / High-risk

Which education AI is high-risk?

Annex III, point 3 covers AI that determines access to education, assesses learning outcomes, or monitors students.

Admissions & enrolment decisions

AI that evaluates applications, ranks candidates, or determines admission eligibility for educational institutions.

Grading & assessment systems

Automated grading tools, essay scoring engines, or AI that evaluates student performance and assigns marks.

Exam proctoring & cheating detection

AI that monitors students during examinations, flags suspicious behaviour, or decides exam validity.

Learning level assessment & tracking

AI that determines proficiency levels, recommends educational pathways, or decides access to programmes.

02 / Probably fine

What's not high-risk in education?

The deciding factor is whether the AI determines access to education or evaluates outcomes in ways that materially affect a student's path.

  • Adaptive learning platforms that personalise content without gating access
  • Administrative chatbots for student queries (transparency obligations only)
  • Classroom scheduling and timetable optimisation tools
  • Plagiarism detection that flags content for human review

Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.

03 / Obligations

What high-risk education AI must do

Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.

  1. 01Risk management system (Article 9)
  2. 02Data governance & bias documentation (Article 10)
  3. 03Full Annex IV technical documentation
  4. 04Automatic event logging (Article 12)
  5. 05Transparency & instructions for deployers (Article 13)
  6. 06Human oversight measures (Article 14)
  7. 07Accuracy, robustness & cybersecurity (Article 15)
  8. 08Conformity assessment (Article 43)
  9. 09EU database registration (Article 49)
  10. 10Post-market monitoring (Article 72)
04 / Your role

Schools and universities are deployers.

Most institutions using third-party AI tools are deployers, not providers. Deployers have lighter obligations, but you still need to use the system as the provider instructs, run a fundamental rights impact assessment (FRIA), and keep human oversight. If you built your own AI in-house, you're the provider and face the full set of obligations.

Read: Deployer vs Provider, which are you?
05 / GDPR overlap

Already GDPR compliant?

Handling student data under GDPR means you already have data-protection processes and impact assessments. Those partially cover Articles 9 and 10. But the AI Act adds what GDPR doesn't: model accuracy documentation, bias testing across protected groups, conformity assessment, and continuous post-market monitoring.

See the full GDPR overlap mapping

Find out where your EdTech AI stands.

Admissions, grading, and assessment AI will be under heavy scrutiny. The classifier is free; classify your system and start generating the documentation you need.

Classify your AI system