1.5 Compliant Use of AI
Take Home message
-
There is no legal vacuum. Data protection law has applied all along.
- The timetable moved. The high-risk duties for education AI start on 2 December 2027, not August 2026. Check your school's handouts.
- Already binding since February 2025. Emotion recognition in schools is prohibited, and schools deploying AI must ensure staff competence. Labelling of AI-generated content starts in August 2026.
- The hardest layer is data protection. No personal data about pupils without a contract that excludes training on your inputs; consent usually does not carry; deleting names is not anonymizing.
- In copyright, the upload is the problem. The teaching exception does not cover feeding protected works into an AI.
- Detectors do not hold up as evidence. Reasoned inference from concrete signs does. Rules must be clear in advance, and labeling beats banning.
- Grades stay human — and rubber-stamping an AI's suggestion is not a human decision.
- Responsibility sits with procurement, not with you — and compliance enables. The schools with clear rules are the ones whose teachers report saving the most time.
If you remember only one sentence from this page: Compliance is a house, not a wall.
The reading journal, third look
Our ninth-grade student, his reading journal, his teacher's suspicion. In Chapter 1.3, it was a question about learning; in Chapter 1.4, about professional judgment. Here it is a court file.
In December 2025 the Administrative Court of Hamburg, Germany, ruled on an urgent application in the case. The teacher had noticed that the journal did not match the boy's writing style in a class test. As a consequence, the school treated it as deception. This was followed by an urgent application to stop this, but the court refused. Undisclosed AI use in schoolwork counts as deception even where the school has no explicit rule against AI. All students must assume they are to work independently unless they have been told which aids are allowed. One caveat to keep in mind from the outset: this is a single court, and the decision is not yet final.
This is a good moment to address the most common misconception in this field. There is no legal vacuum. There never has been.
The house has three storeys
Most teachers envisage AI law as a single wall under construction somewhere in Brussels. However, it is more useful to picture a house that you already live in. The foundation is data protection. It is load-bearing. It was laid years ago. It governs your Tuesday morning. The upper storey is the EU AI Act, Europe's AI law, which categorizes systems according to their potential for harm and imposes stricter obligations the higher the risk. It is partly occupied and still under construction, with the completion date just pushed back. The doors and windows are copyright and examination law — small and specific, and touched daily without noticing.
Ground floor: data protection, clearer than many think
Handling someone's personal data always requires legal permission. As a public body, a school's permission essentially comes from its statutory duties under school law. There is no general license that comes with being a teacher.
Three consequences follow, forming the practical core of this chapter.
Consent does not provide a solution. One obvious solution would be to simply ask the parents. However, this approach has two drawbacks. Firstly, consent must be freely given. In a school context where grades are a factor, a teacher's request does not constitute a free choice. Secondly, consent must be informed, which is difficult to achieve when nobody knows where the data will end up. Permission must come from school law, not a signature, as this shifts responsibility upwards, away from you.