Skip to main content

1.5 Compliant Use of AI

Take Home message

If you remember only one sentence from this page: Compliance is a house, not a wall.

The reading journal, third look

Our ninth-grade student, his reading journal, his teacher's suspicion. In Chapter 1.3, it was a question about learning; in Chapter 1.4, about professional judgment.  Here it is a court file.

In December 2025 the Administrative Court of Hamburg, Germany, ruled on an urgent application in the case. The teacher had noticed that the journal did not match the boy's writing style in a class test. As a consequence, the school treated it as deception.  This was followed by an urgent application to stop this, but the court refused. Undisclosed AI use in schoolwork counts as deception even where the school has no explicit rule against AI. All students must assume they are to work independently unless they have been told which aids are allowed. One caveat to keep in mind from the outset: this is a single court, and the decision is not yet final.

This is a good moment to address the most common misconception in this field. There is no legal vacuum. There never has been.

The house has three storeys

Most teachers envisage AI law as a single wall under construction somewhere in Brussels. However, it is more useful to picture a house that you already live in. The foundation is data protection. It is load-bearing. It was laid years ago. It governs your Tuesday morning. The upper storey is the EU AI Act, Europe's AI law, which categorizes systems according to their potential for harm and imposes stricter obligations the higher the risk. It is partly occupied and still under construction, with the completion date just pushed back. The doors and windows are copyright and examination law — small and specific, and touched daily without noticing.

Ground floor: data protection, clearer than many think

Handling someone's personal data always requires legal permission. As a public body, a school's permission essentially comes from its statutory duties under school law. There is no general license that comes with being a teacher.

Three consequences follow, forming the practical core of this chapter.

Removing names does not anonymize data. In 2024, Germany's data protection authorities jointly stated that if someone could still be identified from the context, the data is still personal. This is particularly problematic in schools because the types of text that teachers most want help with — such as essays, free writing and learning journals — identify their author by style.

The dividing line is the contract: a provider may handle your data if it does so strictly on your instructions and there is a written agreement to this effect. However, the moment it uses what you type for its own purposes, the arrangement collapses because it is no longer working on your behalf. So the practical test is this: Is there such an agreement, and does it exclude training on your inputs? If not, no personal data should be entered.

Two footnotes worth noting: Data relating to health, disability, and special educational needs is subject to even stricter protection under EU law, and at least one German state (Baden-Württemberg) has explicitly prohibited its use in AI systems by ministerial decree. Where private devices are involved, the legal responsibility lies with the school, not you personally, which relieves you and obliges your head teacher.

Upper floor: what the AI Act does and does not require yet

Here is the correction that makes most existing guidance out of date. In July 2026, the EU postponed the heaviest set of AI Act duties for education, which are those attaching to systems classed as high-risk, meaning systems used to decide admissions, to assess what pupils have learned, or to monitor them during examinations, from August 2026 to 2 December 2027.  A great many handouts written in 2025 and early 2026 still print the old date. If a document in your school does, it needs a footnote.

The more useful correction runs the other way:  what already applies is underestimated, and what is endlessly discussed does not apply yet.

Two things have been binding since since 2 February 2025.

  • Emotion recognition in schools is prohibited outright. Systems that claim to read pupils' feelings — attention detection, mood analytics, "engagement" scoring from a webcam — are not a grey area. They sit on the Act's short list of practices that are simply banned.
  • Schools that deploy AI must make sure their staff know what they are doing with it. No fine is attached to this one, which is why it is widely overlooked. It is binding all the same.

Read that second duty alongside Chapter 1.3 and something clicks. The gap between knowing about AI and being able to teach with it is no longer only a professional problem. Since February 2025 it has been a legal obligation.

Since 2 August 2026, AI-generated content has to be labeled as such. From 2 December 2027, systems used to decide who gets admitted, to assess what pupils have learned, or to monitor them during examinations count as high-risk. Whoever uses such a system then assumes the duties that come with it. This incorporates a requirement that the people overseeing it be, in the Act's words,  "competent, trained and authorised". Note the wording. The law has arrived at the same conclusion as the pedagogy: oversight without expertise is not oversight.

Doors and windows: copyright and examinations

Counter-intuitively, what comes out is the easy part. A text or image generated by an AI generally has no human author in the sense copyright requires, so it is usually free of copyright itself. It is not, however, guaranteed to be clean: in the first major European ruling of its kind, a Munich court found that a chatbot had memorized song lyrics and reproduced them almost word-for-word. The court placed the liability on the provider, not on the person who typed the request. Whether a teacher who passes on such material could be liable is, as things stand, an open question. What goes in is the clearer problem, but note that this is a question of copyright, not of the AI Act. The AI Act says nothing about what teachers may feed into a system; that is an older and entirely separate body of law.

The exception that lets teachers copy material for their classes covers exactly that: copying a limited share of a work, for that class. Uploading a protected work into a commercial AI system is a different act, and the exception does not address it. Material intended for school teaching, which is mainly textbooks, is excluded from the exception in any case. So scanning a chapter to have it summarised is an everyday act that the teaching exception does not obviously cover.

How much should that worry you? Less than the gap suggests, and more than nothing. The question is genuinely unsettled: no higher court has ruled on it, and the specialist literature regards the existing exceptions as a poor fit for the situation. Where a rights holder objects, the claim would be a civil one, and in practice, this is a matter for school policy and procurement rather than something an individual teacher can settle. What is not unsettled is the narrow case, and it is the line worth remembering: school textbook and publisher material should not go into AI tools at all — neither scanned nor retyped, not even to generate a worksheet.  

Three rules follow for practice.

  1. Detectors do not carry the burden of proof. What the law does allow is an inference from typical signs. This includes repeated, oddly polished phrasing, a mismatch between what they can write and what they can say, and sources that turn out not to exist. The student can then explain. That is a legitimate route, and it does not require software. Detector output, at best, is one sign among others. The failure rate reported in Chapter 1.4 renders the instrument unusable as evidence.  
  2. Rules must be clear before the assessment, not after. Neither a blanket ban nor a blanket permission holds up. What works is a declaration of independent work with a general clause about AI, plus a duty to state what was used. In Germany, Bavaria went furthest in 2026: its universities may not forbid AI in unsupervised assessments at all, but must require students to declare it. Labeling instead of banning.
  3. Grades stay human. No decision with legal consequences for a person may be made by a machine alone, and a grade is such a decision. Germany's Standing Conference of the Education Ministers puts it even more strongly: assessment is a task only teachers can perform. Crucially, formally waving through an AI's suggestion does not count as a human decision. So the finding from Chapter 1.4, wrong AI feedback is also a pedagogical and a legal problem.  

Law, ethics and didactics therefore converge on the same answer: assess the process, not just the product.

The real address of responsibility responsibility